Safety supervision and detection system for agile development mode management platform in power industry
By introducing multi-source data acquisition, intelligent analysis and security policy management modules in the power industry, combined with deep learning and static code analysis, the problems of security threat identification lag and development integration in the existing technology have been solved, and the safety and efficiency of the power system have been synchronized.
Patent Information
- Application Number
- CN202510447042.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2025-08-26
AI Technical Summary
The existing safety supervision and inspection system is difficult to achieve efficient integration and real-time analysis of multi-source data in the power industry, resulting in lag and one-sidedness in security threat identification, and the inability to deeply integrate security detection into all stages of agile development, affecting development efficiency and business innovation.
It adopts multi-source data acquisition module, data preprocessing module, intelligent analysis and detection engine, security risk assessment module, real-time early warning and response module and security policy management module, combined with deep learning and machine learning algorithms, and analyzes security threats in agile development process in real time, and deeply integrates security supervision and detection into all stages of the development process. Through technologies such as data fingerprint recognition, static code analysis, etc., the accuracy and timeliness of security detection are improved.
It realizes real-time and comprehensive perception of the security status of the middle platform, accurately identify security threats, ensures the synchronous advancement of system security and development efficiency, reduces equipment downtime, and improves production efficiency and code quality.
Smart Images

Figure CN120542901A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of electrical engineering management, and in particular to a safety supervision and detection system for a management center of an agile development model in the power industry. Background Art
[0002] Amid the wave of digital transformation in the power industry, the importance of the management platform, a key platform for integrating various business systems and enabling data sharing and business process collaboration, has become increasingly prominent. It efficiently processes data from all aspects of power production, transmission, and distribution, and serves as a core hub for ensuring stable operation of the power system and improving management efficiency.
[0003] To ensure the secure and stable operation of the management platform, the industry has widely adopted a variety of security technologies and management methods. For example, common firewalls and intrusion detection systems, to a certain extent, block external network attacks, building a basic security defense for the management platform. At the same time, regular system vulnerability scanning and security auditing mechanisms also help to identify and remediate potential security risks, playing a positive role in the overall security of the management platform.
[0004] However, with the in-depth application of the agile development model in the power industry, the existing security supervision and detection system has exposed obvious shortcomings. On the one hand, at the security supervision and detection level, traditional technologies have difficulty in achieving efficient integration and real-time analysis of multi-source data, and are unable to fully and timely perceive the security status of the management center. This leads to lags and one-sidedness in security threat identification, making it difficult to effectively respond to complex and changing network attacks. On the other hand, in terms of integration with agile development, existing technologies are unable to deeply integrate security detection into all stages of development. During the code writing and release and update process, it is difficult to ensure system security without affecting development efficiency and business innovation, and it is impossible to achieve the organic and synchronous advancement of security and development. In view of this, we propose a security supervision and detection system for the management center of the agile development model in the power industry. Summary of the Invention
[0005] In response to the shortcomings of existing technologies, the present invention provides a security supervision and detection system for the power industry's agile development model management platform, which solves the problem that traditional technologies are difficult to achieve efficient integration and real-time analysis of multi-source data, resulting in lagging and one-sided security threat identification.
[0006] To achieve the above objectives, the present invention is implemented through the following technical solutions: a safety supervision and detection system for the management of agile development mode in the power industry, including the following modules:
[0007] The multi-source data acquisition module is used to collect data from multiple data sources at all levels of the management platform, covering data such as code changes, development tool operations, and test results during the agile development process;
[0008] The data preprocessing module cleans, removes noise, converts formats, and normalizes the collected multi-source data. It also applies specific rules to agile development-related data to meet subsequent analysis requirements.
[0009] The intelligent analysis and detection engine uses deep learning and machine learning algorithms to build a security detection model. This model takes into account the rapid iteration characteristics of agile development during training and operation, and conducts real-time analysis and detection of security threats during the agile development process and during the operation of the management platform.
[0010] The security risk assessment module quantifies security risks based on the detection results of the intelligent analysis and detection engine, and considers the impact of different stages of agile development on the security of the management platform during the assessment process;
[0011] The real-time warning and response module sends real-time warning information and takes response measures when security risks are detected, and formulates different warning levels and response strategies for agile development scenarios;
[0012] The security policy management module is used to formulate and adjust security policies. It can dynamically adjust security policies according to the needs and changes of agile development, ensuring the coordination of agile development and management platform security.
[0013] The agile development integration module deeply integrates safety supervision and detection into the agile development process of the power industry, monitors safety status in real time during code writing, testing, deployment and other stages, and ensures that new functions and versions meet safety requirements.
[0014] Preferably, the multi-source data acquisition module has a data fingerprint recognition function, which generates a unique data fingerprint for the code snippets and configuration file data frequently generated in the agile development process. In the subsequent data collection and analysis, by comparing the data fingerprints, the data changes are identified, the data modification points with security risks are located, and the targeted security detection is improved.
[0015] Preferably, the data preprocessing module uses a rule engine to perform syntax and semantic analysis on code change data based on the characteristics of agile development data, removes invalid comments and formatting information, and classifies and standardizes test result data.
[0016] Preferably, the security detection model of the intelligent analysis and detection engine introduces agile development cycle data as features during training, and through time series analysis and anomaly detection algorithms, identifies security vulnerability introduction patterns and abnormal behaviors that may occur in the agile development process, and promptly discovers potential security threats.
[0017] Preferably, the intelligent analysis and detection engine adopts an algorithm improvement based on multimodal deep learning, integrating code semantic features, network traffic features and power business data features. During the agile development process, it performs deep semantic analysis on the logical structure and function call relationship of the code, and at the same time combines the timing characteristics of network traffic and the correlation of power business data to build a security detection model.
[0018] Preferably, when evaluating security risks related to agile development, the security risk assessment module combines the business processes and safety standards of the power industry to conduct differentiated assessments of risks at different development stages, and uses machine learning algorithms to analyze the structure, logic and grammatical features of the code to predict which code fragments may have security vulnerabilities in the future.
[0019] Preferably, the real-time warning and response module sets different warning levels and response strategies for agile development scenarios, and introduces a risk tolerance mechanism to reduce equipment downtime by observing and recording small signal fluctuations or low-risk anomalies that can recover on their own during power production.
[0020] Preferably, the security policy management module supports rapid adjustment of security policies according to the iteration plan and business needs of agile development, including relaxing some non-critical security policies to improve development efficiency during the development of new functions, and executing the complete security policy for a final security check before the system goes online.
[0021] Preferably, the agile development fusion module is integrated into mainstream development tools through development plug-ins, and performs static code analysis in real time during the code writing process to detect potential security vulnerabilities and provide repair suggestions.
[0022] Preferably, the agile development fusion module uses a graph neural network-based method in the code static analysis algorithm to model the code structure and dependency relationships, and identifies and understands the code logic and semantics by analyzing the function call graph and data dependency graph in the code.
[0023] The present invention provides a safety supervision and detection system for the power industry's agile development model management platform. It has the following beneficial effects:
[0024] 1. The intelligent analysis and detection engine established by this invention, at the security supervision and detection level, through the collaborative operation of modules such as multi-source data collection and the intelligent analysis and detection engine, can perceive the security status of the management center in real time and comprehensively, accurately identify various security threats, and greatly improve the timeliness and accuracy of security protection. In terms of integration with agile development, security testing is brought forward to all stages of development, from static analysis during code writing to comprehensive verification before releasing updates. This not only ensures system security, but also does not affect development efficiency and business innovation, achieving the simultaneous advancement of security and development.
[0025] 2. This invention, through the established risk containment mechanism, collects, analyzes, and evaluates abnormal signals in the power production system. It comprehensively considers the characteristics of the abnormal signals, their impact on the production process, and the risk containment mechanism to ultimately determine an appropriate response strategy. The entire process, starting with data collection and proceeding through multiple steps including risk calculation, early warning determination, and conditional judgment, ensures accurate and appropriate handling of abnormal situations, minimizing unnecessary equipment downtime and improving production efficiency while ensuring power system safety.
[0026] 3. This invention performs real-time static code analysis and uses a neural network-based method to model code structure and dependencies, effectively detecting potential security vulnerabilities and providing repair suggestions, significantly improving code quality and development efficiency. In particular, during agile development, through technologies such as lexical analysis and graph neural networks, an in-depth understanding of code logic and semantics is achieved. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] Figure 1 This is the module diagram of the safety supervision and detection system for the power industry's agile development model management platform;
[0028] Figure 2 This is a flow chart of the steps of the risk containment mechanism of the present invention;
[0029] Figure 3 This is the security vulnerability prediction code diagram of the present invention. DETAILED DESCRIPTION
[0030] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the specification of the present invention. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0031] Example:
[0032] Please see the attached Figure 1 - Attachment Figure 3 The embodiment of the present invention provides a security supervision and detection system for the agile development model management platform in the power industry, including the following modules:
[0033] The multi-source data acquisition module is used to collect data from multiple data sources at all levels of the management platform, covering data such as code changes, development tool operations, and test results during the agile development process;
[0034] The data preprocessing module cleans, removes noise, converts formats, and normalizes the collected multi-source data. It also applies specific rules to agile development-related data to meet subsequent analysis requirements.
[0035] The intelligent analysis and detection engine uses deep learning and machine learning algorithms to build a security detection model. This model takes into account the rapid iteration characteristics of agile development during training and operation, and conducts real-time analysis and detection of security threats during the agile development process and during the operation of the management platform.
[0036] The security risk assessment module quantifies security risks based on the detection results of the intelligent analysis and detection engine, and considers the impact of different stages of agile development on the security of the management platform during the assessment process;
[0037] The real-time warning and response module sends real-time warning information and takes response measures when security risks are detected, and formulates different warning levels and response strategies for agile development scenarios;
[0038] The security policy management module is used to formulate and adjust security policies. It can dynamically adjust security policies according to the needs and changes of agile development, ensuring the coordination of agile development and management platform security.
[0039] The agile development integration module deeply integrates safety supervision and detection into the agile development process of the power industry, monitors safety status in real time during code writing, testing, deployment and other stages, and ensures that new functions and versions meet safety requirements.
[0040] The multi-source data acquisition module has a data fingerprint recognition function. It generates a unique data fingerprint for code snippets and configuration file data frequently generated during the agile development process. In subsequent data collection and analysis, by comparing the data fingerprints, it identifies data changes, locates data modification points with security risks, and improves the targeted nature of security detection.
[0041] The data preprocessing module uses a rule engine to perform syntax and semantic analysis on code change data based on the characteristics of agile development data, removes invalid comments and formatting information, and classifies and standardizes test result data.
[0042] The security detection model of the intelligent analysis and detection engine introduces agile development cycle data as features during training. Through time series analysis and anomaly detection algorithms, it identifies security vulnerability introduction patterns and abnormal behaviors that may occur during the agile development process, and promptly discovers potential security threats.
[0043] The intelligent analysis and detection engine adopts an improved algorithm based on multimodal deep learning, integrating code semantic features, network traffic features and power business data features. During the agile development process, it performs deep semantic analysis on the logical structure and function call relationships of the code, and at the same time combines the timing characteristics of network traffic and the correlation of power business data to build a security detection model.
[0044] When assessing security risks associated with agile development, the security risk assessment module combines power industry business processes and safety standards to conduct differentiated risk assessments at different development stages. It also uses machine learning algorithms to analyze the structural, logical, and grammatical features of the code to predict which code snippets are likely to have security vulnerabilities in the future. The following algorithm is established to predict security vulnerabilities in code snippets:
[0045] Step 1: Data Preparation
[0046] Collect code samples and extract code features (such as the number of lines of code, the number of function calls, the use of specific grammatical structures, etc.), and mark each sample for security vulnerabilities to form a training data set. Assume that there are m samples in the training data set, each sample has n features, and the feature vector of the jth sample is The class label is C (j) .
[0047] Step 2: Calculate the prior probability P(C)
[0048] The prior probability P(C) is estimated by the proportion of samples in each category in the training dataset. Assuming that the number of samples with security vulnerabilities in the training dataset is m1, and the number of samples without security vulnerabilities is m2, and m=m1+m2, then the prior probability P(C1) of the class with security vulnerabilities and the prior probability P(C2) of the class without security vulnerabilities are:
[0049]
[0050]
[0051] Step 3: Calculate the likelihood probability P(x i |C)
[0052] For each feature x i For each category C, we need to calculate the probability P(x i |C). If feature x i It is a discrete feature. By counting the samples of class C, feature x i Take the proportion of the number of samples of a certain value to the total number of samples of this category to estimate P(x i |C). For example, for samples with security vulnerabilities, the number of samples with a specific value of the statistical feature x1 is m 11 ,but
[0053] If the feature x i It is a continuous feature, which is usually assumed to obey a certain probability distribution (such as Gaussian distribution), and then P(x i|C). For Gaussian distribution, the probability density function is:
[0054]
[0055] where μ c,i is feature x in category C i The mean of is feature x in category C i The variance of .
[0056] Step 4: Predict the category of new code samples
[0057] For a new code sample, whose feature vector is X = (x1, x2, ... xn), calculate the posterior probability that the sample belongs to the category with security vulnerabilities C1 and the category without security vulnerabilities C2 respectively:
[0058]
[0059]
[0060] Since P(X) is the same for all categories, we can ignore P(X) when comparing the posterior probabilities and only need to compare and The category that maximizes this value is selected as the prediction result, that is:
[0061]
[0062] The real-time warning and response module sets different warning levels and response strategies for agile development scenarios. It also introduces a risk tolerance mechanism. For small signal fluctuations or low-risk anomalies that can recover on their own during power production, it observes and records them to reduce equipment downtime. The following algorithm is established for the risk tolerance mechanism:
[0063] 1. Data collection and feature extraction:
[0064] Collect various monitoring signals from the power production system, such as voltage, current, temperature, etc., and process these raw signals to extract the characteristic value S that can reflect abnormal conditions. At the same time, obtain the characteristic value N of the normal range of the signal, which is usually obtained based on statistical analysis of historical data;
[0065] 2. Determination of impact factor
[0066] Description: Evaluate the impact factor I of the abnormality on the power production process based on factors such as the importance of the production link where the abnormality occurs and the possible consequences of the abnormality. The value of I ranges from 0 to 1, with larger values indicating more severe impact.
[0067] 3. Value at Risk Calculation
[0068] Combine the abnormal signal eigenvalue S, the normal range eigenvalue N, and the influence factor I, and calculate the risk value R using the risk assessment formula;
[0069]
[0070] Among them, W1 and W2 are weight coefficients, and W1 + W2 = 1. These two weight coefficients are determined according to the actual situation and reflect the relative importance of the deviation degree of the abnormal signal and the influencing factors in the risk assessment.
[0071] 4. Warning level determination
[0072] Compare the calculated risk value R with the preset warning thresholds T_1, T_2, T_3 (T1 < T2 < T3) of different levels, and determine the warning level L according to the comparison result
[0073]
[0074] 5. Risk accommodation condition judgment
[0075] For the case where the low-level warning (L = L1) is determined, further judge whether the risk accommodation condition is satisfied. The risk accommodation condition is defined according to the specific power production process and equipment characteristics. For example, the fluctuation range of the abnormal signal is within ±5% of the normal range and the duration does not exceed t minutes.
[0076] Risk accommodation condition;
[0077]
[0078] Among them, ∧ represents the logical AND operation.
[0079] 6. Response strategy decision-making
[0080] Determine the final response strategy A according to the warning level L and the result of the risk accommodation condition judgment.
[0081]
[0082] 7. Execute the response strategy
[0083] According to the determined response strategy A, trigger the corresponding execution actions, such as starting the observation record program, triggering the shutdown instruction, etc., to cope with the abnormal situation in power production.
[0084] The security policy management module supports quickly adjusting security policies according to the iterative plan and business requirements of agile development, including relaxing some non-critical security policies during new function development to improve development efficiency, and executing complete security policies for final security checks before the system goes live.
[0085] The agile development fusion module is integrated into mainstream development tools through the development of plug-ins, and performs static code analysis in real time during the code writing process to detect potential security vulnerabilities and provide repair suggestions.
[0086] The agile development fusion module uses a neural network-based approach to model code structure and dependencies in the code static analysis algorithm. By analyzing the function call graph and data dependency graph in the code, it identifies and understands the code logic and semantics. The following algorithm is established for code analysis in the agile development process:
[0087] Lexical Analysis
[0088] The lexical analyzer takes the source code as input, decomposes it into lexical units, and represents them with a five-tuple M = (Q, Σ, δ, q0, F), where:
[0089] Q is a finite set of states;
[0090] Σ is the alphabet of input symbols;
[0091] δ:Q×Σ→Q is the state transition function;
[0092] q0∈Q is the initial state;
[0093] is the set of terminal states,
[0094] For the input string sequence, starting from the initial state q0, according to the current state and the input character, the state transition function δ is used to perform state transition until the input ends. If the final state belongs to the terminal state set F, the input string sequence is considered to be a legal lexical unit;
[0095] Code structure and dependency modeling algorithm based on neural network
[0096] When modeling code structure and dependencies, neural network-based methods such as graph neural networks are used.
[0097] Graph Neural Networks:
[0098] The function call graph and data dependency graph of the code can be regarded as a graph structure, and graph neural networks can effectively model and analyze this graph structure.
[0099] Graph Convolutional Networks:
[0100] The feature representation of the node is updated by aggregating the node's neighbor information. For the graph G = (V, E), where V is the node set and E is the edge set, the feature representation of node i in the l+1 layer is Calculated by the following formula:
[0101]
[0102] in:
[0103] N(i) is the set of neighbor nodes of node i;
[0104] d i is the degree of node i;
[0105] W (l) is the learnable weight matrix of layer l;
[0106] σ is the activation function, σ(x) = max(0,x);
[0107] Through multi-layer graph convolution operations, graph neural networks can learn the complex relationships between nodes in the code graph, thereby achieving an understanding of the code logic and semantics.
[0108] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.
Claims
1. The power industry agile development model management platform safety supervision and detection system is characterized by: Includes the following modules: The multi-source data acquisition module is used to collect data from multiple data sources at all levels of the management platform, covering data such as code changes, development tool operations, and test results during the agile development process; The data preprocessing module cleans, removes noise, converts formats, and normalizes the collected multi-source data. It also applies specific rules to agile development-related data to meet subsequent analysis requirements. The intelligent analysis and detection engine uses deep learning and machine learning algorithms to build a security detection model. This model takes into account the rapid iteration characteristics of agile development during training and operation, and conducts real-time analysis and detection of security threats during the agile development process and during the operation of the management platform. The security risk assessment module quantifies security risks based on the detection results of the intelligent analysis and detection engine, and considers the impact of different stages of agile development on the security of the management platform during the assessment process; The real-time warning and response module sends real-time warning information and takes response measures when security risks are detected, and formulates different warning levels and response strategies for agile development scenarios; The security policy management module is used to formulate and adjust security policies. It can dynamically adjust security policies according to the needs and changes of agile development, ensuring the coordination of agile development and management platform security. The agile development integration module deeply integrates safety supervision and detection into the agile development process of the power industry, monitors safety status in real time during code writing, testing, deployment and other stages, and ensures that new functions and versions meet safety requirements.
2. The power industry agile development model management platform security supervision and detection system according to claim 1 is characterized in that: The multi-source data acquisition module has a data fingerprint recognition function. It generates a unique data fingerprint for code snippets and configuration file data frequently generated during the agile development process. In subsequent data collection and analysis, by comparing the data fingerprints, it identifies data changes, locates data modification points with security risks, and improves the targeted nature of security detection.
3. The power industry agile development model management platform security supervision and detection system according to claim 1 is characterized in that: The data preprocessing module uses a rule engine to perform syntax and semantic analysis on code change data based on the characteristics of agile development data, removes invalid comments and formatting information, and classifies and standardizes test result data.
4. The power industry agile development model management platform security supervision and detection system according to claim 1 is characterized in that: The security detection model of the intelligent analysis and detection engine introduces agile development cycle data as features during training. Through time series analysis and anomaly detection algorithms, it identifies security vulnerability introduction patterns and abnormal behaviors that may occur during the agile development process, and promptly discovers potential security threats.
5. The power industry agile development model management platform security supervision and detection system according to claim 1 is characterized in that: The intelligent analysis and detection engine adopts an improved algorithm based on multimodal deep learning, integrating code semantic features, network traffic features and power business data features. During the agile development process, it performs deep semantic analysis on the logical structure and function call relationships of the code, and at the same time combines the timing characteristics of network traffic and the correlation of power business data to build a security detection model.
6. The power industry agile development model management platform security supervision and detection system according to claim 1 is characterized in that: When evaluating security risks related to agile development, the security risk assessment module combines the business processes and safety standards of the power industry to conduct differentiated assessments of risks at different development stages. At the same time, it uses machine learning algorithms to analyze the structure, logic, and grammatical features of the code to predict which code fragments may subsequently have security vulnerabilities.
7. The power industry agile development model management platform security supervision and detection system according to claim 1 is characterized in that: The real-time warning and response module sets different warning levels and response strategies for agile development scenarios, and introduces a risk tolerance mechanism. It observes and records small signal fluctuations or low-risk anomalies that can recover on their own during power production to reduce equipment downtime.
8. The power industry agile development model management platform security supervision and detection system according to claim 1 is characterized in that: The security policy management module supports rapid adjustment of security policies based on agile development iteration plans and business needs, including relaxing some non-critical security policies to improve development efficiency during new feature development, and executing the complete security policy for a final security check before the system goes online.
9. The power industry agile development model management platform security supervision and detection system according to claim 1 is characterized in that: The agile development fusion module is integrated into mainstream development tools through the development of plug-ins, and performs static code analysis in real time during the code writing process to detect potential security vulnerabilities and provide repair suggestions.
10. The power industry agile development model management platform security supervision and detection system according to claim 9 is characterized in that: The agile development fusion module uses a graph neural network-based method in the code static analysis algorithm to model the code structure and dependency relationships, and identifies and understands the code logic and semantics by analyzing the function call graph and data dependency graph in the code.