Network security monitoring and analyzing system and method
By deploying a network security monitoring and analysis platform and gateway in the power system, and adopting communication proxy mode and ad hoc network technology, the resource waste and blind spots of isolated network management in the power system network security analysis are solved, and security monitoring and blocking of terminals and isolated networks are realized, and the security and reliability of the power system are improved.
Patent Information
- Application Number
- CN202510793691.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-13
- Publication Date
- 2025-08-12
AI Technical Summary
Network security analysis of power systems faces the problem of difficulty in achieving wide-area distributed multi-level analysis, blind spots in security management of isolated networks, and waste of network security analysis of small and micro terminals.
Deploy a network security monitoring and analysis platform and gateway, adopt a communication proxy mode, build a communication proxy channel through an ad hoc network mode, realize secure data collection and centralized analysis of terminals and isolated networks, and use a network security gateway to perform security blocking and interference.
The network security monitoring and security blocking of a large number of terminals and isolated networks has been achieved, the reliability and security of the power system has been improved, and the resources of terminals and isolated networks have been saved.
Smart Images

Figure CN120474815A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of power network security, and in particular to a network security monitoring and analysis system and method. Background Art
[0002] With the rapid development of new power systems and digital grids, the cybersecurity landscape is evolving, characterized by increasingly blurred boundaries, significantly increased exposure, and heightened risks to system security operations. In this context, a single node security vulnerability can trigger cascading failures, impacting the safe and stable operation of the power system. Therefore, timely monitoring of the system's own cybersecurity status and addressing external cybersecurity threats are crucial to ensuring the secure and reliable supply of energy and electricity.
[0003] Power systems are widely distributed, have complex network structures, a large number of devices, and require high real-time performance and stability. Using traditional Internet-based network security analysis methods to implement network security analysis of power systems presents the following challenges:
[0004] (1) It is difficult to implement network security analysis and processing for a wide-area distributed multi-level power system. Most Internet business systems adopt a B / S (Browser / Server) architecture, which is a centralized business system. Good results can be achieved by concentrating high-intensity network security monitoring and defense at the network boundary entrances and exits of the system. However, the power system (such as the power Internet of Things system) is a distributed business system. The system involves different security partitions and various business systems horizontally, and the system involves master stations, substations / power plants, distribution rooms / distribution cabinets at all levels in depth. The power system has many points and a complex network structure. The single-point security monitoring and defense model using the Internet cannot be applied to the wide-area distributed power system environment. Performing independent security analysis and processing at each network boundary entrance and exit of the power system will result in a waste of resources.
[0005] (2) It is difficult to achieve security management of massive distributed isolated networks. The power system adopts a hierarchical dispatching and control operation mode, which leads to the existence of a large number of isolated networks in the power system. Taking the substation integrated automation system as an example, it adopts a three-layer two-network network architecture. The three layers are the station control layer, the interval layer, and the process layer, and the two networks are the station control layer network and the process layer network. The station control layer network and the dispatching master station, as well as the station control layer network and the process layer network, communicate through the application layer gateway, resulting in the inability to directly route communication between the station control layer network and the process layer network, and between the station control layer network and the dispatching master station, resulting in business islands. It is difficult to send the network security information of the isolated network to the dispatching master station, and it is also difficult to send the network security scanning function of the dispatching master station to the isolated network. The traditional Internet-style network security centralized control model is not applicable to the network security analysis and processing of isolated networks, resulting in blind spots in network security management.
[0006] (3) It is difficult to implement network security analysis for a large number of small and micro terminals. Compared with Internet business systems, power Internet of Things terminal devices have fewer computing resources and their software functions have been heavily tailored, making it impossible to install professional network security functions on them. This makes it difficult to implement professional network security analysis and processing for small and micro terminals. On the other hand, there are many different brands of power Internet of Things terminals, and the implementation methods of the terminal's software and hardware architecture vary. Deploying network security analysis functions on the terminals will face a huge workload of adaptation. Summary of the Invention
[0007] Based on this, it is necessary to provide a network security monitoring and analysis system and method to address the above technical problems, which can realize network security monitoring and security blocking of a large number of terminals and isolated networks, and improve the reliability and safety of the power system.
[0008] In a first aspect, the present application provides a network security monitoring and analysis system, comprising a network security monitoring and analysis platform and a plurality of network security gateways; the network security monitoring and analysis platform is deployed in a power system distributed platform, and the network security gateways are deployed at the network exits of the power system distributed platform, terminals, and isolated networks; the network security gateways adopt a communication proxy mode, and the network security gateways establish a communication proxy channel for application data through an ad hoc network mode; wherein:
[0009] Network security gateway, used to collect network security data from terminals and isolated networks, and transmit the network security data to the network security monitoring and analysis platform;
[0010] The network security monitoring and analysis platform is used to conduct security analysis on network security data. If an abnormal device is detected, a network security blocking instruction is sent to the corresponding network security gateway. An abnormal device refers to a device that has been compromised, infected by a virus, or launched a network attack.
[0011] The network security gateway is also used to work with border network security devices based on network security blocking instructions to securely block the source of network attacks, or to perform targeted interference on the source of network attacks according to preset interference strategies.
[0012] In one embodiment, the network security monitoring and analysis platform is further used to:
[0013] Performing a baseline check based on network security data to obtain a first detection result; the baseline check is used to detect whether the network traffic type, network security log, and transmission file are abnormal;
[0014] Conduct behavioral analysis based on network security data to obtain a second detection result; behavioral analysis is used to detect whether the device's dynamic behavior and behavioral profile are abnormal;
[0015] Performing network threat analysis based on network security data to obtain a third detection result;
[0016] Based on the first detection result, the second detection result, and the third detection result, a security assessment is performed on the network security data.
[0017] In one embodiment, when the network security gateway is deployed, it is configured with the communication address of the network security monitoring and analysis platform and the communication address of the nearest next-hop network security gateway.
[0018] In one of the embodiments, when the network security gateway actively communicates with the network security monitoring and analysis platform, it establishes a relay channel with the nearest next-hop network security gateway based on a pre-configured communication address; encapsulates the data to be sent through the application layer data proxy based on the communication proxy mode; and sends the encapsulated data to the next-hop network security gateway through an encryption strategy based on the relay channel.
[0019] In one embodiment, the network security monitoring and analysis platform, while actively communicating with the target network security gateway, retrieves the correspondence between the target network security gateway and the next-hop network security gateway, and transmits the instructions to be transmitted to the target network security gateway through the network security gateway deployed on the power system distributed platform according to the correspondence.
[0020] In one embodiment, the network security gateway collects network security data of terminals and isolated networks by combining passive monitoring and active detection.
[0021] In a second aspect, the present application further provides a network security monitoring and analysis method, which is applied to the network security monitoring and analysis system described in the first aspect above; the system includes a network security monitoring and analysis platform and several network security gateways; the network security monitoring and analysis platform is deployed in the power system distributed platform, and the network security gateway is deployed at the network exit of the power system distributed platform, terminal, and isolated network; the network security gateway adopts a communication proxy mode, and each network security gateway establishes a communication proxy channel for application data through an ad hoc network mode; the method includes:
[0022] The network security gateway collects network security data from terminals and isolated networks, and transmits the network security data to the network security monitoring and analysis platform;
[0023] The network security monitoring and analysis platform conducts security analysis on network security data. If an abnormal device is detected, it will send a network security blocking instruction to the network security gateway corresponding to the abnormal device. An abnormal device refers to a device that has been compromised, infected by a virus, or has launched a network attack.
[0024] Based on network security blocking instructions, the network security gateway works in conjunction with border network security devices to securely block the source of network attacks, or to perform targeted interference on the source of network attacks according to preset interference strategies.
[0025] In one embodiment, the network security monitoring and analysis platform performs security analysis on network security data, including:
[0026] The network security monitoring and analysis platform performs a baseline check based on the network security data to obtain a first detection result; the baseline check is used to detect whether the network traffic type, network security log, and transmission file are abnormal;
[0027] Conduct behavioral analysis based on network security data to obtain a second detection result; behavioral analysis is used to detect whether the device's dynamic behavior and behavioral profile are abnormal;
[0028] Performing network threat analysis based on network security data to obtain a third detection result;
[0029] Based on the first detection result, the second detection result, and the third detection result, a security assessment is performed on the network security data.
[0030] In one embodiment, the method further comprises:
[0031] When the network security gateway is deployed, it is configured with the communication address of the network security monitoring and analysis platform and the communication address of the nearest next-hop network security gateway.
[0032] In one embodiment, the method further comprises:
[0033] When the network security gateway actively communicates with the network security monitoring and analysis platform, it establishes a relay channel with the nearest next-hop network security gateway based on the pre-configured communication address; encapsulates the data to be sent through the application layer data proxy based on the communication proxy mode; and sends the encapsulated data to the next-hop network security gateway through the encryption strategy based on the relay channel.
[0034] The above-mentioned network security monitoring and analysis system and method include a network security monitoring and analysis platform and several network security gateways; the network security monitoring and analysis platform is deployed in the power system distributed platform, and the network security gateway is deployed at the network exit of the power system distributed platform, terminal and isolated network; the network security gateway adopts a communication proxy mode, and each network security gateway builds a communication proxy channel for application data through a self-organizing network mode; wherein: the network security gateway collects network security data of the terminal and the isolated network, and transmits the network security data to the network security monitoring and analysis platform; the network security monitoring and analysis platform performs security analysis on the network security data, and when an abnormal device is detected, sends a network security blocking instruction to the network security gateway corresponding to the abnormal device; the abnormal device refers to a compromised device, a virus-infected device or a device that launches a network attack; based on the network security blocking instruction, the network security gateway cooperates with the boundary network security device to securely block the source of the network attack, or perform targeted interference on the source of the network attack according to a preset interference strategy. Through this approach, a network security monitoring and analysis system is deployed on the basis of a wide-area distributed, multi-level power system. Centralized analysis and judgment are performed through the network security monitoring and analysis platform, and the network security gateway delegates the security analysis and judgment function to terminals or isolated networks. This eliminates the need to deploy independent security analysis functions on terminals or isolated networks, conserving resources on these terminals or isolated networks. This enables network security monitoring and security blocking for a large number of terminals and isolated networks, improving the reliability and safety of the power system. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments of the present application or related technical descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying any creative work.
[0036] Figure 1 A schematic diagram of a network security monitoring and analysis system according to an embodiment;
[0037] Figure 2 A schematic diagram of the structure of a network security monitoring and analysis system in another embodiment;
[0038] Figure 3 The figure is a flowchart of a network security monitoring and analysis method in one embodiment. DETAILED DESCRIPTION
[0039] In order to make the purpose, technical solutions and advantages of this application more clearly understood, the present application is further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0040] It should be noted that the terms "first", "second", etc. used in this application can be used to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish the first element from the second element. The terms "including" and "having" used in this application and any variations thereof are intended to cover non-exclusive inclusions. The term "plurality" used in this application refers to two or more. The term "and / or" used in this application refers to one of the solutions, or any combination of multiple solutions.
[0041] In an exemplary embodiment, Figure 1 As shown, a network security monitoring and analysis system is provided, which includes a network security monitoring and analysis platform 102 and several network security gateways 104; the network security monitoring and analysis platform 102 is deployed in the power system distributed platform, and the network security gateway 104 is deployed at the network exit of the power system distributed platform, terminal and isolated network; the network security gateway 104 adopts a communication proxy mode, and each network security gateway 104 builds a communication proxy channel for application data through a self-organizing network mode.
[0042] The power system distributed platform refers to a platform with distributed data management and coordinated control capabilities within the power system. Taking the power Internet of Things system as an example, the power system distributed platform refers to the IoT platform deployed in various locations. Terminals refer to power Internet of Things terminals such as electricity meters, oil chromatography sensors, current sensors, voltage sensors, and temperature and humidity sensors. Network security gateway 104 refers to the power Internet of Things gateway.
[0043] It can be understood that in terms of system deployment architecture, this embodiment sets up a network security monitoring and analysis platform 102 on the power system distributed platform to realize centralized analysis of network security risks; and deploys a network security gateway 104 at the network exit of the power system distributed platform, terminals and isolated networks to realize network security data collection, network security blocking and disposal, network security communication agent and other functions of terminals and isolated networks.
[0044] In terms of communication mode, the network security gateway 104 adopts the application layer data communication agent function. Through the self-organizing network mode, each network security gateway 104 builds a communication agent channel for application data, connects the distributed platform, terminal or isolated network of the power system to each other, and realizes application layer network communication between the platform side, terminal side and isolated network.
[0045] Optionally, network security gateways 104 communicate with each other via a VPN (Virtual Private Network) or a dedicated power network. The established communication proxy channel may be an encrypted tunnel within the VPN or the dedicated power network. The network security communication proxy may be implemented using technologies such as VPN and Socks5, or other methods, which are not limited in this embodiment.
[0046] Among them, the communication proxy mode can be understood as: the network security gateway 104 acts as an intermediate component between the terminal (or isolated network) and the network security monitoring and analysis platform 102, using the application layer data communication proxy function to forward, process and optimize communication data at the application layer protocol level.
[0047] The network security gateway 104 is used to collect network security data of terminals and isolated networks and transmit the network security data to the network security monitoring and analysis platform 102 .
[0048] The network security gateway 104 deployed at a terminal collects network security data from the terminal and transmits it to the network security monitoring and analysis platform 102 via the network between network security gateways 104. The network security gateway 104 deployed at an isolated network collects network security data from the isolated network and transmits it to the network security monitoring and analysis platform 102 via the network between network security gateways 104. Optionally, the network security gateway 104 supports access to the terminal and the interior of the isolated network via a trunk (aggregation port), enabling comprehensive monitoring and analysis of individual network data.
[0049] The network security monitoring and analysis platform 102 is used to conduct security analysis on network security data. When an abnormal device is detected, a network security blocking instruction is sent to the network security gateway 104 corresponding to the abnormal device; an abnormal device refers to a compromised device, a virus-infected device, or a device that initiates a network attack.
[0050] Regarding data collection and analysis, at least one network security analysis function is deployed on the network security monitoring and analysis platform 102. This function conducts security assessments on network security data, enabling centralized network security assessment and analysis. This approach eliminates the need to deploy robust network security functions on terminals and isolated networks, thus conserving network security investment. In specific implementations, the issuance of scanning commands and detection data, as well as the transmission of scanning results, are transmitted via the platform-side network security gateway 104 and the terminal (or isolated network)-side network security gateway 104. This enables transparent data transmission from various security tools deployed on the network security monitoring and analysis platform 102, thereby achieving network security monitoring effectiveness on terminals and isolated networks.
[0051] Once the network security monitoring and analysis platform 102 detects the existence of compromised devices, virus-infected devices, or devices that are launching network attacks in the network, it will initiate a network security blocking instruction to the network security gateway 104 of the terminal or isolated network, thereby blocking the network attack behavior in a timely manner.
[0052] The network security gateway 104 is also used to work with the border network security device based on the network security blocking instruction to securely block the network attack source, or to perform targeted interference on the network attack source according to a preset interference strategy.
[0053] After receiving a network security blocking instruction, the network security gateway 104 on the terminal or isolated network side collaborates with the border network security device to securely block the network attack source. Alternatively, based on its own preset jamming strategy (e.g., APR jamming, i.e., network disconnection attack), it conducts targeted jamming of the network attack source to prevent network attacks from the terminal layer to the platform layer. A border network security device is a network security device deployed at the network boundary to protect the internal network from external network attacks and unauthorized access. The border network security device is configured with at least one security blocking policy. By collaborating with the border network security device, the network security gateway 104 can leverage the security blocking policy on the border network security device to securely block the network attack source.
[0054] The aforementioned network security monitoring and analysis system is deployed on the basis of a wide-area distributed multi-level power system. Centralized analysis and judgment are performed through the network security monitoring and analysis platform 102, and the network security gateway 104 delegates the security analysis and judgment function to terminals or isolated networks. This eliminates the need to deploy independent security analysis functions on terminals or isolated networks, thus conserving resources on these terminals or isolated networks. This system can achieve network security monitoring and security blocking for a large number of terminals and isolated networks, thereby improving the reliability and safety of the power system.
[0055] In an exemplary embodiment, the network security monitoring and analysis platform 102 is also used to: perform a baseline check based on the network security data to obtain a first detection result; the baseline check is used to detect whether the network traffic type, the network security log, and the transmission file are abnormal; perform a behavioral analysis based on the network security data to obtain a second detection result; the behavioral analysis is used to detect whether the dynamic behavior of the device is abnormal and whether the behavioral profile is abnormal; perform a network threat analysis based on the network security data to obtain a third detection result; and perform a security assessment on the network security data based on the first detection result, the second detection result, and the third detection result.
[0056] Among them, the network security monitoring and analysis platform 102 deploys a variety of network security analysis functions, including but not limited to: threat intelligence linkage analysis, vulnerability scanning and analysis, virus scanning and analysis, attack chain analysis function, network traffic analysis, network security log analysis, network security tracing, network security disposal, automated response orchestration, trapping deployment, etc.
[0057] Based on a baseline check, the system detects abnormal network traffic types, network security logs, and transferred files. Optionally, it uses deep learning to classify network traffic and compares the classified network traffic types with pre-defined abnormal traffic types to determine whether the network traffic type is abnormal. Using the virus scanning and analysis function, it scans transferred files to determine whether they are abnormal. Using the network security log analysis function, it analyzes the current network security log to determine whether the network security log is abnormal.
[0058] Dynamic behavior analysis and terminal behavior profiling are used to detect abnormalities in device dynamic behavior and behavioral profiling. Network threat analysis is performed using threat intelligence linkage analysis, vulnerability scanning and analysis, virus scanning and analysis, attack chain analysis, and network security tracing to generate detection results.
[0059] Among them, if at least one of the following anomalies is detected in the target device, the target device will be determined as an abnormal device: abnormal network traffic type, abnormal network security log, abnormal transmission file, abnormal device dynamic behavior, abnormal behavior profile, and the presence of network threats.
[0060] Optionally, after receiving relevant network security data, the network security monitoring and analysis platform 102 conducts multi-dimensional in-depth analysis through multi-source data fusion, machine learning, attack chain, threat intelligence, etc., combined with the station control layer and process layer network collaboration, GOOSE network and SV network timing correlation, terminal behavior cross-network correlation and network security gateway 104 feature comparison and other judgment methods based on special architectures to discover hidden attack behaviors in the network.
[0061] In an exemplary embodiment, when the network security gateway 104 is deployed, it is configured with the communication address of the network security monitoring and analysis platform 102 and the communication address of the nearest next-hop network security gateway 104 .
[0062] During deployment, network security gateway 104 is configured with the communication address of network security monitoring and analysis platform 102, using ad hoc networking technology to build a virtual tunnel and employing SDN (Software Defined Network) technology for automatic routing. Furthermore, network security gateway 104 is configured with the communication address (e.g., IP address) of the nearest network security gateway 104 in the next-hop route, establishing reliable communication with network security monitoring and analysis platform 102 and ensuring efficient transmission of network traffic. In this embodiment, relay communication networking capabilities are utilized to connect data across widely distributed, multi-layered, isolated networks at the application layer, enabling centralized security management and control of these isolated networks.
[0063] In an exemplary embodiment, when the network security gateway 104 actively communicates with the network security monitoring and analysis platform 102, it establishes a relay channel with the nearest next-hop network security gateway 104 according to a pre-configured communication address; encapsulates the data to be sent through the application layer data proxy based on the communication proxy mode; and sends the encapsulated data to the next-hop network security gateway 104 through an encryption strategy based on the relay channel.
[0064] During active communication with network security monitoring and analysis platform 102, network security gateway 104 establishes a relay channel with the nearest next-hop network security gateway 104, encapsulates its own IP address and number, and the data to be sent through the application layer data proxy, and sends it to the next-hop network security gateway 104 using the encryption policy. Accordingly, the next-hop network security gateway 104 repeats the above process, ultimately sending the data to network security monitoring and analysis platform 102.
[0065] In an exemplary embodiment, the network security monitoring and analysis platform 102 retrieves the correspondence between the target network security gateway 104 and the next-hop network security gateway 104 during the process of actively communicating with the target network security gateway 104, and transmits the instructions to be transmitted to the target network security gateway 104 through the network security gateway 104 deployed on the power system distributed platform according to the correspondence.
[0066] Among them, in the process of actively communicating with the target network security gateway 104, the network security monitoring and analysis platform 102 retrieves the correspondence between the target network security gateway 104 and the next-hop network security gateway 104, and searches for the shortest path between the network security monitoring and analysis platform 102 and the target network security gateway 104 based on the correspondence between each network security gateway 104 and the next-hop network security gateway 104. The shortest path corresponds to at least two network security gateways 104. According to the shortest path, the <target network security gateway 104 IP address and number, instructions to be transmitted> are sent to the network security gateway 104 closest to the network security monitoring and analysis platform 102. The network security gateways 104 located on the shortest path transmit the instructions to be transmitted downward in turn until they are transmitted to the target network security gateway 104.
[0067] In this embodiment, the data proxy relay strategy based on the application layer enables the traditional power system communication network to fully upload and download various types of data without changing the traditional network architecture and security strategy.
[0068] In an exemplary embodiment, the network security gateway 104 collects network security data of terminals and isolated networks by combining passive monitoring and active detection.
[0069] Among them, network security data includes multiple types of network data, and various types of network data can be collected in combination with multiple methods. The network security data collected by the network security gateway 104 includes but is not limited to IP (Internet Protocol Address), MAC (Media Access Control Address), running services, open ports, security vulnerabilities, security logs, network traffic, etc. The methods of collecting network security data include passive monitoring and active detection. The passive monitoring collection method can not only realize the data collection of device operation logs and network security log information within the isolated network, but also realize the data collection of network security traffic information through network monitoring. It can also collect network security data sent by the network security agent (intelligent body) by opening a dedicated data monitoring port on the network security gateway 104. The active detection collection method is mainly based on the network scanning method to realize the collection of information such as IP, MAC, running services, open ports, and security vulnerabilities.
[0070] The network security gateway 104 accesses each network through a trunk, enabling data collection from each network segment on the terminal side. After collecting network security data, the network security gateway 104 performs preliminary analysis on the relevant information and sends the data to the network security monitoring and analysis platform 102 through a communication relay agent channel.
[0071] In an exemplary embodiment, referring to Figure 2 The network security monitoring and analysis system includes: platform layer, network layer and terminal layer. The platform layer includes the power system platform, the network layer includes VPN / power private network, and the terminal layer includes terminals and sites (i.e., isolated network).
[0072] In terms of system deployment architecture, a network security monitoring and analysis platform is set up in the distributed master station of the power system to realize centralized analysis and assessment of network security risks; a network security gateway is deployed at the network exits of the distributed platform, terminal and isolated network of the power system to realize network security data collection, network security blocking and disposal, network security communication agent and other functions on the terminal (or isolated network) side.
[0073] In terms of communication mode, the network security gateway adopts the application layer data communication agent function. The network security gateways build a communication agent channel for application data through the self-organizing network mode (for example, Figure 2 The encrypted tunnel in the network connects the distributed platforms, terminals or isolated networks of the power system to each other, and realizes application layer network communication between the platform side, terminal side and isolated networks.
[0074] In terms of data collection and analysis, the platform deploys advanced network security analysis functions such as baseline verification, vulnerability scanning, virus scanning, and deception deployment to achieve centralized network security assessment and analysis. On the terminal and isolated network side, only lightweight data collection and communication relay functions are deployed, eliminating the need for powerful network security functions to conserve network security investment. The network security gateway supports trunk access to the internal terminals and isolated networks, enabling comprehensive monitoring and analysis of individual network data.
[0075] Among them, the network security monitoring and analysis platform of the main station system supports docking with third-party network security analysis logic in the form of plug-ins to enhance the functions of network security analysis and disposal. The supported functions include but are not limited to: threat intelligence linkage analysis, vulnerability scanning and analysis, virus scanning and analysis, attack chain analysis function, network traffic analysis, network security log analysis, network security tracing, network security disposal, automated response orchestration, trapping deployment, etc.
[0076] Among them, network security communication agents are divided into southbound agents and northbound agents. Southbound agents refer to the process of proxying network security data from the platform side to the terminal or isolated network through a step-by-step proxy method; northbound agents refer to the process of proxying network security data from the terminal or isolated network to the platform side through a step-by-step proxy method. The implementation methods of network security communication agents include but are not limited to VPN, Socks5 and other technologies. Through application layer communication proxy technology, network security functions deployed on the platform side can be proxied to the terminal and isolated network side, improving the network security monitoring and analysis functions of the terminal and isolated network side. Network security data from the terminal and isolated network side can also be uploaded to the platform side. By opening up the application layer data channels between the main platform and the terminal, data collection, anti-virus monitoring, feature library upgrades and other functions of the terminal and isolated network can be realized.
[0077] Among them, network security gateways can form a multi-level relay communication network through self-organizing network technology, connect the isolated networks of multi-level power systems, realize the upper and lower level communication of multi-level isolated network business data, and support network security data collection and transmission, network security feature library upgrade, network security monitoring, etc.
[0078] Among them, the network security gateway on the platform side adopts a communication proxy mode rather than a data routing mode for both upward and downward network data. Through this mode, the network architecture of the traditional power system can be maintained without destroying it, and existing boundary network equipment and security equipment do not need to change their network routing.
[0079] The network security gateway deployed on the terminal side (or in an isolated network) has network security data collection capabilities. Network security data collection methods include passive monitoring and active probing. Passive monitoring collects data from device operation logs and network security logs within the isolated network. It also collects network security traffic information through network monitoring. Furthermore, dedicated data monitoring ports on the network security gateway can be used to collect network security data sent by network security agents. Active probing primarily relies on network scanning to collect information such as IP addresses, MAC addresses, running services, open ports, and existing security vulnerabilities. This enables network security data collection for a large number of small and micro terminals.
[0080] Among them, the network security gateway has a network security blocking function, which can link the strategies of the border network security devices to block the infected network security devices on the terminal side or the isolated network side. It can also force the infected host to fail or be blocked in communication through data link layer ARP interference.
[0081] Based on the same inventive concept, the present application also provides a network security monitoring and analysis method for use in the aforementioned system. The solution provided by this method is similar to the solution described in the aforementioned system. Therefore, the specific limitations in one or more network security monitoring and analysis method embodiments provided below can be found in the aforementioned limitations on the network security monitoring and analysis system, and will not be further elaborated here.
[0082] In an exemplary embodiment, Figure 3 As shown, a network security monitoring and analysis method is provided, which is applied to the network security monitoring and analysis system described in the first aspect above; the system includes a network security monitoring and analysis platform and a plurality of network security gateways; the network security monitoring and analysis platform is deployed in a power system distributed platform, and the network security gateways are deployed at the network exits of the power system distributed platform, terminals, and isolated networks; the network security gateways adopt a communication proxy mode, and a communication proxy channel for application data is established between the network security gateways through an ad hoc network mode; the method includes:
[0083] In step 302, the network security gateway collects network security data of the terminal and the isolated network, and transmits the network security data to the network security monitoring and analysis platform.
[0084] In step 304, the network security monitoring and analysis platform conducts security analysis on the network security data. If an abnormal device is detected, a network security blocking instruction is sent to the network security gateway corresponding to the abnormal device; an abnormal device refers to a compromised device, a virus-infected device, or a device that initiates a network attack.
[0085] In step 306, the network security gateway works in conjunction with the border network security device based on the network security blocking instruction to securely block the network attack source, or perform targeted interference on the network attack source according to a preset interference strategy.
[0086] The aforementioned network security monitoring and analysis method deploys a network security monitoring and analysis system within a wide-area distributed, multi-tiered power system. Centralized analysis and assessment are performed through a network security monitoring and analysis platform, and a network security gateway delegates the security assessment function to terminals or isolated networks. This eliminates the need for independent security analysis functions within these terminals or isolated networks, conserving their resources. This enables network security monitoring and blocking for a large number of terminals and isolated networks, improving the reliability and safety of the power system.
[0087] In an exemplary embodiment, the network security monitoring and analysis platform performs security analysis on the network security data, including: the network security monitoring and analysis platform performs a baseline check based on the network security data to obtain a first detection result; the baseline check is used to detect whether the network traffic type, the network security log, and the transmission file are abnormal; a behavioral analysis is performed based on the network security data to obtain a second detection result; the behavioral analysis is used to detect whether the dynamic behavior of the device is abnormal and whether the behavioral profile is abnormal; a network threat analysis is performed based on the network security data to obtain a third detection result; and a security analysis is performed on the network security data based on the first detection result, the second detection result, and the third detection result.
[0088] In an exemplary embodiment, the method further includes: when the network security gateway is deployed, the network security gateway is configured with the communication address of the network security monitoring and analysis platform and the communication address of the nearest next-hop network security gateway.
[0089] In an exemplary embodiment, the method also includes: when the network security gateway actively communicates with the network security monitoring and analysis platform, it establishes a relay channel with the nearest next-hop network security gateway according to a pre-configured communication address; based on the communication proxy mode, the data to be sent is encapsulated through the application layer data proxy; based on the relay channel, the encapsulated data is sent to the next-hop network security gateway through an encryption strategy.
[0090] In an exemplary embodiment, the method also includes: the network security monitoring and analysis platform retrieves the correspondence between the target network security gateway and the next-hop network security gateway during the process of actively communicating with the target network security gateway, and transmits the instructions to be transmitted to the target network security gateway through the network security gateway deployed on the power system distributed platform according to the correspondence.
[0091] In an exemplary embodiment, the method further includes: the network security gateway collecting network security data of the terminal and the isolated network by combining passive monitoring and active detection.
[0092] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.
[0093] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.
[0094] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, the memory, database or other media mentioned in each embodiment provided by this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the various embodiments provided herein may be, but are not limited to, general-purpose processors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), programmable logic devices (PLDs), quantum computing-based data processing logic devices, artificial intelligence (AI) processors, and the like.
[0095] The technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0096] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.
Claims
1. A network security monitoring and analysis system, characterized in that: The system includes a network security monitoring and analysis platform and several network security gateways; the network security monitoring and analysis platform is deployed in the power system distributed platform, and the network security gateways are deployed at the network exits of the power system distributed platform, terminals, and isolated networks; the network security gateways adopt a communication proxy mode, and the network security gateways establish a communication proxy channel for application data through an ad hoc network mode; wherein: The network security gateway is used to collect network security data of terminals and isolated networks and transmit the network security data to the network security monitoring and analysis platform; The network security monitoring and analysis platform is used to conduct security analysis on the network security data and, if an abnormal device is detected, send a network security blocking instruction to the network security gateway corresponding to the abnormal device; the abnormal device refers to a compromised device, a virus-infected device, or a device that initiates a network attack; The network security gateway is further configured to work in conjunction with a border network security device based on the network security blocking instruction to securely block the source of a network attack, or to perform targeted interference on the source of a network attack according to a preset interference strategy.
2. The system according to claim 1, wherein: The network security monitoring and analysis platform is also used to: Performing a baseline check based on the network security data to obtain a first detection result; the baseline check is used to detect whether the network traffic type, network security log, and transmission file are abnormal; Performing behavior analysis based on the network security data to obtain a second detection result; the behavior analysis is used to detect whether the dynamic behavior of the device is abnormal and whether the behavior profile is abnormal; Performing a network threat analysis based on the network security data to obtain a third detection result; Perform security analysis on the network security data based on the first detection result, the second detection result, and the third detection result.
3. The system according to claim 1, wherein: When deployed, the network security gateway is configured with the communication address of the network security monitoring and analysis platform and the communication address of the nearest next-hop network security gateway.
4. The system according to claim 3, characterized in that During the process of actively communicating with the network security monitoring and analysis platform, the network security gateway establishes a relay channel with the nearest next-hop network security gateway according to the pre-configured communication address; based on the communication proxy mode, the data to be sent is encapsulated through the application layer data proxy; based on the relay channel, the encapsulated data is sent to the next-hop network security gateway through an encryption strategy.
5. The system according to claim 3, wherein: During the process of actively communicating with the target network security gateway, the network security monitoring and analysis platform retrieves the correspondence between the target network security gateway and the next-hop network security gateway, and transmits the instructions to be transmitted to the target network security gateway through the network security gateway deployed on the power system distributed platform according to the correspondence.
6. The system according to any one of claims 1 to 5, characterized in that The network security gateway collects network security data of terminals and isolated networks by combining passive monitoring and active detection.
7. A network security monitoring and analysis method, characterized in that: The method is applied to a network security monitoring and analysis system according to any one of claims 1 to 6; the system comprises a network security monitoring and analysis platform and a plurality of network security gateways; the network security monitoring and analysis platform is deployed in a power system distributed platform, and the network security gateways are deployed at network exits of the power system distributed platform, terminals, and isolated networks; The network security gateway adopts a communication proxy mode, and each network security gateway builds a communication proxy channel for application data through an ad hoc network mode; the method includes: The network security gateway collects network security data of terminals and isolated networks, and transmits the network security data to the network security monitoring and analysis platform; The network security monitoring and analysis platform performs security analysis on the network security data and, if an abnormal device is detected, sends a network security blocking instruction to the network security gateway corresponding to the abnormal device; the abnormal device refers to a compromised device, a virus-infected device, or a device that initiates a network attack; Based on the network security blocking instruction, the network security gateway cooperates with the border network security device to securely block the network attack source, or perform targeted interference on the network attack source according to a preset interference strategy.
8. The method according to claim 7, characterized in that The network security monitoring and analysis platform performs security analysis on the network security data, including: The network security monitoring and analysis platform performs a baseline check based on the network security data to obtain a first detection result; the baseline check is used to detect whether the network traffic type, network security log, and transmission file are abnormal; Performing behavior analysis based on the network security data to obtain a second detection result; the behavior analysis is used to detect whether the dynamic behavior of the device is abnormal and whether the behavior profile is abnormal; Performing a network threat analysis based on the network security data to obtain a third detection result; Perform security analysis on the network security data based on the first detection result, the second detection result, and the third detection result.
9. The method according to claim 7, characterized in that The method further comprises: When deployed, the network security gateway is configured with the communication address of the network security monitoring and analysis platform and the communication address of the nearest next-hop network security gateway.
10. The method according to claim 9, characterized in that The method further comprises: During the process of actively communicating with the network security monitoring and analysis platform, the network security gateway establishes a relay channel with the nearest next-hop network security gateway according to the pre-configured communication address; based on the communication proxy mode, the data to be sent is encapsulated through the application layer data proxy; based on the relay channel, the encapsulated data is sent to the next-hop network security gateway through an encryption strategy.