Safety monitoring method and equipment for electric power Internet of Things equipment, and storage medium

By monitoring the access behavior of power IoT devices, using clustering algorithms and European-style distance identification equipment, the problem of poor detection accuracy and consistency in the prior art is solved, and more accurate security detection is achieved.

CN120257075APending Publication Date: 2025-07-04LIANSHAN POWER SUPPLY COMPANY OF STATE GRID SICHUAN ELECTRIC POWER
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510178902.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

In the prior art, the safety detection of power IoT devices depends on expert experience setting thresholds, resulting in poor detection accuracy and consistency and lack of objectivity.

Method used

By monitoring the access behavior of power IoT devices, using clustering algorithms to form clusters, calculate the Euclidean distance between the device and the cluster center, and compare it with the preset threshold, it automatically adapts to changes in the device behavior pattern and recognizes abnormal devices.

Benefits of technology

More objective and accurate abnormal detection is achieved, reducing the influence of human factors and improving the accuracy and consistency of detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120257075A_ABST
    Figure CN120257075A_ABST
Patent Text Reader

Abstract

The invention discloses an electric power Internet of Things equipment safety monitoring method and device and a storage medium, and relates to the technical field of safety detection, and the method comprises the steps: monitoring an access behavior of target equipment, and obtaining current access data corresponding to the access behavior in a preset period; according to the current access data, obtaining a target Euclidean distance between the target equipment and a target class cluster center; and comparing the target Euclidean distance with a preset distance threshold, and if the target Euclidean distance is greater than the preset distance threshold, determining that the target device is an abnormal device. According to the method and the device, the Euclidean distance is calculated and the clustering analysis is carried out, so that the operation state of the equipment can be objectively evaluated, and the abnormal behavior of the electric power internet-of-things equipment can be identified more accurately.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of security detection, and particularly to a method, device and storage medium for security monitoring of power Internet of Things devices. Background Art

[0002] Power Internet of Things terminal devices are an important part of the security protection of smart grids. With the expansion of the grid scale, various power Internet of Things terminal devices have increased rapidly, and these devices may become targets for attackers. Conducting security monitoring on power Internet of Things terminal devices helps to detect and respond to these potential security threats in a timely manner, thereby ensuring the overall security of the grid.

[0003] Currently, when conducting security detection on devices in the power Internet of Things, usually based on expert experience, one or more thresholds are set for each piece of operation data, representing the upper or lower limit of the normal working range of the device. The collected operation data is compared with the thresholds. If a certain operation data exceeds the set threshold range, it is considered that the device may be abnormal. However, relying on expert experience to set thresholds has certain subjectivity and uncertainty. Different experts or teams may set different thresholds, thus affecting the accuracy and consistency of abnormal detection.

[0004] The above content is only used to assist in understanding the technical solution of the present application, and does not represent an admission that the above content is prior art. Summary of the Invention

[0005] The main purpose of the present application is to provide a method, device and storage medium for security monitoring of power Internet of Things devices, aiming to solve the technical problem of how to improve the accuracy and effectiveness of security detection of power Internet of Things devices.

[0006] To achieve the above purpose, the present application proposes a method for security monitoring of power Internet of Things devices, and the method includes:

[0007] Monitor the access behavior of the target device, and obtain the current access data corresponding to the access behavior within a preset period;

[0008] According to the current access data, obtain the target Euclidean distance between the target device and the target cluster center;

[0009] Compare the target Euclidean distance with a preset distance threshold. If the distance is greater than the preset distance threshold, the target device is the abnormal device.

[0010] In one embodiment, after the step of comparing the target Euclidean distance with a preset distance threshold, if the distance is greater than the preset distance threshold, and the target device is the abnormal device, it includes:

[0011] Compare the discrete data in the current access data with the historical access data list;

[0012] If the discrete data is not in the historical access data list, the target device is the abnormal device.

[0013] In one embodiment, after the step of comparing the target Euclidean distance with a preset distance threshold, if the distance is greater than the preset distance threshold, the target device is the abnormal device, the following steps are included:

[0014] Determine the continuous access data in the current access data;

[0015] Perform anomaly detection on the continuous access data according to the time series detection algorithm;

[0016] If it is detected that the continuous access data is different from the preset standard threshold, confirm that the target device is the abnormal device.

[0017] In one embodiment, before the step of obtaining the target Euclidean distance between the target device and the target cluster center according to the current access data, the following steps are included:

[0018] Establish an association matrix according to the access data of each device in the Internet of Things within the preset period;

[0019] Calculate the Euclidean distance between the devices according to the elements in the association matrix;

[0020] Perform clustering operations on the devices according to the Euclidean distance to obtain at least one cluster center.

[0021] In one embodiment, before the step of monitoring the access behavior of the target device, the following steps are included:

[0022] Obtain the traffic data in the Internet of Things, and parse the traffic data to obtain the target fields;

[0023] Match the target fields with a preset asset fingerprint rule library to determine the device identifier;

[0024] Determine the target device and device type corresponding to the device identifier through the coding naming specification file.

[0025] In one embodiment, after the step of comparing the target Euclidean distance with a preset distance threshold, if the distance is greater than the preset distance threshold, the target device is the abnormal device, the following steps are included:

[0026] Obtain the abnormal data of the abnormal device, and determine the risk level according to the abnormal data;

[0027] Determine the permission control measures according to the risk level.

[0028] In one embodiment, the steps of obtaining the abnormal data of the abnormal device and determining the risk level according to the abnormal data include:

[0029] Obtain the abnormal data of the abnormal device;

[0030] Input the abnormal data into a preset abnormal analysis algorithm to obtain an abnormal score;

[0031] Compare the abnormal score with a preset abnormal score threshold, and determine the risk level according to the comparison result.

[0032] In one embodiment, the steps of determining the permission control measures according to the risk level include:

[0033] If the risk level is high risk, the permission control measure is to isolate the asset;

[0034] If the risk level is medium risk, the permission control measure is to prohibit access;

[0035] If the risk level is low risk, the permission control measure is to issue an alarm.

[0036] In addition, to achieve the above object, the present application also proposes a power IoT device security monitoring device, which includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, and the computer program is configured to implement the steps of the power IoT device security monitoring method as described above.

[0037] In addition, to achieve the above object, the present application also proposes a storage medium, which is a computer-readable storage medium, and a computer program is stored on the storage medium, and when the computer program is executed by a processor, it implements the steps of the power IoT device security monitoring method as described above.

[0038] The present application provides a method for security monitoring of power IoT devices. By means of a monitoring tool or software, access behavior data of target devices is collected regularly as current access data. The access behavior data of similar devices is clustered using a clustering algorithm to form several clusters. The Euclidean distance between the current access data of the target device and the target cluster center is calculated as the target Euclidean distance. The calculated target Euclidean distance is compared with a preset distance threshold, where the threshold represents the maximum acceptable distance between a normal device and the cluster center. If the target Euclidean distance is greater than the preset distance threshold, it is considered that the access behavior of the target device is different from the behavior pattern of normal devices, and the target device is marked as an abnormal device. If the target Euclidean distance is less than or equal to the preset distance threshold, it is considered that the access behavior of the target device is within the normal range.

[0039] In the present application, since the Euclidean distance is calculated based on actual data, it can reflect the similarity between devices and can automatically adapt to changes in device behavior patterns. It avoids artificially setting access data thresholds and directly compares the current access data with the set access data thresholds, reducing the influence of human factors on the detection results. By automatically calculating the Euclidean distance and comparing it with the preset threshold, more objective and accurate anomaly detection can be achieved. By clustering the access behavior data of similar devices using a clustering algorithm, a more accurate normal behavior pattern can be formed. This helps to more precisely determine whether the access behavior of the target device is abnormal. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present application and used together with the specification to explain the principles of the present application.

[0041] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0042] Figure 1 It is a schematic flow chart provided for Embodiment 1 of the method for security monitoring of power IoT devices of the present application;

[0043] Figure 2 It is a schematic diagram of the clustering result provided for Embodiment 1 of the method for security monitoring of power IoT devices of the present application;

[0044] Figure 3 It is a schematic flow chart provided for Embodiment 3 of the method for security monitoring of power IoT devices of the present application;

[0045] Figure 4Schematic diagram of access data comparison provided for the third embodiment of the power IoT device security monitoring method of this application;

[0046] Figure 5 Another schematic diagram of access data comparison provided for the third embodiment of the power IoT device security monitoring method of this application;

[0047] Figure 6 Schematic flowchart provided for the fourth embodiment of the power IoT device security monitoring method of this application;

[0048] Figure 7 Schematic flowchart provided for the fifth embodiment of the power IoT device security monitoring method of this application;

[0049] Figure 8 Schematic diagram of the analysis result of the anomaly analysis algorithm provided for the fifth embodiment of the power IoT device security monitoring method of this application;

[0050] Figure 9 Schematic diagram of the device structure of the hardware operating environment involved in the power IoT device security monitoring method in the embodiments of this application. Detailed implementation manners

[0051] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of this application and are not used to limit this application.

[0052] For a better understanding of the technical solutions of this application, the following will be described in detail in conjunction with the accompanying drawings of the specification and specific implementation manners.

[0053] The main solution of the embodiments of this application is: monitor the access behavior of the target device and obtain the current access data corresponding to the access behavior within a preset period; according to the current access data, obtain the target Euclidean distance between the target device and the target cluster center; compare the target Euclidean distance with a preset distance threshold, and if the target Euclidean distance is greater than the preset distance threshold, the target device is an abnormal device.

[0054] Power IoT terminal devices are an important part of the security protection of the smart grid. With the expansion of the power grid scale, various power IoT terminal devices have increased rapidly, and these devices may become targets for attackers. Conducting security monitoring on power IoT terminal devices helps to detect and respond to these potential security threats in a timely manner, thereby ensuring the overall security of the power grid.

[0055] Currently, when performing security detection on devices in the power Internet of Things, usually based on expert experience, one or more thresholds are set for each piece of operation data, representing the upper or lower limit of the normal working range of the device. The collected operation data is compared with the thresholds. If a certain piece of operation data exceeds the set threshold range, it is considered that the device may be abnormal. However, relying on expert experience to set thresholds has certain subjectivity and uncertainty. Different experts or teams may set different thresholds, thus affecting the accuracy and consistency of anomaly detection.

[0056] This application provides a method for security monitoring of power Internet of Things devices. Through a monitoring tool or software, access behavior data of the target device is regularly collected as the current access data. The access behavior data of similar devices is clustered using a clustering algorithm to form several clusters. The Euclidean distance between the current access data of the target device and the center of the target cluster is calculated as the target Euclidean distance. The calculated target Euclidean distance is compared with a preset distance threshold, where the threshold represents the maximum acceptable distance between a normal device and the cluster center. If the target Euclidean distance is greater than the preset distance threshold, it is considered that the access behavior of the target device is different from the behavior pattern of normal devices, and the target device is marked as an abnormal device. If the target Euclidean distance is less than or equal to the preset distance threshold, it is considered that the access behavior of the target device is within the normal range.

[0057] In this application, since the Euclidean distance is calculated based on actual data, it can reflect the similarity between devices and can automatically adapt to changes in device behavior patterns. It avoids the need to manually set access data thresholds and directly compares the current access data with the set access data thresholds, reducing the influence of human factors on the detection results. By calculating the Euclidean distance and comparing it with the preset threshold, more objective and accurate anomaly detection can be achieved. By clustering the access behavior data of similar devices using a clustering algorithm, a more accurate normal behavior pattern can be formed. This helps to more precisely determine whether the access behavior of the target device is abnormal.

[0058] It should be noted that the execution subject of this embodiment can be a computing service device with network communication and program running functions, such as a tablet computer, a personal computer, a mobile phone, etc., or an electronic device or device capable of implementing the above functions. Hereinafter, a security monitoring device for power Internet of Things devices will be used as an example to illustrate this embodiment and the following embodiments.

[0059] Based on this, the embodiment of this application provides a method for security monitoring of power Internet of Things devices, referring to Figure 1 , Figure 1 is a schematic flowchart of the first embodiment of the method for security monitoring of power Internet of Things devices in this application.

[0060] In this embodiment, the power IoT device security monitoring method includes steps S100 to S300:

[0061] Step S100, monitor the access behavior of the target device, and obtain the current access data corresponding to the access behavior within a preset period.

[0062] It should be noted that the Internet of Things (IoT) refers to connecting any object to the network through information sensing devices according to an agreed protocol. The object conducts information exchange and communication through information dissemination media to achieve functions such as intelligent identification, positioning, tracking, and supervision.

[0063] In addition, it should be noted that power IoT devices refer to IoT devices based on IoT technology that use various sensing devices to obtain the operating conditions of power equipment or facilities. They can achieve information exchange and interaction through various sensors, software, network connections, and other technologies. These devices can collect data, perform analysis, and respond as needed, thereby achieving automated control and intelligent decision-making. Power IoT devices can include: smart meters, smart distribution boxes, power line monitoring devices, substation auxiliary equipment monitoring systems for monitoring environmental parameters (such as temperature and humidity) in substations, security equipment (such as cameras and access control), and fire-fighting equipment, power inspection drones, smart sensors, and other devices. The access behavior of power IoT devices refers to the interactive behaviors such as data exchange, instruction sending and receiving, etc. between devices, sensors, control systems, etc. in the power IoT.

[0064] In this embodiment, the target device refers to all power IoT devices in the IoT. Real-time monitoring is performed on all target devices, and access data related to the access behavior of the target device is obtained within a preset period. The preset time period can be any set time period, such as one day, one week, or one month. The access data can include: access traffic, source device type, protocol, destination port, destination device type, access time period, access frequency, etc. After collecting the access data, the collected data is processed and analyzed through data analysis tools or scripts to extract the required access data. Exemplarily, SQL query statements are used to extract access records within a specific time period from the database. Data visualization tools (such as Echarts, Tableau, etc.) are used to display the access data in the form of charts, reports, etc.

[0065] Optionally, deploy network traffic monitoring devices (such as traffic analyzers, intrusion detection systems (IDS), or network performance monitoring (NPM) tools) at key network nodes of the power Internet of Things (such as gateways, switches, routers, etc.), and configure the parameters to be monitored (such as access traffic, source device type, protocol, destination port, destination device type, etc.) on the monitoring devices. According to business requirements and security requirements, set the data reporting frequency of the monitoring tool, and use push technologies (such as WebSocket, MQTT, etc.) to push real-time data to the specified client or server. Exemplarily, the data reporting frequency is set to report data once per minute or per hour to ensure the real-time nature of the data. Capture the access behaviors of all passing power Internet of Things devices through the monitoring devices, collect the access data in real time, and store it.

[0066] Optionally, the access behaviors of power Internet of Things devices can be monitored in real time through the monitoring application of the Internet of Things platform. Connect the power Internet of Things devices to the Internet of Things platform by wired or wireless means, register the power Internet of Things devices, and configure the access permissions and monitoring parameters of the devices. According to the monitoring application provided by the Internet of Things platform, monitor the access behaviors of power Internet of Things devices in real time and collect the access data of power Internet of Things devices.

[0067] Step S200, obtain the target Euclidean distance between the target device and the target cluster center according to the current access data.

[0068] It should be noted that the target cluster refers to the clustering formed by the same type of devices to which the target device belongs within a preset time period. The target cluster center is the center point of the feature vectors of all devices in the target cluster.

[0069] In this embodiment, through the clustering algorithm, the access data corresponding to the access behaviors of the target device and the same type of power Internet of Things devices is compared. The behavior data of the same type of devices is divided into multiple clusters, and each cluster represents a normal behavior pattern. Compare the behavior data of the target device with these clusters. If the data points of the target device are at a relatively large distance from all clusters, it indicates that the device has abnormal behavior.

[0070] In this embodiment, an association matrix of access traffic data for a period of time is established. The elements of the matrix can be the number of accesses, access traffic, and access protocol. The Euclidean distance is used to calculate the distance between devices, and clustering operations are performed. The farther away from the center, the more serious the abnormal situation is considered. After obtaining information such as the number of accesses, access traffic, and access protocol of power devices in the Internet of Things, first, data preprocessing is performed. Since the access protocol is a categorical variable, it needs to be converted into a numerical form first. The conversion method can include one-hot encoding or label encoding. After the access protocol is numericalized, the data is standardized. Standardization can be achieved by subtracting the mean from the data and then dividing by the standard deviation, so that the data in each dimension conforms to the standard normal distribution. Through standardization, it can be ensured that each dimension has the same importance in the calculation of Euclidean distance. Secondly, a clustering algorithm is selected, such as K-means, Hierarchical Clustering, etc. And clustering analysis is performed according to the preprocessed data and the selected clustering algorithm to obtain at least one cluster and the cluster center.

[0071] Exemplarily, there are power IoT devices A, B, and C. The number of accesses, access traffic, and access protocol data of them are collected within a specific time period. The number of accesses of device A is 100 times, the access traffic is 500MB, and the access protocol is the HTTP protocol; the number of accesses of device B is 110 times, the access traffic is 480MB, and the access protocol is the HTTP protocol; the number of accesses of device C is 80 times, the access traffic is 600MB, and the access protocol is the FTP protocol. One-hot encoding is used to represent the protocol, with HTTP being 1 and FTP being 0. The distances between device A and device C, and device B and device C are calculated. After calculating the distances between all devices, a clustering algorithm (such as K-means clustering) is used to divide these devices into different clusters. Please refer to Figure 2 , after clustering, each cluster will have a center (that is, a certain average or representative value of all devices in the cluster).

[0072] In this embodiment, the protocol address is converted into binary numerical features through one-hot encoding, enabling the clustering algorithm to process the protocol address features. One-hot encoding does not introduce an order relationship between categories, and each category is independent, improving the accuracy of clustering.

[0073] Step S300, compare the target Euclidean distance with a preset distance threshold. If the target Euclidean distance is greater than the preset distance threshold, the target device is an abnormal device.

[0074] In this embodiment, a reasonable distance threshold is set according to historical data and business logic. This threshold can be determined based on the tightness of the cluster, the distribution characteristics of the data, and the business definition of anomalies. If the distance between the target device and the cluster center is greater than the set threshold, the device is considered to have an anomaly.

[0075] In this embodiment, by comparing the access data of the target device with that of the same type of devices, anomaly detection is performed by combining the Euclidean distance and clustering algorithms. Using statistical and machine learning methods, based on the normal access data of the same type of devices, the anomaly degree of the device is dynamically calculated. Both the Euclidean distance and clustering algorithms are calculated based on the characteristics of the data itself and can automatically adapt to data changes. When the operating state of the device is affected by factors such as environmental changes and device aging, its behavior data may change. The Euclidean distance and clustering algorithms can capture these changes, thus avoiding false alarms or missed alarms. In addition, by calculating the Euclidean distance and performing clustering analysis, the operating state of the device can be evaluated more objectively, and misjudgments caused by human factors can be reduced, enabling more accurate identification of the abnormal behavior of the device.

[0076] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar content as in the above-mentioned first embodiment can be referred to the above introduction and will not be repeated hereinafter. On this basis, please refer to Figure 3 , after step S300, steps A100 to A200 may be included:

[0077] Step A100, comparing the discrete data in the current access data with the historical access data list.

[0078] Step A200, if the discrete data is not in the historical access data list, the target device is the abnormal device.

[0079] In this embodiment, further, by comparing the access data of the target device with its historical access data, it is determined whether there is an abnormal situation in the access behavior of the target device. By learning a large amount of historical access data, a large amount of discrete historical access data is collected from one or more similar devices, and the collected data is cleaned and de-duplicated to ensure that each data point in the list is unique. The preprocessed data is stored in a list, database, or data warehouse for subsequent query and comparison.

[0080] In this embodiment, the discrete data in the current access data may include the destination port, the destination device type, etc. Exemplarily, when determining whether the target device is abnormal by the destination port accessed by the target device within a preset time period, the current access port of the target device is compared with its historical access port list to determine whether the current access port is part of the historical access ports. If the current access port is not in the historical access port list, that is, the current port is brand new and has never been used before, it indicates that the behavior of the target device deviates from the historical behavior baseline and there is an abnormal risk, and the target device is marked as an abnormal device.

[0081] In this embodiment, the historical access list provides a baseline for the normal behavior of the device or user. Any behavior deviating from this baseline may be regarded as abnormal. By comparing the current access data with the historical access list, any new and unprecedented access patterns or data points can be quickly identified. These new data points may indicate potential security threats or unauthorized access attempts. In addition, by combining the historical access list and the normal data of similar devices for comparison, the anomalies in the current access data can be identified more accurately. The historical access list provides the historical behavior baseline of the device itself, while the normal data of similar devices provides a wider range of normal behavior patterns. The combination of the two can screen out abnormal access more comprehensively.

[0082] Based on the first embodiment of the present application, in the third embodiment of the present application, the same or similar content as in the above-mentioned first embodiment can be referred to the above introduction and will not be repeated hereinafter. On this basis, please refer to Figure 3 , after step S300, steps B100 to B300 may be included:

[0083] Step B100, determining the continuous access data in the current access data;

[0084] Step B200, performing anomaly detection on the continuous access data according to the time series detection algorithm;

[0085] Step B300, if it is detected that the continuous access data is different from the preset standard threshold, confirming that the target device is the abnormal device.

[0086] In this embodiment, when determining whether there is an abnormal situation of the target device according to the continuous access data of the target device, the continuous access data of the target device within a preset time period is compared with the historical distribution of the corresponding continuous access data. When the continuous access data of the target device continuously deviates significantly from the historical distribution, it is considered that an abnormal situation has occurred.

[0087] In this embodiment, the continuous access data may include access traffic, access times, etc. Anomaly detection is performed on the continuous access data according to a time series detection algorithm (such as the ARIMA algorithm (Autoregressive Integrated Moving Average model), an algorithm based on a linear model, a long short-term memory network, etc.). Exemplarily, anomaly detection is performed according to the ARIMA algorithm. First, appropriate ARIMA model parameters (p, d, q) are selected according to the characteristics of the data and business requirements, where p represents the order of the autoregressive term, d represents the order of differencing, and q represents the order of the moving average term. The historical data of the target device is used to fit the ARIMA model to obtain the parameter estimation values of the model. The optimal model parameters are determined by minimizing criteria such as the AIC (Akaike Information Criterion) or BIC (Bayesian Information Criterion) of the model. Secondly, the fitted ARIMA model is used to predict the access data for a period of time in the future. The residual between the actual access data and the predicted data is calculated, that is, the difference between the actual value and the predicted value. The residual is compared with a preset residual threshold, and the residual threshold can be determined based on the standard deviation, percentile, or absolute value of the residual, etc. If the residual exceeds the threshold, it is considered that an anomaly exists.

[0088] Please refer to Figure 4 and Figure 5 , the baseline is determined by machine self-learning within a preset period to obtain the access traffic and access times of normal devices. When the traffic of the target device being accessed exceeds the baseline, or the access times exceed the baseline, it indicates that there is an abnormal situation with the target device.

[0089] In this embodiment, anomaly prediction is performed on the continuous access data according to the time series detection algorithm, which can capture the internal laws and trends in the time series data, so as to accurately predict future data, improving the accuracy and timeliness of the prediction. In addition, discrete data usually has clear classifications and boundaries. By comparing with the data in the historical access list, any new and unprecedented access patterns or data points can be quickly identified. Continuous data usually has time series characteristics. Through the time series detection algorithm, future data trends can be predicted, and potential problems can be warned in a timely manner. By using different methods for anomaly detection of discrete and continuous data, the accuracy and efficiency of the detection can be improved.

[0090] Based on the first embodiment of the present application, in the fourth embodiment of the present application, the same or similar content as in the above-mentioned first embodiment can be referred to the above introduction and will not be repeated hereinafter. On this basis, please refer to Figure 6, steps S01 to S03 may also be included before step S100:

[0091] Step S01, obtain the traffic data in the Internet of Things, and parse the traffic data to obtain target fields.

[0092] Step S02, match the target fields with a preset asset fingerprint rule library to determine device identifiers.

[0093] Step S03, determine the target device and device type corresponding to the device identifier through an encoding naming specification file.

[0094] It should be noted that the asset fingerprint rule library is a database containing various digital asset characteristic information. These characteristic information are usually called "asset fingerprints", which can uniquely identify and distinguish different digital assets. By comparing and analyzing the key protocol characteristics in network traffic, various devices and services in the network can be identified and sorted out.

[0095] In this embodiment, according to a network traffic capture tool or device, such as a network traffic analyzer, network monitoring software, DPI (Deep Packet Inspection), etc., traffic data is captured from the network environment of power Internet of Things devices. The traffic data is parsed to extract target fields containing device information, and the obtained target fields are matched with the power grid scenario asset fingerprint rule library to obtain the corresponding device identifier Device ID. After obtaining the device identifier, an interface mapping is performed with the Device ID naming specification file to determine the specific device type. The encoding naming specification file contains the mapping relationship between the device identifier and the device name and type. For example, the encoding starting with 120600 corresponds to the distribution category, and the encoding starting with 130800 corresponds to the substation category.

[0096] In this embodiment, for the tcp protocol, fields such as the reorganized sequence number are obtained, and this field is compared and matched with a built-in third-party open-source tcp library to obtain the device identifier. For the http protocol, after parsing, field information such as header, body, and user-agent is extracted, and these field information are compared and matched with the field information in the asset fingerprint library to obtain the device identifier. For specific protocols (such as the private protocols of manufacturers such as Hikvision, Dahua, and Uniview), target fields capable of asset matching are extracted according to the protocol specifications of the specific protocols.

[0097] In this embodiment, by using the unique identifier DeviceID encoding of relevant traffic to match the corresponding encoding specification, the specific device and device type can be determined. It can avoid the problem that asset identification is inaccurate due to the dynamic change of the IP for asset identification.

[0098] Based on the first embodiment of the present application, in the fifth embodiment of the present application, the same or similar content as that in the above-mentioned first embodiment can be referred to the above introduction and will not be repeated hereinafter. On this basis, please refer to Figure 7 , after step S300, steps S400 to S500 may further be included:

[0099] Step S400, obtaining the abnormal data of the abnormal device, and determining the risk level according to the abnormal data.

[0100] In this embodiment, when the target device is confirmed as an abnormal device, specific abnormal data is extracted. And the abnormal data is input into a preset abnormal analysis algorithm to obtain an abnormal score. The abnormal score is compared with a preset abnormal score threshold, and the risk level is determined according to the comparison result.

[0101] In this embodiment, the abnormal analysis algorithm may be Isolation Forest, One Class SVM (Support Vector Machine), Local Outlier Factor. Isolation Forest is based on the idea of Random Forest and "isolates" abnormal data points by constructing multiple decision trees. Normal data points usually require more splits to be isolated, while abnormal data points are easily isolated quickly. One Class SVM defines the boundary of normal data by training an SVM model that only contains normal data. Any data point outside this boundary is regarded as abnormal. Local Outlier Factor (LOF) identifies outliers by comparing the local density of a data point with the local density of its neighbors. If the local density of a data point is significantly lower than that of its neighbors, it is regarded as abnormal. Please refer to Figure 8 , the red line is the boundary line fitted according to One Class SVM. The blue points are located within the boundary defined by the red line and are considered normal data. The green points are located outside the boundary defined by the red line and are considered abnormal data and are not included in the category of normal data during the training process of the model.

[0102] In this embodiment, the collected abnormal data is cleaned, standardized, and normalized to ensure the stability and accuracy of the algorithm. An appropriate abnormal analysis algorithm can be selected according to the characteristics of the data and the requirements of anomaly detection. If the dataset is large and has a high dimension, the Isolation Forest is selected; if the data distribution is unknown, One Class SVM is selected; if the abnormal points in the local area are concerned, the Local Outlier Factor is selected. The ensemble learning method can also be used to perform weighted averaging on the prediction results of multiple abnormal analysis algorithms. The prediction results of each algorithm are weighted, and then the weighted average is calculated as the final prediction result. The characteristics of normal data are used to train the abnormal analysis algorithm model, and the trained model is applied to calculate the abnormal score of each abnormal data. The abnormal score represents the degree of deviation of the data point from the behavior baseline. After obtaining the abnormal score, the abnormal score is compared with multiple set abnormal score thresholds, and according to the comparison results, the devices corresponding to the abnormal data are divided into corresponding risk levels. The risk levels can be adjusted according to business requirements and security policies, and can include low risk, medium risk, and high risk. Low risk means that the data point slightly deviates from the normal mode, medium risk means that the data point significantly deviates but has not reached a serious level, and high risk means that the data point is extremely abnormal, which may indicate a potential security threat.

[0103] In this embodiment, by selecting the abnormal data most relevant to the abnormal behavior for analysis, the data dimension and computational complexity can be reduced. This can be achieved through methods such as feature importance evaluation and correlation analysis.

[0104] Step S500, determine the permission control measures according to the risk level.

[0105] In this embodiment, after determining the risk level, the permission control measures can also be determined according to the risk level. If the risk level is high risk, the permission control measure is to isolate the asset. Isolating the asset refers to an action of separating the affected systems, devices, data, or network services, etc. from the normal operating environment in order to prevent the spread of damage or protect the security of other systems and data when abnormal behavior or potential security risks are detected. If the risk level is medium risk, the permission control measure is to prohibit access. If the risk level is low risk, the permission control measure is to issue an alarm.

[0106] In this embodiment, an alarm notification is issued when the risk level is low risk. The alarm can be sent to the security administrator or relevant users via email, text message, system log, etc. The alarm information should include the specific details of the deviation for the administrator to perform quick analysis and response.

[0107] When the risk level is medium risk, the access rights of relevant users can be temporarily prohibited. The prohibition of access can be temporary until the administrator confirms normal behavior or takes further security measures. For users whose access is prohibited, clear feedback and appeal channels should be provided.

[0108] When the risk level is high risk, which may indicate malicious behavior or serious security risks, the affected assets should be immediately isolated. Isolating assets can prevent the spread of potential damage and protect the security of other systems and data at the same time. The isolated assets should be subject to detailed security analysis and processing to ensure that there are no security vulnerabilities or threats. The isolated assets can include the following types: (1) System isolation: Remove the affected servers, workstations or other computing devices from the network or place them in an isolated network area to prevent them from continuing to communicate with other systems or spreading malicious code. (2) Data isolation: Separate the infected or suspicious data files, databases or storage media from the production environment for separate analysis and processing. This can prevent malicious data from being further accessed or exploited. (3) Network isolation: By configuring network devices such as firewalls and routers, isolate the affected network area from other network areas, restrict or block the flow of network traffic to prevent the spread of security threats.

[0109] In this embodiment, by setting response measures at different levels, hierarchical processing of abnormal behaviors is achieved, which not only avoids over-reaction but also ensures that key risks are promptly controlled. Taking different measures for different deviation degrees can reasonably allocate security resources, improve response efficiency and reduce operating costs. Through timely and effective permission control, potential security threats can be effectively curbed and the overall security of the system can be enhanced.

[0110] This application provides a security monitoring device for power Internet of Things devices. The security monitoring device for power Internet of Things devices includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the security monitoring method for power Internet of Things devices in the first embodiment above.

[0111] Refer to the following Figure 9 , which shows a schematic structural diagram of a security monitoring device for power Internet of Things devices suitable for implementing the embodiments of this application. The security monitoring device for power Internet of Things devices in the embodiments of this application can include but are not limited to mobile terminals such as mobile phones, laptop computers, PDAs (Personal Digital Assistant), PADs (portable android devices: tablet computers), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc. and fixed terminals such as digital TVs, desktop computers, etc.Figure 9 The illustrated power IoT device security monitoring device is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of this application.

[0112] As Figure 9 shown, the power IoT device security monitoring device may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM: Read Only Memory) 1002 or the program loaded from the storage device 1003 into the random access memory (RAM: Random Access Memory) 1004. In the RAM 1004, various programs and data required for the operation of the power IoT device security monitoring device are also stored. The processing device 1001, the ROM 1002, and the RAM 1004 are connected to each other through a bus 1005. The input / output (I / O) interface 1006 is also connected to the bus. Generally, the following systems may be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 can allow the power IoT device security monitoring device to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows a power IoT device security monitoring device with various systems, it should be understood that it is not required to implement or have all the shown systems. More or fewer systems can be implemented or had alternatively.

[0113] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in this application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device, or installed from the storage device 1003, or installed from the ROM 1002. When the computer program is executed by the processing device 1001, the above functions defined in the methods of the embodiments disclosed in this application are executed.

[0114] The power IoT device security monitoring device provided by this application adopts the power IoT device security monitoring method in the above-mentioned embodiment, and can solve the technical problem of how to improve the accuracy and effectiveness of the security detection of power IoT devices. Compared with the prior art, the beneficial effects of the power IoT device security monitoring device provided by this application are the same as those of the power IoT device security monitoring method provided by the above-mentioned embodiment, and other technical features in this power IoT device security monitoring device are the same as the features disclosed in the method of the previous embodiment, which will not be elaborated here.

[0115] It should be understood that each part disclosed in this application can be implemented by hardware, software, firmware or a combination thereof. In the description of the above embodiments, specific features, structures, materials or characteristics can be combined in a suitable manner in any one or more embodiments or examples.

[0116] As mentioned above, only the specific implementation manners of this application are described, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed in this application can easily think of changes or substitutions, which should be covered within the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

[0117] This application provides a computer-readable storage medium with computer-readable program instructions (i.e., computer programs) stored thereon, and the computer-readable program instructions are used to execute the power IoT device security monitoring method in the above-mentioned embodiment.

[0118] The computer-readable storage medium provided by the present application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or flash memory, optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this embodiment, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, device, or component. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0119] The above computer-readable storage medium may be included in the power Internet of Things device security monitoring device; or it may exist separately without being assembled into the power Internet of Things device security monitoring device.

[0120] The above computer-readable storage medium carries one or more programs. When the one or more programs are executed by the power Internet of Things device security monitoring device, the power Internet of Things device security monitoring device is caused to: monitor the access behavior of the target device and obtain the current access data corresponding to the access behavior within a preset period; obtain the target Euclidean distance between the target device and the target cluster center according to the current access data; compare the target Euclidean distance with a preset distance threshold. If the target Euclidean distance is greater than the preset distance threshold, the target device is an abnormal device.

[0121] Computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The above-mentioned programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any kind of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).

[0122] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of the code, and this module, program segment, or part of the code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutively represented blocks can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0123] The modules described in the embodiments of this application can be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation to the unit itself in some cases.

[0124] The readable storage medium provided in this application is a computer-readable storage medium. The computer-readable storage medium stores computer-readable program instructions (i.e., computer programs) for performing the above-mentioned power IoT device security monitoring method, and can solve the technical problem of how to improve the accuracy and effectiveness of security detection of power IoT devices. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the power IoT device security monitoring method provided in the above embodiments, and will not be elaborated here.

[0125] The above are only some embodiments of the present application, and thus do not limit the patent scope of the present application. Any equivalent structural transformation made under the technical concept of the present application by using the content of the specification and drawings of the present application, or any direct / indirect application in other related technical fields is included in the patent protection scope of the present application.

Claims

1. A method for safety monitoring of power IoT devices, characterized in that, The described method includes: Monitoring the access behavior of a target device and obtaining the current access data corresponding to the access behavior within a preset period; Obtaining the target Euclidean distance between the target device and the target cluster center according to the current access data; Comparing the target Euclidean distance with a preset distance threshold. If the target Euclidean distance is greater than the preset distance threshold, the target device is an abnormal device.

2. The power IoT device security monitoring method according to claim 1, characterized in that, After the step of comparing the target Euclidean distance with the preset distance threshold, if the distance is greater than the preset distance threshold, the target device is the abnormal device, it includes: Comparing the discrete data in the current access data with a historical access data list; If the discrete data is not in the historical access data list, the target device is the abnormal device.

3. The power IoT device security monitoring method according to any one of claims 1 to 2, characterized in that After the step of comparing the target Euclidean distance with the preset distance threshold, if the distance is greater than the preset distance threshold, the target device is the abnormal device, it includes: Determining the continuous access data in the current access data; Performing anomaly detection on the continuous access data according to a time series detection algorithm; If it is detected that the continuous access data is different from a preset standard threshold, confirm that the target device is the abnormal device.

4. The power IoT device security monitoring method according to claim 1, wherein Before the step of obtaining the target Euclidean distance between the target device and the target cluster center according to the current access data, it includes: Establishing an association matrix based on the access data of each device in the Internet of Things within the preset period; Calculating the Euclidean distance between the devices according to the elements in the association matrix; Performing a clustering operation on the devices according to the Euclidean distance to obtain at least one cluster center.

5. The power IoT device security monitoring method according to claim 1, characterized in that, Before the step of monitoring the access behavior of the target device, it includes: Obtaining the traffic data in the Internet of Things and parsing the traffic data to obtain target fields; Matching the target fields with a preset asset fingerprint rule library to determine device identifiers; Determining the target device and device type corresponding to the device identifier through a coding naming specification file.

6. The power IoT device security monitoring method according to claim 1, wherein, After the step of comparing the target Euclidean distance with the preset distance threshold, if the distance is greater than the preset distance threshold, the target device is the abnormal device, it includes: Obtaining the abnormal data of the abnormal device and determining the risk level according to the abnormal data; Determining permission control measures according to the risk level.

7. The power IoT device security monitoring method according to claim 6, characterized in that, The step of obtaining the abnormal data of the abnormal device and determining the risk level according to the abnormal data includes: Obtaining the abnormal data of the abnormal device; Inputting the abnormal data into a preset anomaly analysis algorithm to obtain an anomaly score; Comparing the anomaly score with a preset anomaly score threshold and determining the risk level according to the comparison result.

8. The power IoT device security monitoring method according to claim 6, wherein, The step of determining permission control measures according to the risk level includes: If the risk level is high risk, the permission control measure is to isolate the asset; If the risk level is medium risk, the permission control measure is to prohibit access; If the risk level is low risk, the permission control measure is to issue an alarm.

9. A safety monitoring device for power Internet of Things devices, characterized in that, The device includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, the computer program being configured to implement the steps of the power IoT device security monitoring method according to any one of claims 1 to 8.

10. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the steps of the power IoT device security monitoring method according to any one of claims 1 to 8.