Power network security situation awareness method and system

By deploying latent threat probes on station-level equipment of smart grids, combined with situational awareness models and threat detection engines of regional and comprehensive management-level platforms, situational awareness of power network security is realized, and the problem of difficulty in global event analysis in traditional systems is solved, reducing costs and improving operation and maintenance efficiency.

CN120151072APending Publication Date: 2025-06-13CHINA RESOURCES POWER TECH RES INST CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510423193.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-07
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

The traditional power network security protection system is difficult to realize global event analysis in multiple regions and station environments of the smart grid, resulting in high operation and maintenance difficulties and high construction costs.

Method used

By deploying latent threat probes on site-level equipment, data to be analyzed is collected and transmitted to regional-level platforms, situational awareness models and behavioral portraits are used for abnormal behavior detection, pending security data is generated, and transmitted to the comprehensive management-level platform, and correlation analysis and visual display are carried out in combination with threat detection engine.

Benefits of technology

It realizes unified analysis and display of data from units at all levels, reduces station construction costs, improves operation and maintenance operation efficiency, and overcomes technical defects that are difficult to conduct unified incident investigation and processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151072A_ABST
    Figure CN120151072A_ABST
Patent Text Reader

Abstract

The invention discloses a power network security situation awareness method and system. The method is applied to a power network security situation awareness system, and comprises the following steps: acquiring to-be-analyzed data by using a latent threat probe through station-level equipment, and transmitting the to-be-analyzed data to a corresponding large-area-level platform; performing abnormal behavior detection on the to-be-analyzed data by utilizing a situation awareness model and combining with the behavior portrait through the large-area-level platform, generating to-be-processed security data containing a to-be-processed threat tag and a to-be-processed confidence score, and transmitting the to-be-analyzed data and the to-be-processed security data to a comprehensive management-level platform; performing association analysis on the to-be-processed security data by utilizing a threat detection engine and combining with the to-be-analyzed data through the comprehensive management-level platform to obtain a security data result; and performing visual display of the security threat event based on the security data result through the comprehensive management-level platform. The construction cost of the station is reduced, unified analysis and display of unit data at all levels are realized, and the operation and maintenance efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of network security technology, and in particular, to a power network security situation awareness method and system. Background Art

[0002] With the in-depth promotion of the construction of smart grids, the network security threats faced by power monitoring systems are characterized by diversification and concealment, and power network security situation awareness is required to ensure the safe and stable operation of power networks.

[0003] Traditional network security protection systems mainly rely on single-point defense devices such as firewalls and intrusion detection systems. Considering the characteristics of smart grids that include multiple large regions and substations, if the traditional single-point deployment mode is adopted, each substation needs to separately purchase probes and platforms, which not only has high construction costs, but also makes it difficult to conduct global event analysis from the perspective of the entire power grid, and the operation and maintenance difficulty is large. Summary of the Invention

[0004] The present invention provides a power network security situation awareness method and system, which reduces the construction costs of substations, and at the same time realizes the unified analysis and display of data at all levels, and improves the efficiency of operation and maintenance.

[0005] In a first aspect, the embodiments of the present invention provide a power network security situation awareness method, which is applied to a power network security situation awareness system. The system includes a comprehensive management-level platform, one or more large-region-level platforms under the comprehensive management-level platform, and one or more substation-level devices under each large-region-level platform. The method includes:

[0006] Through the substation-level device, using a latent threat probe to collect data to be analyzed, and transmitting the data to be analyzed to the corresponding large-region-level platform;

[0007] Through the large-region-level platform, using a situation awareness model and combining with a behavior portrait to perform abnormal behavior detection on the data to be analyzed, generating to-be-processed security data including to-be-processed threat labels and to-be-processed confidence scores, and transmitting the data to be analyzed and the to-be-processed security data to the comprehensive management-level platform;

[0008] Through the comprehensive management-level platform, using a threat detection engine and combining with the data to be analyzed to perform correlation analysis on the to-be-processed security data, obtaining a security data result;

[0009] Through the comprehensive management-level platform, performing visual display of security threat events based on the security data result.

[0010] Second aspect, embodiments of the present invention provide a power network security situation awareness system, which includes an integrated management level platform, one or more large regional platforms under the integrated management level platform, and one or more substation-level devices under each large regional platform;

[0011] The substation-level device is used to collect data to be analyzed by using a latent threat probe and transmit the data to be analyzed to the corresponding large regional platform;

[0012] The large regional platform is used to detect abnormal behaviors of the data to be analyzed by using a situation awareness model combined with a behavior portrait, generate pending security data including a pending threat label and a pending confidence score, and transmit the data to be analyzed and the pending security data to the integrated management level platform;

[0013] The integrated management level platform is used to perform correlation analysis on the pending security data by using a threat detection engine combined with the data to be analyzed to obtain a security data result;

[0014] The integrated management level platform is used to perform visual display of security threat events based on the security data result.

[0015] The technical solution of the embodiments of the present invention deploys a latent threat probe at the substation-level device to collect data to be analyzed and transmits the data to be analyzed to the corresponding large regional platform; the large regional platform detects abnormal behaviors of the data to be analyzed of the substation-level devices in its area to generate pending security data, and transmits the data to be analyzed and the pending security data to the integrated management level platform; the integrated management level platform combines the data to be analyzed of each large regional platform to perform correlation analysis and display on the pending security data, thereby realizing the construction of a power network security situation awareness system. This solution deploys a latent threat probe at the substation-level device, deploys a large regional platform in the large area, and deploys an integrated management level platform in the integrated management, reducing the construction cost of the substation. At the same time, it transmits the information related to network security in the substation and the large area to the integrated management level platform, realizing the unified analysis and display of data of each level of units, overcoming the technical defect that it is difficult to conduct unified event investigation and handling in the normal operation scenario, and improving the operation and maintenance efficiency.

[0016] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0018] Figure 1 is a flowchart of a power network security situation awareness method provided in Embodiment 1 of the present invention;

[0019] Figure 2 is a schematic structural diagram of a power network security situation awareness system provided in Embodiment 1 of the present invention;

[0020] Figure 3 is a flowchart of a power network security situation awareness method provided in Embodiment 2 of the present invention;

[0021] Figure 4 is a schematic structural diagram of a power network security situation awareness system provided in Embodiment 2 of the present invention. Detailed implementation manners

[0022] In order to enable those skilled in the art to better understand the solutions of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some, rather than all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0023] It should be noted that the terms "first", "second", etc. in the present invention are used to distinguish similar objects and do not necessarily need to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those clearly listed steps or units, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.

[0024] It can be understood that the data (including but not limited to the data itself, the acquisition or use of the data) involved in the technical solution of the present application should comply with the requirements of relevant laws, regulations and related provisions.

[0025] It should be noted that the acquisition, storage, use, processing, etc. of the data to be analyzed involved in the present invention are all authorized by the user and comply with the relevant provisions of laws and regulations. The use can only be used for network security analysis.

[0026] Embodiment 1

[0027] Figure 1 It is a flowchart of a power network security situation awareness method provided according to Embodiment 1 of the present invention. This embodiment is applicable to the situation of network security situation awareness, and this method can be applied to a power network security situation awareness system.

[0028] Figure 2 It is a schematic structural diagram of a power network security situation awareness system provided according to Embodiment 1 of the present invention. As Figure 2 shown, the system includes an integrated management level platform, one or more regional level platforms under the integrated management level platform, and one or more substation level devices under each regional level platform.

[0029] Among them, the integrated management level platform can be a platform for realizing integrated management in the power network, also known as the first-level platform; the regional level platform can be a platform for realizing regional management in the power network. The region can be a region obtained by dividing the power network according to geographical regions, and the regional level platform is also known as the second-level platform; the substation level device can be a device related to the power network deployed in the substation, also known as the third-level device, which is not limited here.

[0030] Combined with Figure 2 the system in Figure 1 to illustrate the Figure 1 shown method. As

[0031] S110. Through the substation level device, use a latent threat probe to collect the data to be analyzed, and transmit the data to be analyzed to the corresponding regional level platform.

[0032] The latent threat probe can be a security device or tool for detecting potential and hidden threats, and can be deployed in the substation level device. For example, a latent threat probe is deployed in each substation level device. In practical applications, the latent threat probe can be understood as a traffic collection probe.

[0033] The data to be analyzed can be data to be subjected to network security analysis. For example, it can be traffic logs, system logs, device alarm data, etc. corresponding to the substation level device, or data parsed and extracted from the foregoing data, such as network protocols, target addresses (i.e., the addresses of the substation level devices), etc., which is not limited here.

[0034] In this step, through the substation-level device, the latent threat probe deployed in the substation-level device can collect the data to be analyzed of the substation-level device, and securely transmit the data to be analyzed to the corresponding regional-level platform of the substation-level device through an encrypted channel. Among them, the corresponding regional-level platform of the substation-level device can be the regional-level platform corresponding to the region to which the substation-level device belongs.

[0035] S120. Through the regional-level platform, use the situation awareness model combined with the behavior portrait to detect abnormal behaviors in the data to be analyzed, generate the security data to be processed including the threat label to be processed and the confidence score to be processed, and transmit the data to be analyzed and the security data to be processed to the comprehensive management level platform.

[0036] The situation awareness model can be a model for realizing situation awareness. The specific structure of the model is not limited here, as long as it can realize the function of situation awareness. Situation awareness means paying attention to the network security threats faced by the power grid, monitoring the data related to network security, identifying potential network security vulnerabilities and attack behaviors, and preventing network attacks from damaging the operation of the power grid.

[0037] The behavior portrait can be understood as a portrait constructed by analyzing the behaviors of users and assets in the power grid. Through the behavior portrait, the behavior patterns and characteristics of users and assets can be reflected.

[0038] The security data to be processed can be data related to network security to be processed by the comprehensive management level platform. The security data to be processed includes the threat label to be processed and the confidence score to be processed. Among them, the threat label to be processed can be the threat label to be processed by the comprehensive management level platform, and the threat label can reflect threat behaviors, threat types, threat levels, etc. The confidence score to be processed can be the confidence score corresponding to the threat label to be processed, and the confidence score can reflect the credibility of the threat label to be processed. The higher the confidence score, the more likely there is a threat corresponding to the threat label to be processed.

[0039] In this step, through the regional-level platform, the situation awareness model can collect multi-dimensional data of users and assets under the regional-level platform, construct the behavior portraits of each user and asset based on the multi-dimensional data. The asset can be, for example, the substation-level device under the regional-level platform, and the user can be the user of the substation-level device; use the situation awareness model to call the behavior portrait, compare the similarity of the data to be analyzed of each substation-level device under the regional-level platform to obtain the behavior similarity; use the situation awareness model to determine abnormal behaviors based on the behavior similarity combined with threat intelligence, determine the threat label to be processed and the confidence score to be processed corresponding to the abnormal behavior, and generate the security data to be processed; transmit the data to be analyzed received by the regional-level platform and the security data to be processed obtained by analyzing the data to be analyzed to the comprehensive management level platform.

[0040] S130. Through the comprehensive management level platform, use the threat detection engine to perform correlation analysis on the security data to be processed in combination with the data to be analyzed, and obtain the security data result.

[0041] Among them, the threat detection engine can be understood as a key technical component for detecting security threats in the power grid. The security data result can be the result obtained by performing correlation analysis on the security data to be processed in combination with the data to be analyzed.

[0042] In this step, through the comprehensive management level platform, use the threat detection engine to combine the target addresses in the multi-source data to be analyzed, and perform correlation analysis on the security data to be processed. For example, perform correlation analysis on the security data to be processed corresponding to the data to be analyzed whose target addresses belong to the same large area, generate association information. The association information can indicate whether there is an association between the security data to be processed involved in the correlation analysis, and what kind of association exists. For example, it indicates that the threat labels to be processed included in some security data to be processed involved in the correlation analysis are the same; based on the association information, if it is determined that there is an association between some security data to be processed, such as they are all associated with a certain threat source, then update the threat labels to be processed in the associated security data to be processed to the same target threat label, and use the same target threat label to indicate the threat association of the corresponding security data to be processed, and generate a disposal instruction corresponding to the target threat label; process the device corresponding to the security data to be processed through the disposal instruction of the target threat label, and determine the feedback information of the processing; based on the security data to be processed, combine the target threat label and the feedback information to generate the security data result.

[0043] S140. Through the comprehensive management level platform, perform visual display of security threat events based on the security data result.

[0044] In this step, through the comprehensive management level platform, the security data results of each large area can be analyzed to determine the security threat events corresponding to the security data results of each large area. Among them, the security threat event can be an event indicating the existence of a security threat as indicated by the security data result, which is not limited here. For example, use the threat event corresponding to the target threat label in the security data result as the security threat event, and determine the relevant information of the security threat event, such as the occurrence time, frequency, location, severity, and disposal effect feedback after disposal, etc.

[0045] In this step, there is no limit to the way of visual display of security threat events. For example, taking each large area as a unit, display security threat events in the form of a list; or, display the occurrence time, frequency, severity, disposal effect, etc. of security threat events in the form of a bar chart, line chart, etc.; or, display the corresponding location of security threat events in the form of an electronic map or network topology.

[0046] In the technical solution of the embodiment of the present invention, a latent threat probe is deployed at the station-level device to collect data to be analyzed, and the data to be analyzed is transmitted to the corresponding regional-level platform; the regional-level platform performs abnormal behavior detection on the data to be analyzed of the station-level devices within its jurisdiction to generate security data to be processed, and transmits the data to be analyzed and the security data to be processed to the comprehensive management-level platform; the comprehensive management-level platform performs correlation analysis and display on the security data to be processed in combination with the data to be analyzed of each regional-level platform, so as to realize the construction of the power network security situation awareness system. This solution deploys a latent threat probe at the station-level device, deploys a regional-level platform in the region, and deploys a comprehensive management-level platform in the comprehensive management, reducing the construction cost of the station. At the same time, it transmits the information related to network security in the station and the region to the comprehensive management-level platform, realizes the unified analysis and display of data of each level unit, overcomes the technical defect that it is difficult to conduct unified event investigation and processing in the normal operation scenario, and improves the efficiency of operation and maintenance.

[0047] Embodiment 2

[0048] Figure 3 It is a flowchart of a power network security situation awareness method provided according to Embodiment 2 of the present invention. This embodiment is a detailed description based on the above embodiment. Figure 4 It is a schematic structural diagram of a power network security situation awareness system provided according to Embodiment 2 of the present invention. Combining Figure 4 the system in Figure 3 to illustrate the method shown in Figure 3 As shown, the method includes:

[0049] S111. Through the station-level device, use the latent threat probe to obtain the original data related to network security through the bypass listening technology, analyze the original data to obtain the corresponding network protocol and target address, and generate structured data to be analyzed based on the original data, the network protocol and the target address, and transmit the data to be analyzed to the corresponding regional-level platform.

[0050] In this step, through the station-level device, use the latent threat probe to obtain the original data related to network security through the bypass listening technology. The original data includes, for example, the traffic logs, system logs, device alarm data, etc. corresponding to the station-level device; use the parsing engine to identify the network protocol from the original data and extract the target address (i.e., the address of the station-level device); based on the original data, network protocol and target address, generate structured data to be analyzed in a certain format, and the foregoing format is not limited; transmit the data to be analyzed to the corresponding regional-level platform of this station-level device through an encrypted channel. This step can be understood as Figure 4 the data collection shown.

[0051] S121. Through the regional platform, use the situation awareness model to analyze the behaviors of each user and asset under the regional platform, construct a basic portrait, and optimize the basic portrait in combination with the behavior scenario to obtain a behavior portrait.

[0052] In this step, through the regional platform, the situation awareness model can collect multi-dimensional data of users and assets under the regional platform; based on the multi-dimensional data, construct a basic portrait with a preset baseline portrait as the benchmark. In this process, the algorithm can be used to calibrate the behavior deviation, and anomaly detection can be carried out in combination with threat intelligence and alarms can be generated; according to specific behavior scenarios, analyze and adjust the basic portrait of the user or asset, and adjust the range of normal behaviors to generate a behavior portrait.

[0053] Among them, the preset baseline portrait can be a portrait formulated in advance based on various factors such as a large amount of historical data, practical results, and security policies, which can represent a normal behavior pattern or state description. The basic portrait is a portrait constructed based on the baseline portrait. The baseline portrait provides a framework and reference basis for the construction of the basic portrait.

[0054] S122. Through the regional platform, use the situation awareness model to call the behavior portrait to perform a similarity comparison on the data to be analyzed, and obtain a behavior similarity.

[0055] In this step, through the regional platform, use the situation awareness model to call the behavior portrait to perform a similarity comparison on the data to be analyzed. For example, identify and divide groups with similar behaviors and attributes through clustering and other methods to obtain a behavior similarity.

[0056] Through group analysis, the discovery of small probability events and the prediction of future risk trends can be achieved. For example, anomalies can be discovered through group behaviors. Specifically, if servers of different types (such as web services, database services, etc.) are identified in the same group, it is possible that they are infected with the same botnet malware and have similar group behaviors. Combining the identification basis, anomalies can be discovered, the problem source can be located, which is convenient for subsequent abnormal behavior detection; another example is to predict future risk trends through abnormal group relationships. Specifically, through the access relationships within the group, predict whether abnormal devices or compromised devices will affect the core assets within the same group and whether their access paths to the core assets should be cut off.

[0057] Exemplarily, as an implementation of behavior similarity comparison, a user behavior portrait is constructed through a dynamic baseline. For example, the average daily login times of the user is 20 times, and the proportion of compliance protocols exceeds 98%. It captures in real time a sudden high-frequency file transfer based on the Secure Copy Protocol (SCP) on a certain account, 300 times a single day, and unconventional port access behaviors, such as attempting to connect to malicious addresses in the dark web Internet Protocol (IP) library. Combining with the ransomware marked in the threat intelligence library, it is found through time series analysis that the standard deviation of its operation interval exceeds 3.7 times the baseline, and 43% of the instructions deviate from the historical whitelist through discrete feature matching. After comprehensive calculation by the dynamic weight model, a threat value of 92 points is generated. The system automatically blocks the session and isolates the controlled server within 8 seconds, synchronously linking with the firewall to block the lateral penetration traffic, compressing the response to an Advanced Persistent Threat (APT) attack that originally required 4 hours of manual judgment to be completed within 15 seconds, ensuring zero interruption of the core business system.

[0058] S123. Through the large-region platform, use the situation awareness model to detect abnormal behaviors based on the behavior similarity and the threat intelligence library, and determine candidate threat tags and corresponding candidate confidence scores.

[0059] Among them, the threat intelligence library can be a library that centrally stores and manages information about network security threats. Exemplarily, the threat intelligence library can contain some malicious addresses, malicious software features, abnormal behaviors, attack information, etc., which are not limited here.

[0060] In this step, through the large-region platform, use the situation awareness model, call preset rules based on behavior similarity, combine with the threat intelligence library to determine abnormal behaviors and threat types, and generate detection results; optimize the subsequent detection accuracy through dynamic threshold adjustment, and based on the detection results, mark candidate threat tags according to the threat level and threat type of the abnormal behaviors; use the scoring model to generate candidate confidence scores corresponding to the candidate threat tags by combining dynamic weight adjustment. Among them, the preset rules are not limited, such as rules for realizing abnormal behavior detection. This step can be understood as Figure 4 the abnormal behavior detection shown.

[0061] S124. Through the large-region platform, when the candidate confidence score is higher than the set score threshold, use the candidate confidence score as the to-be-processed confidence score, and use the candidate threat tag corresponding to the candidate confidence score as the to-be-processed threat tag to generate to-be-processed security data.

[0062] In this step, through the regional-level platform, when the candidate confidence score is higher than the set score threshold, it indicates that the candidate confidence score and the candidate threat label need to be processed by the comprehensive management-level platform. Then, the candidate confidence score is used as the confidence score to be processed, and the candidate threat label corresponding to the candidate confidence score is used as the threat label to be processed. Based on the confidence score to be processed and the threat label to be processed, the security data to be processed is generated through data encapsulation. Herein, no limitation is imposed on the set score threshold.

[0063] In one embodiment, the method further includes: through the regional-level platform, when the candidate confidence score is higher than the set score threshold, transmitting a warning message to the user or asset corresponding to the candidate confidence score, where the warning message is used to trigger lightweight handling.

[0064] Through the regional-level platform, when the candidate confidence score is higher than the set score threshold, the system starts early warning (i.e., the early warning shown in Figure 4 ), and transmits the warning message to the user or asset corresponding to the candidate confidence score through the warning notification channel to trigger lightweight handling. At the same time, based on the dynamic threshold adjustment and feedback learning mechanism, early risk detection and optimized resource allocation are realized. Herein, the warning message may be the information for the regional-level platform to give an early warning to the station-level equipment, such as it may include the behavior portrait with potential risks, etc., and no limitation is imposed herein.

[0065] In one embodiment, the method further includes: through the regional-level platform, when the candidate confidence score is lower than the set score threshold, marking the behavior of the user or asset corresponding to the candidate confidence score as low risk, and increasing the frequency of abnormal behavior detection.

[0066] Through the regional-level platform, when the candidate confidence score is lower than the set score threshold, it indicates that the candidate confidence score and the candidate threat label do not need to be processed by the comprehensive management-level platform for the time being. Then, the behavior of the user or asset corresponding to the candidate confidence score is marked as low risk, and key monitoring is carried out, and the frequency of data collection and abnormal behavior detection is strengthened.

[0067] S125. Through the regional-level platform, transmit the data to be analyzed and the security data to be processed to the comprehensive management-level platform.

[0068] S131. Through the comprehensive management-level platform, use the threat detection engine to perform correlation analysis on the security data to be processed in combination with the target address in the data to be analyzed, and generate correlation information.

[0069] In this step, through the comprehensive management-level platform, the threat detection engine is used to combine the target addresses in the multi-source data to be analyzed, and the security data to be processed is associated and analyzed. For example, the security data to be processed corresponding to the data to be analyzed with the target addresses belonging to the same large region is associated and analyzed to generate association information. The association information can indicate whether there is an association between the security data to be processed involved in the association analysis and what kind of association exists. That is Figure 4 the association analysis shown

[0070] S132. Through the comprehensive management-level platform, based on the association information, update the threat labels to be processed in the security data to be processed to obtain target threat labels, and trigger the disposal instructions corresponding to the target threat labels.

[0071] In this step, through the comprehensive management-level platform, based on the association information, if it is determined that some security data to be processed is associated, for example, it is determined that all are associated with the servers of a known ransomware attack gang, then the threat labels to be processed in the associated security data to be processed are updated to the same target threat label. The same target threat label indicates that the threat of the corresponding security data to be processed enters the horizontal diffusion stage of ransomware attacks, and based on the threat level, the disposal instructions corresponding to the target threat label are generated.

[0072] S133. Through the comprehensive management-level platform, based on the disposal instructions, perform disposal operations and obtain the feedback information of the disposal operations.

[0073] In this step, through the comprehensive management-level platform, based on the disposal instructions, perform disposal operations, such as automatically blocking all communication connections of the field-level devices corresponding to the security data to be processed and isolating the affected devices according to the disposal instructions. At the same time, mark the abnormal external connection behavior characteristics in the behavior portrait through dynamic behavior optimization. In subsequent detections, the disposal strategy priority is set to the highest, and the feedback information of the field-level devices corresponding to the security data to be processed for the disposal operations is obtained through the feedback learning mechanism.

[0074] S134. Through the comprehensive management-level platform, based on the security data to be processed, combined with the target threat label and the feedback information, obtain the security data result.

[0075] In this step, through the comprehensive management-level platform, based on the security data to be processed, combined with the target threat label and the feedback information, it is output in a standardized format as the security data result. At the same time, the behavior baseline is updated and optimized through dynamic portrait, completing the closed-loop from detection to verification.

[0076] Exemplarily, in an industrial control network, the correlation analysis center of the comprehensive management level platform receives the data to be analyzed and the security data to be processed transmitted by the large area level platform, uses the threat detection engine to perform correlation analysis on the security data to be processed in combination with the target address in the data to be analyzed, and generates correlation information. The correlation information indicates that the IP corresponding to a certain security data to be processed triggered a brute force warning 3 hours ago and had abnormal communication with a device in the same large area; then update the security threat labels to be processed corresponding to the device that triggered the brute force warning and the device with which it had abnormal communication to the same target threat label, and trigger a disposal instruction; block all communication traffic of the above two devices and isolate the associated devices through the disposal instruction. The firewall immediately executes the blocking operation and generates feedback information, and finally integrates the security data to be processed, the target threat label and the feedback information to generate a security data result. Optionally, the feedback information can be transmitted by the above two devices, that is, the device that triggered the brute force warning and the device with which it had abnormal communication, to the monitoring center of the comprehensive management level platform through the large area level platform corresponding to the device for display.

[0077] S141. Through the comprehensive management level platform, visually display the regional comprehensive score, three-dimensional attack topology and security threat events corresponding to the security data result.

[0078] In this step, through the comprehensive management level platform, the security data results of each large area can be analyzed, the regional comprehensive scores related to network security of each large area can be displayed through a dynamic heat map, and a to-do list of security threat events can be listed; based on the regional comprehensive score and the to-do list of security threat events, a three-dimensional attack topology can be generated through an attack chain sand table to display the attack path; the dynamic heat map and real-time alarm stream are presented in the form of multi-screen linkage.

[0079] In one embodiment, the method further includes:

[0080] Through the comprehensive management level platform, determine the target threat level according to the security data result, generate notification information corresponding to the security data result based on the target threat level, and transmit the notification information to the corresponding large area level platform;

[0081] Through the large area level platform, forward the notification information to the corresponding station-level device;

[0082] Through the station-level device, determine the target response strategy corresponding to the notification information in the preset response strategy, and execute the target response strategy.

[0083] Specifically, through the notification response center of the comprehensive management level platform, the threat level is judged according to the threat information and feedback information recorded in the target threat label in the security data result to obtain the target threat level; the notification information corresponding to the security data result is generated according to the target threat level, and the notification information can be the information for realizing notification and warning, and the notification information encapsulated into a specific data exchange format is sent to the corresponding regional platform through the standardized interface; through the regional platform, after parsing the notification information based on the regional policy, it is forwarded to the corresponding station-level device by using the agreed protocol; through the corresponding station-level device, the notification information is received by using the agreed protocol, and after verifying the digital signature, the target response policy corresponding to the notification information is determined from the preset response policy, and the target response policy is executed. Among them, the preset response policy can be a pre-set response policy, such as what response policy is adopted for different notification information pre-set, and it is not specifically limited. That is Figure 4 The notification as shown is sent down.

[0084] In one embodiment, the method further includes:

[0085] Through the comprehensive management level platform, determine the target protection policy according to the security data result, and transmit the target protection policy to the corresponding regional platform;

[0086] Through the regional platform, call the built-in policy adapter to parse the target protection policy to obtain the target defense configuration, and transmit the target defense configuration to the corresponding station-level device;

[0087] Through the station-level device, call the built-in protocol adaptation layer to parse the target defense configuration into target defense instructions, and execute the target defense instructions.

[0088] Specifically, through the policy management center of the comprehensive management level platform, determine the target protection policy according to the security data result, such as what protection policy is adopted for different security data results pre-set, so as to determine the target protection policy during actual application, and transmit the target protection policy to the corresponding regional platform, that is Figure 4 The policy distribution as shown is carried out; through the regional platform, call the built-in policy adapter to parse the target protection policy, and parse it into a defense configuration adapted to the station-level devices in this region, that is, the target defense configuration, and transmit the target defense configuration to the station-level devices in this region through the encrypted channel, that is Figure 4 The protection configuration distribution as shown is carried out; through the station-level device, receive the target defense configuration through the encrypted channel, call the built-in protocol adaptation layer to parse the target defense configuration into the native instructions of the device, that is, the target defense instructions, and execute the target defense instructions.

[0089] It should be noted that the principle of threat detection involved in the embodiments of the present invention can be as follows: For the detection of known threats, it can be achieved by applying machine learning algorithms combined with feature detection to virus detection, Trojan detection, and malicious file detection; for the detection of unknown threats, it can perform threat detection by using artificial intelligence learning without relying on a virus library. On the one hand, it can have strong generalization ability and can identify variant viruses without updating the model. On the other hand, it has a strong detection ability for known family variants.

[0090] It should be noted that the station-level devices in the embodiments of the present invention, namely, the third-level devices, include traffic collection probes, device hosts, firewalls, Web Application Firewalls (WAFs), Intrusion Prevention Systems (IPSs), etc. Web refers to the World Wide Web; the large-region-level platforms in the embodiments of the present invention, namely, the second-level platforms, include security devices, network devices, business systems, device hosts, servers, etc.; the comprehensive management-level platforms in the embodiments of the present invention, namely, the first-level platforms, include traffic collection probes, host device probes, firewalls, WAFs, etc.

[0091] The technical solution of the embodiments of the present invention deploys latent threat probes through distributed deployment to station-level devices, uses a splitter / port mirror for bypass listening, and non-intrusively collects data to be analyzed, and encrypts and transmits the data to be analyzed to the large-region-level platform; through the large-region-level platform, based on the dynamically constructed behavior portraits, multi-dimensional similarity comparison is performed, and combined with threat intelligence weighting to generate security data to be processed including threat labels to be processed and confidence scores to be processed, and push it to the comprehensive management-level platform together with the data to be analyzed; through the comprehensive management-level platform, use the threat detection engine for cross-domain correlation analysis, output the global attack path and disposal strategy, and finally realize the "detection - analysis - response - verification" closed loop.

[0092] The technical solution of the embodiment of the present invention, through a power network security situation awareness system based on a three-level architecture, establishes an event investigation process, a notification and early warning process, and an emergency response process, overcomes the technical defect that it is difficult to conduct unified event investigation and processing in a normal operation scenario, and improves the efficiency of operation and maintenance; through the distributed deployment of latent threat probes, combined with the parsing engine to preliminarily parse the monitored raw data and preliminarily judge the threats of the target addresses, enables the entire system to uniformly confront external threats, and improves the efficiency and security of operation and maintenance; through the behavior analysis of users and assets, continuously learns and constructs behavior portraits for these objects, enables the identification of insider behaviors and latent threats that have invaded, issues early warnings, and improves the security and rapid response capabilities of the system; through the judgment of behavior similarity based on the behavior portrait, combined with abnormal behavior detection, obtains threat labels and confidence scores, enables the system to react early to potential threat behaviors and viruses, and takes preventive measures in advance, improving the defensive and security capabilities of the system; through the correlation analysis of threat behaviors in each region by the first-level platform, enables the rapid discovery of organized and related threat behaviors, makes a disposal response earlier, and improves the identification efficiency of threat behaviors by the system and the defensive capabilities of the system; through the visualization of security data results, enables the staff to timely understand the operation conditions of each region, more clearly and intuitively observe regional anomalies, and improves the reliability of the system; through the platform to monitor the network security situation and promptly dispose of security alerts to avoid security risks, thereby avoiding and reducing the losses caused by viruses and malicious attacks in the network, and effectively improving the independent monitoring and protection capabilities of each level of unit.

[0093] Embodiment III

[0094] The embodiment of the present invention provides a power network security situation awareness system, that is Figure 2 the system shown in the figure, the system includes a comprehensive management level platform, one or more large region level platforms under the comprehensive management level platform, and one or more station level devices under each large region level platform;

[0095] The station level device is used to collect data to be analyzed by using a latent threat probe and transmit the data to be analyzed to the corresponding large region level platform;

[0096] The large region level platform is used to perform abnormal behavior detection on the data to be analyzed by using a situation awareness model combined with a behavior portrait, generate to-be-processed security data including to-be-processed threat labels and to-be-processed confidence scores, and transmit the data to be analyzed and the to-be-processed security data to the comprehensive management level platform;

[0097] The comprehensive management level platform is used to perform correlation analysis on the to-be-processed security data by using a threat detection engine combined with the data to be analyzed to obtain a security data result;

[0098] The comprehensive management level platform is used for visual display of security threat events based on the security data results.

[0099] Furthermore, the station-level device is specifically used for:

[0100] Using a latent threat probe to obtain raw data related to network security through bypass listening technology, parsing the raw data to obtain the corresponding network protocol and target address, and generating structured data to be analyzed based on the raw data, the network protocol, and the target address.

[0101] Furthermore, the large-region level platform is specifically used for:

[0102] Using a situation awareness model to analyze the behaviors of each user and asset under the large-region level platform, constructing a basic portrait, and optimizing the basic portrait in combination with the behavior scenario to obtain a behavior portrait;

[0103] Using the situation awareness model to call the behavior portrait to perform a similarity comparison on the data to be analyzed, and obtaining a behavior similarity;

[0104] Using the situation awareness model to perform abnormal behavior detection based on the behavior similarity and the threat intelligence library, and determining candidate threat labels and corresponding candidate confidence scores;

[0105] When the candidate confidence score is higher than the set score threshold, using the candidate confidence score as the confidence score to be processed, using the candidate threat label corresponding to the candidate confidence score as the threat label to be processed, and generating security data to be processed.

[0106] Furthermore, the large-region level platform is also used for:

[0107] When the candidate confidence score is higher than the set score threshold, transmitting a warning message to the user or asset corresponding to the candidate confidence score, where the warning message is used to trigger lightweight handling.

[0108] Furthermore, the large-region level platform is also used for:

[0109] When the candidate confidence score is lower than the set score threshold, performing a low-risk mark on the behavior of the user or asset corresponding to the candidate confidence score, and increasing the frequency of abnormal behavior detection.

[0110] Furthermore, the comprehensive management level platform is specifically used for:

[0111] Using a threat detection engine to perform correlation analysis on the security data to be processed in combination with the target address in the data to be analyzed, and generating correlation information;

[0112] Update the to-be-processed threat label in the to-be-processed security data based on the associated information to obtain a target threat label, and trigger a disposal instruction corresponding to the target threat label;

[0113] Execute a disposal operation based on the disposal instruction, and obtain feedback information of the disposal operation;

[0114] Based on the to-be-processed security data, combined with the target threat label and the feedback information, obtain a security data result.

[0115] Further, the comprehensive management-level platform is specifically used for:

[0116] Visually display the regional comprehensive score, three-dimensional attack topology, and security threat events corresponding to the security data result.

[0117] Further, the comprehensive management-level platform is also used to determine a target threat level according to the security data result, generate a notification message corresponding to the security data result based on the target threat level, and transmit the notification message to the corresponding large-region-level platform;

[0118] The large-region-level platform is also used to forward the notification message to the corresponding station-level device;

[0119] The station-level device is also used to determine a target response strategy in the preset response strategy corresponding to the notification message, and execute the target response strategy.

[0120] Further, the comprehensive management-level platform is also used to determine a target protection strategy according to the security data result, and transmit the target protection strategy to the corresponding large-region-level platform;

[0121] The large-region-level platform is also used to call the built-in policy adapter to parse the target protection strategy to obtain a target defense configuration, and transmit the target defense configuration to the corresponding station-level device;

[0122] The station-level device is also used to call the built-in protocol adaptation layer to parse the target defense configuration into a target defense instruction, and execute the target defense instruction.

[0123] The power network security situation awareness system provided by the embodiments of the present invention can execute the power network security situation awareness method provided by any embodiment of the present invention, and has the corresponding function modules and beneficial effects for executing the method.

[0124] It should be understood that the various forms of processes shown above can be used, with steps reordered, added or deleted. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.

[0125] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A method for electric power network security situation awareness, characterized in that: Applied to a power network security situation awareness system, the system includes an integrated management-level platform, one or more regional-level platforms under the integrated management-level platform, and one or more station-level devices under each regional-level platform, and the method includes: Through the site-level equipment, the potential threat probe is used to collect the data to be analyzed, and the data to be analyzed is transmitted to the corresponding regional-level platform; Through the regional-level platform, the situational awareness model is used in combination with the behavior profile to detect abnormal behavior of the data to be analyzed, and the security data to be processed including the threat label to be processed and the confidence score to be processed are generated, and the data to be analyzed and the security data to be processed are transmitted to the integrated management-level platform; Through the integrated management-level platform, the threat detection engine is used in combination with the data to be analyzed to perform correlation analysis on the security data to be processed, and a security data result is obtained; Through the integrated management-level platform, a visual display of security threat events is performed based on the security data results.

2. The method according to claim 1, characterized in that Through the site-level equipment, the potential threat probe is used to collect data to be analyzed, including: Through the site-level equipment, the potential threat probe is used to obtain original data related to network security through bypass monitoring technology, the original data is parsed to obtain the corresponding network protocol and target address, and structured data to be analyzed is generated based on the original data, the network protocol and the target address.

3. The method according to claim 1, characterized in that Through the regional platform, the situational awareness model is used in combination with the behavior profile to detect abnormal behavior of the data to be analyzed, and the security data to be processed containing the threat labels to be processed and the confidence scores to be processed are generated, including: Through the regional platform, the behavior of each user and asset under the regional platform is analyzed using a situation awareness model to construct a basic profile, and the basic profile is optimized in combination with the behavior scenario to obtain a behavior profile; Through the regional platform, the situation awareness model is used to call the behavior profile to perform similarity comparison on the data to be analyzed to obtain behavior similarity; Through the regional platform, using the situation awareness model to detect abnormal behaviors based on the behavior similarity and the threat intelligence library, determine candidate threat labels and corresponding candidate confidence scores; Through the regional platform, when the candidate confidence score is higher than the set score threshold, the candidate confidence score is used as the confidence score to be processed, and the candidate threat label corresponding to the candidate confidence score is used as the threat label to be processed to generate security data to be processed.

4. The method according to claim 3, characterized in that Also includes: Through the regional platform, when the candidate confidence score is higher than the set score threshold, a warning message is transmitted to the user or asset corresponding to the candidate confidence score, and the warning message is used to trigger lightweight disposal.

5. The method according to claim 3, characterized in that: Also includes: Through the regional platform, when the candidate confidence score is lower than the set score threshold, the behavior of the user or asset corresponding to the candidate confidence score is marked as low risk, and the frequency of abnormal behavior detection is increased.

6. The method according to claim 1, characterized in that Through the integrated management-level platform, the threat detection engine is used in combination with the data to be analyzed to perform correlation analysis on the security data to be processed, and a security data result is obtained, including: Through the integrated management-level platform, the threat detection engine is used to perform correlation analysis on the security data to be processed in combination with the target address in the data to be analyzed to generate correlation information; By means of the integrated management-level platform, based on the associated information, the to-be-processed threat tag in the to-be-processed security data is updated to obtain a target threat tag, and a disposal instruction corresponding to the target threat tag is triggered; By means of the integrated management-level platform, a disposal operation is performed based on the disposal instruction, and feedback information of the disposal operation is obtained; Through the integrated management-level platform, a security data result is obtained based on the security data to be processed in combination with the target threat tag and the feedback information.

7. The method according to claim 1, characterized in that Through the integrated management-level platform, a visual display of security threat events is performed based on the security data results, including: Through the integrated management-level platform, the regional comprehensive scores, three-dimensional attack topologies and security threat events corresponding to the security data results are visually displayed.

8. The method according to claim 1, characterized in that Also includes: Determine the target threat level according to the security data result through the integrated management-level platform, generate notification information corresponding to the security data result based on the target threat level, and transmit the notification information to the corresponding regional-level platform; Forwarding the notification information to corresponding station-level equipment via the regional-level platform; Through the site-level device, a target response strategy corresponding to the notification information in a preset response strategy is determined, and the target response strategy is executed.

9. The method according to claim 1, characterized in that: Also includes: Determine the target protection strategy according to the security data results through the integrated management-level platform, and transmit the target protection strategy to the corresponding regional-level platform; Through the regional platform, the built-in policy adapter is called to parse the target protection policy to obtain the target defense configuration, and the target defense configuration is transmitted to the corresponding site-level device; Through the site-level device, the built-in protocol adaptation layer is called to parse the target defense configuration into a target defense instruction, and the target defense instruction is executed.

10. A power network security situation awareness system, characterized in that: The system includes an integrated management-level platform, one or more regional-level platforms under the integrated management-level platform, and one or more station-level equipment under each regional-level platform; The site-level equipment is used to collect data to be analyzed using the potential threat probe and transmit the data to be analyzed to the corresponding regional-level platform; The regional-level platform is used to detect abnormal behavior of the data to be analyzed by using the situation awareness model in combination with the behavior profile, generate security data to be processed including threat labels to be processed and confidence scores to be processed, and transmit the data to be analyzed and the security data to be processed to the integrated management-level platform; The integrated management-level platform is used to use the threat detection engine in combination with the data to be analyzed to perform correlation analysis on the security data to be processed, and obtain security data results; The integrated management-level platform is used to visualize security threat events based on the security data results.