Network security management system for new energy power plant
By analyzing the CPU instruction execution context, blockchain technology and hardware acceleration units in real time, the insufficient monitoring and data protection problems in the network security of new energy power plants are solved, and an adaptive security system with advanced threat detection, data integrity protection and fast response is realized.
Patent Information
- Application Number
- CN202510884583.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-30
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2045-06-30
AI Technical Summary
The existing technology lacks real-time monitoring and analysis of the underlying instruction execution context in the network security protection of new energy power plants, making it difficult to deal with advanced persistent threats, and lacks data integrity protection, privacy protection, and system adaptation and self-resilience capabilities.
By analyzing the CPU instruction execution context in real time, blockchain technology is introduced to ensure data integrity, and privacy is protected by zero-knowledge proof, automatic reshaping after security incidents is realized, and hardware acceleration units are introduced to improve response capabilities.
It realizes fine-grained monitoring of system behavior, improves the accuracy of threat detection and system adaptability, ensures data integrity and privacy protection, shortens response time, and enhances system resilience and flexibility.
Smart Images

Figure CN120389914A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power system network security, and specifically to a network security management system for new energy power plants. Background Art
[0002] With the rapid development and wide application of information technology, network security issues have become increasingly prominent. Especially for critical infrastructures such as new energy power plants, once a network security incident occurs, it may lead to serious economic losses and even endanger personal safety. Therefore, building a set of efficient, intelligent, and reliable network security management systems is crucial for ensuring the safe and stable operation of new energy power plants.
[0003] The specification of Chinese invention patent application CN114386809A discloses a network security threat warning and disposal system for nuclear power plants. This system realizes the local network security threat warning and disposal work order circulation of nuclear power plants through the nuclear power plant network security situation awareness system, and forms a knowledge base for the processing method of local network security threat warning and disposal work orders in nuclear power plants, aiming to achieve a standardized process for network security threat warning and disposal in nuclear power plants and efficiently and standardizedly optimize the network security operation management work of nuclear power plants. However, this design mainly focuses on the process management of threat warning and disposal and the construction of the knowledge base, but lacks the ability to deeply monitor and analyze the underlying system behavior, and it is difficult to cope with increasingly complex and advanced threats at the instruction execution level.
[0004] The specification of Chinese invention patent CN113191917B discloses a method for classifying network security threats in a power plant industrial control system based on the radial basis function algorithm. This method monitors the network security abnormal behaviors of the power plant industrial control system, classifies network security events using the RBF neural network, and blocks the network security abnormal behaviors according to the classification results. This design realizes the classification and blocking of network security threats through machine learning algorithms, but its main focus is on the analysis of abnormal behaviors at the network traffic level, and its threat detection ability for more concealed and in-depth attacks using the instruction execution context is limited. In addition, this design does not involve advanced security features such as data integrity protection, privacy protection, and system self-adaptation and self-renewal.
[0005] The above designs have improved the network security protection ability of power plants to a certain extent by establishing threat warning and disposal processes, constructing knowledge bases, and using machine learning for threat classification, but there are still certain limitations. For example, there is a lack of real-time monitoring and analysis of the underlying instruction execution context, making it difficult to effectively cope with complex attacks such as advanced persistent threats (APTs); at the same time, insufficient consideration is given to the integrity of key data, the privacy of operations, and the self-adaptation and self-recovery capabilities of the system. Summary of the Invention
[0006] The object of the present invention is to overcome the deficiencies of the prior art and propose a network security management system for new energy power plants to solve the above-mentioned existing problems.
[0007] By means of real-time analysis of CPU instruction execution context, introducing blockchain technology to ensure data integrity, adopting zero-knowledge proof to protect privacy, realizing automatic reshaping after security events, and hardware acceleration, etc., the ability of new energy power plants to cope with various network security risks is improved.
[0008] The object of the present invention is achieved by the following technical solutions: A network security management system for new energy power plants, comprising: A security defense system, based on a hierarchical architecture, realizes real-time collection of CPU instruction execution context, behavior modeling, anomaly detection, security event recording and global situation awareness, and can adaptively adjust; A blockchain module, which realizes distributed recording, verifiable execution and device status synchronization of key data with anti-tampering characteristics; a privacy protection module, which protects the privacy of key operations; a security reshaping module, which automatically performs security enhancement and policy reconstruction after detecting a security event; an encryption channel, which ensures the confidentiality, integrity and reliability of data transmission between modules; a hardware acceleration unit, which meets the high-frequency and real-time response requirements of the system; The security defense system includes: a data collection module, including an instruction analyzer and a behavior modeling module, which are respectively used for collecting structured instruction execution context data and constructing and updating a normal behavior feature model or portrait; a threat detection module, which receives data from the instruction analyzer and the behavior modeling module, and uses SVM and Isolation Forest algorithms for anomaly detection and risk assessment; an event response module, which records events and triggers predefined responses when the threat detection module detects high risks; a situation awareness module, which integrates data from the event response module, the threat detection module and the behavior modeling module, realizes security situation monitoring and trend analysis, and optimizes the parameters of the behavior modeling module and the threat detection module through feedback; a trust engine, which constructs a four-dimensional trust model, dynamically adjusts weights using reinforcement learning, and realizes dynamic trusted authentication and trust accumulation by combining semantic association and behavior prediction; a policy weaving module, which realizes active response and automatic adjustment of security policies through differential policy evaluation and security grid optimization mechanisms; A context adaptation module, which standardizes device information into trust context and realizes secure access to cross-vendor devices through a trust handshake protocol; the blockchain module includes a trusted execution environment and a chain synchronization module, which are used to ensure the integrity and traceability of key data; the hardware acceleration unit adopts dedicated acceleration and multi-core parallel processing technologies.
[0009] The instruction analyzer includes: an instruction acquisition unit for collecting CPU instruction execution context data in real time; an instruction preprocessing unit for preprocessing instruction data and parsing it into operation codes; a context extraction unit for extracting the context sequence of target instructions and the changes in associated registers; an event record generation unit for structuring the processed data into an event record containing EventID, timestamp, execution trace, PID, memory access address, register status, and information on the previous and subsequent instructions; and a data screening unit for eliminating redundant information. The behavior modeling module includes: a behavior modeling unit that constructs an initial normal behavior feature model or profile through clustering using data from the instruction analyzer, and adaptively updates the feature model or profile during operation to form a multi-dimensional behavior model for threat detection.
[0010] The threat detection module includes: a feature selection unit for receiving the standard event records from the instruction analyzer and the behavior model data output by the behavior modeling module, and performing feature selection; a risk classification unit for performing multi-level risk classification on the data using SVM; an anomaly screening unit for quickly screening for anomalies using the Isolation Forest algorithm; and a risk assessment unit for establishing a risk scoring system and outputting the risk level, event description, and relevant data.
[0011] The event response module includes: an event trigger unit for automatically triggering an event record when the threat detection module detects a high risk; an event association unit for associating the triggered event with relevant information to form an event view; a log recording unit for recording the detailed event information in the security log; and a response trigger unit for automatically triggering predefined response measures based on the risk level.
[0012] The situation awareness module includes: a situation monitoring unit for real-time monitoring and trend analysis of the overall security situation, whose data comes from the event response module, the threat detection module, and the behavior modeling module; a policy recommendation unit for proposing optimization suggestions for security policies by integrating external threat intelligence; and a feedback optimization unit for real-time feedback of the monitoring results to the behavior modeling module and the threat detection module through feedback to optimize the behavior model and detection parameters.
[0013] An encrypted channel is used for information transmission between modules, with digital signatures and check codes attached.
[0014] The hardware acceleration unit includes: a high-frequency acquisition unit for using a dedicated monitoring chip or hardware accelerator in the data acquisition module to achieve high-frequency data acquisition; a parallel monitoring unit for synchronously monitoring multi-core CPU data using multi-core parallel processing technology; and an algorithm acceleration unit for deploying a machine learning acceleration unit in the behavior modeling module and the threat detection module to improve the operation efficiency of relevant algorithms. System optimization and data flow unit, which is optimized for new energy power plant scenarios, connected to the power plant control system and sensor interface, obtains the operating status and environmental parameters in real time, dynamically adjusts the data acquisition frequency, detection sensitivity and response strategy, and generates a security situation report.
[0015] The trust engine includes: a trust model construction unit for constructing a four-dimensional trust model, where the time context credibility embeds time information based on a predefined event time series model; a trust evaluation unit for dynamically adjusting each weight using reinforcement learning, combining semantic association to analyze the resource access intent, and achieving trust accumulation and behavior prediction. The policy weaving module includes: a policy adjustment unit for adopting a differential policy evaluation and security grid optimization mechanism to achieve active adjustment of security policies and behavior suggestions. The context adaptive module includes: a context processing unit for standardizing device information into a trust context, verifying consistency through a trust handshake protocol, and achieving automatic adjustment of the authentication process and access rights.
[0016] The trusted execution environment of the blockchain module includes: an application packaging and signing unit for packaging key industrial control applications into verifiable execution modules and signing them on the blockchain to achieve auditing and traceability. The chain synchronization module of the blockchain module includes: a data synchronization and verification unit for achieving multi-point backup and synchronization of key data, and integrating a privacy protection module to make key operations verifiable. The instruction interception module includes: an instruction review and interception unit for integrating a situational threat engine, reviewing sensitive instructions in real time, and aborting execution and triggering a response when potential risks are detected. The security reshaping module includes: a policy reshaping unit for automatically correcting and reconstructing policies based on security event data, and spreading security enhancement measures through the blockchain consensus mechanism. The blockchain module also includes: a participant management unit for allowing system participants to dynamically join or leave the blockchain network according to security requirements.
[0017] The beneficial effects of the present invention are: 1. By collecting and analyzing the CPU instruction execution context in real time, it can deeply understand the operation behavior of the system at the lowest level, effectively detect advanced threats such as malicious code and Rootkit that are difficult to discover by traditional security means, achieve fine-grained monitoring of system behavior, construct a multi-dimensional behavior model based on the normal instruction execution mode, accurately identify abnormal activities deviating from normal behavior, reduce the false alarm rate, improve the accuracy of threat detection, integrate data from various security modules, achieve real-time monitoring and trend analysis of the entire new energy power plant network security situation, provide a global security perspective for managers, and promptly grasp potential risks.
[0018] 2. The system can dynamically adjust security policies and model parameters according to the changes in the actual environment and attack situation, improving its ability to cope with unknown and new threats. The policy weaving module can actively adjust security policies based on risk assessment and threat intelligence, and put forward security behavior suggestions, transforming security protection from passive response to active defense. Through differential policy evaluation and security grid optimization mechanisms, it realizes the automatic adjustment of security policies, reduces manual intervention, and improves the effectiveness of security policies.
[0019] 3. Using blockchain technology, it provides distributed storage and recording with anti-tampering characteristics for the key operation data, security logs, and policy configurations of the power plant, ensuring the integrity and credibility of the data. Through a trusted execution environment, it ensures the trustworthiness of the source of key industrial control applications and that they have not been tampered with during the execution process. Dedicated encrypted channels are used for communication between the internal modules of the system to ensure the confidentiality, integrity, and reliability of data transmission, preventing data leakage and tampering. Privacy protection technologies such as zero-knowledge proof are adopted to protect the sensitive information of the power plant during critical operations and prevent the risks brought by information leakage.
[0020] 4. The introduction of a hardware acceleration unit significantly improves the system's data collection, analysis, and processing speed, meeting the strict requirements of new energy power plants for high-frequency and real-time security monitoring and response. The dedicated machine learning acceleration unit can improve the operation efficiency of key algorithms such as behavior modeling and threat detection, shorten the analysis time, and reduce resource consumption. The system is optimized for the special scenarios of new energy power plants and can better adapt to the operation characteristics and security requirements of the power plant.
[0021] 5. When the system detects a high-risk security event, it can automatically trigger predefined response measures, shorten the response time, reduce manual intervention, associate the security event with relevant instructions, execution processes, and user information to form a complete event view, which helps security analysts understand the ins and outs of the event. After a serious security event occurs, the security reshaping module can automatically perform security enhancement and policy reconstruction to quickly restore the system's security state and enhance the system's resilience.
[0022] 6. The context adaptive module realizes the security context synchronization and security access control of cross-vendor devices, simplifies security management in heterogeneous environments, and improves overall security. The trust engine realizes dynamic trusted authentication based on a multi-dimensional trust model, can more accurately control access to key resources of the power plant, and allows authorized system participants to dynamically join or leave the blockchain network according to security needs, enhancing the flexibility and manageability of the system.
[0023] 7. The instruction interception module can review sensitive instructions in real time at the instruction execution level to prevent potential malicious operations. The security reshaping module can automatically correct and reconstruct policies based on security event data and spread security enhancement measures through the blockchain consensus mechanism to form a defense system with self-evolution and continuous improvement capabilities. The situation awareness module can integrate external threat intelligence to provide suggestions for optimizing security policies and continuously enhance the system's defense capabilities. Brief Description of the Drawings
[0024] Figure 1 is the system architecture of the present invention Figure 1 ; Figure 2 is the system architecture of the present invention Figure 2 . Detailed Embodiments
[0025] Next, the technical solutions of the present invention will be clearly and completely described in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative efforts fall within the scope of protection of the present invention.
[0026] It should be noted here that the orientation concepts of "left", "right", "up", "down", "front", "back", "inside", and "outside" in the following solutions are all relative directions, and will not be listed one by one here.
[0027] Embodiment 1: As Figures 1 to 2 shown, this embodiment describes the core architecture of a network security management system for a new energy power plant. The system aims to provide comprehensive and adaptive security protection capabilities to cope with increasingly complex network threats and ensure the safe and stable operation of the power plant. The system adopts a hierarchical architecture and integrates a variety of advanced security technologies to effectively protect the key information systems and equipment of the power plant.
[0028] The core architecture of the network security management system includes the following key modules, which work together to jointly build the network security defense line of the power plant: The security defense system is designed based on a hierarchical architecture and focuses on real-time monitoring and analysis of the CPU instruction execution context during the operation of the power plant. It can perform behavior modeling, anomaly detection, security event recording, and global situation awareness, and has the ability to dynamically and adaptively adjust according to the actual environment and attack situation.
[0029] The blockchain module uses blockchain technology to provide tamper-resistant distributed storage and recording for the power plant's key operating data, security logs, and policy configurations. It also supports verifiable execution processes and can synchronize status information between different devices to ensure data consistency and credibility.
[0030] The privacy protection module uses privacy protection technologies such as zero-knowledge proof to protect sensitive information of power plants during key operations (such as policy updates and configuration changes) and prevent information leakage.
[0031] The security reshaping module can automatically trigger the security enhancement and policy reconstruction process when the system detects a serious security incident. It uses a trusted consensus mechanism to deploy new security policies and defense measures throughout the system to achieve "self-evolution" of security.
[0032] The various modules within the system communicate with each other through a dedicated encrypted data channel. This channel not only encrypts the data, but also comes with a digital signature and integrity verification mechanism to ensure the confidentiality, integrity and reliability of the data during transmission, and prevent the data from being eavesdropped, tampered with or forged.
[0033] Hardware acceleration unit. In order to meet the needs of new energy power plants for high-frequency and real-time security response, the system integrates dedicated acceleration and multi-core parallel processing technology at the hardware level. This can significantly improve the speed of data collection, analysis and processing, ensuring that the system can detect and respond to security threats in a timely manner.
[0034] The internal modules of the security defense system are further divided into the following functional modules: The data acquisition module is the data entry point of the security defense system and includes: The instruction analyzer is responsible for collecting instruction execution context data from key servers and control system CPUs of new energy power plants in real time, such as register values and memory addresses. It can perform in-depth analysis and structured conversion of the original machine code to extract meaningful security information.
[0035] The behavioral modeling module builds and updates the normal behavioral characteristic model or portrait of the power plant system in real time based on the data collected by the instruction analyzer. In the early stage of system deployment, it will establish an initial baseline model through learning, and dynamically adjust the model parameters through online adaptive algorithms (such as Kalman filtering) during operation to form a multi-dimensional behavioral model and baseline reference.
[0036] The threat detection module receives data from the instruction analyzer and the behavior modeling module, and uses machine learning algorithms (Support Vector Machine SVM and Isolation Forest) to perform anomaly detection and risk assessment on system behaviors. SVM is used for multi-level risk classification to determine the risk levels of different behaviors; Isolation Forest is used to quickly identify and isolate abnormal behaviors, reducing the consumption of computing resources.
[0037] The event response module, when the risk level detected by the threat detection module reaches the preset threshold, will automatically trigger the recording of security events, associate the events with relevant instructions, execution processes, and user information to form a complete event view. At the same time, according to the risk level, this module can automatically trigger predefined response measures, such as isolating affected processes, blocking access of malicious users, or updating security policies.
[0038] The situation awareness module integrates data from the event response module, the threat detection module, and the behavior modeling module to perform real-time monitoring and trend analysis on the overall power plant network security situation. It can provide an intuitive security dashboard to display the current risk status and potential threat trends, and through a feedback loop, it can real-time feedback security logs, risk assessment, and anomaly detection results to the behavior modeling module and the threat detection module to continuously optimize the behavior model and detection parameters, improving the accuracy and efficiency of detection.
[0039] The trust engine builds a four-dimensional trust model to evaluate the credibility of identity, the credibility of environmental security status, the credibility of resource access behavior, and the credibility of time context (TRT). It uses reinforcement learning algorithms to dynamically adjust the weights of each dimension, and combines semantic association and behavior prediction technologies to achieve dynamic trusted authentication and trust accumulation for power plant users and devices, thereby more precisely controlling resource access.
[0040] The policy weaving module compares the effects of different security policies through differential policy evaluation (such as A / B testing), and uses a security grid optimization mechanism to collaboratively adjust the parameters of each policy. Its goal is to achieve active risk response and automated adjustment of security policies, and can actively propose security behavior suggestions according to the current threat situation and system status, enhancing the overall security defense ability of the power plant.
[0041] The context adaptation module standardizes the configuration information, firmware versions, TLS configurations, security policies, etc. of various devices in the power plant into trust context information. Through the trust handshake protocol, this module can achieve automatic context synchronization and secure access control between cross-vendor devices, thus simplifying security management and improving security in heterogeneous environments.
[0042] The security defense system is responsible for real-time monitoring and analysis of the operating status of the power plant's key systems, identifying potential security threats, and performing preliminary responses and records. Its working principle is to establish a normal behavior pattern by deeply analyzing the details of CPU instruction execution. Once a behavior deviating from the normal pattern is detected, it is marked as abnormal and further processed.
[0043] The blockchain module provides a secure, transparent, and tamper-resistant data storage platform for recording important security-related information. Its working principle is to utilize distributed ledger technology to disperse data storage across multiple nodes. Any data changes require the consensus of multiple nodes in the network, thereby ensuring data integrity and traceability.
[0044] The privacy protection module can ensure that the specific content of operations is not leaked to unauthorized third parties when performing sensitive operations, such as updating security policies or configuring key parameters. Its working principle is to utilize cryptographic technologies such as zero-knowledge proofs, enabling one party (the prover) to prove that they possess certain knowledge without providing any useful information to the other party (the verifier).
[0045] After a serious security incident occurs, the security reshaping module can quickly adjust the system's security posture and enhance the defense capabilities. Its working principle is based on predefined security policies and a trusted consensus mechanism to automatically deploy new security rules, isolate damaged systems, and even roll back to a secure state to achieve rapid recovery and enhanced defense.
[0046] The encrypted channel ensures the security of communication between various modules within the system. Its working principle is to encrypt the transmitted data using encryption algorithms to prevent eavesdropping during data transmission. At the same time, through digital signature and checksum mechanisms, data integrity is ensured to prevent data from being tampered with or forged.
[0047] The hardware acceleration unit enhances the system's ability to process large amounts of real-time data through dedicated hardware accelerators and multi-core parallel processing technologies. Its working principle is to utilize the parallel computing power of the hardware to accelerate key tasks such as data acquisition, instruction analysis, and execution of machine learning algorithms, thereby meeting the requirements of the power plant for real-time security monitoring and response.
[0048] Data processing flow: Data acquisition, the instruction analyzer real-time collects the CPU instruction execution context data of the key systems of the new energy power plant.
[0049] Behavior modeling, the behavior modeling module receives data from the instruction analyzer and constructs and updates the normal behavior feature model or profile of the system.
[0050] Threat Detection: The threat detection module receives the structured event records from the instruction analyzer and the behavior model data output by the behavior modeling module, performs feature selection, and uses the SVM and Isolation Forest algorithms for anomaly detection and risk assessment.
[0051] Event Response: When the threat detection module detects a high risk, the event response module records the event, correlates relevant information, and records the event details in the security log. Meanwhile, it triggers predefined response measures according to the risk level.
[0052] Situation Awareness and Feedback: The situation awareness module integrates the data from the event response module, the threat detection module, and the behavior modeling module, performs security situation monitoring and trend analysis, and feeds back the analysis results to the behavior modeling module and the threat detection module to optimize their parameters.
[0053] Trust Evaluation and Authentication: The trust engine constructs a trust model based on the collected user, environment, behavior, and time information, and performs dynamic evaluation and authentication.
[0054] Policy Management: The policy weaving module realizes the active adjustment and update of security policies through an evaluation and optimization mechanism.
[0055] Context Synchronization and Secure Access: The context adaptation module standardizes device information and realizes secure access to cross-vendor devices through a trust handshake protocol.
[0056] Data Storage and Verification: The blockchain module is used to store key data and ensure the integrity and traceability of the data through a trusted execution environment and a chain synchronization module.
[0057] Privacy Protection: The privacy protection module protects sensitive information during critical operations.
[0058] Security Remodeling: When a security event is detected, the security remodeling module automatically performs security enhancement and policy reconstruction.
[0059] Data Transmission Security: The data transmission between all modules is protected through an encrypted channel.
[0060] By collecting and analyzing the real-time execution context of CPU instructions, it is possible to deeply understand the operating status of the system, timely detect potential malicious behaviors, and make up for the deficiencies of traditional security defense means. The system can dynamically adjust security policies and model parameters according to the actual environment and attack situation, improving the ability to respond to unknown threats. Using blockchain technology, it ensures that the key operation data and security logs of the power plant have anti-tampering characteristics and traceability, providing a reliable basis for security incident analysis and accountability. Adopting technologies such as zero-knowledge proof to protect the sensitive information of the power plant during security management operations and prevent the risks brought by information leakage. The security reshaping module can quickly perform security enhancement and policy reconstruction after detecting serious security incidents, shortening the response time and reducing losses. Through an encrypted channel, it ensures the confidentiality, integrity, and reliability of internal data transmission in the system, preventing malicious attacks during data transmission. The introduction of a hardware acceleration unit significantly improves the data processing ability of the system, meeting the strict requirements of new energy power plants for real-time security monitoring and response. The context adaptation module realizes the security context synchronization and secure access of cross-vendor devices, simplifying security management in heterogeneous environments. The trust engine realizes dynamic trusted authentication based on a multi-dimensional trust model, enabling more precise control of access to key resources of the power plant.
[0061] In summary, the core architecture of the network security management system for new energy power plants described in this embodiment can provide a comprehensive, intelligent, and adaptive security solution for the power plant by integrating a variety of advanced security technologies and modular design, effectively improving the network security protection level of the power plant and ensuring its safe and stable operation.
[0062] Embodiment 2: As Figures 1 to 2 shown, based on the overall architecture described in Embodiment 1, this embodiment focuses on elaborating the specific structure, functions, working principles, data processing flow, and their beneficial effects of the instruction analyzer, behavior modeling module, threat detection module, event response module, and situation awareness module inside the security defense system. These modules are the key components for realizing refined monitoring and response to the network security of new energy power plants.
[0063] The instruction analyzer is the core component of the data collection module and includes the following functional units: The instruction collection unit, as the forefront of data acquisition, is responsible for real-time capturing the instruction stream executed by the CPUs of key servers and control systems in the new energy power plant and extracting its context information, including program counter, register values, memory addresses, operands, etc.
[0064] The instruction preprocessing unit performs preprocessing operations such as cleaning and formatting on the collected original instruction data, parsing complex machine codes into opcode forms that are easier to understand and analyze, laying a foundation for subsequent analysis and modeling.
[0065] Within a preset time window, for a specific target instruction, the context extraction unit extracts the consecutive instruction sequences executed before and after it, and records the changes in relevant registers, thereby constructing the execution context of the instruction, revealing the logical relationships between instructions and potential behavioral intentions.
[0066] The event record generation unit structures and formats the preprocessed and context-extracted instruction data into standard event records. Each record usually contains a unique event ID, occurrence timestamp, program execution trace, system process ID (PID), memory access address, status of key registers, and information about several instructions before and after the target instruction.
[0067] The data screening unit filters and screens the generated event records, removing low-precision, redundant, or information irrelevant to security analysis to reduce the amount of data for subsequent processing and improve analysis efficiency.
[0068] The role of the instruction analyzer is to deeply explore the underlying running behavior of the system, convert the CPU instruction execution into data available for security analysis. Its working principle is through hardware or software Hook technology. Without affecting the normal operation of the system, it monitors the execution process of CPU instructions in real time, parses and conducts correlation analysis on them, and extracts key information that can reflect the system behavior.
[0069] It can monitor the system behavior at the lowest instruction level, detect malicious codes and abnormal operations that are difficult to detect by traditional security means, extract the context of instruction execution, which helps to understand the complete process and potential impact of attack behaviors. The generated standardized event records provide a structured and high-quality data source for behavior modeling and threat detection.
[0070] The behavior modeling module contains core functional units: The behavior modeling unit is responsible for constructing and maintaining the normal behavior feature model or portrait of the system. During the system deployment phase, it uses historical data from the instruction analyzer and learns the normal instruction execution patterns of the system through clustering algorithms such as K-Means to construct an initial baseline model. During the system operation process, it adopts an online adaptive algorithm (such as Kalman filter) to dynamically update the feature model or portrait to adapt to the changes in the system operation state. At the same time, this unit normalizes the various parameters of the feature model or portrait to form a multi-dimensional behavior model and baseline reference.
[0071] The role of the behavior modeling module is to learn and understand the normal behavior patterns of the system, provide a benchmark for subsequent anomaly detection, analyze a large amount of normal behavior data using machine learning algorithms, extract features that can characterize the normal operation state of the system, and establish corresponding mathematical models.
[0072] Data processing flow: Standardized event records from the instruction analyzer ~ Behavior modeling unit (initial feature model or portrait construction, online adaptive update, normalization processing) ~ Multidimensional behavior model output to the threat detection module.
[0073] It can accurately depict the normal operating state of the system and provide a reliable basis for identifying abnormal behaviors.
[0074] Dynamic adaptation to system changes: Through online adaptive update, it can cope with changes in behavior patterns brought about by system configuration, load, etc., reduce the false alarm rate, and the generated multidimensional behavior model can more comprehensively reflect the behavior characteristics of the system, improving the accuracy of anomaly detection.
[0075] The threat detection module includes the following functional units: The feature selection unit receives the standard event records from the instruction analyzer and the behavior model data output by the behavior modeling module, and selects the most effective features for anomaly detection from them, reducing data noise and improving detection efficiency.
[0076] The risk classification unit uses the support vector machine (SVM) algorithm to perform multi-level risk classification on the data after feature selection, classifying different abnormal behaviors into different risk levels, so as to achieve more refined threat management.
[0077] The anomaly screening unit applies the Isolation Forest algorithm to quickly screen the data for anomalies. This algorithm can efficiently discover potential malicious behaviors by isolating anomaly points and reduce the overall computational resource occupancy.
[0078] The risk assessment unit, based on the results of risk classification and anomaly screening, establishes a risk scoring system, comprehensively evaluates the detected abnormal situations, and finally outputs the risk level, event description, and relevant instruction and feature data.
[0079] Function and working principle The role of the threat detection module is to identify abnormal behaviors and potential security threats in the system. Its working principle is to use machine learning algorithms to analyze the behavior data of the system, compare it with the normal behavior model, and judge whether there are anomalies according to preset rules and thresholds.
[0080] Combining the SVM and Isolation Forest algorithms can achieve multi-level risk classification and fast anomaly screening, improve the accuracy and efficiency of detection. The application of the Isolation Forest algorithm helps to reduce the occupancy of computational resources and is suitable for resource-constrained industrial control environments. The output risk level, event description, and relevant data provide important information support for subsequent event response and security analysis.
[0081] The event response module includes the following functional units: The event trigger unit monitors the output of the threat detection module and automatically triggers the event recording process when the detected risk level reaches a preset threshold.
[0082] The event correlation unit correlates the triggered events with relevant instructions, execution processes, user information, and context data to form a complete event view, helping security analysts understand the ins and outs of the events.
[0083] The log recording unit records the detailed information of the events (including timestamp, event type, risk level, participating instructions, user information, and context data) into the security log, providing a basis for subsequent security audits and analyses.
[0084] The response trigger unit automatically triggers predefined response measures according to the risk level of the events, such as isolating affected processes, blocking access of malicious users, updating firewall rules, or activating other security policies.
[0085] The role of the event response module is to take corresponding measures to mitigate or eliminate the impact of security threats after detection. Its working principle is based on preset response strategies and rules, and it automatically executes corresponding operations according to different risk levels.
[0086] It can automatically execute response measures according to preset strategies, shorten the response time, reduce the need for manual intervention, correlate events with relevant information, which helps security analysts comprehensively understand the scope of influence and root causes of events, and the recorded detailed event information provides valuable data for subsequent security audits and analyses.
[0087] The situation awareness module includes the following functional units: The situation monitoring unit integrates data from the event response module, threat detection module, and behavior modeling module, monitors and displays the real-time network security situation of the entire new energy power plant, and conducts long-term trend analysis to predict future security risks.
[0088] The policy recommendation unit integrates external threat intelligence information, such as the latest vulnerability information, attack trends, etc., combines with the current system security situation, and provides suggestions for optimizing security policies to help the power plant improve its overall defense ability.
[0089] The feedback optimization unit, through the feedback loop, real-time feeds back the security logs, risk assessment results, and anomaly detection results collected by the situation monitoring unit to the behavior modeling module and threat detection module, for continuously optimizing the behavior model and detection parameters, improving the accuracy and efficiency of detection, and forming a closed-loop self-optimizing system.
[0090] The role and working principle of the situation awareness module is to provide plant managers with a global safety perspective, helping them understand the current safety situation, predict future risks, and guide the formulation and optimization of safety strategies. Its working principle is to collect, analyze, and visualize data from various safety modules to form a comprehensive understanding of the overall safety situation.
[0091] Provide a comprehensive understanding of the overall cybersecurity situation of the power plant, help managers promptly grasp risks, combine external threat intelligence and the system's own status, and provide targeted suggestions for optimizing safety strategies. Optimize the behavior model and detection parameters through a feedback loop to continuously improve the detection accuracy and efficiency of the system.
[0092] Through the above detailed description, on the basis of Embodiment 1, Embodiment 2 deeply reveals the specific implementation methods of the key modules inside the security defense system and their important roles in the new energy power plant network security management system, further reflecting the technical details and innovation of the invention.
[0093] Embodiment 3: Such as Figures 1 to 2 As shown, on the basis of Embodiment 1 and Embodiment 2, this embodiment further details the key enhancement functions and trusted mechanisms for improving security and reliability in the system, including encrypted communication between modules, the refined implementation of the hardware acceleration unit, the internal operation of the trust and authentication enhancement unit, and the collaborative work of the blockchain module and the active defense mechanism.
[0094] Encryption channel: Dedicated encrypted data channels are established between all modules in the system (including each sub-module inside the security defense system and between the security defense system and the blockchain module, privacy protection module, security reshaping module, etc.). Each channel is isolated from other channels at the physical or logical level to ensure the exclusivity of data transmission.
[0095] The main role of the encryption channel is to ensure the confidentiality, integrity, and reliability of data transmission within the system. Its working principle includes: Data encryption: Advanced encryption algorithms (such as AES, RSA, etc.) are used to encrypt the transmitted data to prevent unauthorized third parties from eavesdropping on the data content; Digital signature: The sender digitally signs the data being sent, and the receiver verifies the signature to confirm the source of the data and prevent data forgery; Checksum: A checksum (such as CRC, SHA, etc.) is attached during data transmission, and the receiver uses the checksum to detect whether the data has errors or been tampered with during transmission.
[0096] Data processing flow: When a module needs to send data to another module, the data is first encrypted, then appended with the digital signature and checksum of the sender, and transmitted to the receiver through a dedicated encrypted channel. After receiving the data, the receiver first checks the checksum to confirm the data integrity; then verifies the digital signature to confirm the data source; finally, decrypts the data using the corresponding key to obtain the original information.
[0097] Prevent data leakage. Encryption ensures that even if the data is intercepted, it cannot be understood by unauthorized parties. Prevent data tampering. Digital signatures and checksums ensure the integrity of the data, and any modification to the data will be detected. Ensure reliable data sources. Digital signatures can verify the sender of the data and prevent malicious modules from disguising their identities to send false information.
[0098] The hardware acceleration unit is integrated at the bottom layer of the system to provide high-performance computing support for key modules. It consists of the following components: The high-frequency acquisition unit uses a dedicated monitoring chip or hardware accelerator (such as FPGA) in the instruction analyzer of the data acquisition module to achieve high-speed and accurate acquisition of the CPU instruction stream, meeting the high-frequency operation requirements of the new energy power plant control system.
[0099] The parallel monitoring unit uses multi-core parallel processing technology (such as multi-core CPUs, GPUs, etc.) to achieve synchronous monitoring and preliminary processing of data from multiple CPU cores, significantly improving the throughput of data processing.
[0100] The algorithm acceleration unit deploys dedicated machine learning acceleration units (such as GPUs, TPUs, etc.) in the behavior modeling module and threat detection module to optimize the operation efficiency of machine learning algorithms such as K-Means clustering, Kalman filtering, SVM, and Isolation Forest, shortening the time for model training and anomaly detection.
[0101] The system optimization and data flow unit is responsible for optimizing for the special scenarios of new energy power plants, such as connecting to the plant's SCADA system, PLC, sensors, etc., to obtain the operation status and environmental parameters of the power plant in real time. At the same time, this unit dynamically adjusts the data acquisition frequency, the sensitivity of anomaly detection, and the response strategy according to the operating characteristics of on-site equipment, and is responsible for generating detailed security situation reports for management decision-making reference.
[0102] The role of the hardware acceleration unit is to improve the performance of the system, enabling it to process and analyze a large amount of real-time data generated by new energy power plants in a timely manner and quickly respond to security threats. Its working principle is to utilize the parallel computing power and dedicated optimization of the hardware to accelerate key data processing and computationally intensive tasks.
[0103] The hardware acceleration unit participates in multiple processes such as data acquisition, behavior modeling, and threat detection. By accelerating with hardware, it improves the processing speed of each process, ultimately enhancing the response speed and analysis efficiency of the entire system.
[0104] To meet the high-frequency and real-time data processing requirements of new energy power plants, shorten the time for behavior modeling and threat detection, and detect and respond to security threats more quickly, the hardware acceleration reduces the burden on the CPU, improves the overall operation efficiency and stability of the system, and can be customized and optimized according to the characteristics of new energy power plants, enhancing the applicability and effectiveness of the system.
[0105] The trust and authentication enhancement unit consists of a trust engine, a policy weaving module, and a context adaptation module, aiming to enhance the trust level of the system and the security of the authentication mechanism.
[0106] Trust engine: The trust model construction unit constructs a four-dimensional trust model, including identity credibility (based on identity authentication and authorization information), environmental security status credibility (based on system vulnerability scanning, configuration compliance, etc. evaluations), resource access behavior credibility (based on historical access records and behavior pattern analysis), and time context credibility (TRT). Among them, TRT relies on a predefined event time series model to embed time information into trust evaluation. For example, it raises the security alert level during critical operation time periods.
[0107] The trust evaluation unit introduces influence weight coefficients and uses reinforcement learning algorithms to dynamically adjust the weights of each dimension to adapt to the changing security situation. At the same time, it combines with the semantic association module to perform natural language analysis on the user's resource access intent, distinguish authorized access and potential malicious access, and perform trust accumulation and behavior prediction based on historical data, providing a basis for dynamic trusted authentication.
[0108] Policy weaving module: The policy adjustment unit adopts differential strategy evaluation (DSE), compares the effects of different defense strategies through methods such as A / B testing, and uses the security mesh optimization (SMO) mechanism to collaboratively adjust the parameters of each strategy to achieve proactive risk response and automated security policy adjustment. This unit can also actively propose security behavior suggestions based on current threat intelligence and system status, such as forcing users to perform secondary authentication, restricting certain high-risk operations, etc.
[0109] Context Adaptive Module: The context processing unit standardizes the configuration information, firmware version, TLS configuration, installed security component information, and the manufacturer's security policies of various devices in the new energy power plant into trust context metadata. Through the Trusted Handshake Protocol (TBEDP), this unit can verify the consistency of device contexts and automatically adjust the authentication process and access permissions according to the trust level of the device and the current security posture. In addition, this unit also supports the sharing of security policies based on federated learning to achieve joint protection across different trust domains.
[0110] This unit realizes dynamic and fine-grained trust management and access control by comprehensively evaluating various factors. Its working principle is to utilize a multi-dimensional trust model, an intelligent policy adjustment mechanism, and flexible context awareness capabilities to improve the security and availability of the system.
[0111] The trust engine receives identity, environment, behavior, and time information from each module, conducts trust assessment, and uses the results for policy weaving modules and context adaptive modules to adjust policies and access control. The policy weaving module adjusts security policies based on the assessment results and external intelligence, while the context adaptive module adjusts authentication and access permissions according to device context and trust level.
[0112] Based on multi-dimensional trust assessment, dynamic and fine-grained access control is achieved, reducing the risk of unauthorized access. The policy weaving module can actively adjust security policies according to risk and threat intelligence to improve the system's defense capabilities. The context adaptive module realizes secure interoperability and unified management of cross-vendor devices. Automated policy adjustment and context synchronization reduce the need for manual intervention.
[0113] Trusted Execution Environment of the Blockchain Module: The application packaging and signature unit packages the key industrial control application programs in the new energy power plant into verifiable execution modules and obtains a digital signature from an authoritative institution on the blockchain, which ensures the trustworthiness of the application source and that it has not been tampered with during execution.
[0114] Chain Synchronization Module of the Blockchain Module: The data synchronization and verification unit realizes multi-point backup and synchronization of key industrial control data and security logs to prevent data loss or malicious tampering caused by a single point of failure. At the same time, this unit integrates the zero-knowledge proof protocol provided by the privacy protection module to achieve transparent verifiability of key operations without revealing sensitive information.
[0115] Instruction Interception Module: The instruction review and interception unit is integrated with the Context-Aware Threat Engine (CATE, although not explicitly listed in the previous claims, but described here as an enhanced function). It intercepts and reviews sensitive instructions such as writing to critical system resources in real time. If a potential destructive operation is detected, the execution of the instruction is aborted and corresponding response measures are triggered.
[0116] Security Reinforcement Module: The policy reinforcement unit is based on historical security event data. This unit can automatically correct and reconstruct security policies. Through the trusted consensus mechanism of the blockchain, new security enhancement measures and updated policies are spread throughout the system, forming a defense system with the ability of self-evolution and continuous improvement.
[0117] Participant Management Unit of the Blockchain Module: The participant management unit allows authorized system participants (such as power plant operation and maintenance personnel, security administrators, etc.) to dynamically join or leave the blockchain network according to security requirements, realizing a dynamic blockchain participation mechanism and enhancing the flexibility and manageability of the system.
[0118] This part provides a trusted data storage and execution environment through blockchain technology. Combining real-time interception at the instruction level and automated security policy reinforcement, it constructs an active defense and self-evolving security system.
[0119] Critical industrial control applications are packaged and signed through a trusted execution environment. Critical data and security logs are backed up and synchronized on the blockchain through the chain synchronization module. The instruction interception module monitors instruction execution in real time, and the security reinforcement module updates security policies according to event data and blockchain consensus.
[0120] Blockchain technology ensures that data cannot be tampered with and can trace the source and history of the data. Through the trusted execution environment, it ensures the security of critical industrial control applications. The instruction interception module can prevent potential attacks at the instruction execution level, and the security reinforcement module can enable the system to automatically recover and enhance its defense capabilities after being attacked. The dynamic blockchain participation mechanism enables the system to adapt to different security requirements.
[0121] Through the above detailed description, on the basis of Embodiment 1 and Embodiment 2, Embodiment 3 further elaborates the enhanced functions and implementation details of the system in terms of security, performance, and trustworthiness, fully demonstrating the innovation and practicality of the invention in the field of new energy power plant network security management.
[0122] The above are only the preferred embodiments of the present invention. It should be understood that the present invention is not limited to the forms disclosed herein, and should not be regarded as excluding other embodiments, but can be used in various other combinations, modifications and environments, and can be changed within the scope of the concept described herein through the above teachings or the techniques or knowledge in the relevant field. As long as the changes and variations made by those skilled in the art do not depart from the spirit and scope of the present invention, they should all be within the protection scope of the appended claims of the present invention.
Claims
1. A network security management system for a new energy power plant, characterized in that, include: The security defense system, based on a layered architecture, implements real-time collection of CPU instruction execution context, behavior modeling, anomaly detection, security event recording, and global situational awareness, and can adaptively adjust. The blockchain module enables distributed recording of key data with tamper-resistant characteristics, verifiable execution, and device status synchronization; the privacy protection module protects the privacy of key operations; The security remodeling module automatically performs security enhancements and policy reconstruction after detecting a security incident; Encrypted channel to ensure the confidentiality, integrity and reliability of data transmission in each module; Hardware acceleration unit to meet the system's high-frequency and real-time response requirements; The security defense system includes: a data acquisition module, including an instruction analyzer and a behavior modeling module, which are respectively used to collect structured instruction execution context data and build and update normal behavior feature models or portraits; a threat detection module, which receives data from the instruction analyzer and the behavior modeling module, and uses the SVM and Isolation Forest algorithms to perform anomaly detection and risk assessment; an event response module, which records events and triggers predefined responses when the threat detection module detects high risks; a situation awareness module, which integrates data from the event response module, the threat detection module, and the behavior modeling module to achieve security situation monitoring and trend analysis, and optimizes the parameters of the behavior modeling module and the threat detection module through feedback; a trust engine, which builds a four-dimensional trust model, uses reinforcement learning to dynamically adjust weights, and combines semantic association and behavior prediction to achieve dynamic trusted authentication and trust accumulation; a policy weaving module, which realizes active response and automatic adjustment of security policies through differential policy evaluation and security grid optimization mechanism; and an instruction interception module. The context adaptation module standardizes device information into a trust context and enables secure access to cross-vendor devices through a trust handshake protocol. The blockchain module includes a trusted execution environment and a chain synchronization module to ensure the integrity and traceability of key data. The hardware acceleration unit uses dedicated acceleration and multi-core parallel processing technology.
2. The network security management system for a new energy power plant according to claim 1, wherein: The instruction analyzer includes: an instruction acquisition unit for collecting CPU instruction execution context data in real time; an instruction preprocessing unit for preprocessing instruction data and parsing it into operation codes; a context extraction unit for extracting the context sequence of the target instruction and the associated register changes; an event record generation unit for structuring the processed data into an event record containing EventID, timestamp, operation trajectory, PID, memory access address, register status and previous and next instruction information; and a data screening unit for eliminating redundant information. The behavior modeling module includes: a behavior modeling unit, which uses the data from the instruction analyzer to construct an initial normal behavior feature model or portrait through clustering, and adaptively updates the feature model or portrait during operation to form a multi-dimensional behavior model for threat detection.
3. The network security management system for a new energy power plant according to claim 2, wherein: The threat detection module includes: a feature selection unit for receiving the standard event records from the instruction analyzer and the behavior model data output by the behavior modeling module, and performing feature selection; a risk classification unit for performing multi-level risk classification on the data using SVM; an anomaly screening unit for quickly screening anomalies using the Isolation Forest algorithm; and a risk assessment unit for establishing a risk scoring system and outputting the risk level, event description, and related data.
4. A network security management system for a new energy power plant according to claim 3, characterized in that: The event response module includes: an event trigger unit for automatically triggering event records when the threat detection module detects high risks; an event correlation unit for correlating the triggered events with relevant information to form an event view; a log recording unit for recording the event details in the security log; and a response trigger unit for automatically triggering predefined response measures according to the risk level.
5. The network security management system for a new energy power plant according to claim 2, wherein: The situation awareness module includes: a situation monitoring unit for performing real-time monitoring and trend analysis on the overall security situation, and its data sources are the event response module, the threat detection module, and the behavior modeling module; a policy recommendation unit for fusing external threat intelligence to propose security policy optimization suggestions; and a feedback optimization unit for real-time feedback of the monitoring results to the behavior modeling module and the threat detection module through feedback to optimize the behavior model and detection parameters.
6. The network security management system for a new energy power plant according to claim 1, characterized in that: An encrypted channel is used for information transmission between the modules, with digital signatures and check codes attached.
7. The network security management system for a new energy power plant according to claim 1, characterized in that: The hardware acceleration unit includes: a high-frequency acquisition unit for using a dedicated monitoring chip or hardware accelerator in the data acquisition module to achieve high-frequency data acquisition; a parallel monitoring unit for synchronously monitoring multi-core CPU data using multi-core parallel processing technology; and an algorithm acceleration unit for deploying a machine learning acceleration unit in the behavior modeling module and the threat detection module to improve the operation efficiency of relevant algorithms. The system optimization and data flow unit is used for optimizing for the new energy power plant scenario, connecting to the power plant control system and sensor interfaces, obtaining the operating status and environmental parameters in real time, dynamically adjusting the data acquisition frequency, detection sensitivity, and response strategy, and generating a security situation report.
8. A network security management system for a new energy power plant according to claim 1, characterized in that: The trust engine includes: a trust model construction unit for constructing a four-dimensional trust model, and the time context credibility embeds time information relying on a predefined event time series model; a trust assessment unit for dynamically adjusting the weights of each right using reinforcement learning, combining semantic association analysis of the resource access intention, and realizing trust accumulation and behavior prediction. The policy weaving module includes: a policy adjustment unit for using a differential policy evaluation and security grid optimization mechanism to achieve active adjustment of security policies and behavior suggestions. The context adaptation module includes: a context processing unit for standardizing device information into a trust context, verifying consistency through a trust handshake protocol, and realizing automatic adjustment of the authentication process and access rights.
9. The network security management system for a new energy power plant according to claim 1, characterized in that: The trusted execution environment of the blockchain module includes: an application packaging and signature unit for packaging key industrial control applications into verifiable execution modules and signing them on the blockchain to achieve auditing and traceability. The chain synchronization module of the blockchain module includes: a data synchronization and verification unit, which is used to implement multi-point backup and synchronization of key data, and integrates a privacy protection module to achieve verifiability of key operations; The instruction interception module includes: an instruction review and interception unit, which is used to integrate a context threat engine, review sensitive instructions in real time, and abort the execution and trigger a response when potential risks are detected; The security reshaping module includes: a policy reshaping unit, which is used to automatically perform policy self-correction and reconstruction based on security event data, and spread security enhancement measures through the blockchain consensus mechanism; The blockchain module further includes: a participant management unit, which is used to allow system participants to dynamically join or leave the blockchain network according to security requirements.
Citation Information
Patent Citations
A Classification Method for Cybersecurity Threats in Power Plant Industrial Control Systems Based on Radial Basis Function Algorithm
CN113191917B
Nuclear power plant network security threat early warning and disposal system
CN114386809A
Data transmission information security management method and system based on Internet of Things
CN117914481A
Substation network security defense system based on artificial intelligence
CN119276602A
Intelligent behavior analysis and anomaly detection system for Internet of Things security
CN119402269A