Intelligent collaborative network security emergency response device and method for novel power system
Through the combination of edge probe acquisition module, intelligent analysis module and digital twin sandbox deduction module, the real-time response problem of complex attacks in power network security protection is solved, high-precision and low-cost intelligent collaborative network security emergency response is achieved, and the network security protection capability of the power system is improved.
Patent Information
- Application Number
- CN202510869913.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-26
- Publication Date
- 2025-08-08
- Estimated Expiration
- 2045-06-26
AI Technical Summary
The existing power network security protection methods are difficult to cope with the evolution of complex attacks, event recognition lags, lack of simulation verification mechanisms, long response chains, lack of edge collaborative intelligence, and difficult to meet the real-time requirements of power services.
The edge probe acquisition module, intelligent analysis module, digital twin sandbox deduction module and strategy optimization module are adopted to achieve rapid model adaptation and improve the intelligence level of detection and response through improved dynamic weight fusion mechanism and meta-learning online optimization.
It significantly improves the effectiveness of network security incident detection and response, reduces the need for labeled data, improves detection accuracy and accuracy of response strategy formulation, and avoids the risk of business interruption caused by excessive isolation.
Smart Images

Figure CN120455158A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of artificial intelligence and power network technology, and in particular to an intelligent collaborative network security emergency response device and method for a new type of power system. Background Art
[0002] In line with the dual carbon goals and energy transition, new power systems are widely adopting information technology to achieve intelligent control. As systems such as relay protection, dispatch automation, and condition monitoring evolve towards a "cloud-edge-end" architecture, their communication networks are becoming increasingly complex.
[0003] Current power network security protection measures mainly include firewalls, intrusion detection systems, access control, etc., but they have the following defects: static rule matching is difficult to cope with the evolution of complex attacks; event recognition is delayed, making it difficult to meet the real-time requirements of power business; there is a lack of simulation verification mechanism, and the policy controllability is insufficient; the response chain is long, and there is a lack of edge collaborative intelligence. Summary of the Invention
[0004] In view of this, the purpose of the present invention is to provide an intelligent collaborative network security emergency response device and method for new power systems. Through an improved dynamic weight fusion mechanism and meta-learning online optimization, rapid model adaptation can be achieved with only a small number of samples, significantly reducing the demand for labeled data; and providing an innovative solution for intelligent diagnosis of power equipment with high precision, strong adaptability and low implementation cost.
[0005] To achieve the above objectives, the present invention adopts the following technical solutions: an intelligent collaborative network security emergency response device for a new power system, comprising: an edge probe acquisition module, an intelligent analysis module, and a digital twin sandbox deduction module;
[0006] The edge probe acquisition module is used to capture the power communication data stream in real time, and the power communication data stream includes protocol characteristics and device behavior characteristics;
[0007] The intelligent analysis module performs attack identification and risk classification on the collected data based on the time series anomaly detection algorithm and vulnerability database;
[0008] The digital twin sandbox deduction module includes:
[0009] Network attack simulator, used to simulate network attack behaviors;
[0010] Power business impact assessor, used to calculate attack-induced voltage deviation and equipment overload risk index business indicators;
[0011] A policy generator is used to calculate the degree of business impact on devices based on sandbox deduction results and obtain device isolation policies;
[0012] The policy execution module is deployed on edge nodes, executes response policies according to priority, and provides feedback on the execution effect;
[0013] The policy optimization module is used to enhance the learning of the parameters of the time series anomaly detection algorithm and the policy generator based on the policy execution feedback, forming a closed-loop optimization;
[0014] The human-computer collaboration module provides policy review, log query, exception confirmation and policy rollback functions.
[0015] In a preferred embodiment, the edge probe acquisition module captures the power communication data stream in real time through high-frequency and low-latency packet capture, and uses a multi-protocol parsing engine to extract protocol behavior characteristics and device behavior characteristics including protocol type, data field behavior pattern, communication periodicity characteristics and device access topology; and converts the characteristics of different devices and protocols into feature vectors in a unified format.
[0016] In a preferred embodiment, the intelligent analysis module performs behavioral anomaly detection on the data collected by the edge probe acquisition module based on a time series anomaly detection algorithm, and performs attack behavior identification and risk classification in combination with a vulnerability database; the vulnerability database includes CVE vulnerability mapping and protocol weakness modeling for key power system equipment; the risk rating output includes:
[0017] Attack type tags: fake message, denial of service, replay;
[0018] Attack confidence score.
[0019] In a preferred embodiment, the policy execution module implements the issuance and execution of response policies by calling the SDN controller or network policy engine, including: blocking the communication IP and port of abnormal devices and dynamically updating the access control list ACL policy; and feedback on the policy success rate, network reconstruction delay and communication stability change indicators after the policy is executed.
[0020] In a preferred embodiment, the strategy optimization module, based on feedback information after strategy execution, enhances learning and training of the anomaly detection algorithm and strategy generator in the intelligent analysis module to achieve closed-loop tuning and adaptive evolution of the detection and response system.
[0021] In a preferred embodiment, the human-computer collaboration module provides an interactive platform including a graphical visual interface and intelligent decision-making suggestions, supports automatic generation of response suggestions and logs, supports manual review and policy modification by operation and maintenance personnel, and supports linkage with the SOC platform for real-time alarms and notifications.
[0022] The present invention also provides an intelligent collaborative network security emergency response method for a new type of power system, which uses the intelligent collaborative network security emergency response device for a new type of power system, including the following steps:
[0023] S1, the edge probe acquisition module captures the power communication data stream in real time, extracts protocol features and device behavior features, and generates standardized feature vectors;
[0024] S2, the intelligent analysis module applies a time series anomaly detection algorithm to the feature vectors, combines the device vulnerability knowledge base and the attack graph database to perform attack identification and risk classification, and outputs the attack type, confidence level, and potentially affected devices;
[0025] S3. For identified high-risk events, the digital twin sandbox simulation module is activated to generate simulated attack scenarios using the network attack simulator and to assess potential business impact using the power business impact assessor.
[0026] S4. The policy generator calculates the degree of impact on the power services of the equipment based on the deduction results and obtains the equipment isolation policy;
[0027] S5. The policy execution module automatically executes response actions at the edge node according to the policy priority and collects execution effect data;
[0028] S6, the strategy optimization module dynamically adjusts the anomaly detection model and response strategy generator based on strategy execution feedback through reinforcement learning to form a closed-loop optimization;
[0029] S7. The human-machine collaboration module provides interactive functions such as policy review, exception confirmation, and policy rollback to support the collaborative response of the system and operation and maintenance personnel.
[0030] In a preferred embodiment, the digital twin sandbox deduction module specifically includes the following steps:
[0031] S31, Network Attack Simulator, uses a combination of rule-driven and data-driven attack modeling to simulate network attack behaviors in a simulation environment;
[0032] S32, the power business impact assessor, calculates the business impact of infected devices in attack scenarios, including business indicators such as voltage deviation and equipment overload risk index;
[0033] The voltage deviation The calculation formula is as follows:
[0034] ;
[0035] Indicates the voltage amplitude of the device after the attack. Indicates the node rated voltage;
[0036] The equipment overload risk index The calculation formula is as follows:
[0037] ;
[0038] Indicates the actual operating power of the device. Indicates the rated power of the device. Indicates the duration of the overload caused by the attack. Indicates the maximum overload time allowed for the device;
[0039] S33. The policy generator generates a device isolation policy based on the deduction results of the network attack simulator and the degree of impact on the device business.
[0040] In a preferred embodiment, generating a device isolation strategy includes the following steps:
[0041] S331. Calculate device isolation scores based on device business impact and device level :
[0042] ,
[0043] D l Indicates the device level, which is determined by the importance of the device. α and β are weighted difference parameters used to balance the weights of the three indicators; S332, based on device isolation score Matching isolation strategies;
[0044] like , immediately carry out physical isolation;
[0045] like , perform logical isolation;
[0046] like , only protocol-level isolation;
[0047] like , no action is taken;
[0048] described 、 、 is the threshold parameter.
[0049] Compared with the existing technology, the present invention has the following beneficial effects: Aiming at the complex and changeable communication environment of the new power system, the present invention proposes an edge detection method based on multi-protocol feature extraction and equipment behavior modeling to improve the detection accuracy; introduces digital twin sandbox deduction in the power system network security protection, comprehensively simulates network attack behavior and power business impact, and estimates changes in indicators such as voltage deviation, frequency limit violation, and equipment overload before the attack actually occurs, thereby improving the accuracy of response strategy formulation and effectively avoiding the risk of business interruption caused by excessive isolation. The present invention can significantly improve the intelligence level and effectiveness of network security incident detection, deduction and response, and provide technical support with practical application value for the safe operation and maintenance of new power systems. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] Figure 1 A schematic diagram of the overall system structure of an intelligent collaborative network security emergency response device for a new type of power system provided for the application.
[0051] Figure 2 A flowchart of a method for an intelligent collaborative network security emergency response device for a new type of power system is provided for the application. DETAILED DESCRIPTION
[0052] The present invention will be further described below with reference to the accompanying drawings and embodiments.
[0053] It should be noted that the following detailed descriptions are illustrative and intended to provide further explanation of the present application. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which the present application belongs.
[0054] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present application; as used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form, and it should be understood that when the terms "comprise" and / or "include" are used in this specification, they indicate the presence of features, steps, operations, devices, components and / or their combinations.
[0055] The present invention discloses an intelligent collaborative network security emergency response device for a new type of power system. Figure 1 , including: edge probe acquisition module, intelligent analysis module and digital twin sandbox deduction module.
[0056] The edge probe acquisition module is used to capture power communication data streams in real time and extract protocol features and device behavior features including protocol types, data field behavior patterns, etc.
[0057] The intelligent analysis module performs attack identification and risk classification on the collected data based on a time series anomaly detection algorithm and a vulnerability database; the vulnerability database is specifically a power system network security vulnerability database.
[0058] Digital twin sandbox simulation module, including:
[0059] A network attack simulator is used to simulate network attack behaviors, such as forging relay protection device sampling values, GOOSE message replay attacks, and DNP3 protocol master station impersonation attacks, among other new power system network attack behaviors;
[0060] The power service impact assessor is used to evaluate the impact of network behavior on the power service of the equipment, including calculating service indicators such as voltage deviation caused by the attack and equipment overload risk index;
[0061] The policy generator is used to calculate the degree of business impact on the device based on the sandbox deduction results and obtain the device isolation policy.
[0062] The policy execution module is deployed on edge nodes, executes response strategies according to priority, and provides feedback on the execution effect.
[0063] The policy optimization module is used to enhance the learning of the parameters of the time series anomaly detection algorithm and the policy generator based on the policy execution feedback, forming a closed-loop optimization.
[0064] The human-computer collaboration module provides policy review, log query, exception confirmation and policy rollback functions.
[0065] More specifically, the aforementioned intelligent collaborative cybersecurity emergency response device for new power systems features an edge probe acquisition module with high-frequency, low-latency packet capture for real-time capture of power communication data streams. It also employs a multi-protocol parsing engine to extract protocol and device behavior characteristics, including protocol type (such as IEC 61850, MODBUS, and DNP3), data field behavior patterns, communication periodicity, and device access topology. Furthermore, a dynamic feature window-based sequence encoding method is used to convert the characteristics of different devices and protocols into feature vectors in a unified format, facilitating subsequent AI model processing.
[0066] Converting the features of different devices and protocols into feature vectors in a unified format is achieved through the following steps:
[0067] 1. Dynamic padding: pad variable-length signature lists for different protocols / devices to a uniform length (zero padding to a maximum dimension of 128).
[0068] 2. Dimensionality reduction: Use PCA (principal component analysis) to compress high-dimensional sparse features to the target dimension (e.g., 64 dimensions).
[0069] 3. Normalization: Perform Min-Max normalization on numerical features to eliminate the impact of dimension.
[0070] More specifically, the intelligent collaborative network security emergency response device for a new power system described above is characterized by the intelligent analysis module performing behavioral anomaly detection on data collected by edge probes based on a time series anomaly detection algorithm, and identifying attack behaviors and grading risks in combination with a device vulnerability knowledge base and an attack graph database. The time series anomaly detection algorithm is an LSTM variational autoencoder (VAE), a Transformer prediction residual model, or other self-supervised anomaly detection method; the vulnerability knowledge base includes CVE vulnerability mapping and protocol weakness modeling for key power system equipment; and the risk rating output includes:
[0071] Attack type label (forged message, denial of service, replay, etc.);
[0072] Attack confidence score.
[0073] More specifically, the intelligent collaborative network security emergency response device for a new power system is characterized in that the digital twin sandbox deduction specifically includes the following steps:
[0074] S31. Network attack simulator uses a combination of rule-driven and data-driven attack modeling methods to simulate network attack behaviors in a simulation environment, including but not limited to forged sample value messages (SV), GOOSE message tampering, link blocking and other attack methods; the attack simulator outputs a list of infected devices (including device ID, IP address, and asset level).
[0075] S32, the power business impact assessor, calculates the business impact of infected devices in attack scenarios, including business indicators such as voltage deviation and equipment overload risk index;
[0076] The voltage deviation is calculated as follows:
[0077] ;
[0078] Indicates the voltage amplitude of the device after the attack. Indicates the rated voltage of the node.
[0079] The calculation formula for the equipment overload risk index is as follows:
[0080] ;
[0081] Indicates the actual operating power of the device. Indicates the rated power of the device. Indicates the duration of the overload caused by the attack (in minutes). Indicates the maximum overload time allowed for the device (minutes), preferably The value is 5.
[0082] S33. The policy generator generates a device isolation policy based on the deduction results of the network attack simulator and the degree of impact on the device business.
[0083] In S31, the rule-driven module process:
[0084] Constructing deterministic attacks based on attack knowledge base:
[0085] Based on the protocol vulnerabilities and CVE vulnerability libraries in power safety standards such as IEC62351, corresponding rule expressions are formed;
[0086] Data-driven module process:
[0087] Probabilistic attack evolution is obtained through attack behavior learning, such as abnormal patterns in real network traffic (such as port scans with sudden entropy changes) and APT attack sequences captured by honeypots.
[0088] Attack generation process:
[0089] 1. Initial seed: Get the basic attack template from the rule base
[0090] 2. Mutation strategy:
[0091] 2.1 Field fuzzy test (modifying the lower 4 bits of the Modbus function code)
[0092] 2.2 Timing Perturbation (Random Delay ±20% Message Interval) Joint Simulation Process:
[0093] 1. Initialization: The rule module loads the vulnerability template corresponding to the corresponding attack.
[0094] 2. Enhancement: The data module injects the learned response characteristics of substation equipment.
[0095] 3. Execution:
[0096] Sending malformed messages in a digital twin environment;
[0097] Monitor whether the protection device sends a TRIP signal by mistake.
[0098] 4. Feedback:
[0099] If successful, record the attack characteristics to the rule base;
[0100] If it fails, adjust the enhancement strategy of the data module.
[0101] In S33, generating a device isolation policy includes the following steps:
[0102] S331. Calculate device isolation scores based on device business impact and device level :
[0103] ,
[0104] D l Indicates the device level, which is determined by the importance of the device. S332, based on device isolation score The matching isolation strategy is shown in Table 1: Table 1:
[0105]
[0106] 、 、 is the threshold parameter, which is continuously optimized in reinforcement learning.
[0107] The policy execution module implements the issuance and execution of response policies by calling the SDN controller or network policy engine, including blocking the communication IP and port of abnormal devices and dynamically updating the access control list (ACL) policy; and after the policy is executed, it provides feedback on indicators such as the policy success rate, network reconstruction delay, and communication stability changes.
[0108] The policy optimization module uses feedback from policy execution to enhance learning and train the anomaly detection algorithm and policy generator in the intelligent analysis module, achieving closed-loop tuning and adaptive evolution of the detection and response system. Enhanced training uses the generated policy and its post-policy execution feedback as samples to optimize the policy generator and the anomaly detection algorithm in the intelligent analysis module.
[0109] The human-machine collaboration module provides an interactive platform including a graphical visual interface and intelligent decision-making suggestions, supports automatic generation of response suggestions and logs, supports manual review and policy modification by operation and maintenance personnel, and supports linkage with the SOC platform for real-time alarms and notifications.
[0110] In the second aspect, the present invention discloses a method based on an intelligent collaborative network security emergency response device for a new type of power system, referring to Figure 2 , including the following steps:
[0111] S1, the edge probe acquisition module captures the power communication data stream in real time, extracts protocol features and device behavior features, and generates standardized feature vectors;
[0112] S2, the intelligent analysis module applies a time series anomaly detection algorithm to the feature vectors, combines the device vulnerability knowledge base and the attack graph database to perform attack identification and risk classification, and outputs the attack type, confidence level, and potentially affected devices;
[0113] S3. For identified high-risk events, the digital twin sandbox simulation module is activated to generate simulated attack scenarios using the network attack simulator and to assess potential business impact using the power business impact assessor.
[0114] S4. The policy generator calculates the degree of impact on the power services of the equipment based on the deduction results and obtains the equipment isolation policy;
[0115] S5. The policy execution module automatically executes response actions at the edge node according to the policy priority and collects execution effect data;
[0116] S6, the strategy optimization module dynamically adjusts the anomaly detection model and response strategy generator based on strategy execution feedback through reinforcement learning to form a closed-loop optimization;
[0117] S7. The human-machine collaboration module provides interactive functions such as policy review, exception confirmation, and policy rollback to support the collaborative response of the system and operation and maintenance personnel.
[0118] The above description is merely an embodiment of the present application and is not intended to limit the scope of protection of the present application. For those skilled in the art, various modifications and variations of the present application are possible. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.
Claims
1. An intelligent collaborative network security emergency response device for a new type of power system, characterized by: include: Edge probe acquisition module, intelligent analysis module, and digital twin sandbox deduction module; The edge probe acquisition module is used to capture the power communication data stream in real time, and the power communication data stream includes protocol characteristics and device behavior characteristics; The intelligent analysis module performs attack identification and risk classification on the collected data based on the time series anomaly detection algorithm and vulnerability database; The digital twin sandbox deduction module includes: Network attack simulator, used to simulate network attack behaviors; Power business impact assessor, used to calculate attack-induced voltage deviation and equipment overload risk index business indicators; A policy generator is used to calculate the degree of business impact on devices based on sandbox deduction results and obtain device isolation policies; The policy execution module is deployed on edge nodes, executes response policies according to priority, and provides feedback on the execution effect; The policy optimization module is used to enhance the learning of the parameters of the time series anomaly detection algorithm and the policy generator based on the policy execution feedback, forming a closed-loop optimization; The human-computer collaboration module provides policy review, log query, exception confirmation and policy rollback functions.
2. The intelligent collaborative network security emergency response device for a new type of power system according to claim 1 is characterized in that: The edge probe acquisition module captures power communication data streams in real time through high-frequency and low-latency packet capture, and uses a multi-protocol parsing engine to extract protocol and device behavior characteristics, including protocol type, data field behavior pattern, communication periodicity characteristics, and device access topology. Convert the features of different devices and protocols into feature vectors in a unified format.
3. The intelligent collaborative network security emergency response device for a new type of power system according to claim 1 is characterized in that: The intelligent analysis module performs behavioral anomaly detection on the data collected by the edge probe acquisition module based on the time series anomaly detection algorithm, and performs attack behavior identification and risk classification in combination with the vulnerability database; The vulnerability database includes CVE vulnerability mapping and protocol weakness modeling for key power system equipment; The risk rating output includes: Attack type tags: fake message, denial of service, replay; Attack confidence score.
4. The intelligent collaborative network security emergency response device for a new type of power system according to claim 1 is characterized in that: The policy execution module implements the issuance and execution of response policies by calling the SDN controller or network policy engine, including blocking the communication IP and port of abnormal devices and dynamically updating the access control list (ACL) policy; and after the policy is executed, it provides feedback on the policy success rate, network reconstruction delay and communication stability change indicators.
5. The intelligent collaborative network security emergency response device for a new type of power system according to claim 1 is characterized in that: The strategy optimization module, based on feedback information after strategy execution, enhances learning and training of the anomaly detection algorithm and strategy generator in the intelligent analysis module, thereby achieving closed-loop tuning and adaptive evolution of the detection and response system.
6. The intelligent collaborative network security emergency response device for a new type of power system according to claim 1 is characterized in that: The human-machine collaboration module provides an interactive platform including a graphical visual interface and intelligent decision-making suggestions, supports automatic generation of response suggestions and logs, supports manual review and policy modification by operation and maintenance personnel, and supports linkage with the SOC platform for real-time alarms and notifications.
7. An intelligent collaborative network security emergency response method for a new power system, using the intelligent collaborative network security emergency response device for a new power system according to any one of claims 1 to 6, comprising the following steps: S1, the edge probe acquisition module captures the power communication data stream in real time, extracts protocol features and device behavior features, and generates standardized feature vectors; S2, the intelligent analysis module applies a time series anomaly detection algorithm to the feature vectors, combines the device vulnerability knowledge base and the attack graph database to perform attack identification and risk classification, and outputs the attack type, confidence level, and potentially affected devices; S3. For identified high-risk events, the digital twin sandbox simulation module is activated to generate simulated attack scenarios using the network attack simulator and to assess potential business impact using the power business impact assessor. S4. The policy generator calculates the degree of impact on the power services of the equipment based on the deduction results and obtains the equipment isolation policy; S5. The policy execution module automatically executes response actions at the edge node according to the policy priority and collects execution effect data; S6, the strategy optimization module dynamically adjusts the anomaly detection model and response strategy generator based on strategy execution feedback through reinforcement learning to form a closed-loop optimization; S7. The human-machine collaboration module provides interactive functions such as policy review, exception confirmation, and policy rollback to support the collaborative response of the system and operation and maintenance personnel.
8. The intelligent collaborative network security emergency response method for a new type of power system according to claim 7 is characterized in that: The digital twin sandbox deduction module specifically includes the following steps: S31, Network Attack Simulator, uses a combination of rule-driven and data-driven attack modeling to simulate network attack behaviors in a simulation environment; S32, the power business impact assessor, calculates the business impact of infected devices in attack scenarios, including business indicators such as voltage deviation and equipment overload risk index; The voltage deviation The calculation formula is as follows: ; Indicates the voltage amplitude of the device after the attack. Indicates the node rated voltage; The equipment overload risk index The calculation formula is as follows: ; Indicates the actual operating power of the device. Indicates the rated power of the device. Indicates the duration of the overload caused by the attack. Indicates the maximum overload time allowed by the device, min (*) indicates the minimum value; S33. The policy generator generates a device isolation policy based on the deduction results of the network attack simulator and the degree of impact on the device business.
9. The intelligent collaborative network security emergency response method for a new type of power system according to claim 8 is characterized in that: Generating a device isolation strategy comprises the following steps: S331. Calculate device isolation scores based on device business impact and device level : , D l Indicates the device level, which is determined by the importance of the device. α and β are weighted difference parameters. S332, based on the device isolation score Matching isolation strategies; like , immediately carry out physical isolation; like , perform logical isolation; like , only protocol-level isolation; like , no action is taken; described 、 、 is the threshold parameter.
Citation Information
Patent Citations
Network security protection method and system
CN117879970A
Power grid safety control method and system based on twin sandbox
CN118797626A
Power distribution network symbiosis simulation system and method based on digital twinning
CN119419954A
Network security attack and defense confrontation scene generation system for novel power system
CN119420556A
AIot-based cloud network side end collaborative reasoning system
CN120012930A
Cited By
Heterogeneous gateway management method, device and equipment based on large model agent and medium
CN121462436A
Smart home security protection method and device based on sandbox
CN122513207A