Network security monitoring method and system for power grid metering

Through real-time monitoring and dynamic analysis of the power grid metering system, an adaptive security protection mechanism is built, which solves the one-way linear problem of security decision-making of the power grid metering system in a dynamic network threat environment, and realizes effective defense against complex network attacks and efficient operation of the system.

CN120454984APending Publication Date: 2025-08-08马越
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510635336.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-16
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

The existing power grid metering system lacks a dynamic regulation mechanism with real-time feedback in a dynamic network threat environment, resulting in the security decision-making process showing one-way linear characteristics and being unable to effectively respond to complex cyber attacks.

Method used

By monitoring the operating data of power nodes, dynamically analyzing abnormal traffic characteristics, adjusting network keys and communication parameters in real time, building an adaptive security protection mechanism, including key updates, communication optimization and equipment status adjustment, forming a "monitoring-evaluation-response" closed loop, and achieving efficient security protection for the power grid metering system.

Benefits of technology

It significantly improves the security protection level and operational reliability of the power grid metering system, can promptly detect key leakage risks, prevent tampering with metering data, reduce retransmission rate, extend the service time of the equipment, dynamically adjust load balancing, and resist new attacks such as quantum computing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120454984A_ABST
    Figure CN120454984A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of telecommunication, and particularly discloses a network security monitoring method and system for power grid metering, and the method comprises the steps: firstly monitoring the operation data of a power node in real time, combining with the dynamic analysis of abnormal flow characteristics, timely finding a key leakage risk, triggering a key updating mechanism, and effectively preventing the tampering of metering data; secondly, channel quality evaluation and encryption strength verification are carried out on communication parameters, a secret key distribution strategy is optimized through an adaptive algorithm, the retransmission rate is reduced, the communication efficiency is improved, novel attack means such as quantum computing can be resisted, and finally parameters such as hardware response delay are monitored in real time; according to the method, potential faults are pre-judged, load balancing is dynamically adjusted, the service life of equipment is prolonged, a'monitoring-evaluation-response 'closed loop is formed, and the safety protection level and operation reliability of a power grid metering system are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of electrical communication technology, and in particular to a network security monitoring method and system for power grid metering. Background Art

[0002] With the rapid development of smart grid and energy internet technologies, power grid metering systems, as the core infrastructure for power trading and load monitoring, are facing increasing requirements for real-time, accuracy, and security in data collection, transmission, and processing. However, power grid metering systems face severe network security challenges due to their own characteristics. Therefore, a security protection mechanism with autonomous immunity is provided for power grid metering systems through multi-dimensional threat perception, real-time abnormal decision-making, and dynamic defense response.

[0003] For example, the invention patent with announcement number CN115834159B announces a network security protection method for power grid informatization construction based on deep learning. By arranging the nodes of the power grid informatization system and converting them into attack paths, an attack map of the power grid informatization system is generated; the network information risk probability based on the attack map is obtained according to the attack map, and the network information risk probability based on the attack map is quantified to obtain a quantified information risk probability set based on the attack map; the quantified information risk probability set is analyzed through a transformer model to obtain the network attack type and the location of the attack node; according to the power grid topology, an active immune structure based on trusted computing technology is designed, and network security is protected by deploying trusted modules.

[0004] For example, the invention patent with publication number CN116418478A discloses a distribution network security protection method based on trusted computing and privacy computing, which includes the following steps: deploying an aggregation layer at the local end, so that the local end includes an edge node layer including smart meters, an aggregation layer including aggregators, and a terminal layer including terminals; treating all smart meters, aggregators, and terminal devices at the local end as network nodes; using trusted computing technology to achieve the security of each node's own state, the trustworthy interaction between each layer, and the trustworthy interaction between edge nodes, and establish trusted communication between each node; the local end combines homomorphic encryption technology to split and re-aggregate the electricity consumption data of each user, so that the aggregator end can only obtain the total electricity consumption of users in the area, but not the electricity consumption of a single user, to achieve security protection.

[0005] However, in the process of implementing the embodiments of the present application, the present application discovered that the above-mentioned technology has at least the following technical problems: the existing security protection framework already has basic capabilities in the anomaly detection and response level, and uses static rule matching and preset threshold triggering to execute security decisions. However, in a dynamically evolving network threat environment, this mechanism exposes significant limitations, namely, its decision-making process presents a one-way linear feature and lacks a dynamic adjustment mechanism based on real-time feedback. Summary of the Invention

[0006] In view of the deficiencies in the prior art, the present invention provides a network security monitoring method and system for power grid metering, which can effectively solve the problems involved in the above-mentioned background technology.

[0007] To achieve the above objectives, the present invention is implemented through the following technical solutions: The first aspect of the present invention provides a network security monitoring method for power grid metering, including: step one, monitoring the operation process of the power node belonging to the power grid metering process, collecting and analyzing the power data of the power node, and determining whether to perform security adjustments to the network key of the power node; step two, obtaining and evaluating the communication parameters of the power node, and determining whether to perform security optimization on the network key of the power node; step three, monitoring the response parameters of the equipment belonging to the power node, and determining whether to adjust the status of the equipment belonging to the power node.

[0008] As a further method, the network key of the power node is securely adjusted. The specific security adjustment process is as follows: obtaining and matching a key duration reduction factor from a security database based on the second metering anomaly impact value of the power node, and shortening the effective duration corresponding to the network key of the power node. At the same time, according to the second metering anomaly impact value of the power node, matching a network key generation rate from the security database, and updating the network key of the terminal to which the power node belongs; monitoring the update process, obtaining a metering anomaly impact index of the power node at the end time of the adjustment period, and comparing it with a metering anomaly impact threshold. If the metering anomaly impact index of the power node at the end time of the adjustment period is less than or equal to the metering anomaly impact threshold, no security enhancement adjustment is performed on the power node. If the metering anomaly impact index of the power node at the end time of the adjustment period is greater than the metering anomaly impact threshold, security enhancement adjustment is performed on the power node. The specific security enhancement adjustment process is as follows: obtaining the second metering anomaly impact value of the power node at the end time of the adjustment period, and shortening the effective duration corresponding to the network key of the power node twice. According to the metering anomaly impact index of the power node, the duration corresponding to the security monitoring period is matched, thereby evaluating the communication parameters of the power node.

[0009] As a further method, the network key of the power node is security optimized. The specific security optimization process is as follows: according to the security communication index of the power node in the security monitoring period, a strength correction factor is matched from the security database, and the network key strength of the power node is increased and optimized, and the network key of the terminal to which the power node belongs is updated; at the same time, according to the security communication index of the power node in the security monitoring period, a duration reduction factor is matched, thereby reducing and optimizing the duration corresponding to the security monitoring period; the security communication index of the power node in the next adjacent security monitoring period is obtained, marked as the security communication optimization index, the metering anomaly impact index decrease rate of the power node in the next adjacent security monitoring period is obtained, the security communication optimization index is compared with the security communication threshold, and the metering anomaly impact index decrease rate is compared with the defined metering anomaly impact index decrease rate. If the first condition exists, there is no need to issue a security warning for the security communication of the power node. If the first condition does not exist, the security communication of the power node is strengthened and adjusted, and a security warning is issued for the security communication of the power node; the first condition specifically refers to that the security communication optimization index is greater than or equal to the security communication threshold, and the metering anomaly impact index decrease rate is less than or equal to the defined metering anomaly impact index decrease rate.

[0010] As a further method, it is determined whether to adjust the state of the device belonging to the power node. The specific determination process is: by evaluating the response parameters of the device belonging to the power node, a response robustness coefficient of the device belonging to the power node is obtained, and compared with the response robustness threshold. If the response robustness coefficient of the device belonging to the power node is greater than or equal to the response robustness threshold, it is determined that the state of the device belonging to the power node is not adjusted; if the response robustness coefficient of the device belonging to the power node is less than the response robustness threshold, it is determined that the state of the device belonging to the power node is adjusted. The specific state adjustment process is: obtaining the basic expansion multiple of the quantum key pool capacity and the basic expansion multiple of the parallel computing rate from the security database, and respectively expanding the quantum key pool capacity and the parallel computing rate of the device belonging to the power node, continuously monitoring the response robustness coefficient of the device belonging to the power node, if the response robustness coefficient of the device belonging to the power node is less than the response robustness threshold, continuing to expand the quantum key pool capacity and the parallel computing rate of the device belonging to the power node until the response robustness coefficient of the device belonging to the power node is greater than or equal to the response robustness threshold, and at the same time obtaining the actual expansion multiple of the quantum key pool capacity and the actual expansion multiple of the parallel computing rate, thereby updating the basic expansion multiple of the quantum key pool capacity and the basic expansion multiple of the parallel computing rate.

[0011] The second aspect of the present invention provides a network security monitoring system for power grid metering, including: a security adjustment module, which is used to monitor the operation process of the power node belonging to the power grid metering process, collect and analyze the power data of the power node, and determine whether to perform security adjustment on the network key of the power node; a security optimization module, which is used to obtain and evaluate the communication parameters of the power node, and determine whether to perform security optimization on the network key of the power node; a state adjustment module, which is used to monitor the response parameters of the equipment belonging to the power node, and determine whether to perform state adjustment on the equipment belonging to the power node.

[0012] Compared with the prior art, the embodiments of the present invention have at least the following advantages or beneficial effects: (1) The present invention provides a network security monitoring method and system for power grid metering. First, the operation data of power nodes are monitored in real time. Combined with dynamic analysis of abnormal traffic characteristics, the risk of key leakage can be discovered in time and the key update mechanism can be triggered, effectively preventing metering data tampering and ensuring the accuracy of transaction settlement. Secondly, the channel quality assessment and encryption strength verification of communication parameters are performed, and the key distribution strategy is optimized through an adaptive algorithm, which not only reduces the retransmission rate and improves communication efficiency, but also can resist new attack methods such as quantum computing. Finally, parameters such as hardware response delay are monitored in real time, potential faults are predicted and load balancing is dynamically adjusted to extend the service life of the equipment. This method forms a "monitoring-assessment-response" closed loop, significantly improving the security protection level and operational reliability of the power grid metering system.

[0013] (2) The present invention achieves precise protection through dynamic key management, shortens the key validity period and accelerates the update based on outlier intelligence, effectively curbs the attack window period, and combines the closed-loop monitoring mechanism with threshold comparison to avoid excessive defense and ensure that risks are controllable. The secondary adjustment strategy forms a "double insurance" for security reinforcement, and differentiated monitoring cycle matching realizes resource optimization configuration, significantly improving the metering system's ability to resist advanced persistent threats, and providing technical support for the construction of an adaptive security ecosystem for the power grid.

[0014] (3) The present invention constructs an adaptive adjustment mechanism by dynamically monitoring the response parameters of the equipment, which significantly improves the system resilience. When the response robustness coefficient is insufficient, it automatically triggers the step-by-step expansion of the quantum key pool capacity and computing rate, forming a "monitoring-expansion-reassessment" closed loop, which not only avoids resource redundancy but also ensures real-time protection. The adaptive parameter update mechanism continuously optimizes the expansion strategy, enabling the system to dynamically match the needs of high-load scenarios and effectively resist complex network attacks, making the power grid metering both efficient and safe. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] The present invention is further described with reference to the accompanying drawings. However, the embodiments in the accompanying drawings do not constitute any limitation to the present invention. A person skilled in the art can obtain other drawings based on the following drawings without creative effort.

[0016] Figure 1 Schematic diagram of the method steps of the present invention.

[0017] Figure 2 This is a schematic diagram of system module connections of the present invention.

[0018] Figure 3 It is a detailed flow chart diagram of the present invention. DETAILED DESCRIPTION

[0019] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0020] Reference Figure 1 As shown, the first aspect of the present invention provides a network security monitoring method for power grid metering, including: step 1, monitoring the operation process of the power node belonging to the power grid metering process, collecting and analyzing the power data of the power node, and determining whether to perform security adjustment on the network key of the power node.

[0021] Specifically, it is determined whether to perform security adjustment on the network key of the power node. The specific determination process is as follows: by analyzing the power data of the power node, the metering anomaly impact index of the power node is obtained, and compared with the metering anomaly impact threshold. If the metering anomaly impact index of the power node is less than or equal to the metering anomaly impact threshold, it is determined that the network key of the power node is not to be securely adjusted. At the same time, the first metering anomaly impact value of the power node is obtained and compared with the first metering anomaly impact threshold. If the first metering anomaly impact value of the power node is less than or equal to the first metering anomaly impact threshold, no pre-adjustment is performed. The above-mentioned metering anomaly impact threshold represents the maximum value allowed by the metering anomaly impact index and is extracted from the security database; the above-mentioned first metering anomaly impact value refers to the degree of deviation between the metering anomaly impact index and the metering anomaly impact threshold when the metering anomaly impact index of the power node is less than or equal to the metering anomaly impact threshold, specifically refers to performing difference processing on the metering anomaly impact threshold and the metering anomaly impact index, and performing ratio processing on the processing result with the metering anomaly impact threshold to finally obtain the first metering anomaly impact threshold; the above-mentioned first metering anomaly impact threshold represents the maximum value of a reasonable range of the first metering anomaly impact value.

[0022] If the first metering anomaly impact value of a power node exceeds the first metering anomaly impact threshold, pre-adjustment is performed. Specifically, the pre-adjustment process involves generating a backup network key for the power node's terminal and storing it in a quantum key pool. The quantum key pool is a secure infrastructure that uses quantum technology to generate and store keys. Its core advantage lies in the information-theoretic security provided by quantum key distribution.

[0023] If the metering anomaly impact index of the power node is greater than the metering anomaly impact threshold, it is determined that the network key of the power node is to be securely adjusted.

[0024] Specifically, the metering anomaly impact index of the power node has a specific analysis process as follows: the power data of the power node includes the power factor anomaly value of the power node, the voltage anomaly event frequency of the power node, and the grid frequency deviation rate of the power node; the above-mentioned power factor anomaly value refers to the degree of deviation between the real-time power factor and the power factor standard value preset by the grid technician. The real-time power factor and the power factor standard value are subjected to difference processing, and the absolute value of the processing result is compared with the power factor standard value to obtain the power factor anomaly value. The real-time power factor can be obtained through smart meter detection; the above-mentioned voltage anomaly event frequency refers to the total number of voltage exceeding the limit (such as overvoltage, undervoltage) or interruption in unit time, which can be obtained through smart meter detection; the above-mentioned grid frequency deviation rate refers to the degree of deviation between the real-time grid frequency and the grid frequency standard value preset by the grid technician. The real-time grid frequency and the grid frequency standard value are subjected to difference processing, and the absolute value of the processing result is compared with the grid frequency standard value to obtain the grid frequency deviation rate. The real-time grid frequency can be obtained through smart meter detection.

[0025] Through the influencing factors, we analyze the degree of influence of the proportional relationship between the power factor abnormal value and the defined power factor abnormal value on the metering abnormality impact index, the degree of influence of the proportional relationship between the voltage abnormality event frequency and the defined voltage abnormality event frequency on the metering abnormality impact index, and the degree of influence of the proportional relationship between the grid frequency deviation rate and the defined grid frequency deviation rate on the metering abnormality impact index. By aggregating the various influence degrees, we can obtain the metering abnormality impact index of the power node.

[0026] The metering anomaly impact index of the power node represents the degree to which the metering process of the power node is affected by the anomaly.

[0027] It needs to be explained that cyber attacks inject false power factor signals by tampering with sensor data (such as constructing a low power factor illusion to bypass reactive compensation monitoring), causing the power factor abnormality value to increase. At the same time, they initiate a voltage control instruction replay attack to create an abnormal event sequence, and exploit the frequency control protocol vulnerability to inject deviation signals, causing the grid frequency to exhibit unnatural fluctuation characteristics, thereby significantly increasing the grid frequency deviation rate and rendering the electricity metering algorithm invalid. The three parameters present non-independent abnormal patterns under the attack scenario, and their combined deviation will cause the metering abnormality impact index to show an upward trend.

[0028] The specific expression of the metering abnormality impact index of the power node is: ; Where, is the metering abnormality impact index of the power node, is the abnormal power factor value of the power node, The power factor abnormal value is preset in the security database. is the frequency of abnormal voltage events at power nodes, The frequency of voltage anomaly events is defined in the safety database. is the grid frequency deviation rate of the power node, It is the defined grid frequency deviation rate preset in the security database. The power factor abnormal value impact factor preset in the security database, is the voltage abnormality event frequency influencing factor preset in the safety database, It is the grid frequency deviation rate influencing factor preset in the security database.

[0029] The above-mentioned definition of abnormal power factor value indicates the maximum value allowed for the abnormal power factor value; the above-mentioned definition of abnormal voltage event frequency indicates the maximum value allowed for the abnormal voltage event frequency; the above-mentioned definition of grid frequency deviation rate indicates the maximum value allowed for the grid frequency deviation rate.

[0030] The above-mentioned power factor abnormal value impact factor is used to quantify the degree of influence of the unit value of the power factor abnormal value on the metering abnormality impact index. The above-mentioned voltage abnormal event frequency impact factor is used to quantify the degree of influence of the unit value of the voltage abnormal event frequency on the metering abnormality impact index. The above-mentioned grid frequency deviation rate impact factor is used to quantify the degree of influence of the unit value of the grid frequency deviation rate on the metering abnormality impact index. The security database stores the correspondence between the power factor abnormal value, the voltage abnormal event frequency and the grid frequency deviation rate and their corresponding impact factors. The power factor abnormal value, the voltage abnormal event frequency and the grid frequency deviation rate can be input into the security database, and the security database can retrieve the power factor abnormal value impact factor, the voltage abnormal event frequency impact factor and the grid frequency deviation rate impact factor, and the value range is between 0 and 1.

[0031] Furthermore, the network key of the power node is securely adjusted, and the specific security adjustment process is: obtaining and matching the key duration shortening factor from the security database based on the second metering anomaly impact value of the power node, and shortening the effective duration corresponding to the network key of the power node, and at the same time matching the network key generation rate from the security database according to the second metering anomaly impact value of the power node, and updating the network key of the terminal to which the power node belongs; the above-mentioned second metering anomaly impact value refers to the degree of deviation between the metering anomaly impact index and the metering anomaly impact threshold when the metering anomaly impact index of the power node is greater than the metering anomaly impact threshold, specifically refers to performing difference processing on the metering anomaly impact index and the metering anomaly impact threshold, performing ratio processing on the processing result and the metering anomaly impact threshold, and finally obtaining the second metering anomaly impact threshold; the above-mentioned key duration shortening factor refers to the difference between the metering anomaly impact index and the metering anomaly impact threshold, and performing ratio processing on the processing result and the metering anomaly impact threshold, and finally obtaining the second metering anomaly impact threshold; the above-mentioned key duration shortening factor refers to the difference between the metering anomaly impact index and the metering anomaly impact threshold, and finally obtaining the second metering anomaly impact threshold. The proportional coefficient for shortening the effective duration is obtained by multiplying the key duration shortening factor by the effective duration corresponding to the network key of the power node, and the processing result is the shortened and adjusted effective duration; the key duration shortening factor, the specific matching process is: the second metering anomaly impact value-key duration shortening factor mapping table is stored in the security database, so the corresponding key duration shortening factor can be directly queried from the security database through the second metering anomaly impact value of the power node; it should be explained that shortening the effective duration corresponding to the network key of the power node means shortening the effective duration corresponding to all network keys of the power node; the above-mentioned network key generation rate, the specific matching process is: the second metering anomaly impact value-network key generation rate mapping table is stored in the security database, so the corresponding network key generation rate can be directly queried from the security database through the second metering anomaly impact value of the power node.

[0032] Monitor the update process, obtain the metering anomaly impact index of the power node at the end of the adjustment period, and compare it with the metering anomaly impact threshold. If the metering anomaly impact index of the power node at the end of the adjustment period is less than or equal to the metering anomaly impact threshold, then the power node will not be subject to security enhancement adjustment. If the metering anomaly impact index of the power node at the end of the adjustment period is greater than the metering anomaly impact threshold, then the power node will be subject to security enhancement adjustment. The specific security enhancement adjustment process is: obtain the second metering anomaly impact value of the power node at the end of the adjustment period, and shorten the effective time corresponding to the network key of the power node for a second time. According to the metering anomaly impact index of the power node, match the time corresponding to the security monitoring period, so as to evaluate the communication parameters of the power node; the above-mentioned adjustment period refers to the time for monitoring the update process. The specific duration is determined by the power grid technicians; the above-mentioned secondary shortening adjustment of the effective duration corresponding to the network key of the power node refers to matching the key duration shortening factor from the security database according to the second metering abnormality impact value of the power node at the end time point of the adjustment period, and shortening the effective duration corresponding to the network key of the power node, which is consistent with the process of matching the key duration shortening factor from the security database based on the second metering abnormality impact value of the power node, and shortening the effective duration corresponding to the network key of the power node; the specific matching process of the duration corresponding to the above-mentioned security monitoring period is: the security database stores a mapping table of metering abnormality impact index-security monitoring period corresponding duration, so the duration corresponding to the corresponding security monitoring period can be directly queried from the security database through the metering abnormality impact index of the power node.

[0033] It should be explained that by dynamically matching the safety monitoring cycle length according to the metering anomaly impact index of the power node and then optimizing the communication parameters, it is possible to avoid excessive monitoring of low-risk nodes, reduce invalid data traffic, and optimize storage and computing resources.

[0034] Step 2: Obtain and evaluate the communication parameters of the power node, and determine whether to perform security optimization on the network key of the power node.

[0035] Specifically, it is determined whether to perform security optimization on the network key of the power node. The specific determination process is: by evaluating the communication parameters of the power node, the security communication index of the power node during the security monitoring period is obtained, and compared with the security communication threshold. If the security communication index of the power node during the security monitoring period is greater than or equal to the security communication threshold, it is determined that the network key of the power node is not security optimized; the above-mentioned security communication threshold represents the minimum value allowed by the security communication index, which is extracted from the security database.

[0036] If the security communication index of the power node during the security monitoring period is less than the security communication threshold, it is determined that the network key of the power node is to be security optimized.

[0037] Specifically, the security communication index of the power node during the security monitoring period is analyzed in the following way: the communication parameters of the power node include the average change rate of the data entropy value of the power node during the security monitoring period, the abnormal protocol traffic ratio of the power node during the security monitoring period, and the link bit error rate ratio of the power node during the security monitoring period; the above-mentioned average change rate of the data entropy value represents the rate of change of the information disorder (or randomness) in the communication data flow per unit time, that is, the average change rate of the data Shannon entropy over time, reflecting the dynamic characteristics and potential anomalies of the data flow, which can be captured by network traffic mirroring; the above-mentioned abnormal protocol traffic ratio represents the proportion of protocol type traffic that is unexpected or deviates from normal behavior in the network to the total traffic during the security monitoring period, which can be obtained by packet capture tools (such as network protocol analyzers); the above-mentioned link bit error rate ratio represents the proportion of the number of bits transmitted with errors in the communication link (such as optical fiber, radio and Ethernet) to the total number of transmitted bits during the security monitoring period, which can be obtained by packet capture tools (such as network protocol analyzers).

[0038] Obtaining the average metering anomaly impact index of the power node during the safety monitoring period refers to obtaining the metering anomaly impact index of the power node during the safety monitoring period in real time and performing average processing to obtain the average metering anomaly impact index.

[0039] Through weight factors, we analyze the influence of the average metering anomaly impact index on the safety communication index, the influence of the deviation between the average change rate of data entropy value and the average change rate of reference data entropy value on the safety communication index, the influence of the proportional relationship between the abnormal protocol traffic ratio and the defined abnormal protocol traffic ratio on the safety communication index, and the influence of the proportional relationship between the link bit error rate ratio and the defined link bit error rate ratio on the safety communication index. The various influence levels are aggregated to obtain the safety communication index of the power node during the safety monitoring period.

[0040] The safety communication index of the power node during the safety monitoring period represents the safety level of the communication of the power node during the safety monitoring period.

[0041] It is important to explain that network security attackers can increase the ratio of abnormal protocol traffic by injecting malformed protocol packets or replaying legitimate traffic. This malformed traffic disrupts normal data distribution patterns, causing information entropy to deviate from baseline values and significantly increasing the average rate of change of data entropy. These dramatic entropy fluctuations directly interfere with the data feature extraction process of the metering algorithm. Electricity metering relies on stable entropy values of voltage and current waveforms to establish prediction models. When the rate of change of entropy is large, the model prediction error grows exponentially, causing the impact index of metering anomalies to rise simultaneously. This distortion creates a "data contamination-metering failure" transmission path, a double feedback loop from link bit error rate ratio to link error rate ratio. An increase in the physical layer bit error rate not only directly reduces communication reliability but also triggers the protocol layer retransmission mechanism, indirectly increasing the ratio of abnormal protocol traffic. At the same time, noise signals generated by bit errors are misinterpreted as valid data, further exacerbating data entropy fluctuations and forming a vicious cycle of "bit errors-traffic anomalies-entropy changes." Network attacks compromise communication security through both the protocol layer and the data layer, while physical layer defects amplify the attack effect. This cross-layer coupling requires the construction of a multi-dimensional security assessment system that integrates protocol analysis, entropy monitoring, and channel quality detection.

[0042] The specific expression of the safety communication index of the power node during the safety monitoring period is: ; Where, is the safety communication index of the power node during the safety monitoring period, a is a constant, is the average measurement abnormality impact index of the power node during the safety monitoring period, is the average measurement anomaly impact index weight factor preset in the security database, is the average change rate of the data entropy value of the power node during the safety monitoring period, is the average rate of change of the entropy value of the reference data preset in the security database, is the abnormal protocol traffic ratio of the power node during the security monitoring period, The abnormal protocol traffic ratio is preset in the security database. is the link bit error rate ratio of the power node during the safety monitoring period, is a defined link error rate ratio preset in the security database, is the weight factor of the average change rate of data entropy value preset in the security database, is the abnormal protocol traffic ratio weight factor preset in the security database, It is the link bit error rate ratio weight factor preset in the security database.

[0043] The above-mentioned reference data entropy value average change rate represents the reference value of the data entropy value average change rate; the above-mentioned definition of abnormal protocol traffic ratio represents the maximum value allowed by the abnormal protocol traffic ratio; the above-mentioned definition of link bit error rate ratio represents the maximum value allowed by the link bit error rate ratio.

[0044] The above-mentioned average metering anomaly impact index weight factor is used to quantify the degree of influence of the unit value of the average metering anomaly impact index after de-uniting on the security communication index. The above-mentioned data entropy value average change rate weight factor is used to quantify the degree of influence of the unit value of the data entropy value average change rate on the security communication index. The above-mentioned abnormal protocol traffic ratio weight factor is used to quantify the degree of influence of the unit value of the abnormal protocol traffic ratio on the security communication index. The above-mentioned link bit error rate ratio weight factor is used to quantify the degree of influence of the unit value of the link bit error rate ratio on the security communication index. The security database stores the correspondence between the average metering anomaly impact index, the average data entropy value change rate, the abnormal protocol traffic ratio weight factor and the link bit error rate ratio and their corresponding weight factors. The average metering anomaly impact index, the average data entropy value change rate, the abnormal protocol traffic ratio weight factor and the link bit error rate ratio can be input into the security database, and the security database can retrieve the average metering anomaly impact index weight factor, the data entropy value average change rate weight factor, the abnormal protocol traffic ratio weight factor and the link bit error rate ratio weight factor, and the value range is between 0 and 1.

[0045] Furthermore, the network key of the power node is security optimized, and the specific security optimization process is: according to the security communication index of the power node during the security monitoring period, the strength correction factor is matched from the security database, and the network key strength of the power node is increased and optimized, and the network key of the terminal to which the power node belongs is updated; the above-mentioned increase and optimization of the network key strength of the power node refers to multiplying the strength correction factor by the network key strength of the power node, and the result of the processing is the increased and optimized network key strength of the power node; the above-mentioned strength correction factor is a value greater than 1, which represents a proportional coefficient for increasing the network key strength of the power node. The specific matching process is: a security communication index-strength correction factor mapping table is stored in the security database, so the corresponding strength correction factor can be directly queried from the security database through the security communication index of the power node during the security monitoring period; the above-mentioned update of the network key of the terminal to which the power node belongs refers to regenerating the network key according to the increased and optimized network key strength, thereby updating the network key of the terminal to which the power node belongs.

[0046] At the same time, according to the safety communication index of the power node within the safety monitoring period, the duration reduction factor is matched to reduce and optimize the duration corresponding to the safety monitoring period; the above-mentioned duration reduction factor is a value less than 1, which represents the proportional coefficient for reducing and optimizing the duration corresponding to the safety monitoring period. The duration reduction factor is multiplied by the duration corresponding to the safety monitoring period, and the processing result is the duration corresponding to the reduced and optimized safety monitoring period, wherein the duration reduction factor, the specific matching process is: the safety communication index-duration reduction factor mapping table is stored in the safety database, so the corresponding duration reduction factor can be directly queried from the safety database through the safety communication index of the power node within the safety monitoring period.

[0047] Obtain the safety communication index of the power node in the next adjacent safety monitoring cycle, mark it as the safety communication optimization index, obtain the metering anomaly impact index decrease rate of the power node in the next adjacent safety monitoring cycle, compare the safety communication optimization index with the safety communication threshold, and compare the metering anomaly impact index decrease rate with the defined metering anomaly impact index decrease rate. If the first condition exists, there is no need to issue a safety warning for the safety communication of the power node. If the first condition does not exist, strengthen the regulation of the safety communication of the power node, and issue a safety warning for the safety communication of the power node. The above-mentioned metering anomaly impact index decrease rate refers to the decrease rate of the metering anomaly impact index of the power node in the next adjacent safety monitoring cycle. The metering anomaly impact index of the power node at the start time of the next adjacent safety monitoring cycle is subtracted from the metering anomaly impact index of the power node at the end time of the next adjacent safety monitoring cycle, and the processing result is compared with the metering anomaly impact index of the power node at the end time of the next adjacent safety monitoring cycle to finally obtain the metering anomaly impact index decrease rate; the metering anomaly impact index decrease rate defined above represents the minimum value allowed for the metering anomaly impact index decrease rate, which is extracted from the security database; the above-mentioned security early warning for the secure communication of the power node has the core goal of identifying risks in advance, blocking the attack chain, and ensuring the communication security of critical infrastructure. The operating status of the power node can be sent to the power grid management personnel in the form of email or the like.

[0048] The first condition specifically refers to that the security communication optimization index is greater than or equal to the security communication threshold, and the measurement anomaly impact index decrease rate is less than or equal to the defined measurement anomaly impact index decrease rate.

[0049] In a specific embodiment, the present invention achieves precise protection through dynamic key management, intelligently shortens key validity and accelerates updates based on outliers, effectively curbs the attack window period, and combines a closed-loop monitoring mechanism with threshold comparison to avoid excessive defense while ensuring controllable risks. The secondary adjustment strategy forms a "double insurance" for security reinforcement, and differentiated monitoring cycle matching achieves optimal resource allocation, significantly improving the metering system's ability to resist advanced persistent threats and providing technical support for building an adaptive security ecosystem for the power grid.

[0050] Step 3: Monitor the response parameters of the equipment belonging to the power node and determine whether to adjust the status of the equipment belonging to the power node.

[0051] In a specific embodiment, the present invention constructs an adaptive adjustment mechanism by dynamically monitoring device response parameters, significantly improving system resilience. When the response robustness coefficient is insufficient, it automatically triggers a step-by-step expansion of the quantum key pool capacity and computing rate, forming a "monitoring-expansion-reassessment" closed loop, which not only avoids resource redundancy but also ensures real-time protection. The adaptive parameter update mechanism continuously optimizes the expansion strategy, enabling the system to dynamically match the needs of high-load scenarios and effectively resist complex network attacks, making power grid metering both efficient and secure.

[0052] Specifically, it is determined whether to adjust the status of the equipment belonging to the power node. The specific determination process is: by evaluating the response parameters of the equipment belonging to the power node, the response robustness coefficient of the equipment belonging to the power node is obtained, and compared with the response robustness threshold. If the response robustness coefficient of the equipment belonging to the power node is greater than or equal to the response robustness threshold, it is determined that the status of the equipment belonging to the power node will not be adjusted; the above-mentioned response robustness threshold represents the minimum value allowed by the response robustness coefficient, which is extracted from the security database.

[0053] If the response robustness coefficient of the device belonging to the power node is less than the response robustness threshold, it is determined that the state of the device belonging to the power node is adjusted. The specific state adjustment process is: obtain the basic expansion multiple of the quantum key pool capacity and the basic expansion multiple of the parallel computing rate from the security database, and expand the quantum key pool capacity and the parallel computing rate of the device belonging to the power node respectively, and continuously monitor the response robustness coefficient of the device belonging to the power node. If the response robustness coefficient of the device belonging to the power node is less than the response robustness threshold, then continue to expand the quantum key pool capacity and the parallel computing rate of the device belonging to the power node until the response robustness coefficient of the device belonging to the power node is greater than or equal to the response robustness threshold, and at the same time obtain the actual expansion multiple of the quantum key pool capacity and the actual expansion multiple of the parallel computing rate, so as to update the quantum key pool capacity. The basic expansion multiple of the key pool capacity and the basic expansion multiple of the parallel computing rate; the above-mentioned basic expansion multiple of the quantum key pool capacity refers to the proportional coefficient for expanding the quantum key pool capacity preset in the security database; the above-mentioned basic expansion multiple of the parallel computing rate refers to the proportional coefficient for expanding the GPU parallel computing rate preset in the security database; the above-mentioned obtaining the basic expansion multiple of the quantum key pool capacity and the basic expansion multiple of the parallel computing rate, and respectively expanding the quantum key pool capacity and the parallel computing rate of the equipment belonging to the power node, refers to multiplying the quantum key pool capacity by the basic expansion multiple of the quantum key pool capacity, and the processing result is the expanded quantum key pool capacity, and multiplying the basic expansion multiple of the parallel computing rate by the GPU parallel computing rate, and the processing result is the expanded quantum key pool capacity.

[0054] Furthermore, the response robustness coefficient of the equipment belonging to the power node is specifically analyzed as follows: the response parameters of the equipment belonging to the power node include the command response delay jitter factor of the equipment belonging to the power node during the safety monitoring period and the peak-to-valley difference of the resource utilization of the equipment belonging to the power node during the safety monitoring period; the above-mentioned peak-to-valley difference of resource utilization refers to the difference between the maximum and minimum values of the CPU resource utilization of the equipment during the safety monitoring period, reflecting the balance of resource allocation. A large peak-to-valley difference indicates that the equipment is instantaneously overloaded or resources are idle, which may cause service interruption or low energy efficiency; the above-mentioned command response delay jitter factor refers to the degree of fluctuation of the response time of the control command (such as the power grid AGC adjustment command), which can be obtained by performing standard deviation processing on the response time of all control commands within the safety monitoring period, and finally obtaining the command response delay jitter factor. The control command response time can be obtained through packet capture tools (such as network protocol analyzers).

[0055] The influence of the average measurement anomaly impact index on the response robustness coefficient, the influence of the security communication index on the response robustness coefficient, and the influence of the response robustness factor on the response robustness coefficient are quantified by weights respectively. The response robustness coefficient of the equipment belonging to the power node is obtained by summarizing the influence degrees. The response robustness coefficient of the equipment belonging to the power node characterizes the response robustness of the equipment belonging to the power node.

[0056] It should be explained that in the power node equipment response system, core parameters form a dynamic interaction mechanism through a bidirectional coupling chain, jointly shaping the response robustness coefficient: a decrease in the average metering anomaly impact index (such as suffering from protocol tampering or replay attacks) will directly lead to an increase in the security communication index. In order to deal with abnormal data, the verification and logging mechanism must be frequently triggered, significantly expanding the peak-to-valley difference in resource utilization. Resource contention further leads to a sharp increase in the command response delay jitter factor, destroying the timing sensitivity of real-time control. The reverse deterioration path also exists: the increase in resource peak-to-valley difference increases the security protocol processing delay, which in turn aggravates the deterioration of the security communication index. The parameters form a closed-loop security threat diffusion mechanism through the chain reaction of "communication vulnerability → data pollution → load fluctuation → timing disorder". Therefore, it is necessary to build a collaborative defense system of security situation awareness and resource elastic scheduling to block this vicious cycle.

[0057] The specific expression of the response robustness coefficient of the equipment belonging to the power node is: ; ; Where, is the response robustness coefficient of the equipment belonging to the power node, is the average measurement abnormality impact index of the power node during the safety monitoring period, is the safety communication index of the power node during the safety monitoring period, is the response robustness factor of the power node during the safety monitoring cycle, is the average measurement anomaly impact index weight preset in the security database, is the security communication index weight preset in the security database, is the response robustness factor weight preset in the security database, is the command response delay jitter factor of the equipment belonging to the power node during the safety monitoring cycle, It is the defined command response delay jitter factor preset in the security database. The peak-to-valley difference in resource utilization of the equipment belonging to the power node during the safety monitoring cycle, It is the preset resource utilization peak and valley difference in the security database. is the command response delay jitter factor weight preset in the security database, It is the preset resource utilization peak-valley difference weight in the security database.

[0058] The above-mentioned definition of the instruction response delay jitter factor indicates the maximum value allowed by the instruction response delay jitter factor; the above-mentioned definition of the resource utilization peak-to-valley difference indicates the maximum value allowed by the resource utilization peak-to-valley difference.

[0059] The weight of the above-mentioned average measurement anomaly impact index is used to quantify the degree of influence of the unit value of the average measurement anomaly impact index after de-uniting on the response robustness coefficient. The weight of the above-mentioned safety communication index is used to quantify the degree of influence of the unit value of the safety communication index after de-uniting on the response robustness coefficient. The weight of the above-mentioned response robustness factor is used to quantify the degree of influence of the unit value of the response robustness factor after de-uniting on the response robustness coefficient. The weight of the above-mentioned instruction response delay jitter factor is used to quantify the degree of influence of the unit value of the instruction response delay jitter factor on the response robustness factor. The weight of the above-mentioned resource utilization peak-valley difference is used to quantify the unit value of the resource utilization peak-valley difference. Regarding the degree of influence on the response robustness factor, the security database stores the correspondence between the average metering anomaly impact index, the security communication index, the response robustness factor, the peak-to-valley difference in resource utilization, and the instruction response delay jitter factor and their corresponding weights. The average metering anomaly impact index, the security communication index, the response robustness factor, the peak-to-valley difference in resource utilization, and the instruction response delay jitter factor can be input into the security database. The security database can retrieve the weight of the average metering anomaly impact index, the weight of the security communication index, the weight of the response robustness factor, the weight of the instruction response delay jitter factor, and the peak-to-valley difference in resource utilization, all of which have a value range of 0 to 1.

[0060] In a specific embodiment, the present invention provides a network security monitoring method for power grid metering. First, real-time monitoring of power node operating data, combined with dynamic analysis of abnormal traffic characteristics, can promptly detect key leakage risks and trigger a key update mechanism, effectively preventing metering data tampering and ensuring the accuracy of transaction settlement. Second, channel quality assessment and encryption strength verification are performed on communication parameters. The key distribution strategy is optimized through an adaptive algorithm, which not only reduces the retransmission rate and improves communication efficiency, but also protects against new attack methods such as quantum computing. Finally, real-time monitoring of parameters such as hardware response delay is carried out to predict potential failures and dynamically adjust load balancing to extend equipment usage. This method forms a "monitoring-assessment-response" closed loop, significantly improving the security protection level and operational reliability of the power grid metering system.

[0061] Reference Figure 2 As shown, the second aspect of the present invention provides a network security monitoring system for power grid metering, comprising: a security adjustment module, a security optimization module, a state adjustment module and a security database.

[0062] The security database is used to store parameters involved in the network security monitoring system for power grid metering.

[0063] The security adjustment module is connected to the security optimization module, the security optimization module is connected to the state adjustment module, and the security adjustment module, the security optimization module and the state adjustment module are all connected to the security database.

[0064] The security adjustment module is used to monitor the operation process of the power nodes belonging to the grid metering process, collect and analyze the power data of the power nodes, and determine whether to make security adjustments to the network keys of the power nodes.

[0065] The security optimization module is used to obtain and evaluate the communication parameters of the power node and determine whether to perform security optimization on the network key of the power node.

[0066] The state adjustment module is used to monitor the response parameters of the equipment belonging to the power node and determine whether to adjust the state of the equipment belonging to the power node.

[0067] Figure 3 This is a detailed flowchart diagram of the present invention, which explains the specific implementation path of the technical solution through a phased diagram system. The flowchart presents the operating specifications and data flow relationship of each key node in a logically progressive manner, providing a visual interpretation framework for the technical solution of the present invention.

[0068] The above content is merely an example and explanation of the structure of the present invention. Those skilled in the art may make various modifications or additions to the described specific embodiments or replace them in a similar manner. As long as they do not deviate from the structure of the invention or exceed the scope defined by the present invention, they should all fall within the scope of protection of the present invention.

Claims

1. A network security monitoring method for power grid metering, characterized in that: include: Step 1: Monitor the operation of the power nodes belonging to the grid metering process, collect and analyze the power data of the power nodes, and determine whether to adjust the network key of the power nodes securely; Step 2: Obtain and evaluate the communication parameters of the power node and determine whether to perform security optimization on the network key of the power node; Step 3: Monitor the response parameters of the equipment belonging to the power node and determine whether to adjust the status of the equipment belonging to the power node.

2. The network security monitoring method for power grid metering according to claim 1, characterized in that: The specific process of determining whether to perform security adjustment on the network key of the power node is as follows: By analyzing the power data of the power node, the metering anomaly impact index of the power node is obtained and compared with the metering anomaly impact threshold. If the metering anomaly impact index of the power node is less than or equal to the metering anomaly impact threshold, it is determined that the network key of the power node will not be securely adjusted. At the same time, the first metering anomaly impact value of the power node is obtained and compared with the first metering anomaly impact threshold. If the first metering anomaly impact value of the power node is less than or equal to the first metering anomaly impact threshold, no pre-adjustment is performed. If the first metering anomaly impact value of the power node is greater than the first metering anomaly impact threshold, pre-adjustment is performed. The specific pre-adjustment process includes: generating a backup network key for the terminal to which the power node belongs and storing it in a quantum key pool; If the metering anomaly impact index of the power node is greater than the metering anomaly impact threshold, it is determined that the network key of the power node is to be securely adjusted.

3. The network security monitoring method for power grid metering according to claim 2, characterized in that: The network key of the power node is securely adjusted, and the specific security adjustment process is as follows: Obtaining and matching a key duration reduction factor from a security database based on the second metering anomaly impact value of the power node, and shortening and adjusting the effective duration of the network key corresponding to the power node; and matching a network key generation rate from the security database based on the second metering anomaly impact value of the power node, and updating the network key of the terminal to which the power node belongs; The update process is monitored to obtain the metering anomaly impact index of the power node at the end time of the adjustment period, and compare it with the metering anomaly impact threshold. If the metering anomaly impact index of the power node at the end time of the adjustment period is less than or equal to the metering anomaly impact threshold, the power node is not subjected to security enhancement adjustment. If the metering anomaly impact index of the power node at the end time of the adjustment period is greater than the metering anomaly impact threshold, the power node is subjected to security enhancement adjustment. The specific security enhancement adjustment process is as follows: the second metering anomaly impact value of the power node at the end time of the adjustment period is obtained, and the effective time corresponding to the network key of the power node is shortened twice. According to the metering anomaly impact index of the power node, the time corresponding to the security monitoring period is matched, thereby evaluating the communication parameters of the power node.

4. The network security monitoring method for power grid metering according to claim 2, characterized in that: The specific analysis process of the metering abnormality impact index of the power node is as follows: The power data of the power node includes the power factor abnormal value of the power node, the voltage abnormal event frequency of the power node, and the grid frequency deviation rate of the power node; Through the influencing factors, the influence degree of the proportional relationship between the power factor abnormal value and the defined power factor abnormal value on the metering abnormality impact index, the influence degree of the proportional relationship between the voltage abnormality event frequency and the defined voltage abnormality event frequency on the metering abnormality impact index, and the influence degree of the proportional relationship between the grid frequency deviation rate and the defined grid frequency deviation rate on the metering abnormality impact index are analyzed respectively. The various influence degrees are aggregated to obtain the metering abnormality impact index of the power node; The metering anomaly impact index of the power node represents the degree to which the metering process of the power node is affected by the anomaly.

5. The network security monitoring method for power grid metering according to claim 1, characterized in that: The specific determination process of whether to perform security optimization on the network key of the power node is as follows: By evaluating the communication parameters of the power node, the security communication index of the power node during the security monitoring period is obtained and compared with the security communication threshold. If the security communication index of the power node during the security monitoring period is greater than or equal to the security communication threshold, it is determined that the network key of the power node will not be optimized for security; If the security communication index of the power node during the security monitoring period is less than the security communication threshold, it is determined that the network key of the power node is to be security optimized.

6. The network security monitoring method for power grid metering according to claim 5, characterized in that: The network key of the power node is optimized for security, and the specific security optimization process is as follows: According to the security communication index of the power node during the security monitoring period, the strength correction factor is matched from the security database, and the network key strength of the power node is increased and optimized, and the network key of the terminal to which the power node belongs is updated; At the same time, according to the safety communication index of the power node during the safety monitoring period, the duration reduction factor is matched, thereby reducing and optimizing the duration corresponding to the safety monitoring period; Obtain a security communication index of the power node in the next adjacent security monitoring cycle, marked as a security communication optimization index, obtain a metering anomaly impact index decrease rate of the power node in the next adjacent security monitoring cycle, compare the security communication optimization index with the security communication threshold, and compare the metering anomaly impact index decrease rate with the defined metering anomaly impact index decrease rate. If the first condition exists, there is no need to issue a security warning for the security communication of the power node. If the first condition does not exist, strengthen the regulation of the security communication of the power node, and issue a security warning for the security communication of the power node. The first condition specifically refers to that the security communication optimization index is greater than or equal to the security communication threshold, and the measurement anomaly impact index decrease rate is less than or equal to the defined measurement anomaly impact index decrease rate.

7. The network security monitoring method for power grid metering according to claim 6, characterized in that: The safety communication index of the power node during the safety monitoring period is analyzed in the following specific process: The communication parameters of the power node include the average change rate of the data entropy value of the power node during the safety monitoring period, the abnormal protocol flow rate ratio of the power node during the safety monitoring period, and the link bit error rate ratio of the power node during the safety monitoring period; The average metering anomaly impact index of the power node during the safety monitoring period is obtained. The weighting factors are used to analyze the impact of the average metering anomaly impact index on the safety communication index, the impact of the deviation between the average change rate of the data entropy value and the average change rate of the reference data entropy value on the safety communication index, the impact of the proportional relationship between the abnormal protocol traffic ratio and the defined abnormal protocol traffic ratio on the safety communication index, and the impact of the proportional relationship between the link bit error rate ratio and the defined link bit error rate ratio on the safety communication index. The various impact levels are aggregated to obtain the safety communication index of the power node during the safety monitoring period. The safety communication index of the power node during the safety monitoring period represents the safety level of the communication of the power node during the safety monitoring period.

8. The network security monitoring method for power grid metering according to claim 1, characterized in that: The specific process of determining whether to adjust the status of the equipment belonging to the power node is as follows: By evaluating the response parameters of the equipment belonging to the power node, the response robustness coefficient of the equipment belonging to the power node is obtained, and compared with the response robustness threshold. If the response robustness coefficient of the equipment belonging to the power node is greater than or equal to the response robustness threshold, it is determined that the state of the equipment belonging to the power node will not be adjusted; If the response robustness coefficient of the device belonging to the power node is less than the response robustness threshold, it is determined that the state of the device belonging to the power node is adjusted. The specific state adjustment process is: obtaining the basic expansion multiple of the quantum key pool capacity and the basic expansion multiple of the parallel computing rate from the security database, and respectively expanding the quantum key pool capacity and the parallel computing rate of the device belonging to the power node, and continuously monitoring the response robustness coefficient of the device belonging to the power node. If the response robustness coefficient of the device belonging to the power node is less than the response robustness threshold, then continue to expand the quantum key pool capacity and the parallel computing rate of the device belonging to the power node until the response robustness coefficient of the device belonging to the power node is greater than or equal to the response robustness threshold, and at the same time obtain the actual expansion multiple of the quantum key pool capacity and the actual expansion multiple of the parallel computing rate, thereby updating the basic expansion multiple of the quantum key pool capacity and the basic expansion multiple of the parallel computing rate.

9. The network security monitoring method for power grid metering according to claim 8, characterized in that: The response robustness coefficient of the equipment belonging to the power node is analyzed in detail as follows: The response parameters of the equipment belonging to the power node include the instruction response delay jitter factor of the equipment belonging to the power node during the safety monitoring period and the peak-to-valley difference of the resource utilization rate of the equipment belonging to the power node during the safety monitoring period; The influence of the average measurement anomaly impact index on the response robustness coefficient, the influence of the safety communication index on the response robustness coefficient, and the influence of the response robustness factor on the response robustness coefficient are quantified by weights. The response robustness coefficient of the equipment belonging to the power node is obtained by summarizing the influence degrees. The response robustness coefficient of the equipment to which the power node belongs represents the response robustness of the equipment to which the power node belongs.

10. A system using the network security monitoring method for power grid metering according to any one of claims 1 to 9, characterized in that: include: The security adjustment module is used to monitor the operation of the power nodes belonging to the grid metering process, collect and analyze the power data of the power nodes, and determine whether to perform security adjustments on the network keys of the power nodes; A security optimization module is used to obtain and evaluate the communication parameters of the power node and determine whether to perform security optimization on the network key of the power node; The state adjustment module is used to monitor the response parameters of the equipment belonging to the power node and determine whether to adjust the state of the equipment belonging to the power node.

Citation Information

Patent Citations

  • A network security protection method for power grid informatization construction based on deep learning

    CN115834159B

  • Power distribution network safety protection method based on trusted computing and privacy computing

    CN116418478A