Network collusion attack prevention method and system based on triple control and identification
Through the triple control and identification method, the security vulnerabilities of the power grid system in network conspiracy attacks are solved, the legality and rationality of the access requester are ensured, the security and stability of the power grid system are improved, and the risk of conspiracy attacks is reduced.
Patent Information
- Application Number
- CN202510571233.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-08-15
AI Technical Summary
When facing cyber-conspiracy attacks, existing power grid systems lack effective security protection measures. Traditional defense methods are difficult to deal with complex conspiracy attacks. The risk of internal personnel abuse their authority is high, threatening the stable operation of the power grid system.
The triple control and authentication method is adopted, including authentication and authentication of access requesters, control and verification of access connectors, and control and audit of controllers. Through technical means such as IP address, multi-factor authentication, secure communication protocol, and minimum authority principle, we ensure the legitimacy of visitors and the rationality of permissions, and prevent unauthorized access and internal abuse.
It improves the security and stability of the power grid system, effectively reduces the risk of network conspiracy attacks, ensures that the identity of the access requester is authentic and reliable, protects the confidentiality and integrity of data transmission, and prevents internal personnel from participating in conspiracy attacks.
Smart Images

Figure CN120498731A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of power grid information security, and in particular to a network collusion attack prevention method and system based on triple control and identification. Background Art
[0002] With the rapid development of internet technology, networks have become an integral part of smart grid systems. The widespread adoption of network technology has connected more devices, systems, and users to the power grid, creating a vast and complex network environment. This complexity provides cyber attackers with more opportunities and entry points, making the means and methods of cyberattacks more diverse and covert. In a network environment, malicious nodes are computing nodes controlled or exploited by attackers. These nodes can perform various malicious actions. Furthermore, by providing mutual cover and coordinated actions, malicious nodes can exploit protocol vulnerabilities or security weaknesses to launch collusive attacks, disrupt the network, or steal sensitive information. This poses a significant potential threat to the stable operation of the power grid system.
[0003] Despite the continuous advancement of network technology, power grid systems still lack sufficient attention to network security. This lack of network security awareness is reflected in a neglect of security policies, technologies, and management, making power grids vulnerable to cyberattacks and providing attackers with opportunities to exploit, further exacerbating the risk of collusion attacks. Furthermore, despite the continuous advancement of network security technology, existing security measures often have limitations. For example, traditional security defenses may not be effective against complex collusion attacks. Furthermore, as network attack methods continue to evolve, security measures also require continuous updating and upgrading. Therefore, a method for preventing collusion attacks based on triple control and authentication is proposed. Summary of the Invention
[0004] Purpose of the invention: The purpose of the present invention is to provide a method and system for preventing network collusion attacks based on triple control and authentication.
[0005] Technical solution: The network collusion attack prevention method based on triple control and authentication of the present invention includes the following steps:
[0006] (1) Authentication of access requesters: Use IP addresses and multiple factors to authenticate the access requester, preventing unauthorized access from the source of network access.
[0007] (2) Control and verification of access connectors: Use secure communication protocols and interface access control mechanisms to protect confidentiality and integrity during data transmission and isolate access requesters from grid system resources;
[0008] (3) Control and audit of controllers: Adopt the principle of least privilege, authority review and adjustment, and operational audit and monitoring measures to ensure that the authority of controllers is reasonable and effectively supervised, and prevent internal personnel from abusing their authority or participating in collusion attacks.
[0009] Furthermore, the step (1) includes:
[0010] (1.1) Access requester IP address authentication: Verify the access requester's IP address based on the established IP address blacklist and whitelist;
[0011] (1.2) Password verification for access requesters: When authorizing access requesters to access grid system resources, the access requesters are required to set a complex and difficult-to-guess password and use the password to log in;
[0012] (1.3) Additional multi-factor authentication for access requesters: When authorizing access requesters to access grid system resources, the access requesters are required to set additional verification information and provide the corresponding verification information when logging in;
[0013] (1.4) Submit operation event log for identification: Record the event log of the above operations and submit it for analysis and identification.
[0014] Furthermore, the step (2) includes:
[0015] (2.1) Encrypted communication connection and data transmission: Use secure communication protocols to connect to the power grid system and encrypt the transmitted data;
[0016] (2.2) Resource interface access control: Access control of the resource interface of the power grid system;
[0017] (2.3) Use session management authentication: Establish a secure session management mechanism, where the server generates a unique and unpredictable session ID and binds the session ID to the requester's IP address and device information;
[0018] (2.4) Submit operation event log for identification: Record the event log of the above operations and submit it for analysis and identification.
[0019] Furthermore, the step (3) includes:
[0020] (3.1) Based on the principle of least privilege: Controllers are required to assign the minimum set of privileges required to complete the task according to the access requester's privileges;
[0021] (3.2) Regular review and adjustment of authority: Regularly review and adjust the authority management strategy of the controller;
[0022] (3.3) Recording controller operation behavior: Monitor the controller's operation behavior or execution policy, record all controller operation logs, and save them together with the access requester event log and access connector event log;
[0023] (3.4) Comprehensive audit and monitoring: Comprehensive analysis of the unified stored access requester event logs, access connector logs, and controller event logs.
[0024] The network collusion attack prevention system based on triple control and authentication of the present invention includes:
[0025] The authentication and identification module is used to authenticate access requesters. It uses IP addresses and multiple factors to authenticate access requesters, preventing unauthorized access from the source of network access.
[0026] The control and verification module is used to control and verify access to the connector. It uses secure communication protocols and interface access control mechanisms to protect the confidentiality and integrity of data transmission and isolate access requesters from grid system resources.
[0027] The control and audit module is used for the control and audit of controllers. It adopts the principle of least privilege, authority review and adjustment, and operational audit and monitoring measures to ensure that the authority of controllers is reasonable and effectively supervised, and prevent insiders from abusing their authority or participating in collusion attacks.
[0028] Furthermore, the authentication and identification module is used for authentication and identification of the access requester, including
[0029] (1.1) Access requester IP address authentication: Verify the access requester's IP address based on the established IP address blacklist and whitelist;
[0030] (1.2) Password verification for access requesters: When authorizing access requesters to access grid system resources, the access requesters are required to set a complex and difficult-to-guess password and use the password to log in;
[0031] (1.3) Additional multi-factor authentication for access requesters: When authorizing access requesters to access grid system resources, the access requesters are required to set additional verification information and provide the corresponding verification information when logging in;
[0032] (1.4) Submit operation event log for identification: Record the event log of the above operations and submit it for analysis and identification.
[0033] Furthermore, the control and verification module is used to control and verify the access connector, including:
[0034] (2.1) Encrypted communication connection and data transmission: Use secure communication protocols to connect to the power grid system and encrypt the transmitted data;
[0035] (2.2) Resource interface access control: Access control of the resource interface of the power grid system;
[0036] (2.3) Use session management authentication: Establish a secure session management mechanism, where the server generates a unique and unpredictable session ID and binds the session ID to the requester's IP address and device information;
[0037] (2.4) Submit operation event log for identification: Record the event log of the above operations and submit it for analysis and identification.
[0038] Furthermore, the control and audit module is used for control and audit by the controller, including:
[0039] (3.1) Based on the principle of least privilege: Controllers are required to assign the minimum set of privileges required to complete the task according to the access requester's privileges;
[0040] (3.2) Regular review and adjustment of authority: Regularly review and adjust the authority management strategy of the controller;
[0041] (3.3) Recording controller operation behavior: Monitor the controller's operation behavior or execution policy, record all controller operation logs, and save them together with the access requester event log and access connector event log;
[0042] (3.4) Comprehensive audit and monitoring: Comprehensive analysis of the unified stored access requester event logs, access connector logs, and controller event logs.
[0043] Beneficial effects: Compared with the existing technology, the present invention has the following significant advantages: by enhancing the security of access requester identity authentication, the present invention can ensure the authenticity and reliability of the access requester's identity and prevent unauthorized access; by adopting a secure communication protocol and interface access control mechanism, the confidentiality and integrity of the data transmission process can be protected, the access connector can be controlled and verified, and the security of data transmission can be improved; through the principle of least privilege, authority review and adjustment, and operation audit and monitoring and other measures, the authority of the controller can be ensured to be reasonable and effectively supervised, and internal personnel can be prevented from abusing their authority or participating in collusion attacks; the implementation of triple control and identification technical solutions can significantly improve the security and stability of the power grid system and effectively reduce the risk of network collusion attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 Flowchart of the present invention. DETAILED DESCRIPTION
[0045] The technical solution of the present invention will be further described below with reference to the accompanying drawings.
[0046] An access requester is a user who issues an access request and attempts to access protected grid system resources. The access requester needs to prove the legitimacy of their identity and submit necessary integrity measurements (such as IP address, user name, password, device information, etc.) for identity authentication and identification. The access connector controls the access requester's access connection to the grid system, receives the access requester's integrity measurement, and may collect its own integrity measurement and send it to the controller for further verification. The controller is responsible for formulating and maintaining the security policy of the grid system, including access control policy, trusted verification, etc., and verifying the validity of the access requester and the access connector.
[0047] Resources are the target objects in the power grid system that access requesters want to access. These can be devices, files, data, applications, and more. Resources need to be properly managed to ensure their security and availability. The Resource Management System (RMS) is responsible for unified management and control of access to resources in the power grid system. Resources in the power grid system are mapped to the RMS. The RMS provides a unified resource access interface for access requesters. Access requesters must log in to the RMS and obtain the appropriate authorization before accessing the target resources through the resource access interface. The RMS also collects all event logs for resource access, from the start of a connection request to the end of a connection (normal termination or abnormal interruption).
[0048] IP address blacklists and whitelists are two important access control methods in network security. They strengthen network security by blocking and allowing access from specific IP addresses, respectively. An IP blacklist is a blocking mechanism that prevents untrusted or known harmful IP addresses from accessing network resources by listing them. However, a blacklist can only intercept known threats; it cannot prevent unknown attacks or newly emerging malicious IP addresses. An IP whitelist is a permission mechanism that allows only IP addresses on the whitelist to access network resources, ensuring that only trusted IP addresses can access the system. However, whitelists are less flexible and need to be manually updated whenever a new IP address needs to be allowed, which is costly in dynamic environments. In network security, IP address blacklists and whitelists are often used in combination.
[0049] A password is an authentication credential set by an access requester to access, use, or manage specific resources, systems, or services. It is usually a sequence of characters selected by the access requester or generated by the system, used to verify the user's identity and authorize their access rights. Characteristics of a strong password: (1) The password should be long enough, containing at least 8 characters, preferably 12 characters or longer. The longer the password, the harder it is to crack; (2) The password must contain a variety of character types, including uppercase letters, lowercase letters, numbers, and special symbols (such as !@#$%&*, etc.), which can enhance the complexity of the password; (3) Do not use easily guessed strings (such as 123456), user names, birthdays, or other personal information as part of the password; (4) Use / assign a different password for each access requester to ensure password uniqueness.
[0050] Multi-factor authentication is a measure to enhance identity authentication security, which requires the access requester to provide two or more authentication factors during the login process. In addition to the password mentioned above, multi-factor authentication also includes ownership factors and biometric factors. Ownership factors refer to physical devices or applications owned by the access requester, such as mobile phones, hardware tokens (such as USB shields), or dynamic tokens generated by mobile applications (such as mobile phone verification codes). Biometric factors refer to the access requester's biological characteristics, such as fingerprints, facial recognition, or iris scans, which are verified through dedicated devices.
[0051] SSL / TLS is a widely used secure communication protocol on the internet, providing confidentiality and data integrity between two communicating applications. Through encryption, authentication, and key management, SSL / TLS protects data between communicating parties from eavesdropping, tampering, or forgery during transmission, thereby ensuring the security and reliability of communications. HTTPS (HTTP over SSL / TLS) is a typical application of SSL / TLS in web browsing, protecting communications between users and websites.
[0052] A session is a series of interactive operations between a requester and a system in a network environment. A session ID is a string that uniquely identifies a user session, generated by the server and assigned to each user. The server verifies the validity of the user's session by checking the session ID. The primary purpose of session management verification is to ensure that only authorized users can access and manipulate data within their session, while preventing sessions from being hijacked or misused by unauthorized users. By verifying user identity and session validity, the system ensures the security and privacy of user data.
[0053] The Principle of Least Privilege (PLP) is a widely adopted permission allocation principle in computer system security. It requires that each system component (including user accounts, processes, and services) be granted only the minimum set of permissions necessary to perform its tasks. The PLP can reduce potential security risks because if a user is granted more permissions than necessary, the additional permissions could be exploited maliciously. For example, a user who only reads data should not be granted write or delete permissions.
[0054] like Figure 1 As shown, the network collusion attack prevention method based on triple control and authentication of the present invention includes:
[0055] During the authentication phase of the access requester, the IP address and multiple factors are used to authenticate the access requester's identity, ensuring that the access requester's identity is authentic and reliable, preventing unauthorized access from the source of network access.
[0056] During the access control and verification phase, secure communication protocols and interface access control mechanisms are used to protect the confidentiality and integrity of data transmission, isolate access requesters and grid system resources, control and verify access connectors, and improve data transmission security.
[0057] During the controller's control and audit phase, we adopt the principle of least privilege, authority review and adjustment, and operational audit and monitoring measures to ensure that the controller's authority is reasonable and effectively supervised, and to prevent insiders from abusing their authority or participating in collusion attacks.
[0058] With the rapid development of Internet technology, the network has become an indispensable part of the smart grid system. The popularization of network technology has enabled more devices, systems, and users to connect to the power grid system, forming a large and complex network environment. In such a complex network environment, malicious nodes can perform various malicious behaviors. Moreover, they can exploit protocol loopholes or security weaknesses through mutual cover and joint actions to launch collusion attacks, destroy the network or steal sensitive information. This will pose a huge potential threat to the stable operation of the power grid system, and may undermine the operational safety and power supply of the power system, causing serious economic losses. The network collusion attack prevention method based on triple control and authentication proposed in this application can implement strict control and authentication between access requesters, access connectors, and controllers in the power grid system, ensure the trustworthy security of the entire process of computing nodes accessing power grid system resources, and effectively reduce the risk of computing nodes accessing the power grid system to launch network collusion attacks due to being controlled by malicious nodes. The present invention can effectively prevent the risk of network collusion attacks, thereby ensuring the security and trustworthiness of communications in complex network environments and protecting the security and stability of power grid system operations.
[0059] The authentication and identification module of the access requester includes:
[0060] (1) Authentication of the access requester's IP address: When an access requester initiates a connection request to a target resource in the power grid system, the controller first receives the connection request information, then parses the request information and obtains the access requester's IP address. If the access requester's IP address is in the blacklist or is an unauthorized IP address, the connection request is blocked and the access requester is denied access. If the IP address is a known and trusted IP address (whitelist), access is allowed.
[0061] (2) Password verification for access requesters: When an access requester logs into the RMS, he or she needs to provide a pre-assigned account and a strong, complex password (such as "H5i1t4$Ices@wh!"). The controller verifies the account and password of the access requester. If they do not match, access is denied; if they match, access is allowed.
[0062] (3) Add multi-factor authentication for access requesters: When access requesters log in, in addition to the password, they are also required to provide other pre-set verification information (such as mobile phone verification code, fingerprint recognition, facial information, etc.). Considering the universality of the verification process, since fingerprint and facial information require special collection equipment, some computing nodes (such as desktops) may not be equipped with them. RMS can use mobile phone verification code to send randomly generated dynamic verification code information to the access requester's mobile phone. The access requester needs to submit the dynamic verification code at the same time when logging in. If the controller confirms that the submitted verification code is consistent with the RMS randomly generated in advance, the access is allowed to continue, otherwise the access is denied;
[0063] (4) Submitting operation event logs for identification: The controller records the event logs of the above operations and submits them to the resource management system RMS for analysis so that abnormal behaviors can be discovered in time and corresponding measures can be taken.
[0064] The control and verification module for access connectors includes the following:
[0065] (1) Encrypted communication connection and data transmission: The access requester's connection request and data transmission use the secure communication protocol HTTPS provided by the access connector to connect to the power grid system, and the SSL / TLS protocol is used to encrypt the connection and data to prevent the data from being intercepted or tampered during transmission;
[0066] (2) Resource interface access control: Since the access interface of the power grid system resources is centrally managed by the resource management system (RMS), after the access requester passes the identity authentication, the controller determines whether the access requester is authorized to access the corresponding resource based on the access requester's permissions. If the access requester has access rights, the RMS will open the interface access rights of the resource to the access requester, and the access connector will maintain the current connection; if not, the access is denied and the access connector will close the current connection.
[0067] (3) Use session management verification: Once the access requester obtains the interface access rights of the target resource, RMS uses a random algorithm to generate a unique and unpredictable session ID. The access connector encrypts the session ID and binds the session ID to the access requester's IP address, device information, etc., and limits the scope of use of the session based on the access rights to ensure the integrity and confidentiality of the session and prevent the session from being hijacked or forged. At the same time, the access connector sets the session timeout. Once the session times out or ends, the expired session ID is destroyed in a timely manner to prevent the session from being abused.
[0068] (4) Submitting operation event logs for identification: The access connector records the event logs of the above operations and submits them to the resource management system RMS for analysis so that abnormal behaviors can be discovered in time and corresponding measures can be taken.
[0069] The controller's control and audit module includes the following:
[0070] (1) Allocation based on the principle of least privilege: The controller allocates the minimum set of permissions required to complete the access request to the access requester in accordance with the principle of least privilege, avoiding security risks caused by excessive permissions. For example, for the target data resource, the access requester's permissions are read and write, and the access request only involves data reading operations. In this case, the permission allocated to the access requester by the controller should be reading the target data resource. If any aspect of the allocated scope and permissions exceeds the principle of least privilege, such as reading other resources or writing the target data resource, it may bring risks to the power grid system.
[0071] (2) Regular review and adjustment of permissions: Regularly review and adjust the permissions management strategy of the controller. Since the role of the access requester may change and the access network environment may change over time, the controller needs to adjust the corresponding resource access rights in a timely manner to ensure the rationality and effectiveness of the permissions.
[0072] (3) Recording the controller's operation behavior: The RMS monitors the controller's operation behavior or execution policy, records all the controller's operation logs, and saves them together with the access requester log and access connector log;
[0073] (4) Comprehensive audit and monitoring: RMS conducts a comprehensive analysis of the uniformly stored access requester event logs, access connector logs, and controller event logs to promptly detect abnormal behavior and take appropriate measures. For example, if the permission allocation that does not comply with the rules appears in this stage (1), it is considered that there may be a risk of internal and external collusion attack. RMS will issue a risk warning, and relevant departments should take preventive measures in a timely manner to avoid security incidents caused by network attacks.
Claims
1. A network collusion attack prevention method based on triple control and authentication, characterized in that: The steps include: (1) Authentication of access requesters: Use IP addresses and multiple factors to authenticate the access requester, preventing unauthorized access from the source of network access. (2) Control and verification of access connectors: Use secure communication protocols and interface access control mechanisms to protect confidentiality and integrity during data transmission and isolate access requesters from grid system resources; (3) Control and audit of controllers: Adopt the principle of least privilege, authority review and adjustment, and operational audit and monitoring measures to ensure that the authority of controllers is reasonable and effectively supervised, and prevent internal personnel from abusing their authority or participating in collusion attacks.
2. The network collusion attack prevention method based on triple control and authentication according to claim 1 is characterized in that: The step (1) comprises: (1.1) Access requester IP address authentication: Verify the access requester's IP address based on the established IP address blacklist and whitelist; (1.2) Password verification for access requesters: When authorizing access requesters to access grid system resources, the access requesters are required to set a complex and difficult-to-guess password and use the password to log in; (1.3) Additional multi-factor authentication for access requesters: When authorizing access requesters to access grid system resources, the access requesters are required to set additional verification information and provide the corresponding verification information when logging in; (1.4) Submit operation event log for identification: Record the event log of the above operations and submit it for analysis and identification.
3. The network collusion attack prevention method based on triple control and authentication according to claim 1 is characterized in that: The step (2) comprises: (2.1) Encrypted communication connection and data transmission: Use secure communication protocols to connect to the power grid system and encrypt the transmitted data; (2.2) Resource interface access control: Access control of the resource interface of the power grid system; (2.3) Use session management authentication: Establish a secure session management mechanism, where the server generates a unique and unpredictable session ID and binds the session ID to the requester's IP address and device information; (2.4) Submit operation event log for identification: Record the event log of the above operations and submit it for analysis and identification.
4. The network collusion attack prevention method based on triple control and authentication according to claim 1 is characterized in that: The step (3) comprises: (3.1) Based on the principle of least privilege: Controllers are required to assign the minimum set of privileges required to complete the task according to the access requester's privileges; (3.2) Regular review and adjustment of authority: Regularly review and adjust the authority management strategy of the controller; (3.3) Recording controller operation behavior: Monitor the controller's operation behavior or execution policy, record all controller operation logs, and save them together with the access requester event log and access connector event log; (3.4) Comprehensive audit and monitoring: Comprehensive analysis of the unified stored access requester event logs, access connector logs, and controller event logs.
5. A network collusion attack prevention system based on triple control and authentication, characterized in that: include: The authentication and identification module is used to authenticate access requesters. It uses IP addresses and multiple factors to authenticate access requesters, preventing unauthorized access from the source of network access. The control and verification module is used to control and verify access to the connector. It uses secure communication protocols and interface access control mechanisms to protect the confidentiality and integrity of data transmission and isolate access requesters from grid system resources. The control and audit module is used for the control and audit of controllers. It adopts the principle of least privilege, authority review and adjustment, and operational audit and monitoring measures to ensure that the authority of controllers is reasonable and effectively supervised, and prevent insiders from abusing their authority or participating in collusion attacks.
6. The network collusion attack prevention system based on triple control and authentication according to claim 5 is characterized in that: The authentication and identification module is used for authentication and identification of the access requester, including (1.1) Access requester IP address authentication: Verify the access requester's IP address based on the established IP address blacklist and whitelist; (1.2) Password verification for access requesters: When authorizing access requesters to access grid system resources, the access requesters are required to set a complex and difficult-to-guess password and use the password to log in; (1.3) Additional multi-factor authentication for access requesters: When authorizing access requesters to access grid system resources, the access requesters are required to set additional verification information and provide the corresponding verification information when logging in; (1.4) Submit operation event log for identification: Record the event log of the above operations and submit it for analysis and identification.
7. The network collusion attack prevention system based on triple control and authentication according to claim 5 is characterized in that: The control and verification module is used to control and verify access to the connector, including: (2.1) Encrypted communication connection and data transmission: Use secure communication protocols to connect to the power grid system and encrypt the transmitted data; (2.2) Resource interface access control: Access control of the resource interface of the power grid system; (2.3) Use session management authentication: Establish a secure session management mechanism, where the server generates a unique and unpredictable session ID and binds the session ID to the requester's IP address and device information; (2.4) Submit operation event log for identification: Record the event log of the above operations and submit it for analysis and identification.
8. The network collusion attack prevention system based on triple control and authentication according to claim 5 is characterized in that: The control and audit module is used for control and audit by the controller, including: (3.1) Based on the principle of least privilege: Controllers are required to assign the minimum set of privileges required to complete the task according to the access requester's privileges; (3.2) Regular review and adjustment of authority: Regularly review and adjust the authority management strategy of the controller; (3.3) Recording controller operation behavior: Monitor the controller's operation behavior or execution policy, record all controller operation logs, and save them together with the access requester event log and access connector event log; (3.4) Comprehensive audit and monitoring: Comprehensive analysis of the unified stored access requester event logs, access connector logs, and controller event logs.
9. An electronic device comprising a memory, a processor, and a program stored in the memory and executable on the processor, wherein: When the processor executes the program, the network collusion attack prevention method based on triple control and authentication according to any one of claims 1 to 4 is implemented.
10. A storage medium storing a computer program, characterized in that: The computer program is designed to implement the network collusion attack prevention method based on triple control and authentication according to any one of claims 1 to 4 when running.