Power grid terminal safety protection system and method based on large language model
By using a large language model to analyze unstructured data to identify security events and generate dynamic defense response strategies in the power grid terminal security protection system, the problems of weak unstructured data processing capabilities and lagging dynamic threat response in the existing technology are solved, and the reliability of grid terminal security protection is improved.
Patent Information
- Application Number
- CN202510345380.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-24
- Publication Date
- 2025-06-24
AI Technical Summary
Existing power grid terminal security technology is difficult to effectively analyze unstructured data, and dynamic threat response is lagging, resulting in low reliability of power grid terminal security protection.
The power grid terminal security protection system based on the large language model is adopted, and structured and unstructured data are collected in real time through the multi-source data acquisition module. The large language model enhancement analysis module analyzes unstructured data to identify security events, generates multi-stage attack chains, and generates dynamic defense response strategies based on the attack chains.
It improves the reliability of grid terminal security protection, can adapt to complex attack modes in real time, and improves the processing capability of unstructured data and the efficiency of dynamic threat response.
Smart Images

Figure CN120200801A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of power grid terminal information security, and in particular, to a power grid terminal security protection system and method based on a large language model. Background Art
[0002] With the development of smart power grids, the number and types of power grid terminal devices are increasing continuously, including smart meters, substation equipment, distributed energy management systems, etc. These devices have become important entry points for hackers to attack power grid systems.
[0003] Traditional power grid terminal security technologies rely on static rules and signature libraries, and have the following deficiencies: weak unstructured data processing capabilities, making it difficult to effectively analyze potential threats in unstructured data such as operation record documents, surveillance videos, and device communication records; lagging dynamic threat response, with increasingly complex attack patterns, and static defense strategies unable to adapt to multi-stage attack chains in real time; resulting in low reliability of power grid terminal security protection.
[0004] In view of this problem, the present invention provides a power grid terminal security protection system and method based on a large language model to solve the above problems. Summary of the Invention
[0005] In order to solve the problems existing in the prior art, the present invention innovatively proposes a power grid terminal security protection system and method based on a large language model, effectively solving the problem of low reliability of power grid terminal security protection caused by the prior art, and effectively improving the reliability of power grid terminal security protection.
[0006] In the first aspect of the present invention, a power grid terminal security protection system based on a large language model is provided, including:
[0007] A multi-source data acquisition module for real-time acquisition of structured and unstructured data of power grid terminals, where the structured data includes system logs, network traffic data, and device operation data, and the unstructured data includes operation record documents, surveillance video content, and device communication records; the power grid terminal is a terminal device deployed on the edge side of the power system;
[0008] A large language model enhanced analysis module for parsing the unstructured data of power grid terminals through a large language model in the power field to identify edge-side security events for power grid terminals; generating a multi-stage attack chain based on a pre-built power attack knowledge base, structured data, and unstructured data of power grid terminals; calculating the load loss rate and voltage qualification rate deviation value caused by the generated attack chain, and generating a dynamic defense response strategy related to the operation mode of the power grid terminal according to the load loss rate and voltage qualification rate deviation value caused by the attack chain;
[0009] A security assessment module, which is used to parse the structured data and unstructured data of grid terminals according to a large language model in the power field, calculate the grid terminal security risk index based on a dynamic security scoring model, and determine the corresponding vulnerability repair strategy for the grid terminal according to the grid terminal security risk index; the dynamic defense response strategy includes the corresponding vulnerability repair strategy for the grid terminal;
[0010] An interaction and output module, which is used to generate a three-dimensional grid threat map composed of grid terminals according to a multi-stage attack chain and mark the attack path; and push the dynamic defense response strategy and the vulnerability repair strategy to the dispatching center in real time.
[0011] The second aspect of the present invention provides a grid terminal security protection method based on a large language model, which is implemented on the basis of the grid terminal security protection system based on a large language model described in the first aspect of the present invention, and includes:
[0012] A multi-source data acquisition module collects the structured data and unstructured data of grid terminals in real time. The structured data includes system logs, network traffic data, and device operation data, and the unstructured data includes operation record documents, monitoring video content, and device communication records; the grid terminal is a terminal device deployed on the edge side of the power system;
[0013] A large language model enhanced analysis module parses the unstructured data of grid terminals through a large language model in the power field to identify edge-side security events for grid terminals; generates a multi-stage attack chain based on a pre-built power attack knowledge base, the structured data and unstructured data of grid terminals; calculates the load loss rate and voltage qualification rate deviation value caused by the generated attack chain, and generates a dynamic defense response strategy related to the grid terminal operation mode according to the load loss rate and voltage qualification rate deviation value caused by the attack chain;
[0014] A security assessment module parses the structured data and unstructured data of grid terminals according to a large language model in the power field, calculates the grid terminal security risk index based on a dynamic security scoring model, and determines the corresponding vulnerability repair strategy for the grid terminal according to the grid terminal security risk index; the dynamic defense response strategy includes the corresponding vulnerability repair strategy for the grid terminal;
[0015] An interaction and output module generates a three-dimensional grid threat map composed of grid terminals according to a multi-stage attack chain and marks the attack path; and pushes the dynamic defense response strategy and the vulnerability repair strategy to the dispatching center in real time.
[0016] The technical solutions adopted by the present invention include the following technical effects:
[0017] 1. The large language model enhanced analysis module of the present invention can parse unstructured data of power grid terminals, identify edge-side security events for power grid terminals; generate multi-stage attack chains based on a pre-built power attack knowledge base, structured data, and unstructured data of power grid terminals; generate dynamic defense response strategies related to the operation mode of power grid terminals according to the load loss rate and voltage qualification rate deviation values caused by the attack chains; the security assessment module can parse the structured data and unstructured data of power grid terminals according to the large language model, calculate the power grid terminal security risk index based on a dynamic security scoring model, and determine the corresponding vulnerability repair strategy for the power grid terminal according to the power grid terminal security risk index; the interaction and output module can generate a three-dimensional power grid threat map composed of power grid terminals according to the multi-stage attack chain, mark the attack path; and push the dynamic defense response strategy and the vulnerability repair strategy to the dispatching center in real time, effectively solving the problem of low reliability of power grid terminal security protection caused by the existing technology and effectively improving the reliability of power grid terminal security protection.
[0018] 2. In the technical solution of the present invention, the threat inference sub-module in the large language model enhanced analysis module can dynamically correct the attack feasibility path through the distribution network topology constraint and the power business time sequence constraint, making the generated simulated attack chain more conform to the actual structure and actual power business of the distribution network; the dynamic strategy generation sub-module can calculate the load loss rate and / or voltage qualification rate deviation value caused by the attack chain, and when the load loss rate is greater than the preset loss rate threshold, and / or, the voltage qualification rate deviation value exceeds the first preset percentage threshold, generate a dynamic defense response strategy related to the operation mode of the power grid terminal. The dynamic defense response strategy includes isolation instructions, load distribution adjustment instructions, and the first priority vulnerability repair strategy for the power grid terminals involved in the attack chain. The first priority vulnerability repair strategy is that the repair priorities of the power grid terminal online operation mode, test and debugging mode, and maintenance mode decrease in turn, improving the adaptability of the dynamic defense response strategy.
[0019] 3. In the technical solution of the present invention, the security assessment module can not only parse the structured data and unstructured data of power grid terminals, identify abnormal behavior patterns of power grid terminal users; but also trigger physical blocking of the peripheral ports of power grid terminals and secondary authentication of dispatching instructions when detecting abnormalities, and at the same time associate the abnormal events with the power security control platform to generate violation work orders; the security assessment sub-module determines the corresponding vulnerability repair strategy for the power grid terminal according to the power grid terminal security risk index; the corresponding vulnerability repair strategy for the power grid terminal is the second priority vulnerability repair strategy. The second priority vulnerability repair strategy is that according to the level of the power grid terminal security risk index, the vulnerability repair priorities decrease in turn, and the execution order of the second priority is less than that of the first priority, further improving the adaptability of the dynamic defense response strategy.
[0020] 4. In the technical solution of the present invention, the dynamic security scoring model can be dynamically adjusted according to the actual situation, further improving the reliability of power grid terminal security protection.
[0021] 5. In the technical solution of the present invention, the security assessment module further includes a terminal status prediction sub-module. The terminal status prediction sub-module is used to predict the fault risk of the power grid terminal by using the large language model in the power field and the LSTM neural network. After predicting the fault risk of the power grid terminal, it triggers the firmware rollback mechanism of the power grid terminal to automatically restore to the trusted version signed by CA, switches the communication channel, and at the same time links the equipment maintenance system to generate preventive maintenance work orders, further improving the reliability of power grid terminal security protection.
[0022] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0024] Figure 1 It is a schematic structural diagram of the system in the first embodiment of the present invention;
[0025] Figure 2 It is a schematic flowchart of a method in the second embodiment of the present invention;
[0026] Figure 3 It is another schematic flowchart of the method in the second embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0027] In order to clearly illustrate the technical features of the present solution, the present invention will be described in detail below through specific embodiments and in combination with their drawings. The following disclosure provides many different embodiments or examples for implementing different structures of the present invention. To simplify the disclosure of the present invention, the components and settings of specific examples are described below. In addition, the present invention may repeat reference numerals and / or letters in different examples. This repetition is for the purpose of simplification and clarity, and does not itself indicate the relationship between the various embodiments and / or settings discussed. It should be noted that the components illustrated in the drawings are not necessarily drawn to scale. The present invention omits the description of well-known components and processing technologies and processes to avoid unnecessarily limiting the present invention.
[0028] Embodiment 1
[0029] As Figure 1As shown in the figure, the present invention provides a power grid terminal security protection system based on a large language model, including:
[0030] A multi-source data acquisition module 1, which is used to collect structured data and unstructured data of the power grid terminal in real time. The structured data includes system logs, network traffic data, and device operation data, and the unstructured data includes operation record documents, monitoring video content, and device communication records; the power grid terminal is a terminal device deployed on the edge side of the power system;
[0031] A large language model enhanced analysis module 2, which is used to parse the unstructured data of the power grid terminal through a large language model in the power field to identify edge-side security events for the power grid terminal; generate a multi-stage attack chain based on a pre-built power attack knowledge base, the structured data, and the unstructured data of the power grid terminal; calculate the load loss rate and the voltage qualification rate deviation value caused by the generated attack chain, and generate a dynamic defense response strategy related to the operation mode of the power grid terminal according to the load loss rate and the voltage qualification rate deviation value caused by the attack chain;
[0032] A security assessment module 3, which is used to parse the structured data and the unstructured data of the power grid terminal according to a large language model in the power field, calculate the power grid terminal security risk index based on a dynamic security scoring model, and determine the corresponding vulnerability repair strategy for the power grid terminal according to the power grid terminal security risk index; the dynamic defense response strategy includes the corresponding vulnerability repair strategy for the power grid terminal;
[0033] An interaction and output module 4, which is used to generate a three-dimensional power grid threat map composed of power grid terminals according to the multi-stage attack chain and mark the attack path; push the dynamic defense response strategy and the vulnerability repair strategy to the dispatching center in real time.
[0034] Among them, the power grid terminals in the multi-source data acquisition module 1 include distribution automation terminals, user-side smart meters, and distributed energy interface devices. The deployment locations of the distribution automation terminals are the feeder nodes of the distribution network, the deployment locations of the user-side smart meters are the access points for industrial and commercial users, and the deployment locations of the distributed energy interface devices are the grid connection points of distributed photovoltaics. The multi-source data acquisition module 1 supports the parsing and standardization of multiple power grid protocols, including DL / T634.5104, DL / T 860, and IEC 61850. The power grid terminals specifically refer to the terminal devices deployed on the edge side of the power system, including distribution automation terminals (DTU / FTU), user-side smart meters (AMI), and distributed energy interface devices (DER Gateway), which are different from the SCADA servers or substation monitoring hosts of the power grid master station system. The deployment locations of the terminal devices are three types of edge scenarios: the feeder nodes of the distribution network, the access points for industrial and commercial users, and the grid connection points of distributed photovoltaics. The acquisition method adopts a real-time data stream processing architecture oriented to the physical characteristics of power equipment, and protocol parsing and feature extraction are completed on the terminal side. The multi-source data acquisition module is built-in with a deep packet inspection (DPI) engine for power protocols, supporting the application layer semantic parsing of communication messages on the edge side, forming a technical difference from the batch log acquisition method adopted by the centralized security evaluation system. At the same time, a lightweight Modbus-TCP protocol adapter is integrated, which is specifically optimized for the communication characteristics of user-side smart meters.
[0035] The sub-modules included in the multi-source data acquisition module 1 are:
[0036] The terminal log acquisition sub-module 11: acquires the operation logs and alarm data of smart meters and substation controllers;
[0037] The physical state monitoring sub-module 12: integrates temperature sensors and voltage monitors to acquire terminal physical state data in real time;
[0038] The protocol traffic parsing sub-module 13: supports the encrypted traffic parsing of protocols such as TCP, UDP, and DL / T 634.5104;
[0039] The edge computing sub-module 14: is deployed at the edge computing device nodes of the substation to achieve local data preprocessing and low-latency transmission.
[0040] The large language model enhanced analysis module 2 includes a semantic understanding sub-module 21, a threat inference sub-module 22, and a dynamic defense response strategy generation sub-module 23.
[0041] The semantic understanding sub-module 21 is used to parse unstructured text data through a large language model in the power field, and extract edge-side security events for grid terminals that include malicious operation record fingerprint features, semantic patterns of device parameter tampering, and false data injection instruction structures; the training data set of the large language model in the power field can include grid terminal device operation manuals, historical monitoring video samples, false data injection attack cases, etc., and the accuracy rate of parsing power professional terms by the fine-tuned large language model in the power field can reach ≥98%.
[0042] Among them, the large language model in the power field is an LLM (Large Language Model) fine-tuned through a knowledge graph in the power field.
[0043] The threat inference sub-module 22 is used to construct a power attack knowledge base based on edge-side security events, grid terminal structured data, and unstructured data, and generate multi-stage attack chain hypotheses based on the pre-built power attack knowledge base, grid terminal structured data, and unstructured data. The power attack knowledge base at least includes a grid terminal firmware vulnerability mapping table, an attack pattern feature matrix, and an edge-side attack sample library, and dynamically corrects the attack feasibility path through distribution network topology constraints and power service time series constraints; among them, the grid terminal firmware vulnerability mapping table stores the corresponding relationships between each grid terminal, firmware, protocol stack version, firmware vulnerability, associated firmware vulnerability, protocol stack version corresponding to the associated firmware vulnerability, firmware to which the protocol stack version corresponding to the associated firmware vulnerability belongs, and the grid terminal where the firmware to which the protocol stack version corresponding to the associated firmware vulnerability belongs is located. The attack pattern feature matrix includes protocol layer attack feature vectors classified according to power system data communication security standards, and the edge-side attack sample library includes grid terminal rate tampering operation sequences and grid terminal false telecontrol signal message time series patterns.
[0044] Among them, multi-stage attack chain hypotheses are generated based on the power attack knowledge base. The power attack knowledge base is constructed using a CPS (Cyber-Physical System in Power) joint modeling method, and includes a distribution terminal firmware vulnerability mapping table (associating CVE-ID with IEC60870-5-104 protocol stack version), an attack pattern feature matrix (protocol layer attack feature vectors classified according to IEC 62351 standard), and an edge-side attack sample library (including smart meter rate tampering operation sequences and DTU false telecontrol signal message time series patterns), and dynamically corrects the attack feasibility path through the functional constraints of terminal devices described in SCL language.
[0045] The power grid terminal firmware vulnerability mapping table stores the corresponding relationships among each power grid terminal, firmware, protocol stack version, firmware vulnerability, associated firmware vulnerability, the protocol stack version corresponding to the associated firmware vulnerability, the firmware to which the protocol stack version corresponding to the associated firmware vulnerability belongs, and the power grid terminal where the firmware to which the protocol stack version corresponding to the associated firmware vulnerability belongs is located. Its form can be shown in Table 1 below:
[0046]
[0047]
[0048] A power grid terminal may include multiple firmware versions. The same firmware may include one or more protocol stack versions. Each protocol stack version may have one or more vulnerabilities. There are association relationships such as attack dependencies and attack sequences between vulnerabilities (to attack vulnerability A, vulnerability B must be attacked first). Table 1 only shows some attributes because the association relationships between vulnerabilities may be two or more (one vulnerability may be associated with multiple vulnerabilities at the same time, or there may be a one-to-one sequential association relationship between multiple vulnerabilities, that is, vulnerability A is associated with vulnerability B or vulnerability C; it may also be that vulnerability A is associated with vulnerability B, and vulnerability B is associated with vulnerability C). This embodiment will not elaborate here. Through the power grid terminal firmware vulnerability mapping table, multiple possible attack paths between different power grid terminals can be obtained.
[0049] The specific process of attack chain generation is not limited in this embodiment. Only the distribution network topology constraint and the power business time sequence constraint are introduced during the attack chain generation process.
[0050] The distribution network topology constraint is specifically as follows: Based on the GIS coordinates of the feeder section, a directed graph of attack propagation is established. The attributes of the power grid terminal nodes include the criticality score of the terminal device assets (classified according to the IEC 61850 logical node type and assigned different scores. Taking a full score of 10 as an example, for nodes with a high level, 6 - 10 points are assigned; for nodes with a low level, 1 - 5 points can be assigned. The specific levels and score assignments can be set flexibly and are not limited in this embodiment). The edge weight fuses the communication protocol type and the physical distance parameter. The attribute information of the power grid terminal nodes and the attack stage affect the attack chain generation from the following dimensions: The node criticality score constructs an attack path screening mechanism. High-value power grid terminal nodes will form necessary nodes for attacks, while low-value power grid terminal nodes can form roundabout attack paths; the edge weight parameter establishes an attack propagation feasibility evaluation model. The communication protocol defect and physical proximity jointly determine the success rate of lateral movement.
[0051] The division of attack phases also needs to meet the time sequence constraints of power services, including ① the AMI user data theft phase (synchronized with the electricity bill settlement cycle), ② the DER grid connection command forgery phase (which needs to conform to the AGC regulation time window), and ③ the feeder protection misoperation triggering phase (matching the circuit breaker opening time delay); that is, the time sequence constraints construct the logical relationship of attack phases, and each attack step needs to meet the sequential dependence relationship of the power service time window. For example, the user data theft phase needs to be completed before the electricity bill calculation time point, the grid connection command forgery phase needs to conform to the AGC regulation time window, and the feeder protection misoperation triggering phase needs to cooperate with the circuit breaker opening action delay, thus forming a multi-stage attack chain with the time sequence characteristics of power services.
[0052] The dynamic policy generation sub-module 23 is used to calculate the load loss rate and / or the deviation value of the voltage qualification rate caused by the attack chain according to the embedded PSCAD power model. When the load loss rate is greater than the preset loss rate threshold, and / or, the deviation value of the voltage qualification rate exceeds the first preset percentage threshold, a dynamic defense response policy related to the grid terminal operation mode is generated. The dynamic defense response policy includes isolation instructions for the grid terminals involved in the attack chain, load distribution adjustment instructions, and the first-priority vulnerability repair policy. The first-priority vulnerability repair policy means that the repair priorities for the grid terminal online operation mode, test and debugging mode, and maintenance and repair mode decrease in sequence.
[0053] Specifically, the CPS co-simulation engine is used to quantitatively evaluate the impact of attacks. The PSCAD (Power Systems Computer Aided Design, a widely used electromagnetic transient simulation software) power model is embedded in the OPNET network simulation (OPNET is a network simulation technology software package) to calculate and simulate the load loss rate (affected load capacity / total feeder capacity × attack success rate) and voltage qualification rate deviation value caused by the attack chain. When the load loss rate > 15% (preset loss rate threshold), and / or the voltage deviation exceeds ±7% (first preset percentage threshold), it is determined as a high-risk threat, and a dynamic defense response strategy related to the grid terminal operation mode is generated. The dynamic defense response strategy includes isolation instructions for the grid terminals involved in the attack chain, load distribution adjustment instructions, and the first-priority vulnerability repair strategy. The first-priority vulnerability repair strategy has the repair priorities decreasing in sequence for the grid terminal online operation mode, test and debugging mode, and maintenance mode. For example, if the FTU is detected to be in the maintenance mode, the associated vulnerability repair priority is reduced, and the collaborative execution timing of the terminal isolation instruction and the load distribution adjustment strategy is optimized through the reinforcement learning algorithm; when the distribution terminal is in the real-time online operation mode, the associated vulnerability repair priority should be increased. At this time, the terminal device is on the critical path of production control, and the exploitation of vulnerabilities will directly threaten the real-time operation safety of the grid; the corresponding relationship between the vulnerability repair priority and the distribution terminal is as follows: the vulnerability repair priority is the highest in the real-time online mode, followed by the test and debugging mode, and the lowest in the maintenance mode; this grading mechanism is based on the impact degree of the device operation state on the real-time control of the grid. In the online mode, the terminal bears the real-time load control and protection functions, and the existence of vulnerabilities will lead to higher-level security risks, so it needs to be disposed of first.
[0054] The security assessment module 3 includes a behavior anomaly detection sub-module 31 and a security assessment sub-module 32. The behavior anomaly detection sub-module 31 is used to parse the structured data and unstructured data of the grid terminal according to the large language model in the power field and the real-time rule engine, and identify the abnormal behavior patterns of the grid terminal users; among them, the abnormal behavior patterns of users include unauthorized tampering of dispatching instructions, cross-position permission boundary crossing operations, maintenance plan conflict operations, dispatching operation time conflicts, peripheral access whitelist conflicts, and operation frequency threshold conflicts; when an anomaly is detected, the physical blockage of the peripheral ports of the grid terminal and the secondary authentication of the dispatching instructions are triggered, and at the same time, the anomaly event is associated with the power security control platform to generate a violation work order;
[0055] Specifically, by combining the LLM with a real-time rule engine, abnormal behaviors in the power grid end-user behavior are identified. Based on the power domain LLM model fine-tuned with power work order operation logs, the semantic context of the office end-user operations is parsed to identify abnormal behavior patterns, including unauthorized dispatching instruction tampering (abnormal matching of IEC 62351-6 standard instruction signatures), cross-position permission overstep operations (violating the NERC CIP permission matrix, where NERC CIP is a cybersecurity standard for critical infrastructure protection), and maintenance plan conflict operations (deviation from the OMS system work order time window > 15 minutes, and the OMS system is the outage management system); the real-time rule engine has a built-in power business operation sequence rule library, including dispatching operation time constraints (the interval between control instructions needs to be ≥ T + 3 minutes), peripheral access whitelist conflicts (only encrypted USBs and dispatching key sticks are allowed), and operation frequency threshold conflicts (the number of work order submissions per unit time exceeds 2σ of the historical baseline, that is, exceeds twice the standard deviation of the historical baseline). Rule matching is implemented using FPGA hardware acceleration to achieve sub-second response; the detection dimension integrates multi-modal data streams, including keyboard operation entropy values (detecting scripted input features), screen behavior heat maps (identifying non-artificial operation trajectories), and network session fingerprints (comparing power security access gateway authentication features), to construct a dynamic user behavior profile; when an abnormality is detected, it triggers physical blocking of the terminal peripheral ports (disabling the USB interface through GPIO control) and secondary authentication of dispatching instructions (requiring synchronous verification of the smart key and iris features). At the same time, the abnormal event is associated with the power security control platform to generate a violation work order. The blocking status is linked to the maintenance plan, and the blocking is automatically lifted when the terminal accesses the distribution network maintenance isolation area.
[0056] The security scoring sub-module 32 is used to calculate the power grid terminal security risk index based on the dynamic security scoring model, and determine the corresponding vulnerability repair strategy for the power grid terminal according to the power grid terminal security risk index; the corresponding vulnerability repair strategy for the power grid terminal is the second-priority vulnerability repair strategy. The second-priority vulnerability repair strategy is that according to the level of the power grid terminal security risk index, the vulnerability repair priorities decrease in turn, and the execution order of the second priority is less than that of the first priority.
[0057] Among them, the dynamic security scoring model is specifically:
[0058] S = α×R + β×C + γ×V + δ×L,
[0059] Among them, α, β, γ, and δ are the power supply reliability weight, attack control ability, vulnerability impact score, and confidence score weight coefficient of the large language model in the power domain respectively, which can be optimized in real time through the federated learning framework; S is the power grid terminal security risk index; R is the power supply reliability weight; C is the attack control ability; V is the vulnerability impact score, and L is the confidence score of the large language model; the higher the power grid terminal security risk index, the greater the security risk.
[0060] Specifically, the power supply reliability weight can be obtained through load level mapping and operation history data analysis. Specifically, it is the product of the load power supply area empowerment value and the correction coefficient. Among them, the empowerment value of the first-level load power supply area is 0.9, the empowerment value of the second-level load area is 0.6, and the empowerment value of the third-level load area is 0.3. And it is dynamically corrected in combination with the power supply availability index of this area in the past three years. The correction coefficient is the square of the product between the actual power supply availability and the target power supply availability, that is, (actual power supply availability / target power supply availability)^2.
[0061] The attack control ability is the sum of the vulnerability score, the attack chain penetration depth coefficient, and the protocol vulnerability multiplier. Among them, the vulnerability score uses a vulnerability threat quantification model to score the vulnerabilities involved in the attack path based on the CVSS vulnerability scoring framework; the attack control ability calculation uses a vulnerability threat quantification model to perform a basic score on the vulnerabilities involved in the attack path based on the CVSS (Common Vulnerability Scoring System) vulnerability scoring framework. The attack chain penetration depth coefficient is specifically: the main station layer attack coefficient is 1.0, the station control layer is 0.7, and the terminal layer is 0.4; the protocol vulnerability multiplier: plaintext protocol × 1.5, encrypted protocol × 0.8. Finally, a quantization index in the 0-1 interval is generated through the normalization processing of the sum of the vulnerability score, the attack chain penetration depth coefficient, and the protocol vulnerability multiplier.
[0062] The specific way to obtain the vulnerability impact score is as follows:
[0063] , where S vi is the severity of the i-th vulnerability; E vi is the vulnerability susceptibility of the i-th vulnerability; I vi is the impact range of the i-th vulnerability; among them, if the i-th vulnerability is located at the power grid terminal, the vulnerability impact score (V) of this power grid terminal is dynamically weighted according to the topological importance of this power grid terminal in the power grid, and all weights can be increased by 30% - 50% accordingly.
[0064] The vulnerability severity S vi can be based on the automatic mapping of the power grid terminal device firmware version and the CVE vulnerability library, and by parsing the <swversion>The label obtains the firmware version, matches the CVSSv3 Attack Complexity metric in the NVD database (National Vulnerability Database), sets the initial default value, and then when it is detected that the attack path needs to meet the physical adjacency condition (the attacker needs to be within 300 meters of the feeder radius), triggers the severity weighting factor × 1.5, that is, the initial default value * 1.5, until the set maximum value is reached;
[0065] Vulnerability susceptibility E vi It can be quantified by real-time network traffic characteristics, calculating the number of abnormal GOOSE message (Generic Object Oriented Substation Event, a fast message transmission mechanism in IEC 61850 for transmitting important real-time signals between grid terminals in a substation) replay times per unit time (>5 times / second triggers the threshold) and the occurrence frequency of Modbus TCP abnormal function codes (deviating from the baseline value by 2σ, that is, 3 times the standard deviation from the baseline value), combined with the terminal port open status (comparing the nmap scan results with the IEC 62351-3 secure communication matrix); the number of abnormal GOOSE message replay times is statistically calculated by the Deep Packet Inspection (DPI) technology for the number of retransmitted messages at the transport layer per second. When repeated sequence number messages exceeding 5 times / second continuously appear within the detection window, it is determined as a malicious replay attack behavior, and the deviation degree of the trigger times from the baseline value is quantified according to (measured value / threshold)^2; the detection of Modbus TCP abnormal function codes adopts a sliding time window statistical mechanism, calculating the standard deviation of the function code type distribution with a 15-minute cycle. When the occurrence frequency of a specific function code exceeds 2 times the standard deviation of the historical baseline mean, a protocol exception event is generated, and its risk intensity is calculated according to (deviation value / baseline value) × protocol type risk coefficient (write / read function codes × 1.2, read-only × 0.8); the exposure risk of the terminal port (authorized open port) is evaluated through a security compliance matrix. Based on the IEC62351-3 standard, a port-service mapping whitelist is constructed and compared with the nmap active scan results, that is, comparing the non-compliance rate; the risk value of the unauthorized open port = Σ (port risk level × service exposure duration), where high-risk ports (such as TCP / 502) are assigned a weight value of 1.0, medium-risk ports 0.6, and low-risk ports 0.3, that is, E vi = The sum of the number of abnormal GOOSE message replay times per unit time, the occurrence frequency of Modbus TCP abnormal function codes, and the exposure risk of the terminal port.
[0066] Vulnerability impact range I vi Calculated based on the electrical connectivity of grid terminal devices in the distribution network topology, using the Betweenness Centrality algorithm to quantify the criticality of the device (establishing a mapping relationship between the calculation result after passing through the Betweenness Centrality algorithm of the electrical connectivity and the device criticality score, that is, the higher the calculation result, the higher the score).
[0067] Dynamically adjust the vulnerability weight S according to the analysis results of the LLM on real-time attack patterns vi 、E vi 、I vi ; combine the physical state data of grid equipment (such as temperature, voltage fluctuation) to correct the security scoring parameters. Among them, the severity of the vulnerability represents the degree of damage that the vulnerability may cause, the vulnerability's susceptibility to attack represents the ease of exploitation of the vulnerability, the scope of impact of the vulnerability represents the scope of impact of the vulnerability on the operation of the power grid, and the vulnerability repair priority represents the urgency of vulnerability repair;
[0068] Specifically, by real-time monitoring the physical state data of grid equipment, such as temperature, voltage fluctuation, etc., evaluate the operation status and health condition of the equipment; when the equipment shows abnormal temperature rise or voltage fluctuation, adjust the security scoring parameters accordingly to reflect the security risks of the equipment in the current state. For example, if the temperature of a certain equipment rises abnormally, it may indicate that the equipment has an overload or fault risk. At this time, the repair priority of the vulnerabilities related to this equipment will be reduced, and at the same time, its security score will be increased to prompt that maintenance and repair need to be carried out as soon as possible. In this way, the dynamic security scoring model can more accurately reflect the actual security condition of the power grid and provide more effective guarantee for the safe operation of the power grid.
[0069] The specific method for obtaining the confidence score L of the large language model in the power field is as follows:
[0070] L = w1×A + w2×C h + w3×H,
[0071] where A is the semantic analysis accuracy rate; C h is the logical consistency score, H is the credibility of historical detection results, and w1, w2, w3 are the weighting coefficients of the semantic analysis accuracy rate, logical consistency score, and credibility of historical detection results respectively, and the sum is 1;
[0072] The semantic analysis accuracy rate A can be obtained through the closed-loop verification of power dispatching work orders. Match the instruction types parsed by the LLM with the actual execution status codes recorded in the OMS system. When the parsing results of the circuit breaker opening and closing instructions and protection setting modification instructions are consistent with the work order operation logs, it is determined as a valid hit; take the ratio of the number of valid hits to the total number of matches as the semantic analysis accuracy rate A.
[0073] C h For the logical consistency score (interpretability of the LLM inference process), it can be calculated based on the IEC 61850 logical node coverage. By comparing the device function nodes activated during the LLM inference process with the legitimate operation paths defined in the SCL configuration file, the score weight is reduced when unauthorized logical nodes (such as unconfigured remote adjustment commands) are detected. That is, the percentage ratio of the number of authorized logical nodes detected to the total number of logical nodes is used as the logical consistency score;
[0074] H is the credibility of historical detection results (false alarm rate ≤ 2%), which can be dynamically calculated based on the false alarm rate of the terminal security incident handling work orders. The proportion of invalid alarm work orders confirmed by security personnel is statistically calculated, and the credibility decay mechanism is triggered when the false alarm rate exceeds the preset threshold;
[0075] The weighting coefficients w1, w2, and w3 can be dynamically adjusted according to the terminal communication quality. When the PTP clock synchronization deviation is detected to exceed 1 microsecond, the semantic analysis weight is reduced. When the MAC layer data frame retransmission rate exceeds 5%, the logical consistency weight is increased to form an adaptive scoring system for power service reliability.
[0076] Moreover, the power supply reliability weight, attack control ability, vulnerability impact score, confidence score weighting coefficient of the large language model in the power domain, power supply reliability weight, attack control ability, vulnerability impact score, and confidence score of the large language model in the power domain support dynamic adjustment.
[0077] Furthermore, the security assessment module 3 also includes a terminal status prediction sub-module 33. The terminal status prediction sub-module 33 is used to predict the grid terminal fault risk by using the large language model in the power domain and the LSTM neural network. Among them, the large language model in the power domain analyzes the SCL configuration change records and unstructured alarm texts, and extracts the characteristics of abnormal firmware upgrades of grid terminal devices and the characteristics of GOOSE message replay attack signs. The LSTM neural network analyzes the temporal correlation of the grid terminal temperature characteristics, voltage harmonic distortion rate characteristics, and CRC error frame rate characteristics, and constructs a multi-dimensional fault feature vector based on the characteristics of abnormal firmware upgrades of grid terminal devices, the characteristics of GOOSE message replay attack signs, the grid terminal temperature characteristics, the voltage harmonic distortion rate characteristics, and the CRC error frame rate characteristics to predict the grid terminal fault risk;
[0078] Specifically, by leveraging the time series analysis capabilities of the LLM and the LSTM neural network, the fault risk of the power grid terminal is predicted. It is a hybrid prediction model based on the joint training of power equipment operation logs and communication messages. The LLM component processes SCL configuration change records and unstructured alarm texts through the IEC 61850-7-4 semantic parsing framework, extracts features of abnormal device firmware upgrades (matching the CVE vulnerability version number pattern) and signs of GOOSE message replay attacks (number of jumps > 5 times within 3 consecutive cycles). The LSTM neural network component synchronously analyzes the time series correlation of device temperature, voltage harmonic distortion rate, and CRC error frame rate, and constructs a multi-dimensional fault feature vector. That is, the features of abnormal device firmware upgrades and signs of GOOSE message replay attacks extracted by the LLM component are used as input data and input into the LSTM neural network component to form a hybrid prediction model to predict the fault risk of the power grid terminal.
[0079] The terminal status prediction sub-module 33 is also used to add physical degradation constraints of the power grid terminal equipment during the prediction of the power grid terminal fault risk. The physical degradation constraint of the power grid terminal equipment is that when the ratio of the device health index of the power grid terminal to the health index baseline value is greater than the second preset percentage threshold for 3 consecutive sampling periods, a device fault prediction event is generated. The device health index of the power grid terminal is the weighted sum of the capacitor aging coefficient of the power grid terminal and the communication error rate threshold.
[0080] Specifically, the physical degradation constraint of the power equipment can be embedded in the hybrid prediction model. Joint modeling is performed on the capacitor aging coefficient of the distribution terminal (the calculation formula is m = 1 - e^(-t / τ), τ = MTBF / ln2, where τ is the time constant, obtained through reliability mathematical conversion from the mean time between failures (MTBF) index provided by the power grid terminal manufacturer, which is a reference parameter characterizing the capacitor aging rate; t is the operating time, referring to the cumulative actual working hours of the capacitor device since it was put into operation, directly determining the growth rate of the aging coefficient; m is the aging coefficient, a normalized index with a value range of 0-1, and when the value approaches 1, it indicates that the capacitor has reached the critical aging state and preventive maintenance is required) and the communication module error rate threshold (BER > 1E-5 triggers an alarm). The device health index (HHI) is calculated in real time through a sliding time window (window length = 6 power frequency cycles) accelerated by FPGA. When the HHI deviates from the baseline value by 30% and lasts for 3 sampling periods, a device fault prediction event is generated.
[0081] The terminal status prediction sub-module 33 is also used to trigger the firmware rollback mechanism of the power grid terminal after predicting the power grid terminal fault risk, automatically restoring to the trusted version signed by CA, switching the communication channel, and simultaneously linking the device maintenance system to generate a preventive maintenance work order.
[0082] The power grid terminal firmware rollback mechanism is specifically to automatically restore to the trusted version signed by the CA, and the communication channel switching instruction is specifically to switch from the wireless public network to the fiber optic longitudinal differential protection dedicated channel. At the same time, the equipment maintenance system is linked to generate a preventive maintenance work order (maintenance priority = HHI deviation × equipment asset weight factor).
[0083] The interaction and output module 4 has the following functions:
[0084] Generate a three-dimensional power grid threat map, in which the attack path is generated by comprehensively analyzing multi-source information such as the power grid network topology, equipment vulnerability information, and historical attack data, using a specific path search algorithm to simulate the vulnerabilities and network connections that attackers may exploit, thereby deducing the attack path; the judgment of high-value power grid terminal nodes is based on factors such as the importance of the node's equipment (such as whether it is located in the core transformer, whether it is located in the key transmission line, etc.), connection complexity (the number and type diversity of connected equipment), and network location. A comprehensive risk assessment model is constructed to score the risk of each node, and nodes with high scores are determined to be high-value power grid terminal nodes; at the same time, the module can dynamically display the terminal health status heat map, update the equipment status information in real time based on sensor data, and indicate the health of the equipment with different colors or brightness; it also supports natural language interactive instructions, such as "cut off the No. 3 transmission line terminal"; and push response strategies to the dispatch center in real time through the 5G communication network.
[0085] After receiving the pushed dynamic defense response strategy and vulnerability repair strategy, the dispatch center isolates the power grid terminals involved in the attack chain, adjusts the load distribution of the power grid terminals involved in the attack chain to the power grid terminals that are not involved, obtains the operation mode and security risk index of the power grid terminals involved in the attack chain, and repairs the vulnerabilities of the power grid terminals involved in the attack chain in turn according to the execution order of the vulnerability repair first priority strategy and the vulnerability repair second priority strategy.
[0086] When adjusting the load distribution, the grid topology is first monitored and analyzed in real time to identify the grid terminal nodes and important lines. At the same time, the load capacity of each grid terminal node and the transmission capacity of the line are evaluated in combination with the grid operation status data, such as voltage, current, power and other information; on this basis, according to the safe operation requirements of the grid and the principle of power supply continuity, priority is given to isolating those grid terminals that are identified as being in online operation mode and have a high grid terminal safety risk index. By adjusting the switch status in the grid, the position of the transformer tap and other means, the load is redistributed to ensure the stable operation of the grid and the reliability of power supply; in addition, the strategy will also take into account the safety status of the terminal. For terminals with potential safety hazards, corresponding measures will be taken to isolate or repair them to prevent the spread of safety risks.
[0087] The large language model enhanced analysis module of the present invention can parse unstructured data of power grid terminals, identify edge-side security events for power grid terminals; generate multi-stage attack chains based on a pre-built power attack knowledge base, structured data, and unstructured data of power grid terminals; generate dynamic defense response strategies related to the operation mode of power grid terminals according to the load loss rate and voltage qualification rate deviation values caused by the attack chains; the security assessment module can parse the structured data and unstructured data of power grid terminals according to the large language model in the power field, calculate the power grid terminal security risk index based on a dynamic security scoring model, and determine the corresponding vulnerability repair strategy for the power grid terminal according to the power grid terminal security risk index; the interaction and output module can generate a three-dimensional power grid threat map composed of power grid terminals according to the multi-stage attack chain, mark the attack path; and push the dynamic defense response strategy and the vulnerability repair strategy to the dispatching center in real time, effectively solving the problem of low reliability of power grid terminal security protection caused by the existing technology, and effectively improving the reliability of power grid terminal security protection.
[0088] In the technical solution of the present invention, the threat reasoning sub-module in the large language model enhanced analysis module can dynamically correct the attack feasibility path through the distribution network topology constraint and the power business time sequence constraint, so that the generated simulated attack chain is more in line with the actual structure and actual power business of the distribution network; the dynamic strategy generation sub-module can calculate the load loss rate and / or voltage qualification rate deviation value caused by the attack chain, and when the load loss rate is greater than the preset loss rate threshold, and / or, the voltage qualification rate deviation value exceeds the first preset percentage threshold, generate a dynamic defense response strategy related to the operation mode of the power grid terminal. The dynamic defense response strategy includes isolation instructions for the power grid terminals involved in the attack chain, load distribution adjustment instructions, and the first priority strategy for vulnerability repair. The first priority strategy for vulnerability repair is that the repair priorities in the online operation mode, test and debugging mode, and maintenance mode of the power grid terminal decrease in turn, improving the adaptability of the dynamic defense response strategy.
[0089] In the technical solution of the present invention, the security assessment module can not only parse the structured data and unstructured data of power grid terminals, identify abnormal behavior patterns of power grid terminal users; but also trigger physical blocking of the external ports of power grid terminals and secondary authentication of dispatching instructions when detecting abnormalities, and at the same time associate the abnormal events with the power security control platform to generate violation work orders.
[0090] The security assessment sub-module determines the corresponding vulnerability repair strategy for the power grid terminal according to the power grid terminal security risk index; the corresponding vulnerability repair strategy for the power grid terminal is the second priority strategy for vulnerability repair. The second priority strategy for vulnerability repair is that according to the level of the power grid terminal security risk index, the vulnerability repair priorities decrease in turn, and the execution order of the second priority is less than that of the first priority, further improving the adaptability of the dynamic defense response strategy.
[0091] In the technical solution of the present invention, the dynamic security scoring model can be dynamically adjusted according to the actual situation, further improving the reliability of the security protection of the power grid terminal.
[0092] In the technical solution of the present invention, the security assessment module further includes a terminal status prediction sub-module, which is used to predict the fault risk of the power grid terminal by using a large language model in the power field and an LSTM neural network; after predicting the fault risk of the power grid terminal, trigger the firmware rollback mechanism of the power grid terminal to automatically restore to a trusted version signed by CA; switch the communication channel, and at the same time link the equipment maintenance system to generate preventive maintenance work orders, further improving the reliability of the security protection of the power grid terminal.
[0093] Embodiment 2
[0094] As Figures 2 - 3 shown, the technical solution of the present invention also provides a power grid terminal security protection method based on a large language model, which is implemented on the basis of a power grid terminal security protection system based on a large language model in Embodiment 1, and includes:
[0095] S1, the multi-source data acquisition module collects the structured data and unstructured data of the power grid terminal in real time, the structured data includes system logs, network traffic data, and device operation data, and the unstructured data includes operation record documents, monitoring video content, and device communication records; the power grid terminal is a terminal device deployed on the edge side of the power system;
[0096] Data acquisition and preprocessing: Real-time obtain the structured data (protocol traffic, device logs) and unstructured data (monitoring video, operation records) of the power grid terminal, and perform encryption and standardization processing;
[0097] S2, the large language model enhanced analysis module analyzes the unstructured data of the power grid terminal through a large language model in the power field, identifies edge-side security events for the power grid terminal; generates a multi-stage attack chain based on a pre-built power attack knowledge base, the structured data and unstructured data of the power grid terminal; calculates the load loss rate and voltage qualification rate deviation value caused by the generated attack chain, and generates a dynamic defense response strategy related to the operation mode of the power grid terminal according to the load loss rate and voltage qualification rate deviation value caused by the attack chain;
[0098] LLM enhanced analysis: Analyze unstructured text, extract security events (such as malicious instruction tampering), and generate multi-stage attack hypotheses (such as false data injection causing power grid frequency instability);
[0099] S3. The security assessment module analyzes the structured and unstructured data of the grid terminal according to the large language model in the power field, calculates the grid terminal security risk index based on the dynamic security scoring model, and determines the corresponding vulnerability repair strategy for the grid terminal according to the grid terminal security risk index; the dynamic defense response strategy includes the corresponding vulnerability repair strategy for the grid terminal.
[0100] Anomaly detection and prediction: Combine the LLM and LSTM networks to predict the equipment failure risk (such as the probability of transformer overheating ≥ 85%), and dynamically adjust the parameters of the security scoring model.
[0101] Dynamic scoring and strategy generation: Aggregate the vulnerability data of multiple substations through the federated learning framework to optimize the vulnerability weights (S v , E v , I v ) and the priority of the response strategy.
[0102] S4. The interaction and output module generates a three-dimensional grid threat map composed of grid terminals according to the multi-stage attack chain and marks the attack path; it real-time pushes the dynamic defense response strategy and the vulnerability repair strategy to the dispatching center.
[0103] Automated response: Execute strategies such as isolation and permission adjustment, and generate a visual report.
[0104] This application can be adapted to the power scenario: support the parsing of power-specific protocols and the fusion analysis of physical states; the reinforcement learning algorithm dynamically optimizes the response strategy to adapt to the multi-stage attack chain; fuse multi-dimensional parameters (vulnerabilities, resources, LLM confidence) to quantify the terminal risk; three-dimensional visualization and natural language interaction improve the operation and maintenance efficiency.
[0105] The large language model enhanced analysis module of the present invention can analyze the unstructured data of the grid terminal, identify the edge-side security events against the grid terminal; generate a multi-stage attack chain based on the pre-built power attack knowledge base, the structured and unstructured data of the grid terminal; generate a dynamic defense response strategy related to the grid terminal operation mode according to the load loss rate and voltage qualification rate deviation value caused by the attack chain; the security assessment module can analyze the structured and unstructured data of the grid terminal according to the large language model, calculate the grid terminal security risk index based on the dynamic security scoring model, and determine the corresponding vulnerability repair strategy for the grid terminal according to the grid terminal security risk index; the interaction and output module can generate a three-dimensional grid threat map composed of grid terminals according to the multi-stage attack chain, mark the attack path; real-time push the dynamic defense response strategy and the vulnerability repair strategy to the dispatching center, effectively solving the problem of low reliability of grid terminal security protection caused by the existing technology, and effectively improving the reliability of grid terminal security protection.
[0106] In the technical solution of the present invention, the threat reasoning sub-module in the large language model enhancement analysis module can dynamically correct the attack feasibility path through the distribution network topology constraint and the power business time sequence constraint, so that the generated simulated attack chain is more in line with the actual structure of the distribution network and the actual power business; the dynamic policy generation sub-module can calculate the load loss rate and / or the voltage qualification rate deviation value caused by the attack chain. When the load loss rate is greater than the preset loss rate threshold, and / or, the voltage qualification rate deviation value exceeds the first preset percentage threshold, a dynamic defense response policy related to the grid terminal operation mode is generated. The dynamic defense response policy includes an isolation instruction for the grid terminal involved in the attack chain, a load distribution adjustment instruction, and a first priority policy for vulnerability repair. The first priority policy for vulnerability repair is that the repair priorities for the grid terminal online operation mode, test and debugging mode, and maintenance mode decrease in turn, improving the adaptability of the dynamic defense response policy.
[0107] In the technical solution of the present invention, the security assessment module can not only analyze the structured data and unstructured data of the grid terminal to identify the abnormal behavior patterns of the grid terminal users; but also when an anomaly is detected, trigger the physical block of the peripheral ports of the grid terminal and the secondary authentication of the dispatching instruction, and at the same time associate the abnormal event with the power security control platform to generate a violation work order;
[0108] The security assessment sub-module determines the corresponding vulnerability repair strategy for the grid terminal according to the grid terminal security risk index; the corresponding vulnerability repair strategy for the grid terminal is the second priority policy for vulnerability repair. The second priority policy for vulnerability repair is that according to the level of the grid terminal security risk index, the vulnerability repair priorities decrease in turn, and the execution order of the second priority is less than that of the first priority, further improving the adaptability of the dynamic defense response policy.
[0109] In the technical solution of the present invention, the dynamic security scoring model can be dynamically adjusted according to the actual situation, further improving the reliability of the grid terminal security protection.
[0110] In the technical solution of the present invention, the security assessment module further includes a terminal state prediction sub-module. The terminal state prediction sub-module is used to predict the grid terminal failure risk by using the large language model in the power field and the LSTM neural network; after predicting the grid terminal failure risk, trigger the grid terminal firmware rollback mechanism to automatically restore to the trusted version signed by CA; switch the communication channel, and at the same time link the equipment maintenance system to generate a preventive maintenance work order, further improving the reliability of the grid terminal security protection.
[0111] Although the specific embodiments of the present invention have been described above in conjunction with the accompanying drawings, they are not limitations on the protection scope of the present invention. Those skilled in the art should understand that various modifications or deformations that can be made without creative efforts on the basis of the technical solutions of the present invention are still within the protection scope of the present invention.< / swversion>
Claims
1. A power grid terminal security protection system based on a large language model, characterized in that: include: A multi-source data acquisition module is used to collect structured data and unstructured data of power grid terminals in real time. The structured data includes system logs, network traffic data, and equipment operation data. The unstructured data includes operation record documents, monitoring video content, and equipment communication records. The power grid terminals are terminal devices deployed at the edge of the power system. The large language model enhanced analysis module is used to parse the unstructured data of power grid terminals through the large language model in the power field and identify edge-side security events targeting power grid terminals; Generate a multi-stage attack chain based on the pre-built power attack knowledge base, structured data of power grid terminals, and unstructured data; calculate the load loss rate and voltage qualification rate deviation value caused by the generated attack chain, and generate a dynamic defense response strategy related to the power grid terminal operation mode according to the load loss rate and voltage qualification rate deviation value caused by the attack chain; The security assessment module is used to parse the structured and unstructured data of the power grid terminal according to the large language model in the power field, calculate the security risk index of the power grid terminal based on the dynamic security scoring model, and determine the corresponding vulnerability repair strategy of the power grid terminal according to the security risk index of the power grid terminal; The dynamic defense response strategy includes a vulnerability repair strategy corresponding to the power grid terminal; The interaction and output module is used to generate a three-dimensional grid threat map consisting of grid terminals based on the multi-stage attack chain and mark the attack path; Push dynamic defense response strategies and vulnerability repair strategies to the dispatch center in real time.
2. The power grid terminal security protection system based on a large language model according to claim 1 is characterized in that: The power grid terminal includes a distribution automation terminal, a user-side smart meter, and a distributed energy interface device. The deployment location of the distribution automation terminal is a distribution network feeder node, the deployment location of the user-side smart meter is an industrial and commercial user access point, and the deployment location of the distributed energy interface device is a distributed photovoltaic grid-connected point.
3. The power grid terminal security protection system based on a large language model according to claim 1 is characterized in that: The large language model enhanced analysis module includes a semantic understanding submodule, a threat reasoning submodule, and a dynamic defense response strategy generation submodule. The semantic understanding submodule is used to parse unstructured text data through a large language model in the power field, and extract edge-side security events targeting power grid terminals, including fingerprint features of malicious operation records, semantic patterns of device parameter tampering, and false data injection instruction structures; A threat reasoning submodule is used to build a power attack knowledge base based on edge security events, structured data of power grid terminals and unstructured data, and generate a multi-stage attack chain hypothesis based on the pre-built power attack knowledge base, structured data of power grid terminals and unstructured data. The power attack knowledge base at least includes a power grid terminal firmware vulnerability mapping table, an attack mode feature matrix, and an edge attack sample library, and dynamically corrects the attack feasibility path through distribution network topology constraints and power business timing constraints; wherein the power grid terminal firmware vulnerability mapping table stores the correspondence between each power grid terminal, firmware, protocol stack version, firmware vulnerability, associated firmware vulnerability, protocol stack version corresponding to the associated firmware vulnerability, firmware corresponding to the protocol stack version corresponding to the associated firmware vulnerability, and the power grid terminal to which the firmware corresponding to the protocol stack version belongs, the attack mode feature matrix includes protocol layer attack feature vectors classified according to the power system data communication security standard, and the edge attack sample library includes power grid terminal rate tampering operation sequence and power grid terminal false remote signaling message timing mode; The dynamic strategy generation submodule is used to calculate the load loss rate and / or voltage qualification rate deviation value caused by the attack chain according to the embedded PSCAD power model. When the load loss rate is greater than the preset loss rate threshold, and / or the voltage qualification rate deviation value exceeds the first preset percentage threshold, a dynamic defense response strategy related to the power grid terminal operation mode is generated. The dynamic defense response strategy includes isolation instructions, load distribution adjustment instructions, and a vulnerability repair first priority strategy for the power grid terminals involved in the attack chain. The vulnerability repair first priority strategy is that the repair priorities of the power grid terminal online operation mode, test and debugging mode, and inspection and maintenance mode are reduced in sequence.
4. The power grid terminal security protection system based on a large language model according to claim 3 is characterized in that: In the topology constraints of the distribution network, high-value grid terminal nodes form the nodes that must be attacked, and low-value grid terminal nodes constitute the circuitous attack paths. The attributes of the grid terminal nodes include the criticality scores of the equipment assets of the grid terminals; high-value grid terminal nodes are grid terminals with a criticality score greater than a preset score threshold, and low-value grid terminal nodes are grid terminals with a criticality score not greater than the preset score threshold; The timing constraints of the power business include the need to complete the electricity fee calculation time in advance during the user data theft stage, the need to comply with the AGC adjustment time window during the grid connection instruction forgery stage, and the need to coordinate the circuit breaker opening action delay during the feeder protection false triggering stage.
5. The power grid terminal security protection system based on a large language model according to claim 3 is characterized in that: The security assessment module includes a behavior anomaly detection submodule and a security scoring submodule. The behavior anomaly detection submodule is used to parse the structured data and unstructured data of the power grid terminal according to the large language model and real-time rule engine in the power field, and identify abnormal behavior patterns of power grid terminal users; wherein, the user abnormal behavior patterns include unauthorized dispatch instruction tampering, cross-position authority out-of-bounds operation, maintenance plan conflict operation, dispatch operation time conflict, peripheral access whitelist conflict, and operation frequency threshold conflict; when an abnormality is detected, the physical blocking of the peripheral port of the power grid terminal and the secondary authentication of the dispatch instruction are triggered, and the abnormal event is associated with the power safety management and control platform to generate a violation work order; The security scoring submodule is used to calculate the power grid terminal security risk index based on the dynamic security scoring model, and determine the corresponding vulnerability repair strategy for the power grid terminal according to the power grid terminal security risk index; the corresponding vulnerability repair strategy for the power grid terminal is a vulnerability repair second priority strategy, and the vulnerability repair second priority strategy is based on the power grid terminal security risk index. The vulnerability repair priority decreases in sequence, and the execution order of the second priority is less than the execution order of the first priority.
6. The power grid terminal security protection system based on a large language model according to claim 5 is characterized in that: The dynamic safety scoring model is as follows: S=α×R+β×C+γ×V+δ×L, Among them, α, β, γ, and δ are the power supply reliability weight, attack control capability, vulnerability impact score, and confidence score weight coefficient of the large language model in the power field, respectively; S is the terminal security risk index; R is the power supply reliability weight; C is the attack control capability; V is the vulnerability impact score, and L is the confidence score of the large language model.
7. The power grid terminal security protection system based on a large language model according to claim 6 is characterized in that: The power supply reliability weight is the product of the weight value of the load power supply area and the correction coefficient, where the weight value of the first-level load power supply area is 0.9, the weight value of the second-level load area is 0.6, and the weight value of the third-level load area is 0.
3. The correction coefficient is the square of the product of the actual power supply availability and the target power supply availability; The attack control capability is the sum of the vulnerability score, the attack chain penetration depth coefficient, and the protocol vulnerability multiplier. The vulnerability score uses a vulnerability threat quantification model to score the vulnerabilities involved in the attack path based on the CVSS vulnerability scoring framework. The vulnerability impact score is obtained as follows: , where S vi is the severity of the ith vulnerability; E vi is the vulnerability level of the i-th vulnerability; vi is the impact scope of the i-th vulnerability; The confidence score L of the large language model in the power field is obtained as follows: L=w1×A+w2×C h +w3×H, Among them, A is the accuracy of semantic analysis; C h is the logical consistency score, H is the credibility of historical detection results, w1, w2, and w3 are the weighted coefficients of semantic analysis accuracy, logical consistency score, and credibility of historical detection results, respectively; the power supply reliability weight, attack control capability, vulnerability impact score, and confidence score weight coefficient of the large language model in the power field, the power supply reliability weight, attack control capability, vulnerability impact score, and confidence score of the large language model in the power field support dynamic adjustment.
8. The power grid terminal security protection system based on a large language model according to claim 5 is characterized in that: The security assessment module also includes a terminal state prediction submodule, which is used to predict the risk of power grid terminal failure by using a large language model in the power field and an LSTM neural network; wherein the large language model in the power field parses SCL configuration change records and unstructured alarm texts, extracts abnormal upgrade features of the firmware of power grid terminal equipment and signs of GOOSE message replay attacks; the LSTM neural network analyzes the temporal correlation of the temperature features, voltage harmonic distortion rate features, and CRC error frame rate features of the power grid terminal, and constructs a multi-dimensional fault feature vector based on the abnormal upgrade features of the firmware of the power grid terminal equipment, signs of GOOSE message replay attacks, temperature features, voltage harmonic distortion rate features, and CRC error frame rate features to predict the risk of power grid terminal failure; The terminal state prediction submodule is also used to add a physical degradation constraint of the power grid terminal equipment to the power grid terminal fault risk prediction process, and the physical degradation constraint of the power grid terminal equipment is that when the ratio of the equipment health index of the power grid terminal to the health index baseline value for three consecutive sampling periods is greater than the second preset percentage threshold, an equipment failure prediction event is generated; the equipment health index of the power grid terminal is the weighted sum of the capacitance aging coefficient of the power grid terminal and the communication bit error rate threshold; The terminal status prediction submodule is also used to trigger the grid terminal firmware rollback mechanism after predicting the risk of grid terminal failure, automatically restore to the trusted version signed by the CA; switch the communication channel, and at the same time link the equipment maintenance system to generate a preventive maintenance work order.
9. The power grid terminal security protection system based on a large language model according to claim 5 is characterized in that: After receiving the pushed dynamic defense response strategy and vulnerability repair strategy, the dispatch center isolates the power grid terminals involved in the attack chain, adjusts the load distribution of the power grid terminals involved in the attack chain to the power grid terminals that are not involved, obtains the operation mode and security risk index of the power grid terminals involved in the attack chain, and repairs the vulnerabilities of the power grid terminals involved in the attack chain in turn according to the execution order of the vulnerability repair first priority strategy and the vulnerability repair second priority strategy.
10. A power grid terminal security protection method based on a large language model, characterized in that: The invention is implemented on the basis of a power grid terminal security protection system based on a large language model according to any one of claims 1 to 9, comprising: The multi-source data acquisition module collects structured data and unstructured data of the power grid terminal in real time. The structured data includes system logs, network traffic data, and equipment operation data. The unstructured data includes operation record documents, monitoring video content, and equipment communication records. The power grid terminal is a terminal device deployed at the edge of the power system. The large language model enhanced analysis module parses the unstructured data of power grid terminals through the large language model in the power field, identifies edge security events targeting power grid terminals; generates a multi-stage attack chain based on the pre-built power attack knowledge base, structured data of power grid terminals, and unstructured data; calculates the load loss rate and voltage qualification rate deviation value caused by the generated attack chain, and generates a dynamic defense response strategy related to the power grid terminal operation mode based on the load loss rate and voltage qualification rate deviation value caused by the attack chain; The security assessment module analyzes the structured data and unstructured data of the power grid terminal according to the large language model in the power field, calculates the security risk index of the power grid terminal based on the dynamic security scoring model, and determines the corresponding vulnerability repair strategy of the power grid terminal according to the security risk index of the power grid terminal; the dynamic defense response strategy includes the corresponding vulnerability repair strategy of the power grid terminal; The interaction and output module generates a three-dimensional power grid threat map composed of power grid terminals based on the multi-stage attack chain, marking the attack path; and pushes dynamic defense response strategies and vulnerability repair strategies to the dispatch center in real time.
Citation Information
Cited By
Regional risk density analysis method and system
CN120579833A
Power terminal adaptive security authentication method and related device
CN121309040A