A method and system for constructing a rule base for automatically generating equipment safety measures

By obtaining the initial deployment status of the power grid and equipment, generating initial comprehensive environmental characteristics, and using a deep reinforcement model to monitor and update the rule base in real time, the problem of the equipment security rule base being insensitive to environmental changes in existing technologies is solved, and dynamic security protection of power grid equipment is achieved.

CN120338088BActive Publication Date: 2025-09-26CIXI SHUBIAN ELECTRICIAN CHENG CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510821380.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-19
Publication Date
2025-09-26
Estimated Expiration
2045-06-19

AI Technical Summary

Technical Problem

The existing device security rule base relies on static data and cannot respond to dynamic changes in the device operating environment in a timely manner, resulting in security protection gaps and an inability to effectively respond to security risks in the new environment.

Method used

By obtaining the initial deployment status of the power grid and equipment, generating initial comprehensive environmental characteristics, building an initial safety measures rule base, and using a deep reinforcement model to monitor and update the rule base in real time, the rule base is dynamically adjusted based on the differences between the current environmental characteristics and the initial characteristics.

Benefits of technology

It realizes real-time perception and precise feature extraction of the operating environment of power grid equipment, can timely detect environmental changes, dynamically update the rule base, improve the safety and adaptability of equipment, reduce the possibility of human error, and improve the efficiency of rule base construction and updating.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120338088B_ABST
    Figure CN120338088B_ABST
Patent Text Reader

Abstract

The present invention provides a method and system for constructing an automatic generation rule base for equipment security measures, relating to the technical field of equipment security management. The method comprises: obtaining the initial deployment status of the power grid and power grid equipment, and generating initial comprehensive environmental characteristics; generating an initial security measure rule base based on the initial comprehensive environmental characteristics; monitoring the power grid and power grid equipment to obtain current operating data, and then fusing the data to obtain multi-source data of the power grid equipment; extracting features from the multi-source data to obtain current comprehensive environmental characteristics; determining whether the operating environment of the power grid equipment has changed based on the current comprehensive environmental characteristics and the initial comprehensive environmental characteristics; and if so, updating the initial security measure rule base based on the current comprehensive environmental characteristics and the initial comprehensive environmental characteristics through a deep reinforcement model to obtain a current security measure rule base. The present invention provides more reliable and intelligent security protection for power grid equipment in complex and changing operating environments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of equipment safety management, and in particular to a method and system for constructing an automatic generation rule base for equipment safety measures. Background Art

[0002] The management of equipment operational safety in power grids is typically based on the initial fixed deployment state of the equipment, relying primarily on static data such as device type, basic configuration information, and known security incident history. A rule base is formed through manual experience summary or simple algorithmic analysis. This provides a certain degree of basic protection for the equipment, ensuring its safe operation in normal environments.

[0003] In related technologies, the operating environment of devices is often in a state of constant change, such as adjustments to network topology, physical relocation of devices, or connection to new peripherals. However, existing rule bases are generally constructed based on static data, making them insensitive to dynamic changes in the device's operating environment. Consequently, changes in the operating environment cannot be detected in a timely manner, rendering existing rules unable to address security risks in new environments. This creates security gaps and seriously threatens the safe operation of devices. Summary of the Invention

[0004] The problem solved by the present invention is how to improve the security of a device security measure rule base.

[0005] To solve the above problems, the present invention provides a method and system for constructing a rule base for automatically generating equipment safety measures.

[0006] In a first aspect, the present invention provides a method for constructing a rule base for automatically generating device security measures. The method is applied to a power grid, wherein the power grid includes a plurality of power grid devices, each of the power grid devices being deployed at a respective node of the power grid. The method includes:

[0007] Acquire an initial deployment state of the power grid and an initial deployment state of the power grid device corresponding to each node of the power grid;

[0008] generating an initial comprehensive environmental feature of the power grid device according to the initial deployment state of the power grid and the initial deployment state of the power grid device;

[0009] generating an initial security measure rule base for the power grid device according to the initial comprehensive environment characteristics;

[0010] monitoring the power grid and the power grid equipment to obtain current operating data of the power grid and the current operating data of the power grid equipment, and fusing the current operating data of the power grid and the current operating data of the power grid equipment to obtain multi-source data of the power grid equipment;

[0011] Extracting features from the multi-source data to obtain current comprehensive environmental features of the power grid equipment;

[0012] determining, based on the current comprehensive environmental characteristics and the initial comprehensive environmental characteristics, whether the operating environment of the power grid device has changed;

[0013] When the operating environment changes, the initial security measure rule base is updated according to the current comprehensive environment characteristics and the initial comprehensive environment characteristics through the deep reinforcement model to obtain the current security measure rule base of the power grid equipment.

[0014] Optionally, generating the initial comprehensive environmental characteristics of the power grid equipment based on the initial deployment state of the power grid and the initial deployment state of the power grid equipment includes: determining the initial operation data of the power grid and the initial operation data of the power grid equipment based on the initial deployment state of the power grid and the initial deployment state of the power grid equipment; performing feature extraction on the initial operation data of the power grid and the initial operation data of the power grid equipment respectively to obtain device status characteristics of the power grid equipment and power grid operation characteristics of the power grid; performing feature fusion on the device status characteristics and the power grid operation characteristics to obtain fusion characteristics, and using the fusion characteristics as the initial comprehensive environmental characteristics.

[0015] Optionally, generating an initial security measure rule base for the power grid equipment based on the initial comprehensive environmental characteristics includes: decomposing the initial comprehensive environmental characteristics into multiple key feature dimensions, and establishing a relationship model between the feature dimensions and the security risks of the power grid equipment; determining a weight value of each key feature dimension based on equipment parameters of the power grid equipment; determining a security risk value of the power grid equipment based on the relationship model and the weight value; and setting an initial security measure rule base based on the security risk value.

[0016] Optionally, the monitoring of the power grid and power grid equipment to obtain current operating data of the power grid and current operating data of the power grid equipment includes: obtaining a monitoring frequency for monitoring the power grid and power grid equipment by mapping the security risk value with a preset mapping table; monitoring the power grid and power grid equipment according to the monitoring frequency to obtain current operating data of the power grid and the power grid equipment at the current time point.

[0017] Optionally, the current operating data of the power grid and the current operating data of the power grid equipment are fused to obtain multi-source data of the power grid equipment, including: format conversion of the current operating data of the power grid and the current operating data of the power grid equipment to obtain the current operating data with the same timestamp and data format; and fusing the current operating data with the same timestamp and data format through a Kalman filtering algorithm to obtain the multi-source data of the power grid equipment.

[0018] Optionally, the feature extraction of the multi-source data to obtain the current comprehensive environmental characteristics of the power grid equipment includes: dividing the multi-source data into multiple data windows with the same time period, and calculating the data analysis parameters in each data window, wherein the data analysis parameters include the data mean, variance, standard deviation, peak, root mean square value, kurtosis, skewness, zero crossing rate and absolute mean value of the data in the data window; integrating the data analysis parameters to obtain the time domain characteristics of the multi-source data; converting the multi-source data from the time domain to the frequency domain through Fourier transform to obtain the frequency domain characteristics of the multi-source data; and obtaining the current comprehensive environmental characteristics based on the time domain characteristics and the frequency domain characteristics.

[0019] Optionally, judging whether the operating environment of the power grid device has changed based on the current comprehensive environmental characteristics and the initial comprehensive environmental characteristics includes: comparing and calculating the current comprehensive environmental characteristics with the initial comprehensive environmental characteristics to obtain the characteristic difference between the current comprehensive environmental characteristics and the initial comprehensive environmental characteristics; judging whether the operating environment of the power grid device has changed based on the relationship between the characteristic difference and a preset difference threshold; wherein, when the characteristic difference is greater than or equal to the preset difference threshold, it is judged that the operating environment of the power grid device has changed; when the characteristic difference is less than the preset difference threshold, it is judged that the operating environment of the power grid device has not changed.

[0020] Optionally, the comparing and calculating the current comprehensive environmental feature with the initial comprehensive environmental feature to obtain the feature difference between the current comprehensive environmental feature and the initial comprehensive environmental feature includes: decomposing the current comprehensive environmental feature and the initial comprehensive environmental feature into multiple corresponding dimensions, and assigning a corresponding weight value to each dimension, wherein each dimension of the current comprehensive environmental feature and the initial comprehensive environmental feature corresponds to each other; calculating the absolute difference corresponding to each dimension according to the difference calculation method corresponding to each dimension; and performing weighted summation based on the absolute difference values ​​and the weight values ​​of all the dimensions to obtain the feature difference.

[0021] Optionally, the deep reinforcement model is used to update the initial security measures rule base according to the current comprehensive environment characteristics and the initial comprehensive environment characteristics to obtain the current security measures rule base of the power grid equipment, including: inputting the current comprehensive environment characteristics and the initial comprehensive environment characteristics into the deep reinforcement model, and taking the operating environment characteristics of the power grid equipment as the state, and taking the update operation of the initial security measures rule base as the action; iteratively updating the action through the deep reinforcement model, and then optimizing the initial security measures rule base according to the action, and judging whether the update of the action is completed through the state; when the action update is completed, updating the initial security measures rule base according to the update operation corresponding to the action to obtain the current security measures rule base.

[0022] In a second aspect, the present invention provides a system for automatically generating a rule base for equipment security measures. The system is applied to a power grid, wherein the power grid includes a plurality of power grid devices, each of which is deployed at a respective node of the power grid. The system includes:

[0023] an acquiring unit, configured to acquire an initial deployment state of the power grid and an initial deployment state of the power grid device corresponding to each node of the power grid;

[0024] an initial setting unit, configured to generate an initial comprehensive environmental feature of the power grid device according to the initial deployment state of the power grid and the initial deployment state of the power grid device;

[0025] The initial setting unit is further configured to generate an initial security measure rule base for the power grid device based on the initial comprehensive environment characteristics;

[0026] a monitoring unit, configured to monitor the power grid and the power grid equipment, obtain current operating data of the power grid and the current operating data of the power grid equipment, and fuse the current operating data of the power grid and the current operating data of the power grid equipment to obtain multi-source data of the power grid equipment;

[0027] A feature extraction unit, configured to extract features from the multi-source data to obtain current comprehensive environmental features of the power grid equipment;

[0028] a judging unit, configured to judge whether the operating environment of the power grid device has changed based on the current comprehensive environmental characteristics and the initial comprehensive environmental characteristics;

[0029] The optimization unit is used to update the initial security measure rule base according to the current comprehensive environment characteristics and the initial comprehensive environment characteristics through a deep reinforcement model when the operating environment changes, so as to obtain the current security measure rule base of the power grid equipment.

[0030] The method and system for constructing a rule base for automatically generating equipment security measures of the present invention constructs and updates security measure rules for each grid device deployed at each node of the power grid. Since the operating environments, functions, and risks faced by grid devices at different nodes vary, the present invention can generate practical security measure rules for each device based on its specific circumstances, thus achieving more accurate and detailed security protection. Specifically:

[0031] The generation of initial comprehensive environmental features provides the foundational data for the construction of the initial rule base and serves as a reference for subsequent environmental change detection. Multi-source data fusion and feature extraction technologies ensure that the system can comprehensively and accurately capture the real-time state of the power grid equipment operating environment and convert it into analyzable feature data. The environmental change detection mechanism compares the current features with the initial features, promptly identifying any subtle changes in the environment and triggering the rule base update process. As the core of intelligent decision-making, the deep reinforcement model dynamically adjusts the rule base based on the changed environmental features to ensure that it always matches the current operating environment.

[0032] Specifically, by capturing the initial deployment state of the power grid and devices and generating initial comprehensive environmental features, this approach not only provides a comprehensive and dynamic foundation for constructing the initial security measures rule base but also establishes a benchmark for subsequent environmental change assessments. Secondly, by continuously monitoring the current operational data of the power grid and devices, this data is integrated with grid data to form multi-source data, and further features are extracted to generate the current comprehensive environmental features. This achieves real-time perception of the dynamic operating environment and accurate feature extraction, in stark contrast to traditional methods that rely solely on static data. This addresses the issue of existing rule bases being insensitive to environmental changes. Traditional methods rely on static data to construct rule bases, making them unable to promptly respond to new risks brought about by environmental changes. Thirdly, by comparing the current comprehensive environmental features with the initial comprehensive environmental features, the approach accurately determines whether the operating environment of power grid devices has changed. Once an environmental change is detected, a deep reinforcement model is used to intelligently update the initial security measures rule base, combining the current and initial features, to generate a current security measures rule base adapted to the new environment. The deep reinforcement model adaptively adjusts rules based on changes in environmental features, thus achieving dynamic updating and optimization of the rule base.

[0033] The power grid of the present invention includes various types of power grid equipment, such as medium-voltage switch stations, ring network units, distribution transformers, smart meters, etc., and the deployment nodes and operating environments of different devices are different. The present invention can construct and update the security measures rule base for these different types of equipment respectively, without the need to develop a specific security measures generation scheme for each device separately, and has good compatibility. Whether it is a new power grid or an upgrade of an existing power grid, it is applicable, has strong versatility, and can be widely used in various power grid scenarios. When the power grid scale is expanded or the equipment is updated, the present invention can easily incorporate the new equipment into the monitoring and rule generation system. It only needs to obtain the initial deployment status and related operating data of the new equipment to generate corresponding security measures rules for it and integrate them into the existing rule base. At the same time, with the continuous learning and optimization of the deep reinforcement model, the entire system can naturally adapt to the changes and development of the power grid. There is no need for large-scale transformation or reconstruction of the original system. It is easy to expand and upgrade the power grid security measures rule base to ensure the safe operation of the power grid at different development stages.

[0034] In summary, the present invention perceives environmental changes in real time through continuous monitoring and feature extraction, and uses a deep reinforcement model to dynamically update the rule base to ensure that it always adapts to the current environment, effectively eliminating security protection gaps caused by environmental changes. Furthermore, the application of the deep reinforcement model enables the rule base to be adaptively updated and optimized, effectively responding to various security risks in the new environment, and significantly improving the security and adaptability of the power grid equipment safety measures rule base. In addition, this dynamic update mechanism also reduces dependence on manual experience, reduces the possibility of human error, and improves the efficiency of rule base construction and updating. Finally, the present invention provides more reliable and intelligent security protection for power grid equipment in a complex and changeable operating environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1 A flowchart of a method for automatically generating a rule base for device security measures according to an embodiment of the present invention;

[0036] Figure 2 This is a structural block diagram of a system for automatically generating a rule base for device security measures according to an embodiment of the present invention. DETAILED DESCRIPTION

[0037] To make the above-mentioned objects, features, and advantages of the present invention more clearly understood, specific embodiments of the present invention are described in detail below with reference to the accompanying drawings. Although certain embodiments of the present invention are shown in the accompanying drawings, it should be understood that the present invention can be implemented in various forms and should not be construed as being limited to the embodiments described herein. Instead, these embodiments are provided to provide a more thorough and complete understanding of the present invention. It should be understood that the drawings and embodiments of the present invention are for illustrative purposes only and are not intended to limit the scope of protection of the present invention.

[0038] It should be understood that the various steps described in the method embodiments of the present invention may be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present invention is not limited in this respect.

[0039] The term "including" and its variations used in this document are open inclusions, that is, "including but not limited to"; the term "based on" means "based at least in part on"; the term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one other embodiment"; the term "some embodiments" means "at least some embodiments"; the term "optionally" means "optional embodiments". The relevant definitions of other terms will be given in the following description. It should be noted that the concepts of "first", "second", etc. mentioned in the present invention are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.

[0040] It should be noted that the modifications of "one" and "multiple" mentioned in the present invention are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly indicated in the context, it should be understood as "one or more".

[0041] The names of the messages or information exchanged between multiple devices in the embodiments of the present invention are only used for illustrative purposes and are not used to limit the scope of these messages or information.

[0042] In the field of power grid equipment operational safety management, traditional rule-base construction methods primarily rely on the initial fixed deployment state of the equipment. These methods are based on static data such as device type, basic configuration information, and historical records of known security incidents, and are then developed through manual experience or simple algorithmic analysis. This static data is generally determined before the equipment is commissioned and remains relatively stable during operation. The device type determines its basic functions and operational characteristics, while basic configuration information includes initial settings such as network parameters and user permissions. Historical records of known security incidents provide empirical references for past security issues. Manual experience-based analysis relies on professional personnel's knowledge of equipment operation and security incidents, while simple algorithmic analysis processes the data through statistical and association rule mining methods. While this approach, based on static data and manual experience, can provide a certain degree of basic protection for equipment and ensure safe operation under standard conditions, it has significant limitations.

[0043] However, the actual operating environment of power grid equipment is constantly changing. Network topology adjustments are common. As power grids expand and are optimized and upgraded, network connectivity may change, impacting inter-device communication and data transmission security. Equipment physical locations may also shift due to grid layout adjustments or equipment maintenance and relocation, exposing them to various physical security threats, such as changes in ambient temperature and humidity or the risk of vandalism. Furthermore, connecting new peripherals is a common operation during device operation, which can introduce new security vulnerabilities or cause compatibility issues with existing equipment. These dynamic changes make it difficult for rule bases built on static data to promptly detect security risks in new environments. Existing rule bases cannot dynamically adapt to these changes, leaving existing rules unresponsive to new security threats. This creates security gaps and seriously threatens the safe operation of equipment. For example, new devices may introduce unknown vulnerabilities, connecting peripherals may introduce malware, and changes in network topology may cause data transmission paths to pass through unsafe areas. These situations can expose equipment to new security risks. Traditional rule bases, lacking the ability to perceive and respond to dynamic changes, are unable to provide effective security protection measures in a timely manner, increasing the vulnerability of power grid equipment to security attacks and reducing the reliability and stability of power grid operations.

[0044] In response to the problems existing in the above-mentioned related technologies, this embodiment provides a method and system for constructing a rule base for automatically generating device security measures.

[0045] Combine Figure 1 As shown, an embodiment of the present invention provides a method for constructing a rule base for automatically generating equipment security measures. The method is applied to a power grid, which includes multiple power grid devices, each of which is deployed at each node of the power grid.

[0046] Specifically, the power grid is a distribution network, which includes a variety of grid equipment distributed across various nodes of the grid. This equipment includes medium-voltage switchgear, a key node in the grid that connects multiple distribution lines and aggregates and distributes electrical energy. Within the switchgear are switchgear, such as circuit breakers and disconnectors, that control and protect the various lines. For example, in the distribution network of a small industrial park, a medium-voltage switchgear is the intersection of the main line and various branch lines. If a branch line fails, the circuit breaker within the switchgear can quickly disconnect the faulty line, preventing the fault from spreading to the entire distribution network.

[0047] Another example is a ring network unit (RMU), typically installed at a node in a distribution network. Its primary components include load switches and fuses. RMUs make distribution network power supply more flexible and reliable, enabling a daisy-chain approach to power supply. For example, in a residential area, multiple RMUs are interconnected to form a ring network power supply structure. Under normal circumstances, each RMU is powered by two adjacent power sources. If one of these power sources fails, the RMU's load switch can switch power to the remaining source, ensuring continued power supply to residents.

[0048] Distribution transformers, located at the end nodes of a distribution network, are critical devices that convert medium-voltage electricity into low-voltage power. The operating status of these transformers directly impacts the quality of power supply to users. For example, in rural distribution networks, each village or small production and processing area has one or more distribution transformers. If a distribution transformer overloads or fails, it can cause voltage instability or even power outages in the area, impacting residents' lives and production activities.

[0049] Smart meters, deployed at user-side nodes, measure electricity usage. They collect real-time electricity usage data and upload it to the distribution network's monitoring system. For example, in a city's commercial office building distribution network, each office is equipped with a smart meter, which accurately measures each user's electricity usage and provides data support for load management and energy efficiency analysis.

[0050] The method comprises:

[0051] An initial deployment state of the power grid and an initial deployment state of the power grid device corresponding to each node of the power grid are obtained.

[0052] Specifically, collect geographic information about the area covered by the power grid, including topography, landforms, and building distribution, to understand the geographic distribution characteristics and environmental factors of power grid equipment. For example, using Geographic Information System (GIS) technology, create a map of the power grid's geographic layout, noting features such as mountains, rivers, and roads. This allows for the impact of these factors on power grid equipment to be considered in the subsequent development of safety measures. For example, equipment in mountainous areas may be at risk of lightning strikes, while equipment near rivers may require attention to flooding risks. Define the grid's connectivity, including the electrical connections between substations, switchyards, ring network units, distribution lines, distribution transformers, and other components. This can be obtained from grid design drawings, wiring diagrams, and other materials. For example, by creating single-line diagrams and network topology diagrams, identify the connections between each node and its neighbors, as well as the location and function of each node in the grid, to determine the current flow path and power supply range. Collect basic parameters of the distribution lines, such as line length, conductor type, diameter, resistance, and reactance. These parameters are essential for calculating line voltage loss, current carrying capacity, and losses. For example, based on the conductor model and length of the line, the impedance of the line can be calculated, and then the voltage drop and power loss of the line under different load conditions can be evaluated, providing a basis for the economic operation of the power grid and the formulation of safety measures.

[0053] At each node in the power grid, determine the type and specific model of grid equipment deployed. Common equipment types include circuit breakers, disconnectors, fuses, distribution transformers, smart meters, reactive power compensation devices, and relay protection devices. Different types of equipment have different functions and operating characteristics, and different models of the same type may also have different parameters and technical indicators. For example, different models of distribution transformers have different parameters such as rated capacity, transformation ratio, and impedance voltage. This information directly affects the safe operation of the equipment and the corresponding safety measures.

[0054] Record the specific installation location of each grid device at the grid node, including its specific location information in locations such as substations, switch stations, distribution rooms, and outdoor towers. Also, collect information about the equipment's surrounding environment, such as temperature, humidity, altitude, and pollution levels. For example, equipment installed outdoors may be affected by severe weather conditions, while equipment installed in basements may face high humidity. These environmental factors can increase the risk of equipment aging and failure. Therefore, it is necessary to develop corresponding protective measures for equipment in different environments within the safety measures rule base. For example, lightning protection, wind protection, and waterproofing measures should be implemented for outdoor equipment, while moisture and condensation prevention measures should be strengthened for basement equipment.

[0055] Obtain the initial configuration parameters of power grid equipment, such as the rated current and protection settings of circuit breakers, the tap changer position and load factor of distribution transformers, and the metering parameters and communication parameters of smart meters. These parameters are essential for the normal operation of the equipment and are an important basis for determining whether the equipment is operating safely. By collecting these parameters, we can understand the initial operating status and performance indicators of the equipment, providing a reference for subsequent monitoring and updating safety measures. For example, the load factor parameter of a distribution transformer can help determine its initial load level. When the operating environment changes or the load increases, this parameter can be used to assess whether the equipment is at risk of overload and promptly adjust the relevant content in the safety measure rule base, such as adjusting the load distribution strategy or adding heat dissipation measures.

[0056] The initial deployment status of the power grid and equipment is comprehensively collected from grid planning and design documents, equipment procurement lists, installation and commissioning records, and other materials. This includes the grid topology (such as substation distribution and transmission line connection methods), equipment types (such as transformers, circuit breakers, and relay protection devices), basic equipment configuration information (such as network parameters, user permission settings, and initial device parameter values), the physical location of the equipment (such as the installation location coordinates of equipment within the substation and the geographic coordinates of outdoor equipment), and the initial connection status of peripherals (such as monitoring sensors and communication modules).

[0057] An initial comprehensive environmental feature of the power grid device is generated according to the initial deployment state of the power grid and the initial deployment state of the power grid device.

[0058] Specifically, key features are extracted from the preprocessed initial deployment state to construct an initial comprehensive environmental feature vector. For example, for the power grid topology, features such as the number of nodes and the complexity of connectivity relationships are extracted. For device types, these are converted into numerical features using methods such as one-hot encoding. For configuration parameters, key parameters are digitized and their initial values ​​are extracted as features. For physical locations, location features are generated based on geographic coordinates or relative position encoding. For initially connected peripherals, features such as device type and connection status are also extracted using methods such as one-hot encoding. Each extracted feature is normalized to eliminate dimensional differences. Weights are then assigned based on their importance to device security, and weighted fusion is performed to construct the initial comprehensive environmental feature vector. Weights can be determined through methods such as expert scoring and historical data analysis. For example, device type and configuration parameters are generally more important in security assessments and can be assigned relatively higher weights.

[0059] An initial security measure rule base for the power grid device is generated according to the initial comprehensive environment characteristics.

[0060] Specifically, based on the initial comprehensive environmental characteristics, security analysis models and algorithms (such as fault tree analysis and risk matrix methods) are used, combined with the safe operation standards and specifications of power grid equipment, to analyze the potential security risks faced by power grid equipment in the initial environment. For example, based on the device's location and connection relationships in the network topology, device nodes vulnerable to network attacks are identified; based on the initial values ​​of configuration parameters, configuration items that may pose security risks are discovered.

[0061] For example, taking a transformer protection system in a power grid as an example, to analyze the possible causes of power outages caused by transformer failures, a safety analysis model, such as a fault tree model, is used to construct a fault tree. The fault tree includes intermediate events such as "overload," "short circuit," and "insulation failure," and is further broken down into basic events such as "load exceeding rated capacity" and "relay protection device failure." Based on the fault tree analysis results, the probability of each basic event is calculated, and key influencing factors are identified. For example, the analysis found that "relay failure" has a significant impact on protection device failure and has a relatively high probability of occurrence. In conjunction with safety operation standards and regulations for power grid equipment (such as the "Power Transformer Operation Regulations"), safety measures are formulated to address these key factors. For example, according to regulations, the regular inspection and maintenance cycle for relays is shortened to once every three months. Redundant protection circuits are designed to ensure that if one circuit fails, another circuit can be promptly activated. Finally, these safety measures are organized and stored to build an initial safety measure rule library for the transformer. For example, rule number 001 states: "Monitor the condition of the transformer relay monthly, recording its actuation count and response time. If the actuation count exceeds the set threshold or the response time delay exceeds the specified value, immediately repair or replace it." This approach generates an initial safety measure rule library that matches the actual operating environment of the transformer based on the initial comprehensive environmental characteristics and fault tree model, providing a foundation for safe transformer operation.

[0062] Based on the identified security risks, appropriate security measures rules are developed, incorporating the experience of security experts and known security policies. Rules include elements such as rule name, applicable conditions, and operational content. For example, access control rules for critical equipment should clearly define the user roles permitted, access time ranges, and authentication methods. The developed security measures rules are organized and stored in an initial security measures rule library. This rule library can be implemented as a database or configuration file to facilitate subsequent query and update operations.

[0063] The power grid and power grid equipment are monitored to obtain current operating data of the power grid and current operating data of the power grid equipment, and the current operating data of the power grid and current operating data of the power grid equipment are integrated to obtain multi-source data of the power grid equipment.

[0064] Specifically, grid monitoring systems (such as SCADA systems and network traffic monitoring tools) are used to collect real-time grid operational data, including network traffic, power transmission, voltage and current values. This data reflects the overall operational status of the grid and network transmission conditions. For example, the SCADA system can obtain real-time power data, line voltage and current information, and other information from each substation in the grid. Network traffic monitoring tools can provide information on the traffic volume and packet transmission rate of the grid communication network.

[0065] Through device management systems and log collection tools, we can obtain operational status data for power grid equipment, including performance indicators (such as CPU usage, memory utilization, and disk I / O frequency), device logs (such as startup and downtime, operation records, and fault alarms), and status changes of connected peripherals (such as peripheral plugging and unplugging, and operating mode switching). This data can reflect the real-time operational status and performance of the equipment.

[0066] The collected current grid operation data and current grid equipment operation data are integrated to generate multi-source data. Data fusion can utilize algorithms such as Kalman filtering and weighted averaging. For example, network traffic data and equipment performance data can be combined and averaged according to specific weights to generate comprehensive data that more comprehensively reflects the equipment's operating status. Furthermore, the data is synchronized in time and formatted uniformly to ensure consistency and integrity across multiple sources, facilitating subsequent feature extraction and analysis.

[0067] Feature extraction is performed on the multi-source data to obtain current comprehensive environmental features of the power grid equipment.

[0068] Specifically, feature extraction is performed on the fused multi-source data. The extracted features should correspond to the initial comprehensive environmental features to facilitate subsequent comparative analysis. Feature extraction can be performed using methods such as signal processing, statistical analysis, and machine learning. For example, traffic features can be extracted from network traffic data, such as the mean and variance of traffic volume, and peak and valley values ​​of traffic rate; performance features can be extracted from device performance data, such as peak CPU usage and average memory usage; and log features can be extracted from device log information, such as log type distribution and log frequency.

[0069] The extracted features are normalized to eliminate dimensional differences and make them comparable. Then, using the same weighting and fusion methods used to construct the initial comprehensive environmental features, the extracted current features are weighted and fused to construct the current comprehensive environmental feature vector. This ensures that the current and initial comprehensive environmental features reside in the same feature space, facilitating subsequent similarity comparisons and environmental change assessments.

[0070] Whether the operating environment of the power grid device has changed is determined based on the current comprehensive environmental characteristics and the initial comprehensive environmental characteristics.

[0071] Specifically, the similarity between the current integrated environment feature vector and the initial integrated environment feature vector can be calculated using methods such as Euclidean distance, cosine similarity, and Manhattan distance. For example, the Euclidean distance formula is used to calculate the distance between two feature vectors in the feature space. A larger distance indicates a greater difference between the two feature vectors, that is, a more significant change in the operating environment. Cosine similarity is used to calculate the cosine value of the angle between the two vectors. A smaller cosine value indicates a greater difference in the vector directions, which means that the operating environment may have changed.

[0072] Set a reasonable similarity threshold based on historical data and actual operating experience. When the calculated similarity is less than the threshold, the operating environment of the power grid equipment is considered to have changed; otherwise, the operating environment is considered unchanged. In practice, the threshold setting can be continuously optimized through historical data analysis and experimental verification to balance the false positive rate and missed positive rate, ensuring timely and accurate detection of changes in the operating environment.

[0073] When the operating environment changes, the initial security measure rule base is updated according to the current comprehensive environment characteristics and the initial comprehensive environment characteristics through the deep reinforcement model to obtain the current security measure rule base of the power grid equipment.

[0074] Specifically, a deep reinforcement learning model is constructed. In a preferred embodiment of the present invention, the deep reinforcement learning model utilizes a deep Q-network (DQN) architecture. Its main components include an experience replay pool, which stores state information before and after changes in the operating environment of power grid equipment, rule update actions taken, and corresponding reward signals. Training is performed by randomly sampling mini-batch data to break down data correlations and improve model stability and convergence speed. A deep neural network (DNN) consists of multiple hidden layers, including fully connected layers and convolutional layers. The input layer receives the difference between the current and initial comprehensive environment feature vectors, as well as the rule features in the initial safety measure rule base. The hidden layers use nonlinear activation functions to extract and learn complex patterns and features in the data. The output layer outputs update actions to the initial safety measure rule base, such as adding rules, deleting rules, and modifying rule parameters. The target network has the same structure as the DNN, but with fixed parameters. Parameters are periodically copied from the DNN to generate target Q values, stabilizing the training process and improving model convergence and performance. Environmental simulation constructs a power grid equipment operating environment simulator, simulating environmental changes and safety risk scenarios, generating a large number of environmental feature samples and corresponding optimal rule update strategies. The training process inputs the simulated data into the DNN, and through interaction with the environment simulator, calculates the Q value of each possible action taken in the current state, uses the loss function to measure the difference between the predicted Q value and the target Q value, and uses an optimization algorithm (such as Adam) to update the network parameters. The target network periodically copies parameters from the DNN, and continuously iterates training until the model converges.

[0075] Specifically, when a change in the operating environment of power grid equipment is detected, the difference between the current and initial comprehensive environmental feature vectors, along with the rule features of the initial security measures rule base, is fed into a trained deep reinforcement learning model. The model uses forward propagation to output updates to the initial security measures rule base, such as adding rules, deleting rules, and modifying rule parameters. The rule management module executes these updates to generate the current security measures rule base, adapting to changes in the power grid equipment operating environment and improving the effectiveness of security protection.

[0076] The model inputs include the difference between the current and initial comprehensive environment feature vectors, as well as the rule features in the initial security measure rule base. Rule features can be used to vectorize rules, such as rule type (access control rules, data encryption rules, etc.) and rule parameters (such as access permission level and encryption algorithm type). The model outputs updates to the initial security measure rule base, including operations such as adding rules, deleting rules, and modifying rule parameters.

[0077] During the model training phase, by simulating changes in the operating environment of power grid equipment, a large number of environmental feature samples and corresponding optimal rule update strategies are generated to construct a training dataset. The model is trained using deep reinforcement learning algorithms (such as DQN and DDPG). The model continuously interacts with the environment in a simulated environment, trying different rule update actions. Model parameters are adjusted based on reward signals from the environment (such as the safety protection effect and system operating efficiency after the rule update), gradually learning the optimal rule update strategy until the model converges.

[0078] When a change in the operating environment of power grid equipment is detected, the difference between the current and initial comprehensive environmental feature vectors, along with the rule features of the initial security measures rule base, is input into the trained deep reinforcement model. Based on the learned strategy, the model outputs updates to the initial security measures rule base. The rule management module executes these actions, such as adding rules to address new environmental security risks, deleting rules that are no longer applicable, and adjusting the parameters of existing rules. This results in a current security measures rule base that adapts to changes in the power grid equipment operating environment and improves the effectiveness of security protection.

[0079] The method and system for constructing a rule base for automatically generating equipment security measures of the present invention constructs and updates security measure rules for each grid device deployed at each node of the power grid. Since the operating environments, functions, and risks faced by grid devices at different nodes vary, the present invention can generate practical security measure rules for each device based on its specific circumstances, thus achieving more accurate and detailed security protection. Specifically:

[0080] The generation of initial comprehensive environmental features provides the foundational data for the construction of the initial rule base and serves as a reference for subsequent environmental change detection. Multi-source data fusion and feature extraction technologies ensure that the system can comprehensively and accurately capture the real-time state of the power grid equipment operating environment and convert it into analyzable feature data. The environmental change detection mechanism compares the current features with the initial features, promptly identifying any subtle changes in the environment and triggering the rule base update process. As the core of intelligent decision-making, the deep reinforcement model dynamically adjusts the rule base based on the changed environmental features to ensure that it always matches the current operating environment.

[0081] Specifically, by capturing the initial deployment state of the power grid and devices and generating initial comprehensive environmental features, this approach not only provides a comprehensive and dynamic foundation for constructing the initial security measures rule base but also establishes a benchmark for subsequent environmental change assessments. Secondly, by continuously monitoring the current operational data of the power grid and devices, this data is integrated with grid data to form multi-source data, and further features are extracted to generate the current comprehensive environmental features. This achieves real-time perception of the dynamic operating environment and accurate feature extraction, in stark contrast to traditional methods that rely solely on static data. This addresses the issue of existing rule bases being insensitive to environmental changes. Traditional methods rely on static data to construct rule bases, making them unable to promptly respond to new risks brought about by environmental changes. Thirdly, by comparing the current comprehensive environmental features with the initial comprehensive environmental features, the approach accurately determines whether the operating environment of power grid devices has changed. Once an environmental change is detected, a deep reinforcement model is used to intelligently update the initial security measures rule base, combining the current and initial features, to generate a current security measures rule base adapted to the new environment. The deep reinforcement model adaptively adjusts rules based on changes in environmental features, thus achieving dynamic updating and optimization of the rule base.

[0082] The power grid of the present invention includes various types of power grid equipment, such as medium-voltage switch stations, ring network units, distribution transformers, smart meters, etc., and the deployment nodes and operating environments of different devices are different. The present invention can construct and update the security measures rule base for these different types of equipment respectively, without the need to develop a specific security measures generation scheme for each device separately, and has good compatibility. Whether it is a new power grid or an upgrade of an existing power grid, it is applicable, has strong versatility, and can be widely used in various power grid scenarios. When the power grid scale is expanded or the equipment is updated, the present invention can easily incorporate the new equipment into the monitoring and rule generation system. It only needs to obtain the initial deployment status and related operating data of the new equipment to generate corresponding security measures rules for it and integrate them into the existing rule base. At the same time, with the continuous learning and optimization of the deep reinforcement model, the entire system can naturally adapt to the changes and development of the power grid. There is no need for large-scale transformation or reconstruction of the original system. It is easy to expand and upgrade the power grid security measures rule base to ensure the safe operation of the power grid at different development stages.

[0083] In summary, the present invention perceives environmental changes in real time through continuous monitoring and feature extraction, and uses a deep reinforcement model to dynamically update the rule base to ensure that it always adapts to the current environment, effectively eliminating security protection gaps caused by environmental changes. Furthermore, the application of the deep reinforcement model enables the rule base to be adaptively updated and optimized, effectively responding to various security risks in the new environment, and significantly improving the security and adaptability of the power grid equipment safety measures rule base. In addition, this dynamic update mechanism also reduces dependence on manual experience, reduces the possibility of human error, and improves the efficiency of rule base construction and updating. Finally, the present invention provides more reliable and intelligent security protection for power grid equipment in a complex and changeable operating environment.

[0084] Optionally, generating the initial comprehensive environmental characteristics of the power grid equipment based on the initial deployment state of the power grid and the initial deployment state of the power grid equipment includes: determining the initial operation data of the power grid and the initial operation data of the power grid equipment based on the initial deployment state of the power grid and the initial deployment state of the power grid equipment; performing feature extraction on the initial operation data of the power grid and the initial operation data of the power grid equipment respectively to obtain device status characteristics of the power grid equipment and power grid operation characteristics of the power grid; performing feature fusion on the device status characteristics and the power grid operation characteristics to obtain fusion characteristics, and using the fusion characteristics as the initial comprehensive environmental characteristics.

[0085] Specifically, initial grid operation data is extracted from grid planning and design documents and historical operation records. This includes the initial network topology (substation locations, transmission line connections, etc.), initial power transmission parameters (initial power transmission values ​​for each line, initial power injection values ​​for substations, etc.), initial voltage and current values ​​(initial voltage amplitudes and phase angles at each node, initial current values ​​for each line, etc.), and the grid's initial operating mode (normal operation mode, maintenance mode, etc.). This data reflects the grid's operational status and network state in its initial deployment state. Initial equipment operating status information is obtained from equipment factory information, installation and commissioning records, and initial operation logs. This includes initial performance indicators (such as the initial load factor of transformers and the initial number of circuit breaker operations), initial configuration parameters (such as network parameters and protection settings), initial connection status (such as the connection status of the equipment to the upper grid and the communication status with other equipment), and initial equipment health (such as the initial insulation level and mechanical condition). This data reflects the operational performance and status of the equipment in its initial deployment state. Features that characterize the equipment's status are extracted from the initial operation data of grid equipment. For example, for transformers, features such as initial load factor, oil temperature, and insulation resistance are extracted; for circuit breakers, features such as initial number of operations, cumulative operation time, and contact resistance are extracted. These features can be directly acquired through equipment monitoring systems (such as transformer oil temperature monitoring devices and circuit breaker operation counters), or indirectly calculated through equipment performance evaluation models (such as load factor calculation models based on equipment operating data and insulation aging assessment models). For the initial operating data of the power grid, features that reflect the grid's operating status are extracted. For example, initial network topology features (such as the number of nodes and connection matrix), initial power transmission features (such as the power transmission value and power flow direction of each line), initial voltage and current features (such as the voltage amplitude and phase angle at each node and the current value of each line), and initial operating mode features (such as the operating mode identifier) ​​are extracted. These features can be directly collected through the grid's dispatching automation system (such as a SCADA system) or indirectly calculated using power flow calculation models (such as the Newton-Raphson power flow algorithm).

[0086] The extracted equipment status features and grid operation features are standardized to eliminate dimensional differences. For example, the Z-score standardization method is used to convert each feature value into the degree of deviation relative to the feature average value. The calculation formula is: ,in, represents the normalized eigenvalue, X represents the original eigenvalue, μ represents the average value of the feature, σRepresents the standard deviation of the feature. A weighted fusion method is used to fuse the standardized device status features with the grid operation features to obtain a fused feature. Weights can be determined using methods such as expert scoring and principal component analysis (PCA).

[0087] For example, according to expert experience, the weights of device status features and grid operation features in comprehensive environmental features are 0.4 and 0.6 respectively. Assuming that the vector of device status features after normalization is [0.5, 0.3, 0.8], and the vector of grid operation features after normalization is [0.6, 0.4, 0.7, 0.5], the calculation formula for fusion features is: , that is, the two feature vectors are added according to the weights to obtain the fused feature vector [0.64, 0.36, 0.76, 0.3]. Finally, the fused feature is used as the initial comprehensive environment feature for the subsequent initial security measure rule base generation step.

[0088] In this optional embodiment, by separately extracting the device status characteristics and grid operation characteristics from the initial operating data of the power grid equipment and performing feature fusion to obtain the initial comprehensive environmental characteristics, the operating environment of the power grid equipment in its initial deployment state can be comprehensively and accurately reflected. On the one hand, separately extracting the device status characteristics and grid operation characteristics allows for targeted analysis of the device's own status and grid operation conditions, ensuring that key information is not lost. On the other hand, the feature fusion process comprehensively considers the mutual influence of the two, making the initial comprehensive environmental characteristics closer to the actual operating environment. This also provides a strong basis for the subsequent accurate judgment of operating environment changes and the dynamic updating of the security measures rule base, effectively improving the level of refinement and dynamic adaptability of power grid equipment security management.

[0089] Optionally, generating an initial security measure rule base for the power grid equipment based on the initial comprehensive environmental characteristics includes: decomposing the initial comprehensive environmental characteristics into multiple key feature dimensions, and establishing a relationship model between the feature dimensions and the security risks of the power grid equipment; determining a weight value of each key feature dimension based on equipment parameters of the power grid equipment; determining a security risk value of the power grid equipment based on the relationship model and the weight value; and setting an initial security measure rule base based on the security risk value.

[0090] Specifically, the initial comprehensive environmental characteristics are decomposed into multiple key characteristic dimensions. First, the individual elements of the initial comprehensive environmental characteristic vector are analyzed to determine the specific characteristic meaning represented by each element. For example, the initial comprehensive environmental characteristic vector may include multiple elements such as device type code, initial device load rate, initial device insulation resistance, initial power flow distribution of the power grid, and initial power grid voltage stability.

[0091] Based on the safe operation principles of power grid equipment and historical safety incident data, a relationship model between each key characteristic dimension and the safety risk of power grid equipment is established. For example, for the characteristic dimension of equipment load rate, analysis of historical data reveals that when the equipment load rate exceeds 80%, the risk of equipment failure due to overheating increases significantly. A linear regression model can be developed to describe the relationship between equipment load rate and overheating failure risk. The model form is: Overheating failure risk value = α × equipment load rate + β, where α and β are model parameters obtained by fitting historical data.

[0092] Collect equipment parameters for power grid equipment, including rated capacity, insulation grade, operating age, and maintenance intervals. These parameters reflect the inherent characteristics and operating status of the equipment. Based on the equipment parameters and expert experience, determine the weight of each key characteristic dimension. For example, for a transformer with a long operating life, the insulation resistance characteristic dimension may have a greater impact on safety risk, so a higher weight can be assigned to this dimension. Weights can be determined using the Analytic Hierarchy Process (AHP). First, construct a judgment matrix, comparing and scoring the importance of each key characteristic dimension in influencing the safety risk of power grid equipment. Then, perform a consistency check and normalization to obtain a weight vector. Substitute the eigenvalue of each key characteristic dimension into the corresponding relational model to calculate the risk contribution value for each dimension. For example, for the equipment load rate characteristic dimension, use the linear regression model established above to substitute the initial load rate of the equipment into the model to calculate the risk contribution value for overheating failure. Based on the weight of each key characteristic dimension, the risk contribution values ​​of each dimension are weighted and summed. The calculation formula is: Power grid equipment safety risk value = ∑(weight value × risk contribution value). For example, assuming the weight of the equipment load factor dimension is 0.3, its risk contribution is 0.6; the weight of the insulation resistance dimension is 0.5, its risk contribution is 0.4; and the weight of the power grid flow distribution dimension is 0.2, its risk contribution is 0.5. Therefore, the power grid equipment safety risk value = 0.3 × 0.6 + 0.5 × 0.4 + 0.2 × 0.5 = 0.44.

[0093] Based on the calculated safety risk values ​​for power grid equipment, in conjunction with safety standards and regulations, an initial safety measure rule base is established. Safety risk values ​​are categorized into different risk levels. For example, a safety risk value between 0 and 0.3 represents low risk, corresponding to safety measures such as regular inspections and routine maintenance; a safety risk value between 0.3 and 0.6 represents medium risk, corresponding to safety measures such as enhanced monitoring and increased maintenance frequency; and a safety risk value between 0.6 and 1.0 represents high risk, corresponding to safety measures such as immediate shutdown for maintenance and implementation of emergency protective measures. For each risk level, detailed safety measure rules are developed, including monitoring indicator thresholds, operational procedures, and responsible personnel. For example, for a high-risk level, thresholds for key monitoring indicators (such as temperature and pressure) are clearly defined. When a monitoring indicator exceeds the threshold, an alarm is automatically triggered, the corresponding emergency operation procedures are executed, and designated responsible personnel are notified for handling. These safety measure rules are organized and stored in the initial safety measure rule base for easy subsequent query and execution.

[0094] In this optional embodiment, the initial comprehensive environmental characteristics are decomposed into multiple key characteristic dimensions, and a relationship model between these dimensions and security risks is established, making the assessment of power grid equipment security risks more detailed and accurate. By considering the impact of each key characteristic dimension separately, the potential risks of power grid equipment in different aspects can be comprehensively identified, avoiding omissions or misjudgments that may result from single-metric assessments. Weights for each key characteristic dimension are determined based on the equipment parameters of the power grid equipment, fully accounting for the individual differences and operating characteristics of different equipment. This personalized weighting ensures that the security risk assessment results are more consistent with actual operating conditions, improving the scientific nature and reliability of the assessment. Furthermore, the security risk value of the power grid equipment is calculated by combining the relationship model and weights, achieving a quantitative description of security risks. This quantitative risk expression facilitates a more intuitive comparison of security risk levels for different equipment or operating conditions, providing a clear quantitative basis for the subsequent formulation of security measures. The initial security measure rule base is established based on the security risk value, ensuring the targeted and effective nature of security measures. Different security measure rules corresponding to different risk levels enable timely and effective protective measures to be taken for high-risk equipment or high-risk conditions, reducing the probability and impact of security incidents. This facilitates the subsequent adjustment of security measures. When the operating environment or equipment parameters of the power grid equipment change, the security risk value can be re-evaluated according to the new initial comprehensive environment characteristics, and the security measure rule base can be updated accordingly to ensure the continued effectiveness of the security measures.

[0095] Optionally, the monitoring of the power grid and power grid equipment to obtain current operating data of the power grid and current operating data of the power grid equipment includes: obtaining a monitoring frequency for monitoring the power grid and power grid equipment by mapping the security risk value with a preset mapping table; monitoring the power grid and power grid equipment according to the monitoring frequency to obtain current operating data of the power grid and the power grid equipment at the current time point.

[0096] Specifically, the monitoring frequency for the power grid and its equipment is first determined by mapping the security risk value to a preset mapping table. This predefined mapping table, based on historical operational data of power grid equipment, safety standards, and expert experience, specifies the monitoring frequency corresponding to different security risk ranges. For example, when the security risk value is in the low-risk range (e.g., 0-0.3), the corresponding monitoring frequency can be set to once an hour; when the security risk value is in the medium-risk range (e.g., 0.3-0.6), the corresponding monitoring frequency is increased to once every half hour; and when the security risk value is in the high-risk range (e.g., 0.6-1.0), the corresponding monitoring frequency is further increased to once every ten minutes. The preset mapping table fully considers the monitoring frequency requirements for different risk levels to ensure that potential safety hazards are detected promptly. The power grid and its equipment are then monitored according to the determined monitoring frequency to obtain current operational data for the grid and its equipment at the current point in time.

[0097] In optional embodiments of the present invention, the monitoring process involves various monitoring methods and technologies, including but not limited to the following: Monitoring of power grid operating parameters: Utilizing the power grid's Supervisory Control and Data Acquisition (SCADA) system, real-time grid operating parameters, such as voltage, current, and power at each node, are collected. The SCADA system, through a sensor network deployed within the power grid, accurately collects these key parameters at a set time interval (i.e., monitoring frequency) and transmits them to a monitoring center. Monitoring of equipment status: Utilizing an equipment status monitoring system, the operating status of power grid equipment is tracked in real time. For example, temperature sensors, pressure sensors, and vibration sensors installed on the equipment monitor key indicators such as temperature, pressure, and vibration. These sensors collect data at a set monitoring frequency and transmit the data to the monitoring system via a data acquisition card or communication module. Monitoring of network traffic: Network traffic monitoring tools are used to monitor network traffic in real time on the power grid's communication network. These tools collect statistics on inbound and outbound network traffic, packet transmission rates, and other information at a set monitoring frequency, enabling timely detection of network anomalies or potential network attacks. Security event monitoring: Utilize a Security Information and Event Management (SIEM) system to collect and analyze security event logs from power grids and equipment. The SIEM system can obtain log information from various security devices and systems, analyze and aggregate it according to a set monitoring frequency, and promptly detect signs of security incidents.

[0098] In this optional embodiment, the current operational data obtained from monitoring is recorded and stored for subsequent data fusion and feature extraction. This data not only directly reflects the current operational status of the power grid and equipment, but also serves as an important basis for assessing the safety status of the power grid and equipment. Regular monitoring according to the monitoring frequency ensures timely acquisition of the latest operational data, providing timely and accurate data support for subsequent assessment of operational environment changes and updating the safety measure rule library.

[0099] Optionally, the current operating data of the power grid and the current operating data of the power grid equipment are fused to obtain multi-source data of the power grid equipment, including: format conversion of the current operating data of the power grid and the current operating data of the power grid equipment to obtain the current operating data with the same timestamp and data format; and fusing the current operating data with the same timestamp and data format through a Kalman filtering algorithm to obtain the multi-source data of the power grid equipment.

[0100] Specifically, because the current operating data of the power grid and the current operating data of power grid devices may come from different monitoring systems, their timestamp formats may be inconsistent. For example, the timestamps of power grid operating data are expressed in Coordinated Universal Time (UTC), while the timestamps of device operating data are in local time. It is necessary to convert the timestamps of all data to a unified time standard. This embodiment uses a time conversion algorithm to convert timestamps in different time formats into a unified absolute timestamp (such as a Unix timestamp, which is the number of seconds since January 1, 1970, 00:00:00 UTC). For example, the timestamp "2024-07-10 14:30:00 UTC" in the power grid operating data is converted to a Unix timestamp of 1720591800 seconds. The local timestamp "2024-07-10 22:30:00+08:00" (Beijing Time) in the device operating data is also converted to a Unix timestamp of 1720591800 seconds.

[0101] At the same time, it is considered that the data formats output by different monitoring systems may be different. The power grid operation data may be stored in XML format, containing information such as device number, parameter name, parameter value and timestamp; while the equipment operation data may be stored in CSV format, with columns including time, device ID, operating status, etc. These data need to be converted into a unified internal data format. A common data structure can be defined, such as using a dictionary or JSON format, which contains fields such as "device identification", "parameter type", "parameter value" and "timestamp". For power grid operation data in XML format, use an XML parser to extract the corresponding fields and fill them into the common data structure; for equipment operation data in CSV format, use a CSV reader to read the data and also fill it into the common data structure.

[0102] The Kalman filter algorithm first initializes model parameters, including the initial value of the state vector (which can be initial measurements of grid and device operating data, such as initial voltage and device temperature), the state transition matrix (determined based on the system's dynamic characteristics. For example, for a linear system, the state transition matrix can be the identity matrix plus a matrix consisting of the time step multiplied by dynamic factors such as velocity), the observation matrix (which defines how observations are derived from the state vector and is typically a matrix for extracting parameter values), the process noise covariance matrix (which reflects the uncertainty of the system process and can be initialized based on experience or system characteristics), and the measurement noise covariance matrix (which reflects the uncertainty of the measurement data and can be initialized based on information such as sensor accuracy). Current operating data with the same timestamp and unified data format are used as input observations for the Kalman filter algorithm. For example, assume the voltage value in the grid operating data is 102.5V and the device temperature value in the device operating data is 55.3°C, and both data have the same timestamp. These observations are substituted into the Kalman filter algorithm. The algorithm first predicts the next state based on the state transition matrix. It then updates the state estimate based on the observations and the observation matrix, adjusting the estimated uncertainty based on the process noise and measurement noise covariance matrices. After iterative calculation, the fused multi-source data of power grid equipment is obtained. This data integrates the information of power grid operation data and equipment operation data, reduces the uncertainty of the data, and improves the accuracy and reliability of the data.

[0103] In this optional embodiment, data format conversion ensures consistency in timestamps and data formats between the current operating data of the power grid and devices. Unified timestamps eliminate time discrepancies between different data sources, enabling data analysis and processing based on the same time base. Unified data formats simplify the complexity of subsequent data processing and improve data operability and interoperability. This uniformity provides a solid foundation for the fusion and comprehensive analysis of multi-source data. Secondly, the application of the Kalman filter algorithm effectively improves data quality and reliability. Through prediction and update steps, the Kalman filter dynamically estimates system status, reducing measurement noise and data uncertainty. When processing data from multiple sensors or monitoring systems, it comprehensively considers the characteristics of each data source and assigns appropriate weights to each. This approach not only improves data accuracy but also enhances data robustness, ensuring that the fused multi-source data more accurately reflects the actual operating status of power grid devices. Furthermore, the fusion of multi-source data provides a more comprehensive view of power grid device operations. By integrating power grid and device operating data, the operating environment and status of the device can be understood from multiple perspectives. This comprehensive perspective helps more accurately assess the security risks of power grid equipment, promptly identify potential issues, and make more effective decisions. Finally, high-quality multi-source data supports better subsequent analysis and processing. Whether used for feature extraction to update comprehensive environmental features or for training and optimizing deep reinforcement learning models, accurate and reliable input data is critical to ensuring the performance of the entire system. Providing high-quality multi-source data improves the efficiency and effectiveness of the entire system for automatically generating safety measures for power grid equipment, thereby enhancing the safety management and operational stability of power grid equipment.

[0104] Optionally, the feature extraction of the multi-source data to obtain the current comprehensive environmental characteristics of the power grid equipment includes: dividing the multi-source data into multiple data windows with the same time period, and calculating the data analysis parameters in each data window, wherein the data analysis parameters include the data mean, variance, standard deviation, peak, root mean square value, kurtosis, skewness, zero crossing rate and absolute mean value of the data in the data window; integrating the data analysis parameters to obtain the time domain characteristics of the multi-source data; converting the multi-source data from the time domain to the frequency domain through Fourier transform to obtain the frequency domain characteristics of the multi-source data; and obtaining the current comprehensive environmental characteristics based on the time domain characteristics and the frequency domain characteristics.

[0105] Specifically, the multi-source data is segmented into multiple data windows at fixed time intervals, with each window containing data from the same time period. For example, if the multi-source data is sampled once per second and the selected time window length is 10 seconds, each data window will contain data from 10 sampling points. Data windows can overlap, for example, with adjacent windows overlapping by 5 sampling points, to ensure data continuity and smoothness. For the data within each data window, a series of data parsing parameters are calculated.

[0106] These parameters include: Data average: Calculate the arithmetic mean of all data points in the data window, the formula is ,in is the number of data points, is the value of each data point; the variance is used to measure the degree of deviation of the data point from the mean, and the formula is ; The standard deviation is the square root of the variance, which is used to measure the degree of dispersion of the data. The formula is The peak value is used to find the maximum value within the data window. A simple iterative algorithm can be used to traverse all data points and record the maximum value. The root mean square value is used to measure the effective value of the data, especially for periodic data. The formula is ; Kurtosis is used to describe the peak degree of data distribution, and the formula is ; Skewness is used to measure the symmetry of data distribution, and the calculation formula is The zero-crossing rate is used to calculate the number of times the signal in the data window crosses the zero axis from positive to negative or from negative to positive. The zero-crossing point can be determined by comparing the signs of adjacent data points and counting the number of times. The absolute mean is used to calculate the average of the absolute values ​​of the data points. The formula is .

[0107] The data analysis parameters obtained by the above calculations are integrated to form the time domain characteristics of the multi-source data. For example, the mean, variance, standard deviation and other parameters of each data window are arranged in order to form a feature vector. If each data window has 9 analysis parameters, then each window corresponds to a 9-dimensional time domain feature vector. Convert the multi-source data from the time domain to the frequency domain using the fast Fourier transform (FFT) algorithm. For the data in each data window, apply FFT to calculate its spectrum. The FFT algorithm decomposes the time domain signal into multiple sinusoidal wave components and obtains the amplitude and phase information of each frequency component. For example, for a length of The FFT will output frequency components (assuming is an even number). Based on the FFT results, frequency domain features are extracted. Common frequency domain features include: dominant frequency, the frequency component with the largest amplitude in the spectrum, which can be determined by finding the frequency corresponding to the maximum amplitude in the FFT result. Spectral power, which calculates the power of each frequency component, specifically the square of the amplitude, is ,in is the frequency Spectral energy calculates the integral or sum of spectral power within a specified frequency range and is used to measure the energy distribution of a signal in the frequency domain.

[0108] The time domain features and frequency domain features are fused to form the current comprehensive environmental features. A simple concatenation method can be used to concatenate the time domain feature vector and the frequency domain feature vector into a longer feature vector. For example, if the time domain features have 9 dimensions and the frequency domain features have 3 dimensions (dominant frequency, spectral power, and spectral energy), the fused current comprehensive environmental feature vector will have 12 dimensions. To eliminate dimensional differences and numerical ranges between different features, the fused feature vector can be normalized. Common normalization methods include min-max normalization (scaling the data to the range [0, 1]) or z-score normalization (transforming the data into a distribution with a mean of 0 and a standard deviation of 1).

[0109] In this optional embodiment, by calculating data analysis parameters within the data window, such as mean, variance, standard deviation, peak, root mean square value, kurtosis, skewness, zero-crossing rate, and absolute mean, the statistical characteristics of the data are comprehensively captured, reflecting the short-term operational fluctuations and trends of power grid equipment. These parameters describe the data's central tendency, dispersion, and distribution from different perspectives, effectively identifying abnormal fluctuations and potential problems in the data. Multi-source data is converted from the time domain to the frequency domain via Fourier transform to obtain frequency domain features. Frequency domain analysis can reveal periodic variations and frequency components in the data, helping to identify periodic interference or potential failure modes in power grid equipment operation. For example, the presence of certain frequency components may indicate abnormal equipment operation, and frequency domain features can accurately capture this information. Time and frequency domain features are integrated to form the current comprehensive environmental features. This fusion approach fully leverages the advantages of both time and frequency domain features, taking into account both the short-term fluctuations and statistical characteristics of the data and the periodicity and frequency distribution of the data. The fused feature vectors are more comprehensive and richer, more accurately reflecting the actual operating environment of power grid equipment, providing more reliable data support for subsequent security risk assessments and rule base updates. By calculating parameters sensitive to data distribution patterns, such as kurtosis and skewness, subtle changes in the data distribution can be more sensitively detected, potentially indicating abnormalities in equipment operating status. Frequency domain features, such as changes in the dominant frequency, can also promptly reflect abnormal deviations in equipment operating frequency, helping to proactively detect equipment failures or potential safety risks and enhancing the system's fault warning capabilities. The generated current comprehensive environmental features provide high-quality input data for subsequent intelligent analysis, such as deep reinforcement learning models. These feature vectors incorporate both the statistical characteristics of the data and frequency distribution information, enabling the model to more accurately learn the mapping between the power grid equipment operating environment and safety risks. This improves the scientific nature and effectiveness of safety measure rule base updates and enhances the overall intelligence of the power grid equipment safety management system. By calculating parameters such as standard deviation and root mean square value, data stability and reliability can be assessed. Changes in these parameters promptly reflect changes in data quality, enabling the system to adjust monitoring strategies in a timely manner. At the same time, the stability analysis of frequency domain characteristics can further enhance the system's adaptability and robustness to data changes.

[0110] In summary, this embodiment not only improves the comprehensiveness and accuracy of power grid equipment operating status monitoring, but also enhances the system's anomaly detection capabilities and intelligent decision support, providing strong protection for the safe operation of power grid equipment.

[0111] Optionally, judging whether the operating environment of the power grid device has changed based on the current comprehensive environmental characteristics and the initial comprehensive environmental characteristics includes: comparing and calculating the current comprehensive environmental characteristics with the initial comprehensive environmental characteristics to obtain the characteristic difference between the current comprehensive environmental characteristics and the initial comprehensive environmental characteristics; judging whether the operating environment of the power grid device has changed based on the relationship between the characteristic difference and a preset difference threshold; wherein, when the characteristic difference is greater than or equal to the preset difference threshold, it is judged that the operating environment of the power grid device has changed; when the characteristic difference is less than the preset difference threshold, it is judged that the operating environment of the power grid device has not changed.

[0112] Specifically, the current integrated environment features are compared with the initial integrated environment features to calculate the feature difference between them. The calculation method can use Euclidean distance, Manhattan distance, or cosine similarity.

[0113] For example, the difference between two feature vectors is calculated using the Euclidean distance formula: ;in, The first one represents the current comprehensive environmental characteristics eigenvalues, The first eigenvalues, is the number of dimensions of the feature vector.

[0114] A feature difference threshold is pre-set based on historical data and expert experience. For example, the threshold can be set to 0.5 (this value needs to be adjusted based on the actual application scenario and data characteristics). If the calculated feature difference is greater than or equal to 0.5, it is determined that the operating environment of the power grid equipment has changed. This indicates that the current operating environment is significantly different from the initial environment, which may introduce new security risks. If the feature difference is less than 0.5, it is determined that the operating environment of the power grid equipment has not changed. In this case, the operating environment of the power grid equipment can be considered relatively stable, and the existing security measure rule base still applies.

[0115] In this optional embodiment, changes in the operating environment of power grid equipment are quantified into a specific numerical value by calculating feature differences. This quantification makes changes in the operating environment intuitive and measurable, facilitating subsequent judgment and decision-making. For example, using Euclidean distance to calculate feature differences can clearly reflect the degree of difference between the current operating environment and the initial environment, providing a clear basis for determining whether to update the security measure rule base. By determining the relationship between the feature differences and a preset difference threshold, significant changes in the operating environment of power grid equipment can be promptly detected. When the feature differences are greater than or equal to the preset difference threshold, a change in the operating environment is immediately determined, triggering an update of the security measure rule base. This timely response mechanism helps power grid equipment maintain safe and stable operation in a dynamically changing operating environment, reducing security risks caused by environmental changes. By setting a reasonable preset difference threshold, false positives caused by random noise or minor fluctuations can be effectively reduced, while also avoiding missed positives caused by overly high thresholds. The threshold is determined based on historical data and expert experience, ensuring accurate and reliable judgments.

[0116] For example, by analyzing large amounts of historical data, it is determined that when the feature difference reaches a certain value in specific scenarios, changes in the operating environment will have a significant impact on device security, thereby appropriately setting thresholds. Furthermore, when the feature difference exceeds the threshold, it clearly indicates that the security measures rule base needs to be updated; when the feature difference falls below the threshold, it indicates that the existing rule base still applies. This clear judgment standard helps automate and standardize security management processes, reducing the uncertainty caused by human intervention and subjective judgment. The calculation and judgment results of the feature difference provide trigger signals for the dynamic adjustment of the deep reinforcement learning model. When the operating environment changes, the deep reinforcement learning model is promptly notified to update the security measures rule base, ensuring that the model always learns and optimizes based on the latest operating environment characteristics, improving the model's adaptability and effectiveness.

[0117] In summary, through the calculation of feature differences and threshold judgment, we can achieve quantitative assessment, timely response, and accurate judgment of changes in the operating environment of power grid equipment, providing reliable support for the safety management of power grid equipment and ensuring that power grid equipment can always maintain safe and stable operation in a constantly changing operating environment.

[0118] Optionally, the comparing and calculating the current comprehensive environmental feature with the initial comprehensive environmental feature to obtain the feature difference between the current comprehensive environmental feature and the initial comprehensive environmental feature includes: decomposing the current comprehensive environmental feature and the initial comprehensive environmental feature into multiple corresponding dimensions, and assigning a corresponding weight value to each dimension, wherein each dimension of the current comprehensive environmental feature and the initial comprehensive environmental feature corresponds to each other; calculating the absolute difference corresponding to each dimension according to the difference calculation method corresponding to each dimension; and performing weighted summation based on the absolute difference values ​​and the weight values ​​of all the dimensions to obtain the feature difference.

[0119] Specifically, decompose the current comprehensive environmental features and the initial comprehensive environmental features into multiple corresponding dimensions. For example, assume that the comprehensive environmental features include five dimensions: equipment load rate, insulation resistance, grid flow distribution, equipment temperature, and voltage stability. Ensure that each dimension of the current and initial features corresponds to each other, that is, the equipment load rate dimension corresponds to the same position or identifier in the two features. If the current comprehensive environmental features are represented as a vector: , the initial comprehensive environment characteristics are expressed as: , then the index of each dimension corresponds to the same feature type. Assign a corresponding weight value to each dimension. The weight value reflects the importance of the dimension in the overall feature difference. Weight assignment can be based on expert experience, historical data analysis, or feature importance assessment algorithms (such as principal component analysis). For example, assuming that the equipment load rate and insulation resistance have a greater impact on safety, the weights are 0.3 and 0.25 respectively; the power grid flow distribution weight is 0.2; the equipment temperature and voltage stability weights are 0.15 and 0.1 respectively. The weight vector is expressed as: Weights must be assigned so that the sum of all weights is 1. Select an appropriate difference calculation method based on the characteristics of each dimension. For continuous numeric dimensions (such as equipment load factor and insulation resistance), use the absolute difference calculation method.

[0120] For example, the absolute difference in equipment load factor is calculated as: For other types of data (such as categorical data or ordinal data), you may need to use a different difference measurement method, such as Hamming distance. According to the selected difference calculation method, calculate the absolute difference value of each dimension. For example, if the device load rate of the current comprehensive environment feature is 80% and the device load rate of the initial comprehensive environment feature is 70%, then the absolute difference value of the device load rate dimension is: Similarly, calculate the absolute difference of other dimensions: .

[0121] The feature difference is obtained by weighted summation based on the absolute difference and weight value of all dimensions. The calculation formula is: ,in, Indicates the The absolute difference in dimensions, Indicates the The weight value of each dimension, is the number of dimensions. Assume that the absolute difference of each dimension is calculated as: , the weight vector is: , then the feature difference is calculated as: , which indicates that the characteristic difference between the current comprehensive environmental characteristics and the initial comprehensive environmental characteristics is 6.5.

[0122] In this optional embodiment, decomposing features into multiple dimensions and calculating differences for each dimension allows for more precise identification of specific aspects that have changed. For example, by separately calculating differences in dimensions such as equipment load rate and insulation resistance, it can be determined whether the overall difference is caused by load changes or insulation performance degradation, providing a basis for subsequent targeted safety measures. Furthermore, weights are assigned to each dimension, fully considering the importance of each dimension in its impact on the operating environment of power grid equipment. This avoids the errors that can result from simple averaging, allowing feature differences to more accurately reflect the significance and criticality of changes in the operating environment. By clarifying the differences in each dimension and their weighted contributions, a detailed explanation is provided for determining whether the operating environment has changed. This helps operations and maintenance personnel understand the specific factors that trigger environmental change determinations, enhancing the transparency and credibility of decision-making. Weight assignments can be adjusted based on different power grid equipment types or specific application scenarios. For example, the weight of the insulation resistance dimension can be increased for older equipment, enabling a precise assessment of the differences in specific equipment under specific circumstances. The obtained feature difference is a quantitative indicator that comprehensively considers the changes and weights of various dimensions. It provides an accurate quantitative basis for whether the security measures rule base needs to be updated in the future, avoids unnecessary rule updates or missed updates, and improves the efficiency and effectiveness of the entire security management process.

[0123] Optionally, the deep reinforcement model is used to update the initial security measures rule base according to the current comprehensive environment characteristics and the initial comprehensive environment characteristics to obtain the current security measures rule base of the power grid equipment, including: inputting the current comprehensive environment characteristics and the initial comprehensive environment characteristics into the deep reinforcement model, and taking the operating environment characteristics of the power grid equipment as the state, and taking the update operation of the initial security measures rule base as the action; iteratively updating the action through the deep reinforcement model, and then optimizing the initial security measures rule base according to the action, and judging whether the update of the action is completed through the state; when the action update is completed, updating the initial security measures rule base according to the update operation corresponding to the action to obtain the current security measures rule base.

[0124] Specifically, the current comprehensive environment features and the initial comprehensive environment features are integrated into a feature vector as the state input of the deep reinforcement model.

[0125] For example, suppose the current comprehensive environment characteristics are: , the initial comprehensive environmental characteristics are: , then the state input can be expressed as the concatenation vector of the two: .in, ,in, Represents the current comprehensive environment feature vector. is the eigenvalue of each dimension of the current comprehensive environment feature vector, each Represents the value of a specific feature in the current environment, such as equipment load rate, insulation resistance, etc. Indicates the total number of features. ,in, represents the initial comprehensive environment feature vector. is the eigenvalue of each dimension of the initial comprehensive environment feature vector, each Represents the corresponding characteristic value of the device in the initial deployment state, The feature dimensions in are one-to-one corresponding. ,in, Represents the state input of the deep reinforcement learning model. It is composed of the current comprehensive environment feature vector and the initial comprehensive environment feature vector The concatenated vector.

[0126] This splicing approach in this embodiment integrates current and initial environmental features to form a complete state representation, reflecting the dynamic changes in the power grid equipment operating environment. Update operations on the initial security measure rule base are defined as actions, including adding rules, deleting rules, and modifying rule parameters. Each action can be represented as a vector.

[0127] For example, a new rule action can be expressed as: ,in Indicates the type of the newly added rule. Represents the specific parameters of the newly added rules. Build a deep reinforcement learning model, such as a deep Q-network (DQN). This model primarily consists of a neural network. The input layer receives the state vector, the hidden layer extracts features using a nonlinear activation function, and the output layer outputs the Q-value for each possible action, representing the expected cumulative reward of taking that action under the current state. Build a power grid equipment operating environment simulator to simulate different operating environment changes and security risk scenarios. The model is trained through interaction with the simulator. In each training step, the model selects an action based on the current state. After executing the action, the simulator returns the new state and a reward signal. Design a reasonable reward function to evaluate the effectiveness of the action. For example, positive rewards are given when the action effectively reduces the safety risk of power grid equipment; negative rewards are given when the action increases the safety risk or introduces new risks.

[0128] The reward function can be defined as: ;in, Indicates the change of security risk value, Indicates the impact of rule base update operations on system operation efficiency (such as device operation delays caused by rule updates, etc.). and is the weight coefficient.

[0129] Using experience replay, samples of each state-action-reward-new-state cycle are stored in an experience replay pool. During training, small batches of samples are randomly drawn from the experience replay pool for gradient descent training to update network parameters and optimize Q-value estimates. The target network periodically copies parameters from the master network to stabilize the training process.

[0130] In actual applications, when a change in the operating environment of power grid equipment is detected, the current comprehensive environmental features and the initial comprehensive environmental features are input into the trained deep reinforcement model. The model outputs the Q value of each possible action based on the current state and selects the action with the largest Q value as the current optimal action. The initial security measure rule base is updated based on the selected action. For example, if the optimal action is to add a new access control rule, the corresponding rule is added to the rule base. The updated rule base serves as the current security measure rule base. By defining the conditions for the completion of the update, such as whether the action output by the model remains stable for multiple consecutive time steps, or the updated rule base is verified to be effective in a simulation environment, it is determined whether the action update is complete. When the update completion conditions are met, the update action is stopped, and the final updated rule base is used as the current security measure rule base for the security management of actual power grid equipment.

[0131] In this optional embodiment, a deep reinforcement learning model automatically learns optimal update actions based on current and initial comprehensive environmental characteristics, enabling intelligent updates to the initial security measures rule base. This eliminates the need for full human involvement in rule base maintenance and updates, improving efficiency and reducing human error. The model optimizes the rule base based on real-time differences in comprehensive environmental characteristics, ensuring that the updated rule base accurately adapts to the current operating environment and effectively improving the security of power grid equipment in dynamically changing environments. By determining the completion of action updates based on status, the model can dynamically adapt to changes in the power grid equipment operating environment and promptly adjust the security measures rule base to ensure it remains optimal, enhancing the system's responsiveness to environmental changes. A cumulative reward mechanism during model training ensures that rule base updates consistently advance the security protection capabilities of power grid equipment, ensuring that each update enhances the effectiveness of the rule base in addressing security risks. By determining whether an action update is complete, the model determines whether to apply the update, avoiding system instability caused by incomplete or frequent updates and ensuring a stable and reliable update process. The model continuously learns and optimizes its strategies during each update, continuously improving the accuracy and adaptability of rule base updates and contributing to the continuous evolution of system performance.

[0132] The present invention provides a system for automatically generating a rule base for equipment security measures. The system is applied to a power grid, wherein the power grid includes a plurality of power grid devices, each of which is deployed at a respective node of the power grid. The system includes:

[0133] an acquiring unit, configured to acquire an initial deployment state of the power grid and an initial deployment state of the power grid device corresponding to each node of the power grid;

[0134] an initial setting unit, configured to generate an initial comprehensive environmental feature of the power grid device according to the initial deployment state of the power grid and the initial deployment state of the power grid device;

[0135] The initial setting unit is further configured to generate an initial security measure rule base for the power grid device based on the initial comprehensive environment characteristics;

[0136] a monitoring unit, configured to monitor the power grid and the power grid equipment, obtain current operating data of the power grid and the current operating data of the power grid equipment, and fuse the current operating data of the power grid and the current operating data of the power grid equipment to obtain multi-source data of the power grid equipment;

[0137] A feature extraction unit, configured to extract features from the multi-source data to obtain current comprehensive environmental features of the power grid equipment;

[0138] a judging unit, configured to judge whether the operating environment of the power grid device has changed based on the current comprehensive environmental characteristics and the initial comprehensive environmental characteristics;

[0139] The optimization unit is used to update the initial security measure rule base according to the current comprehensive environment characteristics and the initial comprehensive environment characteristics through a deep reinforcement model when the operating environment changes, so as to obtain the current security measure rule base of the power grid equipment.

[0140] The advantages of the system for automatically generating a rule base for equipment security measures of the present invention over the prior art are the same as the advantages of the method for automatically generating a rule base for equipment security measures over the prior art, and are not described in detail here.

[0141] Although the present invention is disclosed as above, the scope of protection disclosed by the present invention is not limited thereto. Those skilled in the art may make various changes and modifications without departing from the spirit and scope of the present invention, and these changes and modifications will fall within the scope of protection of the present invention.

Claims

1. A method for constructing a rule base for automatically generating equipment security measures, characterized in that: The method is applied to a power grid, the power grid including a plurality of power grid devices, each of the power grid devices being respectively deployed at a respective node of the power grid, and the method comprising: Acquire an initial deployment state of the power grid and an initial deployment state of the power grid device corresponding to each node of the power grid; generating an initial comprehensive environmental feature of the power grid device according to the initial deployment state of the power grid and the initial deployment state of the power grid device; generating an initial security measure rule base for the power grid device according to the initial comprehensive environment characteristics; monitoring the power grid and the power grid equipment to obtain current operating data of the power grid and the current operating data of the power grid equipment, and fusing the current operating data of the power grid and the current operating data of the power grid equipment to obtain multi-source data of the power grid equipment; Extracting features from the multi-source data to obtain current comprehensive environmental features of the power grid equipment; determining, based on the current comprehensive environmental characteristics and the initial comprehensive environmental characteristics, whether the operating environment of the power grid device has changed; When the operating environment changes, the initial security measure rule base is updated according to the current comprehensive environment characteristics and the initial comprehensive environment characteristics through the deep reinforcement model to obtain the current security measure rule base of the power grid equipment.

2. The method for constructing a rule base for automatically generating equipment security measures according to claim 1, characterized in that: Generating the initial comprehensive environmental characteristics of the power grid device according to the initial deployment state of the power grid and the initial deployment state of the power grid device includes: Determining initial operation data of the power grid and initial operation data of the power grid devices according to the initial deployment state of the power grid and the initial deployment state of the power grid devices; performing feature extraction on the initial operation data of the power grid and the initial operation data of the power grid equipment respectively to obtain device state features of the power grid equipment and power grid operation features of the power grid; The device state feature and the power grid operation feature are subjected to feature fusion to obtain a fusion feature, and the fusion feature is used as the initial comprehensive environment feature.

3. The method for constructing a rule base for automatically generating equipment security measures according to claim 2, characterized in that: Generating an initial security measure rule base for the power grid device according to the initial comprehensive environment characteristics includes: Decomposing the initial comprehensive environmental characteristics into multiple key characteristic dimensions, and establishing a relationship model between the characteristic dimensions and the security risks of the power grid equipment; Determining a weight value of each of the key feature dimensions according to device parameters of the power grid device; Determining a security risk value of the power grid equipment according to the relationship model and the weight value; An initial security measure rule base is set according to the security risk value.

4. The method for constructing a rule base for automatically generating equipment security measures according to claim 3, characterized in that: The monitoring of the power grid and the power grid equipment to obtain current operation data of the power grid and the current operation data of the power grid equipment includes: Obtaining a monitoring frequency for monitoring the power grid and power grid equipment by mapping the security risk value with a preset mapping table; The power grid and the power grid equipment are monitored according to the monitoring frequency to obtain current operating data of the power grid and the power grid equipment at a current time point.

5. The method for constructing a rule base for automatically generating equipment security measures according to claim 4, characterized in that: The fusing the current operation data of the power grid and the current operation data of the power grid equipment to obtain multi-source data of the power grid equipment includes: Performing format conversion on the current operation data of the power grid and the current operation data of the power grid device to obtain the current operation data with the same timestamp and data format; The current operation data with the same timestamp and data format are fused through a Kalman filter algorithm to obtain the multi-source data of the power grid equipment.

6. The method for constructing a rule base for automatically generating equipment security measures according to claim 1, characterized in that: The extracting features from the multi-source data to obtain the current comprehensive environmental features of the power grid equipment includes: Divide the multi-source data into a plurality of data windows with the same time period, and calculate data analysis parameters in each of the data windows, wherein the data analysis parameters include the data mean, variance, standard deviation, peak value, root mean square value, kurtosis, skewness, zero crossing rate, and absolute mean value of the data in the data window; Integrating the data analysis parameters to obtain time domain features of the multi-source data; Converting the multi-source data from the time domain to the frequency domain by Fourier transform to obtain frequency domain features of the multi-source data; The current comprehensive environment feature is obtained according to the time domain feature and the frequency domain feature.

7. The method for constructing a rule base for automatically generating equipment security measures according to claim 1, characterized in that: The determining, based on the current comprehensive environmental characteristics and the initial comprehensive environmental characteristics, whether the operating environment of the power grid device has changed includes: Comparing and calculating the current comprehensive environmental feature with the initial comprehensive environmental feature to obtain a feature difference between the current comprehensive environmental feature and the initial comprehensive environmental feature; Determining whether the operating environment of the power grid device has changed based on a relationship between the characteristic difference and a preset difference threshold; When the characteristic difference is greater than or equal to the preset difference threshold, it is determined that the operating environment of the power grid device has changed. When the characteristic difference is less than the preset difference threshold, it is determined that the operating environment of the power grid device has not changed.

8. The method for constructing a rule base for automatically generating equipment security measures according to claim 7, characterized in that: The comparing and calculating the current comprehensive environmental feature with the initial comprehensive environmental feature to obtain a feature difference between the current comprehensive environmental feature and the initial comprehensive environmental feature includes: Decomposing the current integrated environment feature and the initial integrated environment feature into a plurality of corresponding dimensions, and assigning a corresponding weight value to each dimension, wherein each dimension of the current integrated environment feature and the initial integrated environment feature corresponds to each other; Calculate the absolute difference value corresponding to each dimension according to the difference calculation method corresponding to each dimension; The feature difference is obtained by performing a weighted summation based on the absolute difference values ​​and the weight values ​​of all the dimensions.

9. The method for constructing a rule base for automatically generating equipment security measures according to claim 1, characterized in that: The method of updating the initial security measure rule base according to the current comprehensive environment characteristics and the initial comprehensive environment characteristics through the deep reinforcement model to obtain the current security measure rule base of the power grid device includes: Inputting the current integrated environment characteristics and the initial integrated environment characteristics into the deep reinforcement model, taking the operating environment characteristics of the power grid device as a state, and taking an update operation on the initial security measure rule base as an action; Iteratively updating the action through a deep reinforcement model, optimizing the initial security measure rule base based on the action, and determining whether the update of the action is completed through the status; When the action update is completed, the initial security measure rule base is updated according to the update operation corresponding to the action to obtain the current security measure rule base.

10. A system for automatically generating a rule base for equipment security measures, characterized in that: The system is applied to a power grid, the power grid including a plurality of power grid devices, each of which is deployed at a respective node of the power grid. The system includes: an acquiring unit, configured to acquire an initial deployment state of the power grid and an initial deployment state of the power grid device corresponding to each node of the power grid; an initial setting unit, configured to generate an initial comprehensive environmental feature of the power grid device according to the initial deployment state of the power grid and the initial deployment state of the power grid device; The initial setting unit is further configured to generate an initial security measure rule base for the power grid device based on the initial comprehensive environment characteristics; a monitoring unit, configured to monitor the power grid and the power grid equipment, obtain current operating data of the power grid and the current operating data of the power grid equipment, and fuse the current operating data of the power grid and the current operating data of the power grid equipment to obtain multi-source data of the power grid equipment; A feature extraction unit, configured to extract features from the multi-source data to obtain current comprehensive environmental features of the power grid equipment; a judging unit, configured to judge whether the operating environment of the power grid device has changed based on the current comprehensive environmental characteristics and the initial comprehensive environmental characteristics; The optimization unit is used to update the initial security measure rule base according to the current comprehensive environment characteristics and the initial comprehensive environment characteristics through a deep reinforcement model when the operating environment changes, so as to obtain the current security measure rule base of the power grid equipment.

Citation Information

Patent Citations

  • Method for creating security measure rule base and computer readable storage medium

    CN115796839A

  • Reinforcement learning-based edge computing smart power grid resource scheduling method and system

    CN119944602A