A smart collaborative network security emergency response device and method for new power systems
By combining edge probes and digital twin sandbox modules, power network attacks can be identified in real time and isolation strategies can be generated, solving the problem of delayed response to complex attacks in power network security and achieving efficient and accurate emergency response.
Patent Information
- Application Number
- CN202510869913.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-26
- Publication Date
- 2025-12-02
- Estimated Expiration
- 2045-06-26
AI Technical Summary
Existing power network security protection measures are insufficient to cope with complex attack evolution, have lagging event identification, lack simulation verification mechanisms, have long response chains, lack edge collaborative intelligence, and are unable to meet the real-time requirements of power business.
An edge probe module is used to capture power communication data in real time. Combined with an intelligent analysis module, attack identification and risk classification are performed. A digital twin sandbox is used to simulate network attack behavior, calculate the impact on power services, generate equipment isolation policies, and execute response policies according to priority through a policy execution module to form a closed-loop optimization.
It significantly improves the intelligence and effectiveness of network security incident detection, simulation and response, reduces the need for labeled data, and provides a high-precision and low-cost emergency response solution.
Smart Images

Figure CN120455158B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of artificial intelligence and power network technology, and in particular to an intelligent collaborative network security emergency response device and method for new power systems. Background Technology
[0002] Against the backdrop of "dual carbon" goals and energy transition, new power systems are widely adopting information technology to achieve intelligent control. As systems such as relay protection, dispatch automation, and condition monitoring evolve towards a "cloud-edge-device" architecture, their communication networks are becoming increasingly complex.
[0003] Current power network security protection measures mainly include firewalls, intrusion detection systems, and access control, but they have the following shortcomings: static rule matching, which is difficult to cope with complex attack evolution; event identification is lagging behind, which is difficult to meet the real-time requirements of power business; there is a lack of simulation verification mechanism, resulting in insufficient policy controllability; and the response chain is long, lacking edge collaborative intelligence. Summary of the Invention
[0004] In view of this, the purpose of this invention is to provide an intelligent collaborative network security emergency response device and method for new power systems. Through an improved dynamic weight fusion mechanism and meta-learning online optimization, the model can be quickly adapted with only a small number of samples, significantly reducing the need for labeled data. This provides an innovative solution for intelligent diagnosis of power equipment that combines high accuracy, strong adaptability and low implementation cost.
[0005] To achieve the above objectives, the present invention adopts the following technical solution: an intelligent collaborative network security emergency response device for new power systems, comprising: an edge probe acquisition module, an intelligent analysis module, and a digital twin sandbox simulation module;
[0006] The edge probe acquisition module is used to capture power communication data streams in real time, and the power communication data streams include protocol characteristics and device behavior characteristics.
[0007] The intelligent analysis module uses a time series anomaly detection algorithm and a vulnerability database to identify attacks and classify risks in the collected data.
[0008] The digital twin sandbox simulation module includes:
[0009] A network attack simulator used to simulate network attack behavior;
[0010] The power business impact assessor is used to calculate business indicators such as voltage deviation and equipment overload risk index caused by attacks.
[0011] The strategy generator is used to calculate the degree to which devices are affected by business based on the sandbox simulation results and obtain device isolation strategies.
[0012] The strategy execution module is deployed on edge nodes, executes response strategies according to priority, and provides feedback on the execution results;
[0013] The strategy optimization module is used to enhance the parameters of the time series anomaly detection algorithm and the policy generator based on policy execution feedback, forming a closed-loop optimization.
[0014] The human-machine collaboration module provides functions such as policy review, log query, anomaly confirmation, and policy rollback.
[0015] In a preferred embodiment, the edge probe acquisition module captures power communication data streams in real time through high-frequency, low-latency packet capture, and uses a multi-protocol parsing engine to extract protocol behavior features and device behavior features, including protocol type, data field behavior patterns, communication periodicity features, and device access topology; and transforms the features of different devices and protocols into feature vectors in a unified format.
[0016] In a preferred embodiment, the intelligent analysis module performs behavioral anomaly detection on the data collected by the edge probe acquisition module based on a time-series anomaly detection algorithm, and combines it with a vulnerability database to identify attack behaviors and classify risks; the vulnerability database includes CVE vulnerability mapping and protocol weakness modeling for key power system equipment; the risk rating output includes:
[0017] Attack type tags: spoofed messages, denial of service, replay;
[0018] Attack confidence score.
[0019] In a preferred embodiment, the policy execution module issues and executes response policies by calling the SDN controller or network policy engine, including: blocking the communication IP and port of abnormal devices and dynamically updating the Access Control List (ACL) policy; and feeding back policy success rate, network reconstruction latency, and communication stability change indicators after policy execution.
[0020] In a preferred embodiment, the policy optimization module, based on feedback information after policy execution, enhances the training of the anomaly detection algorithm and policy generator in the intelligent analysis module to achieve closed-loop optimization and adaptive evolution of the detection and response system.
[0021] In a preferred embodiment, the human-machine collaboration module provides an interactive platform including a graphical visual interface and intelligent decision suggestions, supports automatic generation of response suggestions and logs, supports manual review and policy modification by operation and maintenance personnel, and supports linkage with the SOC platform for real-time alarms and notifications.
[0022] This invention also provides an intelligent collaborative network security emergency response method for new power systems, employing the aforementioned intelligent collaborative network security emergency response device for new power systems, comprising the following steps:
[0023] S1. The edge probe acquisition module captures power communication data streams in real time, extracts protocol features and device behavior features, and generates standardized feature vectors.
[0024] S2, the intelligent analysis module applies a time series anomaly detection algorithm to the feature vectors, and combines the device vulnerability knowledge base and attack graph database to identify attacks and classify risks, outputting the attack type, confidence level and potential affected devices;
[0025] S3. For identified high-risk events, activate the digital twin sandbox simulation module to generate simulated attack scenarios through a network attack simulator and assess the potential business impact through a power business impact assessor.
[0026] S4. Based on the simulation results, the strategy generator calculates the degree of impact on the equipment's power business and obtains the equipment isolation strategy.
[0027] S5. The strategy execution module automatically executes response actions at edge nodes according to strategy priority and collects execution effect data;
[0028] S6. The strategy optimization module dynamically adjusts the anomaly detection model and response strategy generator through reinforcement learning based on policy execution feedback, forming a closed-loop optimization.
[0029] The S7 human-machine collaboration module provides interactive functions such as policy review, anomaly confirmation, and policy rollback to support collaborative responses between the system and maintenance personnel.
[0030] In a preferred embodiment, the digital twin sandbox simulation module specifically includes the following steps:
[0031] S31, Network Attack Simulator, adopts a combination of rule-driven and data-driven attack modeling methods to simulate network attack behavior in a simulation environment;
[0032] S32, Power Business Impact Assessor, calculates the business impact of infected devices under attack scenarios, including business indicators such as voltage deviation and device overload risk index;
[0033] The voltage deviation The calculation formula is as follows:
[0034] ;
[0035] This indicates the voltage amplitude after a device attack. Indicates the node's rated voltage;
[0036] The equipment overload risk index The calculation formula is as follows:
[0037] ;
[0038] Indicates the actual operating power of the equipment. Indicates the rated power of the equipment. This indicates the duration of the overload caused by the attack. Indicates the maximum allowable overload time of the device;
[0039] S33. The policy generator generates device isolation policies based on the simulation results of network attack simulators and the degree of impact on device services.
[0040] In a preferred embodiment, the generation device isolation strategy includes the following steps:
[0041] S331. Calculate device isolation score based on device business impact and device level. :
[0042] ,
[0043] D l The equipment level is determined by its importance, with α and β being weighted difference parameters used to balance the weights of the three indicators; S332, based on equipment isolation score. Matching isolation strategies;
[0044] like Immediately implement physical isolation;
[0045] like Perform logical isolation;
[0046] like Only protocol-level isolation;
[0047] like If so, no action will be taken;
[0048] The , , This is the threshold parameter.
[0049] Compared with existing technologies, this invention has the following advantages: Addressing the complex and dynamic communication environment of new power systems, this invention proposes an edge detection method based on multi-protocol feature extraction and device behavior modeling, improving detection accuracy. It introduces digital twin sandbox simulation into power system network security protection, comprehensively simulating network attack behavior and its impact on power services. This allows for the prediction of changes in indicators such as voltage deviation, frequency overruns, and equipment overload before an actual attack occurs, improving the accuracy of response strategy formulation and effectively avoiding the risk of service interruption caused by excessive isolation. This invention can significantly improve the intelligence and effectiveness of network security event detection, simulation, and response, providing practical technical support for the safe operation and maintenance of new power systems. Attached Figure Description
[0050] Figure 1 This is a schematic diagram of the overall system structure of an intelligent collaborative network security emergency response device for a new type of power system, provided for the application.
[0051] Figure 2 A flowchart illustrating a method for an intelligent collaborative network security emergency response device for a new type of power system, provided in the application. Detailed Implementation
[0052] The present invention will be further described below with reference to the accompanying drawings and embodiments.
[0053] It should be noted that the following detailed descriptions are illustrative and intended to provide further explanation of this application. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains.
[0054] It should be noted that the terminology used herein is for the purpose of describing particular implementations only and is not intended to limit the exemplary implementations according to this application; as used herein, the singular form is intended to include the plural form as well, unless the context clearly indicates otherwise; furthermore, it should be understood that when the terms “comprising” and / or “including” are used in this specification, they indicate the presence of features, steps, operations, devices, components and / or combinations thereof.
[0055] This invention discloses an intelligent collaborative network security emergency response device for novel power systems, with reference to... Figure 1 It includes: an edge probe acquisition module, an intelligent analysis module, and a digital twin sandbox simulation module.
[0056] The edge probe acquisition module is used to capture power communication data streams in real time and extract protocol features and device behavior features, including protocol type and data field behavior patterns.
[0057] The intelligent analysis module, based on time series anomaly detection algorithms and a vulnerability database, performs attack identification and risk classification on the collected data; the vulnerability database is specifically a power system network security vulnerability database.
[0058] The digital twin sandbox simulation module includes:
[0059] Network attack simulators are used to simulate network attack behaviors, such as forging relay protection device sampling values, GOOSE message replay attacks, and DNP3 protocol master station spoofing attacks, and other new types of power system network attack behaviors.
[0060] The power service impact assessor is used to evaluate the impact of network behavior on the power service of equipment, including calculating service indicators such as voltage deviation caused by attacks and equipment overload risk index.
[0061] The strategy generator is used to calculate the degree to which devices are affected by business based on the results of sandbox simulations, and to obtain device isolation strategies.
[0062] The strategy execution module is deployed on edge nodes, executes response strategies according to priority, and provides feedback on the execution results.
[0063] The strategy optimization module is used to enhance the parameters of the time series anomaly detection algorithm and the strategy generator based on policy execution feedback, forming a closed-loop optimization.
[0064] The human-machine collaboration module provides functions such as policy review, log query, anomaly confirmation, and policy rollback.
[0065] More specifically, the aforementioned intelligent collaborative network security emergency response device for new power systems includes an edge probe acquisition module with high-frequency, low-latency packet capture capabilities. This module captures power communication data streams in real time and employs a multi-protocol parsing engine to extract protocol and device behavioral characteristics, including protocol type (e.g., IEC 61850, MODBUS, DNP3), data field behavior patterns, communication periodicity characteristics, and device access topology. Simultaneously, a sequence encoding method based on dynamic feature windows is used to transform the characteristics of different devices and protocols into a unified feature vector format, facilitating subsequent processing by artificial intelligence models.
[0066] Transforming the features of different devices and protocols into a unified format feature vector is achieved through the following steps:
[0067] 1. Dynamic padding; pads variable-length feature lists from different protocols / devices to a uniform length (zero padding up to the maximum dimension of 128).
[0068] 2. Dimensionality reduction: Use PCA (Principal Component Analysis) to compress high-dimensional sparse features to the target dimension (e.g., 64 dimensions).
[0069] 3. Normalization: Perform Min-Max normalization on numerical features to eliminate the influence of dimensions.
[0070] More specifically, the aforementioned intelligent collaborative network security emergency response device for new power systems is characterized in that the intelligent analysis module performs behavioral anomaly detection on data collected by edge probes based on a time-series anomaly detection algorithm, and combines an equipment vulnerability knowledge base and an attack graph database to identify attack behaviors and classify risks. The time-series anomaly detection algorithm is an LSTM variational autoencoder (VAE), a Transformer predictive residual model, or other self-supervised anomaly detection methods; the vulnerability knowledge base includes CVE vulnerability mapping and protocol weakness modeling for key power system equipment; the risk rating output includes:
[0071] Attack type tags (spoofed messages, denial of service, replay, etc.);
[0072] Attack confidence score.
[0073] More specifically, the aforementioned intelligent collaborative network security emergency response device for new power systems is characterized in that the digital twin sandbox simulation specifically includes the following steps:
[0074] S31, Network Attack Simulator, adopts a combination of rule-driven and data-driven attack modeling methods to simulate network attack behaviors in a simulation environment, including but not limited to Forged Sampled Value (SV) packets, GOOSE packet tampering, link blocking and other attack methods; the attack simulator outputs a list of infected devices (including device ID, IP address, asset level).
[0075] S32, Power Business Impact Assessor, calculates the business impact of infected devices under attack scenarios, including business indicators such as voltage deviation and device overload risk index;
[0076] The formula for calculating voltage deviation is as follows:
[0077] ;
[0078] This indicates the voltage amplitude after a device attack. This indicates the node's rated voltage.
[0079] The formula for calculating the equipment overload risk index is as follows:
[0080] ;
[0081] Indicates the actual operating power of the equipment. Indicates the rated power of the equipment. Indicates the duration (in minutes) of overload caused by the attack. Indicates the maximum allowable overload time (in minutes) of the device, preferably The value is 5.
[0082] S33. The policy generator generates device isolation policies based on the simulation results of network attack simulators and the degree of impact on device services.
[0083] In S31, the rule-driven module process is as follows:
[0084] Constructing deterministic attacks based on an attack knowledge base:
[0085] Based on protocol vulnerabilities and CVE vulnerability databases in power safety standards such as IEC62351, corresponding rule expressions are formed.
[0086] Data-driven module process:
[0087] Probabilistic attack evolution can be learned through attack behavior learning. Examples include: abnormal patterns in real network traffic (such as port scans with entropy mutations) and APT attack sequences captured by honeypots.
[0088] Attack generation process:
[0089] 1. Initial Seed: Retrieve basic attack templates from the rule base.
[0090] 2. Mutation strategy:
[0091] 2.1 Field fuzzing test (modify the lower 4 bits of the Modbus function code)
[0092] 2.2 Co-simulation process for timing perturbations (random delay ± 20% message interval):
[0093] 1. Initialization: The rules module loads the vulnerability template corresponding to the attack.
[0094] 2. Enhancement: The data module injects the learned substation equipment response characteristics.
[0095] 3. Execution:
[0096] Sending malformed messages in a digital twin environment;
[0097] Monitor whether the protection device erroneously sends a TRIP signal.
[0098] 4. Feedback:
[0099] If successful, the attack characteristics are recorded in the rule base.
[0100] If it fails, adjust the enhancement strategy for the data module.
[0101] In S33, generating a device isolation policy includes the following steps:
[0102] S331. Calculate device isolation score based on device business impact and device level. :
[0103] ,
[0104] D l Indicates the equipment level, determined by the importance of the equipment. S332, Based on equipment isolation score. The matching isolation strategies are shown in Table 1:
[0105] Table 1:
[0106]
[0107] , , The threshold parameter is continuously optimized during reinforcement learning.
[0108] The policy execution module issues and executes response policies by calling the SDN controller or network policy engine, including blocking abnormal device communication IPs and ports and dynamically updating access control lists (ACLs); and after policy execution, it provides feedback on indicators such as policy success rate, network reconstruction latency, and changes in communication stability.
[0109] The policy optimization module, based on the feedback information after policy execution, reinforces the anomaly detection algorithm and policy generator in the intelligent analysis module to achieve closed-loop tuning and adaptive evolution of the detection and response system. Reinforcement training optimizes the policy generator by using the generated policy and its post-execution feedback information as samples; simultaneously, it optimizes the anomaly detection algorithm in the intelligent analysis module.
[0110] The human-machine collaboration module provides an interactive platform that includes a graphical visual interface and intelligent decision suggestions. It supports automatic generation of response suggestions and logs, manual review and policy modification by operation and maintenance personnel, and real-time alarms and notifications in conjunction with the SOC platform.
[0111] Secondly, this invention discloses a method based on an intelligent collaborative network security emergency response device for a new type of power system, with reference to... Figure 2 This includes the following steps:
[0112] S1. The edge probe acquisition module captures power communication data streams in real time, extracts protocol features and device behavior features, and generates standardized feature vectors.
[0113] S2, the intelligent analysis module applies a time series anomaly detection algorithm to the feature vectors, and combines the device vulnerability knowledge base and attack graph database to identify attacks and classify risks, outputting the attack type, confidence level and potential affected devices;
[0114] S3. For identified high-risk events, activate the digital twin sandbox simulation module to generate simulated attack scenarios through a network attack simulator and assess the potential business impact through a power business impact assessor.
[0115] S4. Based on the simulation results, the strategy generator calculates the degree of impact on the equipment's power business and obtains the equipment isolation strategy.
[0116] S5. The strategy execution module automatically executes response actions at edge nodes according to strategy priority and collects execution effect data;
[0117] S6. The strategy optimization module dynamically adjusts the anomaly detection model and response strategy generator through reinforcement learning based on policy execution feedback, forming a closed-loop optimization.
[0118] The S7 human-machine collaboration module provides interactive functions such as policy review, anomaly confirmation, and policy rollback to support collaborative responses between the system and maintenance personnel.
[0119] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. A smart collaborative network security emergency response method for new power systems, characterized in that, Includes the following steps: S1. The edge probe acquisition module captures power communication data streams in real time, extracts protocol features and device behavior features, and generates standardized feature vectors. S2, the intelligent analysis module applies a time series anomaly detection algorithm to the feature vectors, and combines the device vulnerability knowledge base and attack graph database to identify attacks and classify risks, outputting the attack type, confidence level and potential affected devices; S3. For identified high-risk events, activate the digital twin sandbox simulation module to generate simulated attack scenarios through a network attack simulator and assess the potential business impact through a power business impact assessor. S4. Based on the simulation results, the strategy generator calculates the degree of impact on the equipment's power business and obtains the equipment isolation strategy. S5. The strategy execution module automatically executes response actions at edge nodes according to strategy priority and collects execution effect data; S6. The strategy optimization module dynamically adjusts the anomaly detection model and response strategy generator through reinforcement learning based on policy execution feedback, forming a closed-loop optimization. S7, the human-machine collaboration module provides policy review, anomaly confirmation, and policy rollback interaction functions to support collaborative response between the system and operation and maintenance personnel; The digital twin sandbox simulation module specifically includes the following steps: S31, Network Attack Simulator, adopts a combination of rule-driven and data-driven attack modeling methods to simulate network attack behavior in a simulation environment; S32, Power Business Impact Assessor, calculates the business impact of infected devices under attack scenarios, including: voltage deviation and device overload risk index; The voltage deviation The calculation formula is as follows: , This indicates the voltage amplitude after a device attack. Indicates the node's rated voltage; The equipment overload risk index The calculation formula is as follows: , Indicates the actual operating power of the equipment. Indicates the rated power of the equipment. This indicates the duration of the overload caused by the attack. This indicates the maximum allowable overload time for the device, and min(*) indicates taking the minimum value; S33. The policy generator generates device isolation policies based on the simulation results of network attack simulators and the degree of impact on device services.
2. The intelligent collaborative network security emergency response method for new power systems according to claim 1, characterized in that, The generated device isolation strategy includes the following steps: S331. Calculate device isolation score based on device business impact and device level. : , The equipment level is determined by its importance, with α and β being weighted difference parameters; S332, based on equipment isolation score. Matching isolation strategies; like Immediately implement physical isolation; like Perform logical isolation; like Only protocol-level isolation; like If so, no action will be taken; The , , This is the threshold parameter.
3. A smart collaborative network security emergency response device for new power systems, characterized in that, The method for intelligent collaborative network security emergency response for new power systems as described in claim 1 or 2 includes: an edge probe acquisition module, an intelligent analysis module, and a digital twin sandbox simulation module. The edge probe acquisition module is used to capture power communication data streams in real time, and the power communication data streams include protocol characteristics and device behavior characteristics. The intelligent analysis module uses a time series anomaly detection algorithm and a vulnerability database to identify attacks and classify risks in the collected data. The digital twin sandbox simulation module includes: A network attack simulator used to simulate network attack behavior; The power business impact assessor is used to calculate business indicators such as voltage deviation and equipment overload risk index caused by attacks. The strategy generator is used to calculate the degree to which devices are affected by business based on the sandbox simulation results and obtain device isolation strategies. The strategy execution module is deployed on edge nodes, executes response strategies according to priority, and provides feedback on the execution results; The strategy optimization module is used to enhance the parameters of the time series anomaly detection algorithm and the policy generator based on policy execution feedback, forming a closed-loop optimization. The human-machine collaboration module provides functions such as policy review, log query, anomaly confirmation, and policy rollback.
4. The intelligent collaborative network security emergency response device for a new type of power system according to claim 3, characterized in that, The edge probe acquisition module captures power communication data streams in real time through high-frequency, low-latency packet capture, and uses a multi-protocol parsing engine to extract protocol behavior features and device behavior features, including protocol type, data field behavior patterns, communication periodicity features, and device access topology. Transform the characteristics of different devices and protocols into feature vectors in a unified format.
5. The intelligent collaborative network security emergency response device for a new type of power system according to claim 3, characterized in that, The intelligent analysis module performs behavioral anomaly detection on the data collected by the edge probe acquisition module based on the time series anomaly detection algorithm, and combines the vulnerability database to identify attack behavior and classify risks. The vulnerability database includes CVE vulnerability mapping and protocol weakness modeling for critical equipment in the power system. The risk rating output includes: Attack type tags: spoofed messages, denial of service, replay; Attack confidence score.
6. The intelligent collaborative network security emergency response device for a new type of power system according to claim 3, characterized in that, The policy execution module issues and executes response policies by calling the SDN controller or network policy engine, including blocking abnormal device communication IPs and ports and dynamically updating access control list (ACL) policies; and after policy execution, it provides feedback on policy success rate, network reconstruction latency, and communication stability change indicators.
7. The intelligent collaborative network security emergency response device for a new type of power system according to claim 3, characterized in that, The strategy optimization module, based on feedback information after strategy execution, enhances the training of the anomaly detection algorithm and strategy generator in the intelligent analysis module to achieve closed-loop optimization and adaptive evolution of the detection and response system.
8. The intelligent collaborative network security emergency response device for a new type of power system according to claim 3, characterized in that, The human-machine collaboration module provides an interactive platform that includes a graphical visual interface and intelligent decision suggestions. It supports automatic generation of response suggestions and logs, manual review and policy modification by operation and maintenance personnel, and real-time alarms and notifications in conjunction with the SOC platform.
Citation Information
Patent Citations
Network security protection method and system
CN117879970A