Data processing method based on multiple protocols, terminal equipment and storage medium

By configuring multi-protocol data processing methods and blocking rules in the Linux system of the substation, the false issuance of remote control systems is automatically blocked, and the problems of low efficiency and security risks of remote control locking in the substation are solved, and efficient and secure remote control permission locking is achieved.

CN120390044APending Publication Date: 2025-07-29CYG SUNRI CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510546657.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

In substations, manual remote control locking work efficiency is low and there is a safety risk. Especially in substations with large scale or large number of interval units, it is difficult to effectively block the remote control system's false issuance or failure instructions, resulting in the operation interval equipment being incorrectly remotely controlled.

Method used

Using a multi-protocol-based data processing method, different blocking rules are configured in the remote motor/monitoring background of the Linux system. By obtaining the message data of the remote control system and filtering out messages containing specific control instructions according to preset filtering rules, and using the iptables tool to block these instructions, the remote control permissions are automatically locked locally.

Benefits of technology

It improves the working efficiency of remote control operation of substations, reduces safety risks, ensures the stable operation of secondary equipment, and reduces manual intervention and operation complexity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120390044A_ABST
    Figure CN120390044A_ABST
Patent Text Reader

Abstract

The invention is suitable for the technical field of substation automation of a power system, and provides a multi-protocol-based data processing method, terminal equipment and a storage medium, and the method comprises the steps: obtaining first message data which is a communication instruction sent to target equipment by a remote control system; filtering out second message data from the first message data according to a preset filtering rule; wherein the second message data is message data, in which the first message data contains a first control instruction, and the first control instruction is used for indicating the target equipment to execute an operation action; and carrying out blocking processing on the second message. According to the method, the control instruction sent by the remote control system can be blocked, and the remote control authority of the operation interval equipment is automatically locked locally, so that the working efficiency is effectively improved, and the safety risk is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the technical field of substation automation in the power system, and particularly relates to a data processing method, a terminal device, and a storage medium based on multiple protocols. Background Art

[0002] The reconstruction, expansion, and maintenance of operating substations are common tasks in the power grid. Before a remote control test, to ensure work safety and prevent mis-remote control of equipment in the operating interval due to misissued commands or failures in the remote control system, the remote control authority of the equipment in the operating interval needs to be locked locally.

[0003] In the related art, the remote control locking work is manually completed by operation and maintenance personnel. For example, in the case of configuring a hard pressure plate at the remote control outlet, the disconnection and connection of the control circuit are achieved by the withdrawal and insertion operations of the pressure plate. For the case where no hard pressure plate is configured, the remote control authority of the equipment in the operating interval is locked locally by switching the control mode of the control component. For substations with a large scale or a large number of interval units, the above manual operations have a heavy workload, low work efficiency, and there are safety risks. Summary of the Invention

[0004] Embodiments of this application provide a data processing method, a terminal device, and a storage medium based on multiple protocols, which can block control instructions sent by a remote control system, automatically lock the remote control authority of equipment in the operating interval locally, effectively improve work efficiency, and reduce safety risks.

[0005] In a first aspect, embodiments of this application provide a data processing method, including:

[0006] Obtain first message data, where the first message data is a remote operation instruction sent by a remote control system to a target device;

[0007] Filter out second message data from the first message data according to a preset filtering rule, and perform a blocking process on the second message; where the second message data is the message data in the first message data that contains a first control instruction.

[0008] In the embodiment of the present application, in a remote control system, a control end sends operation instructions to a target device, and these instructions are transmitted in the form of messages. Collect the message data sent from the remote control system to the target device, and screen the first message data according to some pre-set filtering rules to find the messages containing a specific "first control instruction". The first control instruction is a specific operation instruction that needs to be intercepted, and the corresponding message data is "second message data". Screen multiple second message data from the first message data. Once the second message data is found, the system will immediately take measures to prevent these messages from continuing to be transmitted to the target device, avoiding the target device from executing operation instructions that may bring risks. By screening the remote operation instructions through the pre-set filtering rules and intercepting the second message data containing the specific first control instruction, the control instructions sent by the remote control system can be blocked during special maintenance tasks of the power grid, and the remote control permission of the target device can be automatically locked locally, effectively improving the work efficiency and reducing the safety risk.

[0009] In a possible implementation manner of the first aspect, the filtering rules include a first rule and a second rule, and the method further includes:

[0010] If the communication protocol corresponding to the target device is the first communication protocol, match the first template corresponding to the first communication protocol from multiple pre-set protocol templates, and generate a first rule according to the first template;

[0011] If the communication protocol corresponding to the target device is the second communication protocol, match the second template corresponding to the second communication protocol from multiple pre-set protocol templates, and generate a second rule according to the second template.

[0012] In the embodiment of the present application, the pre-set protocol templates are carefully designed and tested, and can accurately reflect the characteristics and requirements of the corresponding communication protocol. By matching the templates to generate rules, the omissions and errors that may occur when manually designing rules can be avoided, ensuring the accuracy of the rules.

[0013] In a possible implementation manner of the first aspect, filtering out the second message data from the first message data according to the pre-set filtering rules includes:

[0014] If the first message data conforms to the first communication protocol, filter out the first key information from the first message data according to the first rule, and determine the message data corresponding to the filtered first key information as the second message data; wherein, the first key information is the string information corresponding to the first control instruction;

[0015] If the first message data conforms to the second communication protocol, determine a preset position from the first message data. If the second key information corresponding to the preset position is the string information corresponding to the first control instruction, determine the message data corresponding to the preset position as the second message data.

[0016] In the embodiments of the present application, the method of processing according to different protocols respectively avoids the misjudgment or missed judgment situations that may occur when using a single rule to process all messages, and can improve the accuracy of obtaining key information, providing reliable data support for subsequent processing and decision-making.

[0017] In a possible implementation manner of the first aspect, the method further includes:

[0018] Obtain filtering rules at preset intervals;

[0019] Parse the filtering rules to determine the first attribute information included in the filtering rules;

[0020] Monitor the security management status of the target device according to the first attribute information;

[0021] If there is a risk in the security management status of the target device, reset the filtering rules.

[0022] In the embodiments of the present application, by obtaining filtering rules at preset intervals and parsing the filtering rules to determine the first attribute information included therein (such as the type of the rule, the applicable scope, the matching conditions, etc.), and monitoring the security management status of the target device according to these attribute information. This monitoring method based on attribute information has high accuracy and can deeply understand the operation of the filtering rules and the security protection status of the target device.

[0023] In a possible implementation manner of the first aspect,

[0024] Monitoring the security management status of the target device according to the first attribute information includes:

[0025] Judge whether the first attribute information conforms to the attributes corresponding to the target device;

[0026] If the first attribute information does not conform to the attributes corresponding to the target device, determine that there is a risk in the security management status of the target device.

[0027] In the embodiments of the present application, by judging whether the first attribute information (parsed from the filtering rules, which may include relevant attributes such as the applicable scope, conditions, operations, etc. of the rule) conforms to the attributes corresponding to the target device (such as the security configuration of the device itself, the rule attributes allowed for normal operation, etc.), potential security problems can be accurately discovered.

[0028] In a possible implementation of the first aspect, the method further includes:

[0029] Obtaining first log information in real time; the first log information includes events that occur during the process of transmitting first packet data;

[0030] Matching second log information corresponding to third key information from the first log information according to a preset expression; wherein, the third key information is identification information corresponding to a blocking event, and the blocking event is used to block second packet data;

[0031] Classifying the blocking event according to the second log information.

[0032] In the embodiments of the present application, by using a preset expression to match second log information corresponding to third key information (identification information corresponding to a blocking event) from the first log information, accurate positioning of key information is achieved, and classifying the blocking event according to the second log information helps to more deeply understand the nature and characteristics of the blocking event. Different types of blocking events may have different causes and impacts, and through classification, they can be systematically analyzed and studied.

[0033] In a possible implementation of the first aspect, classifying the blocking event according to the second log information includes:

[0034] Obtaining second attribute information corresponding to the blocking event in the second log information;

[0035] If the second attribute information matches the first rule, determining the blocking event as a first type of event;

[0036] If the second attribute information matches the second rule, determining the blocking event as a second type of event.

[0037] In the embodiments of the present application, by obtaining second attribute information corresponding to the blocking event in the second log information (such as the time when the blocking event occurs, the source IP, destination IP, protocol used, etc.), the detailed characteristics of the blocking event can be deeply understood. After classifying the blocking event, the corresponding response strategy can be quickly determined according to the category of the event.

[0038] In a possible implementation of the first aspect, the method further includes:

[0039] After monitoring that the user selects multiple target devices on the user interface, obtaining a third communication protocol corresponding to each target device;

[0040] For each target device, if the third communication protocol between the remote control system and the target device is a first communication protocol or a second communication protocol, generating a third rule corresponding to the third communication protocol between the remote control system and the target device;

[0041] Generate a security component according to the third rules corresponding to multiple target devices respectively;

[0042] Obtain the first packet data through the security component and filter out the second packet data from the first packet data according to the preset filtering rules.

[0043] In the embodiments of the present application, the user can select multiple target devices at one time on the user interface, and the system will automatically process these devices, including obtaining protocol information, generating rules, and security components, etc. This centralized management method reduces manual intervention and operation complexity, and improves the efficiency of device management.

[0044] In a second aspect, an embodiment of the present application provides a terminal device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the data processing method according to any one of the above first aspects.

[0045] In a third aspect, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the data processing method according to any one of the above first aspects.

[0046] In a fourth aspect, an embodiment of the present application provides a computer program product. When the computer program product runs on a terminal device, it causes the terminal device to execute the data processing method according to any one of the above first aspects.

[0047] It can be understood that the beneficial effects of the above second aspect to the fourth aspect can refer to the relevant descriptions in the above first aspect, and will not be repeated here. Description of the Drawings

[0048] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0049] Figure 1 is a flowchart of the data processing method provided by the embodiment of the present application;

[0050] Figure 2 is a flowchart of setting the filtering rules provided by the embodiment of the present application;

[0051] Figure 3 is a structural diagram of the filtering rule deployment provided by the embodiment of the present application;

[0052] Figure 4 It is a schematic flowchart of filtering message data provided by an embodiment of the present application;

[0053] Figure 5 It is a schematic structural diagram of controlling message blocking provided by an embodiment of the present application;

[0054] Figure 6 It is a schematic flowchart of monitoring the security management status of a device provided by an embodiment of the present application;

[0055] Figure 7 It is a schematic structural diagram of monitoring the security management status of a device provided by an embodiment of the present application;

[0056] Figure 8 It is a schematic flowchart of obtaining a blocking event provided by an embodiment of the present application;

[0057] Figure 9 It is a schematic flowchart of classifying a blocking event provided by an embodiment of the present application;

[0058] Figure 10 It is a schematic structural diagram of classifying a blocking event provided by an embodiment of the present application;

[0059] Figure 11 It is a schematic structural diagram of a terminal device provided by an embodiment of the present application. Detailed implementation manners

[0060] In the following description, for the purpose of illustration rather than limitation, specific details such as specific system architectures, technologies, etc. are presented to thoroughly understand the embodiments of the present application. However, those skilled in the art should understand that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present application.

[0061] It should be understood that when used in the specification and appended claims of the present application, the term "comprising" indicates the presence of the described features, wholes, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.

[0062] It should also be understood that the term "and / or" as used in the specification and appended claims of the present application refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.

[0063] As used in the specification of this application and the appended claims, the term "if" may be construed, depending on the context, as "when", or "once", or "in response to determining", or "in response to detecting". Similarly, the phrase "if determined" or "if [the described condition or event] is detected" may be construed, depending on the context, to mean "once determined", or "in response to determining", or "once [the described condition or event] is detected", or "in response to detecting [the described condition or event]".

[0064] In addition, in the description of the specification of this application and the appended claims, the terms "first", "second", "third", etc. are used only for distinguishing descriptions and cannot be construed as indicating or implying relative importance.

[0065] Reference to "one embodiment" or "some embodiments" or the like described in the specification of this application means that a specific feature, structure, or characteristic described in connection with that embodiment is included in one or more embodiments of this application. Thus, statements such as "in one embodiment", "in some embodiments", "in other some embodiments", "in still other embodiments", etc. that appear in different places in this specification do not necessarily all refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in another way.

[0066] The renovation, expansion, and maintenance of operating substations are common tasks in the power grid. Before remote control tests, to ensure work safety and prevent mis-remote control of equipment in the operating interval due to misissued commands or failures in the remote control system, it is necessary to lock the remote control permission of the equipment in the operating interval locally.

[0067] In related technologies, the remote control locking work is manually completed by operation and maintenance personnel. For example, in the case of configuring a hard pressure plate at the remote control outlet, the disconnection and connection of the control loop are achieved by the withdrawal and insertion operations of the pressure plate. For the case where no hard pressure plate is configured, the remote control permission of the equipment in the operating interval is locked locally by switching the control mode of the control component. For substations with a large scale or a large number of interval units, the above manual operations have a heavy workload, low work efficiency, and there are safety risks.

[0068] To solve the problems existing in related technologies, the embodiments of this application provide a data processing method based on multiple protocols. In this application, in the remote terminal unit / monitoring background of the Linux system, different blocking rules are configured for different communication protocols. The blocking rules are used to block the messages containing specific messages to achieve the blocking of control commands. In the above way, the identification and blocking of control commands in a multi-communication protocol environment are realized.

[0069] Among them, in the substation automation system, the Linux system is often applied to remote terminal units (RTUs) and monitoring background devices due to its stability, open source nature, and powerful network processing capabilities. The RTU is responsible for collecting data of various devices in the substation and communicating with remote control systems; the monitoring background provides an interactive interface for operation and maintenance personnel to monitor and control substation devices in real time. These two work together and become a key link to ensure the stable operation of the substation. In the technical solution of this patent, they serve as the core platform and undertake important tasks such as data processing, instruction transmission, and device status monitoring.

[0070] See Figure 1 , which is a schematic flowchart of the data processing method provided by the embodiments of this application. By way of example and not limitation, the method may include the following steps:

[0071] S101, obtain first message data, where the first message data is a communication instruction sent by a remote control system to a target device.

[0072] In the embodiments of this application, the target device is equivalent to secondary equipment in the power system. Among them, secondary equipment is equipment in the power system used for control, protection, measurement, monitoring, and communication, and complements the primary equipment directly involved in the production, transmission, and distribution of electric energy. In the operation and management of substations, precise control and effective protection of secondary equipment are crucial. The communication instructions sent by the remote control system target the secondary equipment and aim to achieve remote operation and management of it. However, during the renovation, expansion, and maintenance of substations, to prevent incorrect remote control, these instructions need to be intercepted and processed at the RTU / monitoring background to ensure that the secondary equipment operates in a safe state.

[0073] "First message data" refers to the communication instructions sent by the remote control system to the secondary equipment. These instructions contain commands for operating the secondary equipment (such as circuit breakers, disconnectors, etc.), such as opening / closing instructions, parameter adjustment instructions, etc. During actual operation, to ensure the accurate transmission of these instructions and at the same time ensure system safety, they need to be obtained and processed at the RTU / monitoring background of the Linux system. By obtaining these message data, the system can grasp the operation intention of the remote control system in real time and provide a data basis for subsequent instruction blocking and device control.

[0074] When obtaining the first message data at the RTU / monitoring background of the Linux system, the data packets transmitted on the network interface can be obtained by using a network packet capture tool, and these data packets can be filtered and analyzed to extract the first message data we need. Or the network communication data can be obtained by using the APIs or interfaces provided by some RTU / monitoring background systems. The specific method for obtaining the first message data is not specifically limited here.

[0075] S102. Filter out the second message data from the first message data according to a preset filtering rule. The second message data is the message data in the first message data that contains a first control instruction, and the first control instruction is used to instruct a target device to perform an operation action.

[0076] In an embodiment of the present application, in a remote terminal unit / monitoring background of a Linux system, a series of filtering rules are set in advance according to the security requirements for the operation of substation equipment, communication protocol specifications, and past operation and maintenance experience. These rules are the core basis of the entire data screening mechanism, which defines which data needs to be focused on and processed.

[0077] As a set of communication instructions sent by a remote control system to secondary equipment, the first message data contains various instruction information. Some of these instructions are normal device operation instructions, and some may have potential risks due to system failures, mistransmissions, etc. Through the preset filtering rules, the system will check and match the first message data one by one. In this process, the system will read each message data and analyze whether its content meets the requirements of the filtering rules.

[0078] The second message data filtered out after filtering is the message data in the first message data that contains a first control instruction. These first control instructions have clear operation directions and are used to instruct secondary equipment to perform operation actions such as switching on and off, adjusting parameters, etc. In the actual operation of a substation, the switching on and off operation is directly related to the on and off of the circuit. If it is executed incorrectly, it may cause power outages or equipment damage. Therefore, accurately identifying and processing this second message data containing the first control instruction is a key link to ensure the safe and stable operation of secondary equipment.

[0079] In one embodiment, see Figure 2 ..., which is a schematic flowchart of setting a filtering rule provided by an embodiment of the present application. As shown in Figure 2 shown, the filtering rule in S102 includes a first rule and a second rule. The method further includes:

[0080] S201. If the communication protocol corresponding to the target device is a first communication protocol, match the first template corresponding to the first communication protocol from multiple preset protocol templates, and generate the first rule according to the first template.

[0081] In the embodiments of the present application, the filtering rule plays a key role in ensuring the communication security of the power system. It can screen out the message data containing specific control instructions to prevent misoperations or malicious instructions from damaging the equipment. The filtering rule here includes a first rule, which corresponds to a first communication protocol. Among them, the first communication protocol can be the IEC61850 protocol, which is an important communication standard in the power system and is used to achieve reliable data transmission between secondary devices such as substation relay protection devices (target devices) and monitoring systems (remote terminal units / monitoring backends of the Linux system).

[0082] If the protocol information corresponding to the secondary device, i.e., the target device, is the IEC61850 protocol (i.e., the first communication protocol), then the template related to the IEC61850 protocol (the first template) can be found from multiple preset protocol templates (preset protocol template library). These templates usually have set a basic rule framework according to the protocol characteristics, such as applicable matching algorithms, default matching ranges (such as the entire message or specific fields), etc. The template library may already contain some examples of common control reference keywords, but in actual applications, it is necessary to further clarify according to specific requirements. On the one hand, referring to the keyword examples in the template library and based on an in-depth understanding of the IEC61850 protocol, more representative control reference keywords are mined from the protocol specifications; on the other hand, by analyzing the historical message data in the actual operating environment, the strings frequently associated with control operations are found as supplementary keywords.

[0083] According to the determined control reference keywords, the relevant parameters in the template are adjusted and filled. If the string matching method (such as exact match, contains match, regular expression match, etc.) is specified in the template, the method matching the keyword characteristics is selected; the control reference keywords are accurately filled into the specified positions in the template. If the template also contains a setting for the matching range, such as matching from the Xth byte to the Yth byte of the message, the range is determined or adjusted according to the actual situation. For the IEC61850 protocol, it is generally set to full-text match. The adjusted information of each part of the template is integrated to form a complete message string recognition rule, and then the first rule in the filtering rule is obtained by integrating the IP corresponding to the target device with the string recognition rule. For example, the application keyword included in the first rule is "|24344F24|", and the matching range configuration is full text.

[0084] S202. If the communication protocol corresponding to the target device is the second communication protocol, then the second template corresponding to the second communication protocol is matched from multiple preset protocol templates, and the second rule is generated according to the second template.

[0085] In the embodiments of the present application, the filtering rule includes a second rule, which corresponds to a second communication protocol. Among them, the first communication protocol may be the IEC60870-5-103 protocol, which is an important communication standard in the power system and is used to achieve reliable data transmission between secondary devices such as substation relay protection devices (target devices) and monitoring systems (remote terminal units / monitoring background of the Linux system). The message of this protocol includes an Application Service Data Unit (ASDU), which contains multiple fields as key identifiers to convey information, and different fields have different meanings. For example, the type identifier distinguishes the information type, and the transmission cause indicates the purpose of data transmission. In the remote control scenario, a specific combination of key identifiers represents a control command message.

[0086] If the protocol information corresponding to the secondary device, i.e., the target device, is the IEC60870-5-103 protocol (i.e., the second communication protocol), then a template related to the IEC60870-5-103 protocol (the second template) can be searched from multiple preset protocol templates (preset protocol template library). The template should include a basic description of the ASDU structure of the application service, such as the approximate positions of each field, data types, etc., and the offset information for the control command identifier. Some templates may also provide the value range or examples of common control command identifiers.

[0087] According to the offset information in the template, determine the specific byte offset from the start position of the ASDU to the control command identifier field. Combining the control command identifier examples provided by the template and the actual application scenario, clarify the specific value or value range of the control command identifier to be detected. For some complex control logics, multiple identifiers or identifier combinations may be involved, and it is necessary to sort them out according to the template guidance and actual situation. Based on the template and combined with the IP information corresponding to the target device, construct an ASDU parsing rule (i.e., the second rule). For example, the second rule stipulates that when the first byte is "|40|" or "|41|", or the first byte is "|0A|", the fifth byte is "|FE|", and the sixth byte is one of "|F8|", "|F9|", "|FA|", "|FB|", this message is a control command message. The message data can be filtered or screened according to the above ASDU parsing rule.

[0088] In the above method, the preset protocol template has been carefully designed and tested, and can accurately reflect the characteristics and requirements of the corresponding communication protocol. By matching the template to generate rules, it is possible to avoid omissions and errors that may occur when manually designing rules, and ensure the accuracy of the rules.

[0089] In one embodiment, before step S101, i.e., obtaining the first message data, it is necessary to perform initialization operations on the secondary device or the monitoring background, including:

[0090] After detecting that the user selects multiple target devices on the user interface, obtain the third communication protocol corresponding to each target device; for each target device, if the third communication protocol corresponding to the target device is the first communication protocol or the second communication protocol, generate a third rule corresponding to the third communication protocol between the remote control system and the target device; generate a security component according to the third rules corresponding to the multiple target devices respectively; obtain the first message data through the security component and filter out the second message data from the first message data according to a preset filtering rule.

[0091] In the embodiment of the present application, in a system, there is usually a user interface for the user to operate. The user can select multiple target devices on this interface according to their own needs. These target devices are multiple secondary devices in the power system. When the user completes the selection of the target devices, the system will, for each selected target device, obtain the corresponding third communication protocol. For each target device, the system will check whether the corresponding third communication protocol is the above-mentioned set first communication protocol (IEC61850 protocol) or the second communication protocol (IEC60870-5-103). If the third communication protocol corresponding to the target device is the first communication protocol or the second communication protocol, the system will generate a third rule corresponding to the third communication protocol between the remote control system and the target device.

[0092] The system will integrate the third rules corresponding to the multiple target devices respectively, comprehensively consider the requirements and characteristics of each rule, and generate a security component based on the integrated rules. This security component can be regarded as a software module or a hardware device with specific security functions. It can process and control communication data according to preset rules to ensure the security of data during transmission. The security component will obtain the first message data from the network and filter the first message data according to the preset filtering rule.

[0093] See Figure 3 , which is a schematic structural diagram of the deployment of the filtering rule provided by the embodiment of the present application. As Figure 3 shown, the steps include:

[0094] ① Select a maintenance work surface and determine the target device

[0095] During initialization, the user needs to select a suitable maintenance work surface according to the specific maintenance object and task, which is equivalent to selecting the interval to be maintained. Each interval includes multiple secondary devices (target devices).

[0096] ② Determine whether the target device constructs a filtering rule

[0097] Determine whether the filtering rules corresponding to the target device are deployed. If there are secondary devices for which the filtering rules have not been constructed, execute step ③; otherwise, execute step ⑦.

[0098] ③ Determine whether the communication protocol of the target device conforms to the preset communication protocol

[0099] The preset communication protocol includes the preset first communication protocol (IEC61850 protocol) and the second communication protocol (IEC60870-5-103). Determine whether the communication protocol corresponding to the target device is the first communication protocol or the second communication protocol. If so, execute step ④; otherwise, execute step ②.

[0100] ④ Obtain the blocking template according to the communication protocol

[0101] Obtain the corresponding protocol template from the preset protocol template library according to the communication protocol corresponding to the target device. The protocol template usually has a basic rule framework set according to the protocol characteristics.

[0102] ⑤ Construct the filtering rules through the device IP

[0103] Write the IP corresponding to the device (target device) into the protocol template corresponding to the target device, and the process rules corresponding to the target device can be constructed.

[0104] ⑥ Append the filtering rules to the security component

[0105] Append the process rules corresponding to each target device to the security component. This component is used to send to the monitoring system for deploying the filtering rules for the target device, and is used to monitor the first packet data and filter the first packet data.

[0106] ⑦ Download the security component to the remote control unit / monitoring background and execute

[0107] ⑧ End

[0108] In the above method, the user can select multiple target devices at one time on the user interface, and the system will automatically process these devices, including obtaining protocol information, generating rules, and security components, etc. This centralized management method reduces manual intervention and the complexity of operations, and improves the efficiency of device management.

[0109] In one embodiment, refer to Figure 4 , which is a schematic flow diagram of filtering packet data provided by the embodiment of the present application. As Figure 4 shown, step S102 includes:

[0110] S301, if the first message data conforms to the first communication protocol, filter out the first key information from the first message data according to the first rule, and determine the message data corresponding to the filtered first key information as the second message data; wherein, the first key information is the string information corresponding to the first control instruction.

[0111] In the embodiment of the present application, after obtaining the message data (the first message data) sent by the remote control system to the target device through the remote terminal / monitoring background of the Linux system, first, the system will analyze the received first message data. When the first message data conforms to the first communication protocol, the system will filter it according to the first rule. Specifically, it is to check whether there is string information corresponding to the first control instruction in the message. This can be achieved through a string search algorithm. Once the matching string information is found, it is determined as the first key information. After filtering out the first key information, the system will extract the part of the message data containing these key information as the second message data.

[0112] For example, the application keyword included in the first rule in the above example is "|24344F24|", and the matching range is configured as the full text. Among them, the application keyword "|24344F24|" is the first key information. By performing a full-text match on the first message data for strings containing |24344F24|, all the message data corresponding to the strings containing |24344F24| that are matched are determined as the second message data.

[0113] S302, if the first message data conforms to the second communication protocol, determine the preset position from the first message data. If the second key information corresponding to the preset position is the string information corresponding to the first control instruction, then determine the message data corresponding to the preset position as the second message data.

[0114] In the embodiment of the present application, when the first message data conforms to the second communication protocol, the system will filter it according to the second rule. Specifically, determine the preset position according to the protocol specification (the second rule). This may require parsing the header information of the message, referring to the description of the field position in the protocol document, etc., extracting the second key information from the preset position, and comparing it with the string information corresponding to the first control instruction. If the two are the same, it indicates that the message contains the required control instruction. If the second key information matches the string information corresponding to the first control instruction, then determine the message data corresponding to the preset position as the second message data, and this part of the data will be further processed.

[0115] In the above example, according to the second rule, when the first byte is "|40|" or "|41|", or when the first byte is "|0A|", the fifth byte is "|FE|", and the sixth byte is one of "|F8|", "|F9|", "|FA|", "|FB|", this message is a control command message. Among them, the preset positions include the first byte, the fifth byte, and the sixth byte. When matching the first message data according to the second rule, first extract the string information (the second key information) corresponding to the first byte, the fifth byte, and the sixth byte in the first message data. If the string information corresponding to each of the first byte, the fifth byte, and the sixth byte conforms to the above second rule, the message data corresponding to the first byte, the fifth byte, and the sixth byte is determined as the second message data.

[0116] In the above method, the method of processing according to different protocols respectively avoids the misjudgment or missed judgment situations that may occur when using a single rule to process all messages, can improve the accuracy of obtaining key information, and provides reliable data support for subsequent processing and decision-making.

[0117] S103, perform blocking processing on the second message.

[0118] In the embodiment of the present application, after obtaining the message data (the second message data) containing instructions in the first message data, corresponding blocking strategies need to be adopted to prevent the second message from continuing to be transmitted in the network and avoid it from reaching the target device or destination.

[0119] Specifically, the first rule and the second rule in the filtering rules are generated based on the iptables (firewall) tool. When configuring the first rule and the second rule, add the operation of discarding the filtered second message data, that is, blocking its continued transmission. The filtering rules (the first rule and the second rule) added in the iptables firewall of the Linux system include. If the source IP address of the second message data is the IP of a certain known target device, a command similar to iptables -A OUTPUT -s target device IP address -j DROP can be used to discard it.

[0120] See Figure 5 , which is a schematic structural diagram of the control message blocking provided by the embodiment of the present application. As Figure 5 shown, its steps include:

[0121] ① The remote terminal / monitoring background obtains the message

[0122] Monitor the message data (i.e., the first message data) sent by the remote control system to the secondary device through the remote terminal / monitoring background, and obtain the first message data through the corresponding message capture method when detecting the transmission of message data.

[0123] ② Determine whether the target device address matches the address of the blocked device

[0124] After receiving the first packet data, analyze it to determine whether the IP of the blocked device in the packet data is the IP corresponding to the target device. If it is, proceed to step ③; if not, release the packet data.

[0125] ③ Load the String module engine

[0126] The String module engine is a program module with string matching capabilities. Loading it means loading this module into the system's operating environment, enabling the system to utilize the string matching capabilities provided by this module to process data such as network packets and log information. In this application, the program module with string matching capabilities is the module component corresponding to the filtering rule.

[0127] ④ Determine whether the packet contains the characteristic string

[0128] According to the loaded filtering rule module, determine whether the first packet data contains the characteristic string (the first key information or the second key information). If it contains, execute step ⑤; if not, release the packet data.

[0129] ⑤ Write the packet data containing the characteristic string into the system log.

[0130] ⑥ Quietly discard the packet without sending a response.

[0131] ⑦ End

[0132] In the above method, collect the packet data sent from the remote control system to the target device, and screen the first packet data according to some preset filtering rules to find the packets containing the specific "first control instruction". The first control instruction is a specific operation instruction that needs to be intercepted, and the corresponding packet data is the "second packet data". Screen multiple second packet data from the first packet data. Once the second packet data is found, the system will immediately take measures to prevent these packets from continuing to be transmitted to the target device, avoiding the target device from executing the operation instructions that may bring risks. By screening the remote operation instructions through the preset filtering rules and intercepting the second packet data containing the specific first control instruction, it is possible to block the control instructions sent by the remote control system during special maintenance tasks of the power grid, automatically lock the remote control authority of the target device to the local, effectively improving work efficiency and reducing security risks.

[0133] In one embodiment, refer to Figure 6 , which is the schematic flow diagram of monitoring the security management status of the device provided by the embodiment of the present application. As Figure 6 shown, the method further includes:

[0134] S401. Obtain the filtering rules at preset intervals.

[0135] In the embodiments of the present application, in a power system, to ensure the safe operation of substation equipment, it is crucial to build an automated inspection process for blocking strategies. The iptables can be used to periodically obtain the currently enabled blocking rule set (i.e., the filtering rule set) of the remote terminal unit / monitoring background of the Linux system.

[0136] Among them, iptables is a powerful firewall tool in the Linux system that can filter and control network data packets. Using its command-line interface, the currently effective blocking rule set in the system can be obtained. In the automated inspection process, a fixed period is set, such as performing the acquisition operation every 5 minutes or 15 minutes. By writing a script and using the iptables -L command to list all rule tables and saving the results, these rules are the key lines of defense to ensure the safety of secondary equipment and prevent incorrect remote control commands.

[0137] S402. Analyze the filtering rules to determine the first attribute information included in the filtering rules.

[0138] In the embodiments of the present application, the obtained blocking rule set contains numerous rules, and each rule has its specific attributes. The key attributes (the first attribute information) include the matching conditions of the rules (such as source IP address, destination IP address, port number, protocol type, etc.), execution actions (such as DROP, ACCEPT, REJECT, etc.), and specific identifiers related to secondary equipment (target equipment) (such as control keywords for different protocols, etc.).

[0139] By analyzing these attributes, the functions and influence scopes of each rule can be deeply understood. A parsing program is written using a text parsing tool or programming language (such as C / C++) to extract these key attributes from the output result of the iptables -L command and organize them into a structured data format for subsequent analysis.

[0140] S403. Monitor the security management status of the target device according to the first attribute information.

[0141] In the embodiments of the present application, based on the extracted key attributes of the rules, the management status of the security measures of secondary equipment (i.e., the security management status) can be inferred. For example, whether the secondary equipment can receive control commands from the remote control system. If it can, it is determined that there may be problems with the management status of the security measures of the secondary equipment and further analysis or deployment of filtering rules is required.

[0142] In one embodiment, step S403 includes:

[0143] Determine whether the first attribute information conforms to the attributes corresponding to the target device; if the first attribute information does not conform to the attributes corresponding to the target device, it is determined that there is a risk in the security management status of the target device.

[0144] In the embodiments of the present application, if there is an execution action of DROP (discard) included in the attribute information of a certain secondary device, and the destination IP address in the rule corresponds to this device, it means that the remote control instruction of this device is blocked and is in a secure security management state; if there is no corresponding blocking rule or the rule configuration is incorrect, there may be potential security hazards. Summarize and display the security management status of the secondary device and present it to the operation and maintenance personnel in a visual manner, such as through the indicator lights or charts on the monitoring interface, so that the operation and maintenance personnel can quickly understand the security management situation of the secondary devices in the entire substation, discover potential risks in a timely manner and take measures.

[0145] In the above method, by determining whether the first attribute information (parsed from the filtering rule, which may include relevant attributes such as the applicable scope, conditions, operations, etc. of the rule) conforms to the attributes corresponding to the target device (such as the security configuration of the device itself, the rule attributes allowed for normal operation, etc.), potential security problems can be accurately discovered.

[0146] S404, if there is a risk in the security management status of the target device, reset the filtering rule.

[0147] In the embodiments of the present application, in the case where there is a risk in the security management of the secondary device, the adjustment direction of the filtering rule can be determined according to the specific situation of the risk. If it is the attack risk of an external illegal IP address, then the new filtering rule should focus on blocking the network traffic from these risk sources; if the risk stems from the abnormal communication behavior of internal devices, it is necessary to refine and restrict the access rules for the internal network.

[0148] See Figure 7 is a schematic structural diagram for monitoring the security management status of a device provided by an embodiment of the present application. As Figure 7 shown, its steps include:

[0149] ① Obtain the filtering rule list in the remote terminal unit / monitoring background

[0150] ② Determine whether the rule list contains an unparsed rule list

[0151] If it contains, execute step ③; if it does not contain, execute step ⑤.

[0152] ③ Parse the filtering rule and extract the attribute information

[0153] Parse each filtering rule through regular expressions or the like to parse out the attribute information corresponding to the filtering rule (the first attribute information), including the blocked IP (the IP of the target device) and the blocked keyword (the first key information or the second key information).

[0154] ④ Determine the security management status of the target device

[0155] Based on the attribute information in the parsed filtering rules, it can be determined whether the filtering rules are correctly deployed for the target device to determine whether there are risks in the security management device of the target.

[0156] ⑤ End

[0157] In the above method, by obtaining the filtering rules at preset intervals and parsing the filtering rules, the first attribute information included therein (such as the type, scope of application, matching conditions, etc. of the rules) is determined, and the security management status of the target device is monitored based on this attribute information. This monitoring method based on attribute information has high accuracy and can deeply understand the operation of the filtering rules and the security protection status of the target device.

[0158] In one embodiment, refer to Figure 8 , which is a schematic flowchart of the process for obtaining blocking events provided by an embodiment of the present application. As Figure 8 shown, the method further includes:

[0159] S501, obtain the first log information in real time; the first log information includes events that occur during the process of transmitting the first packet data.

[0160] In the embodiment of the present application, in order to comprehensively master the blocking policy part situation of secondary devices and the specific events of blocked packets, the kernel log of the Linux system can be monitored, and the kernel log can be analyzed to comprehensively understand the deployment situation of the blocking policy for secondary devices.

[0161] Among them, the Linux system kernel log is the first log information, which records information in many aspects such as the Linux system kernel, application programs, and network activities. These logs contain the key data corresponding to various events that occur during the operation of the system, providing the original data source for subsequent analysis.

[0162] Specifically, the first log information can be subscribed through the syslog daemon process. Syslog is a standard tool in the Linux system for recording system messages and events. The syslog daemon process plays an important role. It is responsible for subscribing to kernel-level logs and collecting information from multiple aspects such as the system kernel, application programs, and network activities.

[0163] S502. Match the second log information corresponding to the third key information from the first log information; wherein, the third key information is the identification information corresponding to the blocking event, and the blocking event is used to block the second packet data.

[0164] In the embodiment of the present application, in order to master the situation of the blocking strategy part of the secondary device and the specific events of the blocked packets, the logs related to the blocking event can be filtered out from the first log information.

[0165] In order to accurately filter out iptables blocking events from a large amount of log information, the engine can use the method of matching the log prefix keywords with a regular expression (preset expression). In the Linux system, the logs of iptables blocking events usually have a specific format and prefix keywords. For example, it may start with specific strings such as "iptables:DROP" or "iptables:REJECT". By writing a suitable regular expression, such as "^iptables:DROP.*", the log entries related to iptables blocking can be quickly and accurately identified. This method can efficiently extract the required key information from the massive logs and improve the parsing efficiency.

[0166] S503. Classify the blocking event according to the second log information.

[0167] In the embodiment of the present application, in order to deeply analyze iptables blocking events, the engine constructs a data extraction model. This model is responsible for parsing key data from the captured log entries, including information such as the destination IP of the packet, the protocol, and the matching rule entries. In the log entries, this information usually exists in a specific format. For example, "DROP tcp 192.168.1.10:80->192.168.1.20:8080". Through the data extraction model, important information such as the destination IP (192.168.1.20), the protocol (tcp), and the matching rule entry (DROP) can be accurately extracted.

[0168] The data extraction model uses techniques such as string parsing and field splitting to accurately parse the destination IP, protocol, and matching rule entries from the log entries according to the format specification of the log (second log information). In this way, the original log data is transformed into structured and valuable information, which is convenient for subsequent analysis and processing. According to the parsed information, the engine classifies and archives the iptables blocking events.

[0169] In the above method, the second log information corresponding to the third key information (identification information corresponding to the blocking event) is matched from the first log information by using a preset expression, realizing the accurate positioning of the key information. Classifying the blocking event according to the second log information helps to understand the nature and characteristics of the blocking event more deeply. Different types of blocking events may have different causes and impacts, and through classification, they can be systematically analyzed and studied.

[0170] In one embodiment, referring to Figure 9 , it is a schematic flowchart of classifying a blocking event provided by an embodiment of the present application. As Figure 9 shown, step S503 includes:

[0171] S601, obtaining second attribute information corresponding to the blocking event in the second log information.

[0172] In the embodiment of the present application, each blocking event will have relevant attribute descriptions in the log, and these attribute information are used to characterize the characteristics of the blocking event, such as the time when the blocking event occurs, the source IP address involved, the destination IP address, the protocol type used, the specific rules for blocking, etc. Extracting these attribute information related to the blocking event from the second log information is the process of obtaining the second attribute information.

[0173] S602, if the second attribute information matches the first rule, then determine the blocking event as a first type of event.

[0174] In the implementation of the present application, the obtained second attribute information is compared with the first rule. If certain attribute values or combinations of attribute values in the second attribute information exactly match the conditions set in the first rule, it is considered a match. When the second attribute information successfully matches the first rule, this blocking event is classified as a first type of event.

[0175] S603, if the second attribute information matches the second rule, then determine the blocking event as a second type of event.

[0176] In the embodiment of the present application, similar to the case of the first rule, when the second attribute information is compared with the second rule and it is found that the conditions set in the second rule are met, the blocking event is determined as a second type of event.

[0177] In the above method, by obtaining the second attribute information corresponding to the blocking event in the second log information (such as the time when the blocking event occurs, the source IP, destination IP, protocol used, etc.), the detailed characteristics of the blocking event can be deeply understood. After classifying the blocking event, the corresponding response strategy can be quickly determined according to the category of the event.

[0178] Referring to Figure 10, which is a schematic structural diagram for classifying blocking events provided by an embodiment of the present application. As Figure 10 shown, the steps are as follows:

[0179] ① Read the kernel logs in the remote terminal / monitoring background in real time

[0180] Read the kernel logs in the system in real time, which are the first log information, and subscribe to the kernel logs of the system through the syslog daemon to analyze them.

[0181] ② Determine whether new logs are generated

[0182] During the reading process, determine whether new logs are generated in the system. If new logs are generated, execute step ③; if no new logs are generated, continue to execute step ①.

[0183] ③ Parse the log prefix, source and destination IPs, and processing rules using regular expressions

[0184] Use regular expressions to match the log prefix keywords and analyze the process rules corresponding to the log prefix keywords. That is, the attribute information corresponding to the filtering rules includes source and destination IPs, etc.

[0185] ④ Determine whether the log prefix conforms to the preset prefix

[0186] Determine whether the log prefix keyword matched by the regular expression conforms to the preset prefix. Among them, the preset prefix is the prefix corresponding to the iptables blocking event. The logs of the iptables blocking event usually have a specific format and prefix keyword. Through the above method, the iptables blocking event can be accurately screened out from a large amount of log information.

[0187] ⑤ Record the blocking event logs according to the IP

[0188] After matching the preset prefix, record the corresponding log information (the second log information) according to the IP corresponding to the prefix, and classify and file the second log information. The classification can be based on the IP of the target device or the protocol type corresponding to the log. This is to facilitate subsequent tracing based on the classified and filed logs.

[0189] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0190] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the above division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of each functional unit and module are only for the convenience of mutual distinction and do not limit the protection scope of this application. The specific working process of the units and modules in the above system can refer to the corresponding process in the foregoing method embodiment and will not be elaborated herein.

[0191] Figure 11 It is a schematic structural diagram of the terminal device provided by the embodiment of the present application. As Figure 11 shown, the terminal device 11 of this embodiment includes: at least one processor 110 ( Figure 11 only one is shown in the figure), a processor, a memory 111, and a computer program 112 stored in the memory 111 and executable on at least one processor 110. When the processor 110 executes the computer program 112, it implements the steps in any of the foregoing data processing method embodiments.

[0192] The terminal device can be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The terminal device may include, but is not limited to, a processor and a memory. Those skilled in the art can understand that Figure 11 this is only an example of the terminal device 11 and does not constitute a limitation on the terminal device 11. It may include more or fewer components than shown in the figure, or combine some components, or different components. For example, it may also include input and output devices, network access devices, etc.

[0193] The so-called processor 110 may be a Central Processing Unit (CPU), and the processor 110 may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0194] In some embodiments, the memory 111 may be an internal storage unit of the terminal device 11, such as the hard disk or memory of the terminal device 11. In other embodiments, the memory 111 may also be an external storage device of the terminal device 11, such as a plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, Flash Card, etc. equipped on the terminal device 11. Further, the memory 111 may also include both the internal storage unit and the external storage device of the terminal device 11. The memory 111 is used to store an operating system, application programs, a Boot Loader, data, and other programs, such as the program code of a computer program. The memory 111 may also be used to temporarily store data that has been output or is to be output.

[0195] The embodiments of the present application also provide a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the steps in the above method embodiments can be implemented.

[0196] The embodiments of the present application provide a computer program product, and when the computer program product runs on a terminal device, the terminal device can implement the steps in the above method embodiments when executed.

[0197] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the processes in the above-described embodiment methods of this application, a computer program can be used to instruct relevant hardware to complete. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-described various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can at least include: any entity or device that can carry the computer program code to the device / terminal device, recording medium, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electrical carrier signal, telecommunication signal, and software distribution medium. For example, a USB flash drive, a mobile hard disk, a magnetic disk, or an optical disc, etc. In some jurisdictions, according to legislation and patent practice, the computer-readable medium cannot be an electrical carrier signal and a telecommunication signal.

[0198] In the above embodiments, the descriptions of the various embodiments have their own focuses. For the parts not detailed or recorded in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0199] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of this application.

[0200] In the embodiments provided in this application, it should be understood that the disclosed device / terminal device and method can be implemented in other ways. For example, the device / terminal device embodiments described above are merely illustrative. For example, the division of modules or units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be in an electrical, mechanical, or other form.

[0201] The unit described as a separation component may or may not be physically separated. The component displayed as a unit may or may not be a physical unit, that is, it may be located in one place or may be distributed across multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0202] The above embodiments are only used to illustrate the technical solutions of the present application, rather than limiting them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.

Claims

1. A data processing method, characterized in that, Including: Obtain first message data, where the first message data is a communication instruction sent by a remote control system to a target device; Filter out second message data from the first message data according to a preset filtering rule; wherein, the second message data is message data in the first message data that contains a first control instruction, and the first control instruction is used to instruct the target device to perform an operation action; Perform a blocking process on the second message.

2. The data processing method according to claim 1, wherein The filtering rule includes a first rule and a second rule, and the method further includes: If the communication protocol corresponding to the target device is a first communication protocol, match the first template corresponding to the first communication protocol from multiple preset protocol templates, and generate the first rule according to the first template; If the communication protocol corresponding to the target device is a second communication protocol, match the second template corresponding to the second communication protocol from multiple preset protocol templates, and generate the second rule according to the second template.

3. The data processing method according to claim 2, wherein The filtering out the second message data from the first message data according to the preset filtering rule includes: If the first message data conforms to the first communication protocol, filter out first key information from the first message data according to the first rule, and determine the message data corresponding to the filtered first key information as the second message data; wherein, the first key information is string information corresponding to the first control instruction; If the first message data conforms to the second communication protocol, determine a preset position in the first message data. If the second key information corresponding to the preset position is the string information corresponding to the first control instruction, determine the message data corresponding to the preset position as the second message data.

4. The data processing method according to claim 1, characterized in that The method further includes: Obtain the filtering rule at preset intervals; Parse the filtering rule to determine first attribute information included in the filtering rule; Monitor the security management status of the target device according to the first attribute information; If there is a risk in the security management status of the target device, reset the filtering rule.

5. The data processing method according to claim 4, wherein The monitoring the security management status of the target device according to the first attribute information includes: Judge whether the first attribute information conforms to the attribute corresponding to the target device; If the first attribute information does not conform to the attribute corresponding to the target device, determine that there is a risk in the security management status of the target device.

6. The data processing method according to claim 2, wherein The method further includes: Obtain first log information in real time; the first log information includes events that occurred during the transmission of the first message data; Match second log information corresponding to third key information from the first log information according to a preset expression; wherein, the third key information is identification information corresponding to a blocking event, and the blocking event is used to intercept the second message data; Classify the blocking event according to the second log information.

7. The data processing method according to claim 6, wherein The classifying the blocking event according to the second log information includes: Obtain second attribute information corresponding to the blocking event in the second log information; If the second attribute information matches the first rule, determine the blocking event as a first type of event; If the second attribute information matches the second rule, determine the blocking event as a second type of event.

8. The data processing method according to claim 2, characterized in that The method further includes: After monitoring that the user selects multiple target devices on the user interface, obtain the third communication protocol corresponding to each target device; For each target device, if the third communication protocol corresponding to the target device is the first communication protocol or the second communication protocol, generate a third rule corresponding to the third communication protocol between the remote control system and the target device; Generate a security component according to the third rules respectively corresponding to the multiple target devices; Obtain the first packet data through the security component and filter out the second packet data from the first packet data according to a preset filtering rule.

9. A terminal device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, the method according to any one of claims 1 to 7 is implemented.