Security protection processing method and device for security protection architecture of power grid data center
By constructing a judgment matrix and genetic algorithm optimization, combined with AHP hierarchical analysis method and entropy weight method, the comprehensive and quantitative problems of the security protection architecture evaluation of the power grid data center are solved, and the rationality of the security protection processing strategy is realized to ensure the safety and stability of the power system.
Patent Information
- Application Number
- CN202510201395.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2025-06-20
AI Technical Summary
The existing technology cannot conduct a comprehensive and quantitative security assessment of the security protection architecture of the power grid data center, resulting in the inability to reasonably determine the safety protection processing strategy, affecting the safe and smooth operation of the power system.
A comprehensive evaluation method based on AHP hierarchical analysis method and entropy weight method is adopted to calculate subjective and objective weight values by constructing a judgment matrix, and combining genetic algorithm optimization, the combined weight coefficient is determined to achieve a comprehensive evaluation and processing strategy for the security protection architecture of the power grid data center.
It has achieved a comprehensive and quantitative assessment of the security protection architecture of the power grid data center, and can reasonably determine the safety protection processing strategy to ensure the safe and smooth operation of the power system.
Smart Images

Figure CN120185853A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of security technologies, and particularly to a security protection processing method and device for a security protection architecture of a power grid data center. Background Art
[0002] A power grid data center is a center for data calculation and network storage. The power system realizes data acquisition, storage, exchange, and processing and utilization through the power grid data center. In recent years, with the wide promotion and application of big data technology and cloud computing technology, establishing a power grid data center has become an inevitable path in the current enterprise digitalization process. The current power grid data center is the main entity for carrying information systems. Through the establishment of the power grid data center, the power system can easily realize data calculation and network storage. However, the current power grid data center faces various risks in the Internet, and it is necessary to accurately evaluate the security of the security protection architecture of the power grid data center to ensure that security problems of the power grid data center can be discovered in time and strengthened to ensure the safe and stable operation of the power system.
[0003] In recent years, in order to ensure the security of the security protection architecture of the power grid data center, existing evaluation methods include questionnaire surveys, tool detection, manual verification, document review, and penetration testing, etc.
[0004] Among them, the questionnaire survey method collects various aspects of information about the security architecture of the power grid data center by distributing questionnaires to the staff of the power grid data center. The tool detection method uses professional security detection tools to scan and detect the power grid data center to discover potential security vulnerabilities and weaknesses. The manual verification method is carried out by professional security personnel to conduct on-site verification of the power grid data center to ensure that various security measures are effectively implemented. However, the current evaluation methods for the security of the power grid data center security architecture are relatively single, unable to accurately evaluate the security of the overall security architecture of the power grid data center, and unable to quantitatively evaluate the security of the architecture through indicators, and the evaluation methods have certain limitations. Summary of the Invention
[0005] In view of the problems in the prior art, embodiments of the present invention provide a security protection processing method and device for a security protection architecture of a power grid data center, which can at least partially solve the problems existing in the prior art.
[0006] On the one hand, the present invention proposes a security protection processing method for a security protection architecture of a power grid data center, including:
[0007] Calculating score values respectively corresponding to each protection layer based on the evaluation results of each protection layer for each data sample;
[0008] Wherein, each of the protection layers is included in the security protection architecture of the power grid data center;
[0009] Based on the pre-constructed judgment matrix and the total number of data samples, subjective weight values corresponding to each scoring value are calculated, and an allocation coefficient between the objective weight value and the subjective weight value is determined according to the difference degree between the objective weight value and the subjective weight value corresponding to each scoring value;
[0010] Among them, the order of the judgment matrix is equal to the number of protection layers, the diagonal elements are 1, and the ratio of the elements in the latter row above the diagonal to the elements in the previous row reflects the importance degree between adjacent two protection layers, and the elements below the diagonal are the reciprocals of the corresponding elements above the diagonal;
[0011] A combined weight coefficient is determined according to the allocation coefficient, the subjective weight value and the objective weight value, an evaluation result of the security protection architecture is calculated according to the combined weight coefficient and each scoring value, and a corresponding security protection processing strategy is determined according to the evaluation result of the security protection architecture, so as to realize the security protection processing of the security protection architecture.
[0012] Among them, calculating the scoring values corresponding to each protection layer based on the evaluation results of each protection layer for each data sample respectively includes:
[0013] Calculating the sum of the evaluation results corresponding to each protection layer respectively, and taking the ratio of the sum of the evaluation results to the total number of data samples as the scoring values corresponding to each protection layer.
[0014] Among them, calculating the subjective weight values corresponding to each scoring value based on the pre-constructed judgment matrix and the total number of data samples includes:
[0015] Solving the maximum eigenvalue of the judgment matrix, and performing consistency verification on the judgment matrix according to the maximum eigenvalue and the total number of data samples;
[0016] If it is determined that the consistency verification result is less than the preset threshold, the subjective weight value is determined according to the elements in the judgment matrix at this time.
[0017] Among them, the security protection processing method of the security protection architecture of the power grid data center further includes:
[0018] If it is determined that the consistency verification result is greater than or equal to the preset threshold, the genetic algorithm is used to optimize the elements in the judgment matrix;
[0019] The subjective weight value is determined according to the optimized elements in the optimized judgment matrix.
[0020] Among them, the security protection processing method of the security protection architecture of the power grid data center further includes:
[0021] The entropy weight method is used to determine the objective weight values corresponding to each scoring value respectively.
[0022] Among them, determining the distribution coefficient between the objective weight value and the subjective weight value according to the degree of difference between the objective weight value and the subjective weight value corresponding to each scoring value respectively includes:
[0023] Express the degree of difference according to the mean square error expression, and solve to obtain the distribution coefficient based on the following constraint conditions:
[0024]
[0025] α + β = 1
[0026] Among them, MSE is the mean square error, Z j is the subjective weight value corresponding to the j-th protection layer, W j is the objective weight value corresponding to the j-th protection layer, α is the distribution coefficient corresponding to the subjective weight value, and β is the distribution coefficient corresponding to the objective weight value.
[0027] Among them, determining the corresponding security protection processing strategy according to the security protection architecture evaluation result includes:
[0028] Determine the numerical interval where the value corresponding to the security protection architecture evaluation result is located according to the preset numerical interval;
[0029] Determine the security protection processing strategy corresponding to the numerical interval according to the preset correspondence;
[0030] Among them, the preset correspondence includes the mapping relationship between the preset numerical interval and the preset security protection processing strategy.
[0031] On the one hand, the present invention proposes a security protection processing device for the security protection architecture of a power grid data center, including:
[0032] A calculation unit, configured to calculate the scoring values corresponding to each protection layer respectively based on the evaluation results of each protection layer by each data sample;
[0033] Among them, each protection layer is included in the security protection architecture of the power grid data center;
[0034] A determination unit, configured to calculate the subjective weight values corresponding to each scoring value respectively based on the pre-constructed judgment matrix and the total number of data samples, and determine the distribution coefficient between the objective weight value and the subjective weight value according to the degree of difference between the objective weight value and the subjective weight value corresponding to each scoring value respectively;
[0035] Among them, the order of the judgment matrix is equal to the number of protection layers, the diagonal elements are 1, and the ratio of the elements in the row immediately below the diagonal to the elements in the previous row reflects the importance degree between two adjacent protection layers, and the elements below the diagonal are the reciprocals of the corresponding elements above the diagonal;
[0036] A protection unit is configured to determine a combined weight coefficient according to the distribution coefficient, the subjective weight value, and the objective weight value, calculate a security protection architecture evaluation result according to the combined weight coefficient and each scoring value, and determine a corresponding security protection processing strategy according to the security protection architecture evaluation result, so as to implement security protection processing on the security protection architecture.
[0037] On the other hand, an embodiment of the present invention provides an electronic device, including: a processor, a memory, and a bus, where
[0038] The processor and the memory communicate with each other through the bus;
[0039] The memory stores program instructions executable by the processor, and the processor can execute the following methods by invoking the program instructions:
[0040] Based on the evaluation results of each protection layer for each data sample, calculate the scoring values corresponding to each protection layer respectively;
[0041] Among them, each of the protection layers is included in the security protection architecture of the power grid data center;
[0042] Based on a pre-constructed judgment matrix and the total number of data samples, calculate the subjective weight values corresponding to each scoring value respectively, and determine the distribution coefficient between the objective weight value and the subjective weight value according to the difference degree between the objective weight value and the subjective weight value corresponding to each scoring value respectively;
[0043] Among them, the order of the judgment matrix is equal to the number of protection layers, the diagonal elements are 1, and the ratio of the elements in the row immediately below the diagonal to the elements in the previous row reflects the importance degree between two adjacent protection layers, and the elements below the diagonal are the reciprocals of the corresponding elements above the diagonal;
[0044] Determine a combined weight coefficient according to the distribution coefficient, the subjective weight value, and the objective weight value, calculate a security protection architecture evaluation result according to the combined weight coefficient and each scoring value, and determine a corresponding security protection processing strategy according to the security protection architecture evaluation result, so as to implement security protection processing on the security protection architecture.
[0045] An embodiment of the present invention provides a non-transitory computer-readable storage medium, including:
[0046] The non-transitory computer-readable storage medium stores computer instructions that cause the computer to execute the following method:
[0047] Based on the evaluation results of each protection layer for each data sample, calculate the scoring values corresponding to each protection layer respectively;
[0048] Among them, each of the protection layers is included in the security protection architecture of the power grid data center;
[0049] Based on the pre-constructed judgment matrix and the total number of data samples, calculate the subjective weight values corresponding to each scoring value respectively, and determine the distribution coefficient between the objective weight value and the subjective weight value according to the difference degree between the objective weight value and the subjective weight value corresponding to each scoring value;
[0050] Among them, the order of the judgment matrix is equal to the number of protection layers, the diagonal elements are 1, and the ratio of the elements in the row after the diagonal to the elements in the previous row reflects the importance degree between adjacent two protection layers, and the elements below the diagonal are the reciprocals of the corresponding elements above the diagonal;
[0051] Determine the combined weight coefficient according to the distribution coefficient, the subjective weight value and the objective weight value, calculate the security protection architecture evaluation result according to the combined weight coefficient and each scoring value, and determine the corresponding security protection processing strategy according to the security protection architecture evaluation result, so as to implement security protection processing for the security protection architecture.
[0052] The safety protection processing method and device for the safety protection architecture of a power grid data center provided by an embodiment of the present invention calculate the scoring values corresponding to each protection layer based on the evaluation results of each data sample for each protection layer; wherein, each of the protection layers is included in the safety protection architecture of the power grid data center; based on a pre-constructed judgment matrix and the total number of data samples, calculate the subjective weight values corresponding to each scoring value, and determine the distribution coefficient between the objective weight value and the subjective weight value according to the difference degree between the objective weight value and the subjective weight value corresponding to each scoring value; wherein, the order of the judgment matrix is equal to the number of protection layers, the diagonal elements are 1, and the ratio of the elements in the subsequent row above the diagonal to the elements in the previous row reflects the importance degree between two adjacent protection layers, and the elements below the diagonal are the reciprocals of the corresponding elements above the diagonal; determine the combined weight coefficient according to the distribution coefficient, the subjective weight value and the objective weight value, calculate the safety protection architecture evaluation result according to the combined weight coefficient and each scoring value, and determine the corresponding safety protection processing strategy according to the safety protection architecture evaluation result, so as to implement the safety protection processing of the safety protection architecture, and be able to more reasonably determine the safety protection processing strategy based on a more comprehensive and quantifiable safety protection architecture evaluation result, thereby ensuring the safe and stable operation of the power system. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention, and for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings. In the drawings:
[0054] Figure 1 is a flowchart of the safety protection processing method for the safety protection architecture of a power grid data center provided by an embodiment of the present invention.
[0055] Figure 2 is an explanatory schematic diagram of the safety protection architecture of a power grid data center provided by an embodiment of the present invention.
[0056] Figure 3 is a flowchart of the safety protection processing method for the safety protection architecture of a power grid data center provided by another embodiment of the present invention.
[0057] Figure 4 is a schematic structural diagram of the safety protection processing device for the safety protection architecture of a power grid data center provided by an embodiment of the present invention.
[0058] Figure 5 is a schematic physical structure diagram of an electronic device provided by an embodiment of the present invention. Detailed Implementation Modes
[0059] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer and more understandable, the following further elaborates on the embodiments of the present invention in conjunction with the accompanying drawings. Herein, the illustrative embodiments of the present invention and their descriptions are used to explain the present invention, but not to limit the present invention. It should be noted that, without conflict, the embodiments in this application and the features in the embodiments can be arbitrarily combined with each other.
[0060] Explanation of Related Terms:
[0061] Power Grid Data Center: The power grid data center plays a crucial role in the power industry. It is not only a professional institution for data management but also a platform for data sharing, data services, and digital innovation.
[0062] Security Protection Architecture: It refers to the overall framework of a set of strategies, methods, technologies, and tools used to protect information systems or physical facilities from unauthorized access, damage, or data leakage. It aims to build a multi-level and all-round defense system to ensure the security of information systems or physical facilities. It provides real-time monitoring, early warning, and response capabilities to potential threats by integrating various security technologies and strategies, thereby protecting critical data and business continuity.
[0063] AHP (Analytic Hierarchy Process): The Analytic Hierarchy Process, abbreviated as AHP, refers to a decision-making method that decomposes the elements related to decision-making into levels such as objectives, criteria, and solutions, and then conducts qualitative and quantitative analyses on this basis. The AHP decomposes the decision-making problem into different hierarchical structures in the order of the overall objective, sub-objectives at each level, evaluation criteria, and specific alternative investment plans. Then, by using the method of solving the eigenvector of the judgment matrix, the priority weights of each element at each level with respect to a certain element at the previous level are obtained. Finally, the weighted sum method is used to hierarchically merge the final weights of each alternative plan with respect to the overall objective. The alternative plan with the largest final weight is the optimal plan.
[0064] Entropy Weight Method: An objective weighting method. In information theory, entropy represents a measure of uncertainty. The entropy weight method uses the concept of information entropy to determine the weight by calculating the entropy values of various factors to judge their dispersion degree. Specifically, the smaller the information entropy value, the greater the dispersion degree of the index, the greater the role of the index in comprehensive evaluation, and the higher its weight.
[0065] Figure 1 It is a schematic flowchart of the security protection processing method for the security protection architecture of a power grid data center provided by an embodiment of the present invention. As Figure 1 shown, the security protection processing method for the security protection architecture of a power grid data center provided by the embodiment of the present invention includes:
[0066] Step S1: Based on the evaluation results of each protection layer for each data sample, calculate the scoring values corresponding to each protection layer respectively;
[0067] Among them, each of the protection layers is included in the security protection architecture of the power grid data center.
[0068] Step S2: Based on the pre-constructed judgment matrix and the total number of data samples, calculate the subjective weight values corresponding to each scoring value respectively. According to the degree of difference between the objective weight value and the subjective weight value corresponding to each scoring value, determine the distribution coefficient between the objective weight value and the subjective weight value;
[0069] Among them, the order of the judgment matrix is equal to the number of protection layers, the diagonal elements are 1, and the ratio of the elements in the row below the diagonal to the elements in the previous row reflects the importance degree between adjacent two protection layers. The elements below the diagonal are the reciprocals of the corresponding elements above the diagonal.
[0070] Step S3: Determine the combined weight coefficient according to the distribution coefficient, the subjective weight value and the objective weight value. Calculate the security protection architecture evaluation result according to the combined weight coefficient and each scoring value, and determine the corresponding security protection processing strategy according to the security protection architecture evaluation result, so as to realize the security protection processing of the security protection architecture.
[0071] In the above step S1, the device calculates the scoring values corresponding to each protection layer respectively based on the evaluation results of each protection layer for each data sample;
[0072] Among them, each of the protection layers is included in the security protection architecture of the power grid data center. The device can be a computer device that executes this method. It should be noted that the acquisition and analysis of data involved in the embodiments of the present invention are authorized by the user. As Figure 2 shown, based on the security requirements of the power grid data center, the characteristics of the network architecture, potential security threats, and best practices of security protection, the present invention establishes a security protection architecture security evaluation index system for the power grid data center, covering the application layer security, virtualization layer security, and infrastructure layer security of the power grid data center. That is, each protection layer of the present invention can be selected as three layers, corresponding to the application layer, virtualization layer, and infrastructure layer respectively. The above security protection architecture security evaluation index system, that is, the preset corresponding relationship, is shown in Table 1:
[0073] Table 1
[0074]
[0075] The evaluation results provided by experts according to Table 1 (the security protection scores at all levels in Table 1) can be used as a data sample. For example, the evaluation result of Expert A for the application layer is 2.2, the evaluation result for the virtualization layer is 2.8, and the evaluation result for the infrastructure layer is 3.2. Similarly, n experts can provide n evaluation results, that is, n data samples.
[0076] Calculating the scoring scores corresponding to each protection layer respectively based on the evaluation results of each data sample for each protection layer includes:
[0077] Calculating the sum of the evaluation results corresponding to each protection layer respectively, and taking the ratio of the sum of the evaluation results to the total number of data samples as the scoring scores corresponding to each protection layer respectively. If three experts participate, that is, the total number of data samples is 3, referring to the above example, if the evaluation result of Expert B for the application layer is 2.6, and if the evaluation result of Expert C for the application layer is 1.8, then the scoring score = (2.2 + 2.6 + 1.8) / 3 = 2.2. For the virtualization layer and the infrastructure layer, it will not be elaborated here. By respectively represent the scoring score of the application layer, the scoring score of the virtualization layer, and the scoring score of the infrastructure layer.
[0078] In the above step S2, the device calculates the subjective weight values corresponding to each scoring score based on the pre-constructed judgment matrix and the total number of data samples, and determines the distribution coefficient between the objective weight value and the subjective weight value according to the difference degree between the objective weight value and the subjective weight value corresponding to each scoring score;
[0079] Among them, the order of the judgment matrix is equal to the number of protection layers, the diagonal elements are 1, and the ratio of the elements in the latter row above the diagonal to the elements in the previous row reflects the importance degree between adjacent two protection layers, and the elements below the diagonal are the reciprocals of the corresponding elements above the diagonal. Referring to the above description, the order of the judgment matrix is 3-order, and the judgment matrix can be constructed based on the AHP (Analytic Hierarchy Process) and according to Table 2.
[0080] Table 2
[0081]
[0082] In the order of the application layer, the virtualization layer, and the infrastructure layer, the virtualization layer in Table 2 is the latter of the application layer, and the infrastructure layer is the latter of the virtualization layer.
[0083] Calculating the subjective weight values corresponding to each scoring score based on the pre-constructed judgment matrix and the total number of data samples includes:
[0084] Solve the maximum eigenvalue of the judgment matrix, and perform consistency verification on the judgment matrix according to the maximum eigenvalue and the total number of data samples; the judgment matrix can be consistency-verified according to the following expression:
[0085]
[0086] where CI is the consistency verification index, λ max is the maximum eigenvalue, and n is the total number of data samples.
[0087] RI is the average random consistency index, which is related to the matrix order, and the relationship is shown in Table 3:
[0088] Table 3
[0089] Matrix order 1 2 3 4 5 6 7 8 9 10 RI 0 0 0.52 0.89 1.12 1.26 1.36 1.41 1.46 1.49
[0090] Referring to the above example, the judgment matrix of the present invention is of order 3, and the RI value is 0.52.
[0091] If it is determined that the consistency verification result is less than the preset threshold, then determine the subjective weight value according to the elements in the judgment matrix at this time. The consistency verification result CR = CI / RI, and the preset threshold can be set independently according to the actual situation, and can be selected as 0.1. The subjective weight values are denoted as Z1, Z2, and Z3.
[0092] The security protection processing method of the security protection architecture of the power grid data center further includes:
[0093] If it is determined that the consistency verification result is greater than or equal to the preset threshold, then use the genetic algorithm to optimize the elements in the judgment matrix;
[0094] Determine the subjective weight value according to the optimized elements in the optimized judgment matrix. As Figure 3 shown, use the interval scale method to establish a judgment matrix after the preliminary result of the existing analytic hierarchy process, use the genetic algorithm to iterate out better matrix index weights, minimize the subjectivity of the decision maker, iterate until the consistency verification of the matrix is satisfied, and output the obtained index weights, that is, the subjective weight values Z1, Z2, and Z3.
[0095] The security protection processing method of the security protection architecture of the power grid data center further includes:
[0096] Use the entropy weight method to determine the objective weight values corresponding to each scoring value. x i,j is the value of the jth index (protection layer) of the ith data sample, and the matrix is constructed as follows:
[0097]
[0098] First, normalize the indicators of each layer. The security indicators of each level of the power grid data center security architecture are positive indicators. The normalization process for each indicator is as follows:
[0099]
[0100] where j ∈ 1, 2, 3, thus realizing the conversion of the original indicator X into the standardized indicator Y respectively.
[0101] Calculate the proportion of the i-th sample in the j-th layer's security Xj to this indicator according to the following formula:
[0102]
[0103] Calculate the entropy value of the security indicator Xj of this layer according to the following formula:
[0104]
[0105] Calculate the objective weight value according to the following expression:
[0106]
[0107] In order to reflect both the intuitive evaluation of experts on the power grid data center security architecture and the objective security law, the weight values obtained by the above two evaluation methods need to be combined and calculated to obtain the combined weight coefficient.
[0108] The determination of the distribution coefficient between the objective weight value and the subjective weight value according to the difference degree between the objective weight value and the subjective weight value corresponding to each scoring value includes:
[0109] Express the difference degree according to the mean square error expression, and solve to obtain the distribution coefficient based on the following constraint conditions:
[0110]
[0111] α + β = 1
[0112] where MSE is the mean square error, Z j is the subjective weight value corresponding to the j-th protection layer, W j is the objective weight value corresponding to the j-th protection layer, α is the distribution coefficient corresponding to the subjective weight value, and β is the distribution coefficient corresponding to the objective weight value.
[0113] Measure the difference degree between the two groups of weights through the mean square error, as shown in the following formula:
[0114]
[0115] To ensure that the degree of difference between the final weight values is consistent with the degree of difference between their corresponding distribution coefficients, an equation is established between the mean square errors of the two groups of weights and the distribution coefficients as follows:
[0116]
[0117] α + β = 1
[0118] By simultaneously solving the above two equations, the distribution coefficients α and β corresponding to the two groups of weights can be obtained.
[0119] In the above step S3, the device determines the combined weight coefficient based on the distribution coefficient, the subjective weight value, and the objective weight value, calculates the security protection architecture evaluation result based on the combined weight coefficient and each scoring value, and determines the corresponding security protection processing strategy according to the security protection architecture evaluation result to implement security protection processing on the security protection architecture. The determining the combined weight coefficient based on the distribution coefficient, the subjective weight value, and the objective weight value includes:
[0120] The combined weight coefficient Q is calculated according to the following formula j :
[0121] Q j = αZ j + βW j
[0122] The calculating the security protection architecture evaluation result based on the combined weight coefficient and each scoring value includes:
[0123] The security protection architecture evaluation result is calculated according to the following formula:
[0124]
[0125] The determining the corresponding security protection processing strategy according to the security protection architecture evaluation result includes:
[0126] Determining the numerical interval in which the value corresponding to the security protection architecture evaluation result is located according to a preset numerical interval;
[0127] Determining the security protection processing strategy corresponding to the numerical interval according to a preset correspondence;
[0128] Among them, the preset correspondence includes the mapping relationship between the preset numerical interval and the preset security protection processing strategy. The relevant description in Table 1 above can be referred to and will not be elaborated here.
[0129] In addition to the content in Table 1, the security protection processing strategy may further include the following content:
[0130] Trust control policies, alarm control policies, and blocking control policies.
[0131] The trust control policies include physical security protection measures, boundary security protection measures, host security protection measures, application security protection measures, data security protection measures, network security protection measures, etc. Physical security protection measures mainly include computer room location selection, computer room access control, anti-theft, lightning protection, firewalls, waterproofing and moisture-proofing, anti-static, temperature and humidity control, power supply, and electromagnetic protection, aiming to protect the computer, network and other information system devices and storage media stored from physical environment damage, natural disasters, and human operation errors and malicious damage. Boundary security protection measures are mainly due to the network attack risks such as SQL injection, script attacks, and virus attacks faced by the boundary of the flexible regulation function construction of the network source-load. At the same time, sensitive business data flowing through the boundary, such as power trading data declarations, planned settlement result information, business documents, etc., face risks of leakage and tampering. Deploy information strong isolation devices, firewalls, and intrusion detection devices, etc., to ensure boundary security. Host security protection measures mainly include: identity authentication, access control, virus and intrusion prevention, vulnerability scanning, security patch update, resource control, security audit, data backup, etc. Application security protection measures are mainly due to the risks such as user authentication deception, permission and information leakage, and tampering faced by the load regulation platform application services and business information. Strictly control user authentication, encrypt the storage and transmission of sensitive information, and strengthen permission management and log auditing to ensure system security. Application security protection measures include: identity authentication, access control, input and output verification, configuration management, session management, encryption technology, parameter operation, exception management, logging and auditing. Data security protection measures are mainly due to the sensitive data of the load regulation platform including auxiliary peak shaving declaration information, auxiliary peak shaving settlement result information, etc., which face risks of tampering and leakage during transmission and storage. Ensure data security through encryption, integrity verification, etc.; at the same time, to ensure the disaster recovery ability of the information system, effectively back up key data. Network security protection measures mainly include intranet security monitoring, device security management, device link redundancy, network device processing capacity guarantee, vulnerability scanning, device security hardening, and configuration file backup.
[0132] The security protection processing method of the security protection architecture of the power grid data center provided by the embodiment of the present invention calculates the scoring values corresponding to each protection layer based on the evaluation results of each protection layer for each data sample; wherein, each of the protection layers is included in the security protection architecture of the power grid data center; based on the pre-constructed judgment matrix and the total number of data samples, calculates the subjective weight values corresponding to each scoring value, and determines the distribution coefficient between the objective weight value and the subjective weight value according to the difference degree between the objective weight value and the subjective weight value corresponding to each scoring value; wherein, the order of the judgment matrix is equal to the number of protection layers, the diagonal elements are 1, and the ratio of the elements in the latter row above the diagonal to the elements in the previous row reflects the importance degree between two adjacent protection layers, and the elements below the diagonal are the reciprocals of the corresponding elements above the diagonal; determines the combined weight coefficient according to the distribution coefficient, the subjective weight value and the objective weight value, calculates the security protection architecture evaluation result according to the combined weight coefficient and each scoring value, and determines the corresponding security protection processing strategy according to the security protection architecture evaluation result, so as to realize the security protection processing of the security protection architecture, and can more reasonably determine the security protection processing strategy based on a more comprehensive and quantifiable security protection architecture evaluation result, thereby ensuring the safe and stable operation of the power system.
[0133] Further, the calculating the scoring values corresponding to each protection layer based on the evaluation results of each protection layer for each data sample includes:
[0134] Calculates the sum of the evaluation results corresponding to each protection layer respectively, and takes the ratio of the sum of the evaluation results to the total number of data samples as the scoring values corresponding to each protection layer respectively. Refer to the above embodiments for illustration and will not be elaborated here.
[0135] Further, the calculating the subjective weight values corresponding to each scoring value based on the pre-constructed judgment matrix and the total number of data samples includes:
[0136] Solves the maximum eigenvalue of the judgment matrix, and performs consistency verification on the judgment matrix according to the maximum eigenvalue and the total number of data samples; refer to the above embodiments for illustration and will not be elaborated here.
[0137] If it is determined that the consistency verification result is less than the preset threshold, the subjective weight value is determined according to the elements in the judgment matrix at this time. Refer to the above embodiments for illustration and will not be elaborated here.
[0138] Further, the security protection processing method of the security protection architecture of the power grid data center further includes:
[0139] If it is determined that the consistency check result is greater than or equal to the preset threshold, the genetic algorithm is used to optimize the elements in the judgment matrix; reference may be made to the above embodiments for description and details are not repeated here.
[0140] The subjective weight value is determined according to the optimized elements in the optimized judgment matrix. Reference may be made to the above embodiments for description and details are not repeated here.
[0141] Further, the security protection processing method of the security protection architecture of the power grid data center further includes:
[0142] The entropy weight method is used to determine the objective weight value corresponding to each scoring value. Reference may be made to the above embodiments for description and details are not repeated here.
[0143] Further, determining the distribution coefficient between the objective weight value and the subjective weight value according to the difference degree between the objective weight value corresponding to each scoring value and the subjective weight value includes:
[0144] The difference degree is expressed according to the mean square error expression, and the distribution coefficient is obtained by solving based on the following constraint conditions:
[0145]
[0146] α + β = 1
[0147] where MSE is the mean square error, Z j is the subjective weight value corresponding to the jth protection layer, W j is the objective weight value corresponding to the jth protection layer, α is the distribution coefficient corresponding to the subjective weight value, and β is the distribution coefficient corresponding to the objective weight value. Reference may be made to the above embodiments for description and details are not repeated here.
[0148] Further, determining the corresponding security protection processing strategy according to the security protection architecture evaluation result includes:
[0149] Determine the numerical interval in which the value corresponding to the security protection architecture evaluation result is located according to the preset numerical interval; reference may be made to the above embodiments for description and details are not repeated here.
[0150] Determine the security protection processing strategy corresponding to the numerical interval according to the preset correspondence; reference may be made to the above embodiments for description and details are not repeated here.
[0151] where the preset correspondence includes the mapping relationship between the preset numerical interval and the preset security protection processing strategy. Reference may be made to the above embodiments for description and details are not repeated here.
[0152] Figure 4 is the structural schematic diagram of the security protection processing device of the security protection architecture of the power grid data center provided by an embodiment of the present invention, asFigure 4 As shown in Figure 4 , the security protection processing device of the security protection architecture of the power grid data center provided by the embodiment of the present invention includes a calculation unit 401, a determination unit 402, and a protection unit 403, where:
[0153] The calculation unit 401 is configured to calculate, based on the evaluation results of each protection layer for each data sample, the scoring values corresponding to each protection layer respectively; wherein, each of the protection layers is included in the security protection architecture of the power grid data center; the determination unit 402 is configured to calculate, based on a pre-constructed judgment matrix and the total number of data samples, the subjective weight values corresponding to each scoring value respectively, and determine the distribution coefficient between the objective weight value and the subjective weight value according to the difference degree between the objective weight value and the subjective weight value corresponding to each scoring value respectively; wherein, the order of the judgment matrix is equal to the number of protection layers, the diagonal elements are 1, and the ratio of the elements in the latter row above the diagonal to the elements in the previous row reflects the importance degree between two adjacent protection layers, and the elements below the diagonal are the reciprocals of the corresponding elements above the diagonal; the protection unit 403 is configured to determine the combined weight coefficient according to the distribution coefficient, the subjective weight value, and the objective weight value, calculate the security protection architecture evaluation result according to the combined weight coefficient and each scoring value, and determine the corresponding security protection processing strategy according to the security protection architecture evaluation result, so as to implement the security protection processing of the security protection architecture.
[0154] Specifically, the calculation unit 401 in the device is configured to calculate, based on the evaluation results of each protection layer for each data sample, the scoring values corresponding to each protection layer respectively; wherein, each of the protection layers is included in the security protection architecture of the power grid data center; the determination unit 402 is configured to calculate, based on a pre-constructed judgment matrix and the total number of data samples, the subjective weight values corresponding to each scoring value respectively, and determine the distribution coefficient between the objective weight value and the subjective weight value according to the difference degree between the objective weight value and the subjective weight value corresponding to each scoring value respectively; wherein, the order of the judgment matrix is equal to the number of protection layers, the diagonal elements are 1, and the ratio of the elements in the latter row above the diagonal to the elements in the previous row reflects the importance degree between two adjacent protection layers, and the elements below the diagonal are the reciprocals of the corresponding elements above the diagonal; the protection unit 403 is configured to determine the combined weight coefficient according to the distribution coefficient, the subjective weight value, and the objective weight value, calculate the security protection architecture evaluation result according to the combined weight coefficient and each scoring value, and determine the corresponding security protection processing strategy according to the security protection architecture evaluation result, so as to implement the security protection processing of the security protection architecture.
[0155] The security protection processing device of the security protection architecture of the power grid data center provided by the embodiment of the present invention calculates the scoring values corresponding to each protection layer based on the evaluation results of each protection layer for each data sample; wherein, each of the protection layers is included in the security protection architecture of the power grid data center; based on the pre-constructed judgment matrix and the total number of data samples, calculates the subjective weight values corresponding to each scoring value respectively, and determines the distribution coefficient between the objective weight value and the subjective weight value according to the difference degree between the objective weight value and the subjective weight value corresponding to each scoring value respectively; wherein, the order of the judgment matrix is equal to the number of protection layers, the diagonal elements are 1, and the ratio of the elements in the subsequent row above the diagonal to the elements in the previous row reflects the importance degree between two adjacent protection layers, and the elements below the diagonal are the reciprocals of the corresponding elements above the diagonal; determines the combined weight coefficient according to the distribution coefficient, the subjective weight value and the objective weight value, calculates the security protection architecture evaluation result according to the combined weight coefficient and each scoring value, and determines the corresponding security protection processing strategy according to the security protection architecture evaluation result, so as to implement the security protection processing of the security protection architecture, and can more reasonably determine the security protection processing strategy based on a more comprehensive and quantifiable security protection architecture evaluation result, thereby ensuring the safe and stable operation of the power system.
[0156] The embodiment of the security protection processing device of the security protection architecture of the power grid data center provided by the embodiment of the present invention can specifically be used to execute the processing procedures of the above method embodiments, and its functions will not be described in detail here, and reference can be made to the detailed description of the above method embodiments.
[0157] Figure 5 It is a schematic diagram of the physical structure of the electronic device provided by the embodiment of the present invention, as Figure 5 shown, the electronic device includes: a processor 501, a memory 502, and a bus 503;
[0158] Wherein, the processor 501 and the memory 502 communicate with each other through the bus 503;
[0159] The processor 501 is used to call the program instructions in the memory 502 to execute the methods provided by the above method embodiments, for example, including:
[0160] Based on the evaluation results of each protection layer for each data sample respectively, calculates the scoring values corresponding to each protection layer respectively;
[0161] Wherein, each of the protection layers is included in the security protection architecture of the power grid data center;
[0162] Based on a pre - constructed judgment matrix and the total number of data samples, subjective weight values corresponding to each scoring value are calculated. According to the degree of difference between the objective weight value and the subjective weight value corresponding to each scoring value, the distribution coefficient between the objective weight value and the subjective weight value is determined;
[0163] Among them, the order of the judgment matrix is equal to the number of protection layers, the diagonal elements are 1, and the ratio of the elements in the row below the diagonal to the elements in the previous row above the diagonal reflects the importance degree between adjacent two protection layers. The elements below the diagonal are the reciprocals of the corresponding elements above the diagonal;
[0164] According to the distribution coefficient, the subjective weight value and the objective weight value, the combined weight coefficient is determined. According to the combined weight coefficient and each scoring value, the evaluation result of the security protection architecture is calculated, and the corresponding security protection processing strategy is determined according to the evaluation result of the security protection architecture, so as to realize the security protection processing of the security protection architecture.
[0165] This embodiment discloses a computer program product. The computer program product includes a computer program stored on a non - transient computer - readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the methods provided in the above - mentioned method embodiments. For example, it includes:
[0166] Based on the evaluation results of each protection layer for each data sample respectively, the scoring values corresponding to each protection layer are calculated;
[0167] Among them, each protection layer is included in the security protection architecture of the power grid data center;
[0168] Based on a pre - constructed judgment matrix and the total number of data samples, subjective weight values corresponding to each scoring value are calculated. According to the degree of difference between the objective weight value and the subjective weight value corresponding to each scoring value, the distribution coefficient between the objective weight value and the subjective weight value is determined;
[0169] Among them, the order of the judgment matrix is equal to the number of protection layers, the diagonal elements are 1, and the ratio of the elements in the row below the diagonal to the elements in the previous row above the diagonal reflects the importance degree between adjacent two protection layers. The elements below the diagonal are the reciprocals of the corresponding elements above the diagonal;
[0170] According to the distribution coefficient, the subjective weight value and the objective weight value, the combined weight coefficient is determined. According to the combined weight coefficient and each scoring value, the evaluation result of the security protection architecture is calculated, and the corresponding security protection processing strategy is determined according to the evaluation result of the security protection architecture, so as to realize the security protection processing of the security protection architecture.
[0171] This embodiment provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and the computer program causes the computer to execute the methods provided in the foregoing method embodiments, for example, including:
[0172] Based on the evaluation results of each protection layer for each data sample, calculate the scoring values corresponding to each protection layer respectively;
[0173] Among them, each of the protection layers is included in the security protection architecture of the power grid data center;
[0174] Based on the pre-constructed judgment matrix and the total number of data samples, calculate the subjective weight values corresponding to each scoring value respectively. According to the difference degree between the objective weight value and the subjective weight value corresponding to each scoring value, determine the distribution coefficient between the objective weight value and the subjective weight value;
[0175] Among them, the order of the judgment matrix is equal to the number of protection layers, the diagonal elements are 1, and the ratio of the elements in the row behind the diagonal to the elements in the previous row reflects the importance degree between adjacent two protection layers. The elements below the diagonal are the reciprocals of the corresponding elements above the diagonal;
[0176] Determine the combined weight coefficient according to the distribution coefficient, the subjective weight value and the objective weight value. Calculate the security protection architecture evaluation result according to the combined weight coefficient and each scoring value, and determine the corresponding security protection processing strategy according to the security protection architecture evaluation result, so as to implement the security protection processing of the security protection architecture.
[0177] Those skilled in the art should understand that the embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.
[0178] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, and the combination of processes and / or blocks in the flowcharts and / or block diagrams can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate for realizing in the process Figure 1 one process or multiple processes and / or blocksFigure 1 means for the functions specified in one or more boxes.
[0179] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to work in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including an instruction means that implements the functions specified in one Figure 1 process or processes and / or boxes Figure 1 or more boxes.
[0180] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus, such that a series of operational steps are performed on the computer or other programmable apparatus to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one Figure 1 process or processes and / or boxes Figure 1 or more boxes.
[0181] In the description of this specification, descriptions with reference to the terms "one embodiment", "a specific embodiment", "some embodiments", "for example", "example", "specific example", or "some examples", etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.
[0182] The specific embodiments described above further elaborate the objectives, technical solutions, and beneficial effects of the present invention. It should be understood that the above are only specific embodiments of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included in the protection scope of the present invention.
Claims
1. A security protection processing method for a security protection architecture of a power grid data center, characterized in that: include: Based on the evaluation results of each data sample for each protection layer, the scoring values corresponding to each protection layer are calculated; Wherein, each of the protection layers is included in the security protection architecture of the power grid data center; Based on the pre-constructed judgment matrix and the total number of data samples, the subjective weight values corresponding to each scoring score are calculated, and the distribution coefficient between the objective weight value and the subjective weight value is determined according to the degree of difference between the objective weight value and the subjective weight value corresponding to each scoring score; The order of the judgment matrix is equal to the number of protection layers, the diagonal elements are 1, and the ratio of the elements in the next row above the diagonal to the elements in the previous row reflects the importance between two adjacent protection layers, and the elements below the diagonal are the reciprocals of the corresponding elements above the diagonal; A combined weight coefficient is determined according to the allocation coefficient, the subjective weight value and the objective weight value, a security protection architecture evaluation result is calculated according to the combined weight coefficient and each scoring score, and a corresponding security protection processing strategy is determined according to the security protection architecture evaluation result to implement security protection processing for the security protection architecture.
2. The security protection processing method for the security protection architecture of the power grid data center according to claim 1 is characterized in that: The evaluation results of each protection layer based on each data sample are used to calculate the scoring values corresponding to each protection layer, including: The sum of the evaluation results corresponding to each protection layer is calculated, and the ratio of the sum of the evaluation results to the total number of data samples is used as the scoring value corresponding to each protection layer.
3. The security protection processing method for the security protection architecture of the power grid data center according to claim 1 is characterized in that: The subjective weight values corresponding to the respective scoring scores are calculated based on the pre-constructed judgment matrix and the total number of data samples, including: Solving the maximum eigenvalue of the judgment matrix, and performing a consistency check on the judgment matrix according to the maximum eigenvalue and the total number of data samples; If it is determined that the consistency check result is less than the preset threshold, the subjective weight value is determined according to the elements in the judgment matrix at this time.
4. The security protection processing method for the security protection architecture of the power grid data center according to claim 3 is characterized in that: The security protection processing method of the security protection architecture of the power grid data center also includes: If it is determined that the consistency check result is greater than or equal to a preset threshold, optimizing the elements in the judgment matrix using a genetic algorithm; The subjective weight value is determined according to the optimized elements in the optimized judgment matrix.
5. The security protection processing method for the security protection architecture of the power grid data center according to claim 1 is characterized in that: The security protection processing method of the security protection architecture of the power grid data center also includes: The entropy weight method is used to determine the objective weight values corresponding to each scoring score.
6. The security protection processing method for the security protection architecture of the power grid data center according to claim 1 is characterized in that: The step of determining the distribution coefficient between the objective weight value and the subjective weight value according to the difference between the objective weight value and the subjective weight value respectively corresponding to each scoring score includes: The difference degree is expressed according to the mean square error expression, and the allocation coefficient is obtained by solving based on the following constraints: α+β=1 Among them, MSE is the mean square error, Z j is the subjective weight value corresponding to the jth protection layer, W j is the objective weight value corresponding to the jth protection layer, α is the allocation coefficient corresponding to the subjective weight value, and β is the allocation coefficient corresponding to the objective weight value.
7. The security protection processing method for the security protection architecture of the power grid data center according to claim 1 is characterized in that: Determining a corresponding security protection processing strategy according to the security protection architecture evaluation result includes: Determine the numerical interval in which the numerical value corresponding to the security protection architecture evaluation result lies according to the preset numerical interval; Determine a security protection processing strategy corresponding to the numerical range according to a preset corresponding relationship; Among them, the preset corresponding relationship includes a mapping relationship between the preset numerical range and the preset security protection processing strategy.
8. A security protection processing device for a security protection architecture of a power grid data center, characterized in that: include: A calculation unit, used to calculate the scoring values corresponding to each protection layer based on the evaluation results of each data sample on each protection layer; Wherein, each of the protection layers is included in the security protection architecture of the power grid data center; A determination unit, for calculating the subjective weight values corresponding to each scoring score based on a pre-constructed judgment matrix and the total number of data samples, and determining a distribution coefficient between the objective weight value and the subjective weight value according to the degree of difference between the objective weight value and the subjective weight value corresponding to each scoring score; The order of the judgment matrix is equal to the number of protection layers, the diagonal elements are 1, and the ratio of the elements in the next row above the diagonal to the elements in the previous row reflects the importance between two adjacent protection layers, and the elements below the diagonal are the reciprocals of the corresponding elements above the diagonal; A protection unit is used to determine a combined weight coefficient according to the allocation coefficient, the subjective weight value and the objective weight value, calculate a security protection architecture evaluation result according to the combined weight coefficient and each scoring score, and determine a corresponding security protection processing strategy according to the security protection architecture evaluation result to implement security protection processing on the security protection architecture.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Cited By
Method and device for evaluating safety protection capability of power optical transmission system
CN121012679A