Power network equipment vulnerability repair method and system based on dynamic behavior analysis

By analyzing the dynamic behavior of power network equipment, a set of vulnerability remediation strategies is generated, which solves the problem of difficulty in identifying the dynamic coupling effect between equipment operating status and environmental factors in existing technologies. This enables adaptive vulnerability remediation of power network equipment, improving the efficiency and adaptability of vulnerability identification and remediation.

CN120567476BActive Publication Date: 2026-05-05SHANDONG SIJI TECH CO LTD +2
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHANDONG SIJI TECH CO LTD
Filing Date
2025-05-27
Publication Date
2026-05-05

AI Technical Summary

Technical Problem

Existing methods for detecting vulnerabilities in power network equipment are unable to capture the dynamic coupling effect between equipment operating status and environmental factors, resulting in the inability to identify hidden vulnerabilities. Furthermore, fixed remediation strategies lack the ability to respond to real-time load status of equipment and sudden changes in the environment, which can easily lead to delays in the remediation of critical vulnerabilities or unnecessary maintenance operations.

Method used

By acquiring the operational data set of power network equipment, dynamic behavior analysis is performed to generate a dynamic behavior feature set. Based on preset dynamic policy matching rules, vulnerability features are extracted, a vulnerability remediation policy set is generated, and remediation operations are performed in combination with execution priority and condition parameters. The policy rules are optimized using remediation verification data to adapt to the complex and ever-changing power network environment.

Benefits of technology

It effectively identifies hidden abnormal device behaviors caused by complex environmental interactions, enhances the ability to discover unknown vulnerability types, achieves adaptive matching between remediation operations and real-time device operating conditions and environmental status, ensures priority handling of critical vulnerabilities, and maintains a stable level of security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120567476B_ABST
    Figure CN120567476B_ABST
Patent Text Reader

Abstract

This invention provides a method and system for patching vulnerabilities in power network equipment based on dynamic behavior analysis. It involves acquiring a set of operational data from the power network equipment, performing dynamic behavior analysis on this data to obtain a set of dynamic behavior features from multiple operational cycles. Based on preset dynamic policy matching rules, vulnerability features are extracted from the dynamic behavior feature set to generate a set of vulnerability patching strategies corresponding to abnormal behavior patterns. According to the execution priority and execution condition parameters in the vulnerability patching strategy set, vulnerability patching operations on the power network equipment are triggered, and patched equipment operational verification data is acquired. Based on the difference parameters between the equipment operational verification data and preset security operation standards, a patching effect evaluation result is generated, and the dynamic policy matching rules are adjusted according to the difference parameters. This invention enables the vulnerability patching system to maintain a stable level of security protection in complex and ever-changing power network environments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data processing, and more specifically, to a method and system for repairing vulnerabilities in power network equipment based on dynamic behavior analysis. Background Technology

[0002] With the rapid development of smart grids, power network equipment vulnerability remediation technology has become a core component in ensuring the safe operation of the power grid. Current mainstream vulnerability detection methods typically rely on static feature matching of equipment operation logs, identifying known security threats through comparison with a pre-built vulnerability feature database, and executing remediation operations according to a fixed priority. However, such methods struggle to capture the dynamic coupling effect between equipment operating status and environmental factors, resulting in the ineffective identification of hidden vulnerabilities induced by external environmental factors such as electromagnetic interference and sudden changes in temperature and humidity. Simultaneously, fixed remediation strategies lack responsiveness to real-time equipment load status and sudden environmental changes, easily leading to delays in critical vulnerability remediation or unnecessary maintenance operations consuming system resources, revealing insufficient adaptability in complex and ever-changing power grid operation scenarios. Summary of the Invention

[0003] This invention provides a method and system for repairing vulnerabilities in power network equipment based on dynamic behavior analysis.

[0004] In a first aspect, embodiments of the present invention provide a method for patching vulnerabilities in power network equipment based on dynamic behavior analysis, comprising: acquiring a set of operational data of the power network equipment, the set of operational data including multiple operational cycle data, each operational cycle data including at least one equipment operational status parameter and a corresponding external environment parameter; performing dynamic behavior analysis on the set of operational data to obtain a set of dynamic behavior features of the multiple operational cycle data; the set of dynamic behavior features being used to characterize abnormal behavior patterns of the power network equipment within the operational cycle; performing vulnerability feature extraction processing on the set of dynamic behavior features based on preset dynamic policy matching rules to generate a set of vulnerability patching strategies corresponding to the abnormal behavior patterns; the set of vulnerability patching strategies including execution priority and execution condition parameters of multiple patching instructions; triggering vulnerability patching operations of the power network equipment according to the execution priority and execution condition parameters in the set of vulnerability patching strategies, and acquiring patched equipment operational verification data; generating a patching effect evaluation result based on the difference parameters between the equipment operational verification data and preset security operation standards, and adjusting the dynamic policy matching rules according to the difference parameters.

[0005] Secondly, embodiments of the present invention provide a computer system, including: a memory storing a computer program; and a processor for loading the computer program to implement the above-described method for repairing power network equipment vulnerabilities based on dynamic behavior analysis.

[0006] The power network equipment vulnerability remediation method provided by this invention constructs a multi-dimensional analysis model by integrating equipment operating status parameters and external environmental parameters. This overcomes the limitation of traditional vulnerability detection, which separates intrinsic equipment faults from environmental causes, and effectively identifies hidden abnormal equipment behaviors caused by complex environmental interactions. Based on an abnormal pattern extraction mechanism using dynamic behavioral feature sets, it can capture progressive vulnerability characteristics that change with the environment during equipment operation, significantly improving the ability to discover unknown vulnerability types. Through a set of remediation strategies generated by dynamic policy matching rules, combined with the dual constraints of execution priority and execution condition parameters, it achieves adaptive matching between remediation operations and real-time equipment operating conditions and environmental states, ensuring priority handling of critical vulnerabilities. At the same time, by leveraging the feedback of differences between remediation verification data and safe operation standards, it dynamically optimizes policy matching rules, enabling the vulnerability remediation system to have continuous evolution capabilities and maintain a stable level of security protection in complex and ever-changing power network environments. Attached Figure Description

[0007] Figure 1 This is a flowchart of a method for repairing vulnerabilities in power network equipment based on dynamic behavior analysis, provided by an embodiment of the present invention.

[0008] Figure 2 This is a schematic diagram of the composition of a computer system provided in an embodiment of the present invention. Detailed Implementation

[0009] Please see Figure 1 , Figure 1 The flowchart illustrates a method for patching vulnerabilities in power network equipment based on dynamic behavior analysis, provided in an embodiment of the present invention. This method can be executed by a computer system and may include the following steps:

[0010] Step S100: Obtain the operating data set of the power network equipment. The operating data set includes multiple operating cycle data. Each operating cycle data contains at least one equipment operating status parameter and the corresponding external environment parameter.

[0011] An operational dataset is a collection of data obtained from monitoring power network equipment over a period of time. This data reflects the operational status of the power network equipment. Multiple operational cycle data represent data obtained from monitoring the equipment's operation at different time intervals. Each operational cycle represents a complete operational process of the equipment from an initial state to an end state. Equipment operational status parameters are various data describing the operational status of the power network equipment itself, such as voltage, current, power, temperature, and frequency. These parameters reflect the equipment's performance and operational status. External environmental parameters are data related to the external environment in which the equipment operates, such as ambient temperature, humidity, air pressure, and electromagnetic interference intensity. External environmental factors can affect the operation of the equipment. Obtaining operational datasets of power network equipment can be achieved by deploying various sensors within the power network.

[0012] Step S200: Perform dynamic behavior analysis on the set of operating data to obtain a set of dynamic behavior features for multiple operating cycles; the set of dynamic behavior features is used to characterize the abnormal behavior patterns of power network equipment during the operating cycle.

[0013] Dynamic behavior analysis involves in-depth analysis of operational data sets to uncover dynamic patterns and characteristics within the data. By analyzing the changes in equipment operating status parameters and external environmental parameters over time, and the relationships between them, abnormal behavior during equipment operation can be identified. The dynamic behavior feature set is a collection of features obtained after analysis and processing, which accurately describes the abnormal behavior patterns that power network equipment may exhibit during its operating cycle. Abnormal behavior patterns are deviations from normal operating conditions, such as sudden increases or decreases in voltage, abnormal current fluctuations, and abnormal temperature increases.

[0014] There are various methods for performing dynamic behavioral analysis on operational datasets. For example, time series analysis can be used to analyze equipment operating status parameters to identify trends and periodic patterns over time; spatial analysis methods can be used to analyze external environmental parameters to determine the scope and extent of environmental factors' influence on equipment operation. Machine learning algorithms, such as cluster analysis and anomaly detection algorithms, can also be combined to classify and identify anomalies in operational data.

[0015] In one implementation, step S200 may specifically include the following steps S210 to S240:

[0016] Step S210: Perform time-series correlation analysis on the equipment operating status parameters in each operating cycle data to generate a first behavioral feature sequence related to the time dimension.

[0017] Temporal correlation analysis analyzes the changes in equipment operating status parameters over time, identifying temporal dependencies and mutual influences among these parameters. By analyzing the values ​​of equipment operating status parameters at different time points, it determines the correlation patterns and trends between them. The first behavioral feature sequence is a series of time-related feature sequences generated based on the results of temporal correlation analysis. These feature sequences reflect the dynamic changes of equipment operating status parameters over time.

[0018] Time-series correlation analysis of equipment operating status parameters can be performed using time series analysis methods such as the Autoregressive Integral Moving Average (ARIMA) model. The specific implementation process is as follows: The time-series data of the equipment operating status parameters is tested for stationarity. If the data is not stationary, it is differencing to make it stationary. Then, the parameters of the ARIMA model are determined based on the stationary time-series data, such as the autoregressive order p, the differencing order d, and the moving average order q. Next, the ARIMA model with determined parameters is used to fit and predict the time-series data, obtaining the model coefficients and predicted values. Finally, a first-row feature sequence related to the time dimension is generated based on the model coefficients and predicted values. For example, for the voltage data of a power device, using the ARIMA(1,1,1) model for time-series correlation analysis, by fitting and predicting the voltage data, a first-row feature sequence related to the time dimension is obtained. This sequence reflects the trend and fluctuation characteristics of voltage changes at different time points.

[0019] Step S220: Perform spatial distribution analysis on external environmental parameters to determine the set of spatial correlation characteristics of the environment in which the power network equipment is located.

[0020] Spatial distribution analysis studies the spatial distribution patterns and variation characteristics of external environmental parameters, and analyzes the correlations between environmental parameters at different locations. By analyzing the spatial distribution of external environmental parameters, we can understand the spatial characteristics of the environment in which power network equipment is located, and the spatial impact of environmental factors on equipment operation. The spatial correlation feature set is a set of features determined based on the results of spatial distribution analysis. These features can describe the spatial dependencies and the degree of synergistic influence of the environment in which power network equipment is located.

[0021] Spatial distribution analysis of external environmental parameters can be performed using Geographic Information System (GIS) technology and spatial statistical analysis methods. The specific implementation process is as follows: External environmental parameters are correlated with the geographical location information of power network equipment to construct a spatial dataset. Then, GIS technology is used to visualize the spatial dataset, allowing for a direct observation of the spatial distribution of external environmental parameters. Next, spatial statistical analysis methods, such as Moran's I, are used to analyze the spatial autocorrelation between environmental parameters at different locations. Based on the results of the spatial autocorrelation analysis, the spatial correlation patterns and strengths of the environmental parameters are determined. Finally, these spatial correlation patterns and strengths are combined into a spatial correlation feature set.

[0022] In one implementation, step S220 may specifically include the following steps S221 to S226:

[0023] Step S221: Obtain a set of real-time environmental parameters collected by multiple environmental monitoring nodes deployed in the environment where the power network equipment is located. The set of real-time environmental parameters includes temperature distribution data, humidity distribution data, and electromagnetic interference intensity data.

[0024] A real-time environmental parameter set is a collection of various parameters about the environment in which power grid equipment is located, collected by multiple environmental monitoring nodes at a given moment. Temperature distribution data describes the temperature conditions at different locations in the environment, humidity distribution data reflects the humidity levels at different locations, and electromagnetic interference intensity data indicates the degree of electromagnetic interference at different locations. Environmental monitoring nodes are devices installed around the power grid equipment to collect environmental parameters. These nodes can transmit the collected environmental parameters to a data processing center in real time or periodically. Obtaining a real-time environmental parameter set can be achieved by strategically deploying multiple environmental monitoring nodes in the environment where the power grid equipment is located.

[0025] Step S222: Based on the physical layout topology of the power network equipment, map the deployment location of the environmental monitoring nodes to the corresponding area division result of the physical layout topology, and generate an environmental parameter distribution map containing area identifiers.

[0026] A physical layout topology diagram is a graphic representation of the layout and connections of power network equipment in physical space. It displays information such as equipment location, connecting lines, and area divisions. The area division results are the identifiers and extents of different regions obtained by dividing the space occupied by power network equipment based on the physical layout topology diagram. An environmental parameter distribution diagram is a graphic generated by correlating environmental parameters collected by environmental monitoring nodes with the area division results in the physical layout topology diagram. It visually displays the distribution of environmental parameters in different regions.

[0027] Mapping the deployment locations of environmental monitoring nodes to the corresponding regional division results in the physical layout topology map can be implemented as follows: First, obtain the geographical location information of the environmental monitoring nodes, such as latitude and longitude coordinates. Then, according to the regional division rules in the physical layout topology map, determine the region to which each environmental monitoring node belongs. Finally, associate the environmental parameters collected by the environmental monitoring nodes with the corresponding regional identifiers to generate an environmental parameter distribution map containing the regional identifiers.

[0028] Step S223: Perform fluctuation consistency detection on the temperature distribution data, humidity distribution data, and electromagnetic interference intensity data corresponding to the same area in the environmental parameter distribution map, and extract the parameter change trend features that meet the fluctuation consistency conditions.

[0029] Fluctuation consistency detection analyzes whether the fluctuations of different environmental parameters (temperature, humidity, and electromagnetic interference intensity) within the same region are consistent, that is, whether the changing trends of these parameters are synchronous or related. Parameter change trend characteristics are features extracted from environmental parameters that meet the fluctuation consistency condition, reflecting the changing trend of the parameters, such as upward trends, downward trends, and periodic fluctuations.

[0030] To detect the consistency of fluctuations in temperature, humidity, and electromagnetic interference intensity data corresponding to the same area marker in an environmental parameter distribution map, statistical methods such as the Pearson correlation coefficient can be used. The specific implementation process is as follows: Extract the temperature, humidity, and electromagnetic interference intensity data sequences corresponding to the same area marker from the environmental parameter distribution map. Then, calculate the Pearson correlation coefficient between these data sequences to determine their correlation. If the correlation coefficient is greater than a preset threshold, the fluctuations of these parameters are considered consistent. Next, perform trend analysis on the parameter data sequences that meet the fluctuation consistency condition, for example, by fitting the data sequences using the least squares method to obtain the parameter change trend curves. Finally, extract the parameter change trend features from the change trend curves, such as slope and intercept.

[0031] Step S224: Generate an environmental correlation strength index between adjacent regions based on the parameter change trend characteristics. The environmental correlation strength index is used to characterize the degree of synergistic impact of environmental parameter changes in different regions on the operation of power network equipment.

[0032] The environmental correlation strength index is a quantitative indicator used to measure the degree of correlation between changes in environmental parameters between adjacent areas and the degree of synergistic impact on the operation of power grid equipment. Parameter change trend characteristics are features extracted in the previous step that reflect the changing trends of environmental parameters. By analyzing the relationships between the parameter change trend characteristics of adjacent areas, the environmental correlation strength index can be generated.

[0033] Generating environmental correlation strength indices between adjacent regions based on parameter variation trend characteristics can employ methods such as spatial autoregressive models (SAR). The specific implementation process is as follows: First, determine the relationship between adjacent regions based on the environmental parameter distribution map, and construct a spatial weight matrix for the adjacent regions. Then, using the parameter variation trend characteristics of the adjacent regions as independent variables, establish a spatial autoregressive model. By estimating and testing the model, obtain its coefficients. Finally, calculate the environmental correlation strength index between adjacent regions based on the model coefficients.

[0034] Step S225: Based on the device connection relationship in the physical layout topology diagram, perform topology propagation verification on the environmental correlation strength index and screen out the effective environmental correlation strength index that matches the signal transmission path of the device connection relationship.

[0035] Topology propagation verification verifies the rationality of the propagation of environmental correlation strength indicators in the power network based on the device connection relationships in the physical layout topology diagram, ensuring that the propagation matches the signal transmission paths of the device connections. Valid environmental correlation strength indicators are those selected after topology propagation verification that accurately reflect the impact of device connection relationships and environmental parameter changes on the operation of power network equipment. Specifically, topology propagation verification of environmental correlation strength indicators based on device connection relationships in the physical layout topology diagram involves: extracting device connection relationships and signal transmission path information from the physical layout topology diagram; then, simulating the propagation process of environmental parameter changes in the power network based on the calculated results of the environmental correlation strength indicators; and finally, checking whether the propagation of the environmental correlation strength indicators matches the signal transmission paths of the device connections. If they match, the environmental correlation strength indicator is considered valid; otherwise, it is excluded.

[0036] Step S226: Combine the effective environmental correlation strength index and its corresponding regional identifier into a spatial correlation feature set, which is used to indicate the spatial dependence of external environmental parameters of power network equipment.

[0037] The spatial correlation feature set is a collection of effective environmental correlation strength indicators and their corresponding regional identifiers. It accurately describes the spatial dependencies and mutual influences of external environmental parameters of power network equipment. By combining effective environmental correlation strength indicators with regional identifiers, the environmental correlation between different regions can be clearly displayed, providing an important basis for subsequent vulnerability analysis and remediation.

[0038] Combining effective environmental association strength indicators and their corresponding regional identifiers into a spatial association feature set can be achieved using data structures. For example, a list or dictionary can be used to store the effective environmental association strength indicators and their corresponding regional identifiers. Each element in the list can be a tuple containing a regional identifier and an environmental association strength indicator, while the key in the dictionary can be a regional identifier, and the value can be the corresponding environmental association strength indicator.

[0039] Step S230: Perform multi-dimensional fusion processing on the first behavioral feature sequence and the spatial correlation feature set to obtain the fused behavioral feature vector of each running cycle data.

[0040] Multidimensional fusion processing involves comprehensively processing feature data from different dimensions (first-order feature sequences and spatial correlation feature sets) to extract more comprehensive and valuable feature information. The fused behavioral feature vector is a vector obtained after multidimensional fusion processing. It contains the temporal dimension features of equipment operating status parameters and the spatial dimension features of external environment parameters, and can more accurately describe the behavioral characteristics of power network equipment in each operating cycle.

[0041] Principal Component Analysis (PCA) and other methods can be used to perform multidimensional fusion of the first-row feature sequence and the spatial correlation feature set. The specific implementation process is as follows: First, preprocess the first-row feature sequence and the spatial correlation feature set to ensure they have the same data format and scale. Then, merge the preprocessed data into a multidimensional dataset. Next, use PCA to reduce the dimensionality of the multidimensional dataset and extract the principal components. Finally, combine the principal components to form a fused behavioral feature vector.

[0042] Step S240: Perform abnormal pattern recognition processing on the fused behavior feature vector, extract the feature dimensions that exceed the preset safety threshold in the fused behavior feature vector, and determine the abnormal fluctuation data corresponding to the feature dimensions as abnormal behavior patterns in the dynamic behavior feature set.

[0043] Anomaly pattern recognition involves analyzing the fused behavior feature vector to identify potential anomaly patterns. A preset safety threshold is a pre-defined standard value used to determine whether a feature dimension is normal. Abnormal fluctuation data refers to the specific data corresponding to feature dimensions in the fused behavior feature vector that exceed the preset safety threshold. Anomaly behavior patterns are patterns identified from the abnormal fluctuation data that reflect abnormal behavior of power network equipment.

[0044] Anomaly detection methods such as the Isolation Forest algorithm can be used to perform anomaly pattern recognition on fused behavioral feature vectors. The specific implementation process is as follows: The fused behavioral feature vectors are input into the Isolation Forest algorithm for training. The Isolation Forest algorithm constructs multiple decision trees based on the data distribution, assigning each data point to a different leaf node. Then, the path length of each data point in the decision tree is calculated; the shorter the path length, the more likely the data point is to be an anomaly. Next, based on a preset safety threshold, it is determined whether each feature dimension in the fused behavioral feature vector exceeds the threshold. If it exceeds the threshold, the abnormal fluctuation data corresponding to that feature dimension is identified as an abnormal behavioral pattern. For example, for a set of fused behavioral feature vectors, the Isolation Forest algorithm is used for training and anomaly detection. A preset safety threshold is set to a certain value; when the value of a certain feature dimension exceeds this threshold, the abnormal fluctuation data corresponding to that feature dimension is considered an abnormal behavioral pattern and added to the dynamic behavioral feature set.

[0045] In one implementation, step S240 may specifically include the following steps S241 to S244:

[0046] Step S241: Obtain the standard behavioral feature set of the power network equipment during the historical operating cycle. The standard behavioral feature set includes multiple standard feature dimensions of the power network equipment in the vulnerability-free state and their corresponding standard fluctuation ranges.

[0047] The standard behavioral feature set is a collection of features obtained by analyzing and statistically processing historical operating cycle data of power network equipment under vulnerability-free conditions. Standard feature dimensions are various characteristic indicators describing the normal operating state of power network equipment, such as equipment operating status parameters like voltage, current, and power, as well as external environmental parameters like ambient temperature and humidity. The standard fluctuation range is the allowable fluctuation range for each standard feature dimension under normal operating conditions, reflecting the stability and reliability of equipment operation.

[0048] Obtaining a set of standard behavioral characteristics for power network equipment over its historical operating cycle can be achieved by: collecting operational data of the power network equipment over a past period, ensuring that the equipment was in a vulnerability-free state during this time; then cleaning and preprocessing the collected operational data to remove noise and outliers; next, using statistical analysis methods such as mean and standard deviation to calculate the average value and fluctuation range of each standard characteristic dimension; and finally, combining the standard characteristic dimensions and their corresponding standard fluctuation ranges into a set of standard behavioral characteristics.

[0049] Step S242: Match each feature dimension in the fused behavior feature vector with the standard feature dimension to determine the target feature dimension in the fused behavior feature vector that matches the standard feature dimension.

[0050] Feature dimension matching involves comparing each feature dimension in the fused behavioral feature vector with the standard feature dimensions in the standard behavioral feature set to identify the correspondence between them. Target feature dimensions are the feature dimensions in the fused behavioral feature vector that match the standard feature dimensions; these feature dimensions are used for subsequent anomaly detection and analysis.

[0051] Matching each feature dimension in the fused behavioral feature vector with a standard feature dimension can be done using either the feature name or the feature meaning. The specific implementation process is as follows: Label the feature dimensions in both the fused behavioral feature vector and the standard behavioral feature set, clearly defining the name and meaning of each feature dimension. Then, iterate through each feature dimension in the fused behavioral feature vector, comparing its name or meaning with the standard feature dimensions in the standard behavioral feature set. If the name or meaning is the same, the feature dimension is considered to match the standard feature dimension and is identified as the target feature dimension.

[0052] Step S243: Calculate the deviation parameter between the current fluctuation data of the target feature dimension and the standard fluctuation range. If the deviation parameter exceeds the preset deviation threshold, the target feature dimension is marked as an abnormal feature dimension.

[0053] The deviation parameter is a quantitative indicator used to measure the degree of deviation between the current fluctuation data of a target feature dimension and the standard fluctuation range. The preset deviation threshold is a pre-set standard value used to determine whether the target feature dimension is abnormal. An abnormal feature dimension is a feature dimension whose deviation parameter between the current fluctuation data of the target feature dimension and the standard fluctuation range exceeds the preset deviation threshold.

[0054] The deviation parameter between the current fluctuation data and the standard fluctuation range for the target feature dimension can be calculated using the following formula: Deviation parameter = |Current fluctuation data - Center value of standard fluctuation range| / Half width of standard fluctuation range. Here, the center value of the standard fluctuation range is the average value of the standard fluctuation range, and the half width of the standard fluctuation range is half the difference between the upper and lower limits of the standard fluctuation range.

[0055] Step S244: Generate an anomaly weight distribution map based on the deviation parameters of all anomaly feature dimensions, and determine the dominant anomaly type of the anomaly behavior pattern through the anomaly feature dimension with the largest weight value in the anomaly weight distribution map.

[0056] An anomaly weight distribution chart is a graphical or data structure used to display the deviation parameters of all anomaly feature dimensions and their corresponding weight values. The weight value represents the importance of each anomaly feature dimension in the anomaly behavior pattern; the larger the deviation parameter, the larger the weight value. The dominant anomaly type is the anomaly type corresponding to the anomaly feature dimension that plays a major role in the anomaly behavior pattern. By identifying the dominant anomaly type, vulnerability remediation can be more targeted.

[0057] Generating an anomaly weight distribution map based on the deviation parameters of all anomaly feature dimensions can be achieved using a normalization method. First, collect the deviation parameters for all anomaly feature dimensions and identify the maximum and minimum values. Next, use a linear normalization formula to convert each deviation parameter into a weight value between 0 and 1: Weight value = (Deviation parameter - Minimum value) / (Maximum value - Minimum value). Finally, combine each anomaly feature dimension and its corresponding weight value to form an anomaly weight distribution map, which can be visualized using bar charts, pie charts, or other visual methods.

[0058] Step S300: Based on the preset dynamic policy matching rules, perform vulnerability feature extraction processing on the dynamic behavior feature set to generate a vulnerability remediation policy set corresponding to the abnormal behavior pattern; the vulnerability remediation policy set contains the execution priority and execution condition parameters of multiple remediation instructions.

[0059] The preset dynamic policy matching rules are pre-defined rules used to match dynamic behavioral feature sets with vulnerability remediation policies. These rules consider the characteristics of abnormal behavior patterns, device operating status, and environmental factors. Vulnerability feature extraction processing extracts vulnerability-related feature information from the dynamic behavioral feature set to provide a basis for subsequent vulnerability remediation policy generation. The vulnerability remediation policy set is a collection of remediation policies generated based on the vulnerability feature extraction processing results. Each remediation policy contains multiple remediation instructions, and each instruction has its corresponding execution priority and execution condition parameters. The execution priority determines the execution order of the remediation instructions, while the execution condition parameters specify the preconditions for the execution of the remediation instructions, such as device operating status and environmental parameters.

[0060] Based on preset dynamic policy matching rules, vulnerability feature extraction processing is performed on a set of dynamic behavioral features to generate a set of vulnerability remediation strategies corresponding to abnormal behavior patterns. Specifically, this can be implemented as follows: The set of dynamic behavioral features is input into preset dynamic policy matching rules, and the feature set is analyzed and matched according to the rules. The rules can be implemented based on a rule engine, defining a series of conditions and actions. When the set of dynamic behavioral features meets a certain condition, the corresponding action is triggered, extracting vulnerability-related feature information. Then, based on the extracted vulnerability feature information, the corresponding remediation strategy is searched from a pre-built vulnerability remediation knowledge base. The vulnerability remediation knowledge base is a database storing various vulnerability types and their corresponding remediation strategies. Finally, the found remediation strategies are organized and sorted, the execution priority and execution condition parameters of each remediation instruction are determined, and a set of vulnerability remediation strategies is generated.

[0061] In one implementation, step S300 may specifically include the following steps S310 to S340:

[0062] Step S310: Match a set of candidate repair strategies from a preset vulnerability repair knowledge base based on the dominant anomaly type. The set of candidate repair strategies contains multiple candidate repair instructions and corresponding repair condition constraints.

[0063] The dominant anomaly type is the anomaly type that plays a major role in the abnormal behavior pattern, as identified above, such as abnormal voltage increases or abnormal temperature increases. The pre-defined vulnerability remediation knowledge base is a database storing various vulnerability types and their corresponding remediation strategies. These strategies are derived from expert experience and historical data. The candidate remediation strategy set is a collection of remediation strategies matched from the vulnerability remediation knowledge base based on the dominant anomaly type. Each strategy contains multiple candidate remediation instructions, and each candidate remediation instruction has its corresponding remediation condition constraints. The remediation condition constraints are the conditions that must be met to execute the remediation instruction, such as the device's operating status and environmental parameters.

[0064] Matching candidate remediation strategies from a pre-defined vulnerability remediation knowledge base based on the dominant anomaly type can be achieved through keyword matching. First, the dominant anomaly type is converted into keywords, for example, "abnormal voltage increase" is converted to "voltage increase". Then, the pre-defined vulnerability remediation knowledge base is searched for remediation strategies containing these keywords, and the found remediation strategies are combined into a candidate remediation strategy set.

[0065] Step S320: Analyze the scope of vulnerability impact on the dynamic behavior feature set to determine the set of device components and associated environmental areas affected by the abnormal behavior pattern.

[0066] Vulnerability impact scope analysis examines the extent and degree of impact of anomalous behavior patterns on power network equipment and its environment. This is achieved through in-depth analysis of dynamic behavioral characteristic sets to identify the equipment components and environmental areas affected by the anomalous behavior patterns. The equipment component set refers to the collection of individual components of the power network equipment affected by the anomalous behavior patterns, such as transformers, switches, and capacitors. The associated environmental area refers to the area that overlaps with the physical deployment area of ​​the affected equipment components or is indirectly affected by the anomalous behavior patterns, such as areas where environmental parameters like temperature, humidity, and electromagnetic interference around the equipment change.

[0067] Analyzing the impact range of vulnerabilities in dynamic behavioral feature sets to determine the set of device components and associated environmental regions affected by abnormal behavior patterns can be implemented as follows: Based on the abnormal behavior patterns in the dynamic behavioral feature set, combined with the topology and component connection relationships of power network equipment, analyze the propagation path and impact range of the abnormal behavior patterns within the equipment. Shortest path algorithms and depth-first search algorithms from graph theory can be used for this analysis. Then, based on the physical deployment location and spatial association feature set of the device components, determine the environmental monitoring areas overlapping with the physical deployment areas of the affected device components. Finally, analyze the changes in environmental parameters in these environmental monitoring areas during the period in which the abnormal behavior patterns occur, and mark the monitoring areas with abrupt parameter changes as associated environmental regions.

[0068] In one implementation, step S320 may specifically include the following steps S321 to S326:

[0069] Step S321: Obtain the component dependency graph of the power network equipment. The component dependency graph contains the signal interaction paths and energy supply dependencies between equipment components.

[0070] A component dependency graph is a graphical representation of the interdependencies between components in a power network device. It illustrates the signal interaction paths and energy supply dependencies between these components. Signal interaction paths represent the communication and control routes between components via signals, while energy supply dependencies represent the energy supply and consumption relationships between components. By obtaining the component dependency graph, we can understand the interactions and impacts between components, providing a foundation for subsequent vulnerability impact analysis.

[0071] Obtaining the component dependency diagram of power network equipment can be achieved by: collecting design documents, topology information, and equipment configuration files for the power network equipment, which contain the connection relationships and dependencies between equipment components. Then, using graphical tools, these connections and dependencies are plotted as a component dependency diagram. During the plotting process, different lines and symbols are used to represent signal interaction paths and energy supply dependencies. For example, solid lines represent energy supply dependencies, and dashed lines represent signal interaction paths. Finally, the plotted component dependency diagram is reviewed and verified to ensure its accuracy and completeness.

[0072] Step S322: Perform time-series matching between the abnormal behavior patterns in the dynamic behavior feature set and the signal interaction paths in the component dependency graph to identify the first-level affected components directly triggered by the abnormal fluctuation signal.

[0073] Timing matching compares the temporal changes of abnormal behavior patterns with the signal interaction paths in the component dependency graph to identify the propagation order and impact range of abnormal fluctuation signals along these paths. The first-level affected components are those directly triggered by the abnormal fluctuation signals; these components are the initial targets affected by the abnormal behavior patterns.

[0074] Time-series matching of anomalous behavior patterns in a dynamic behavior feature set with signal interaction paths in the component dependency graph can be performed using time series analysis and graph matching algorithms. First, time series analysis is performed on the anomalous behavior patterns in the dynamic behavior feature set to extract features such as the start time, duration, and trend of anomalous fluctuation signals. Then, a signal propagation model is constructed based on the signal interaction paths in the component dependency graph. Graph matching algorithms are then used to match the features of the anomalous fluctuation signals with the signal propagation model to determine the propagation order and impact range of the anomalous fluctuation signals along the signal interaction paths. Finally, based on the matching results, the first-level affected components directly triggered by the anomalous fluctuation signals are identified.

[0075] Step S323: Based on the energy supply dependency relationship in the component dependency graph, traverse the energy supply paths associated with the first-level affected components to determine the second-level affected components indirectly triggered by the energy supply interruption.

[0076] Energy supply dependencies describe the energy supply and consumption relationships between equipment components. A component dependency diagram clearly shows the energy source and supply path of each equipment component. Traversing the energy supply paths associated with the first-level affected components involves starting with the first-level affected component and sequentially searching along the energy supply dependencies to find its upstream and downstream components, determining which components will be indirectly affected by the energy supply interruption of the first-level affected component. The second-level affected components are those indirectly affected by the energy supply interruption of the first-level affected component.

[0077] Based on the energy supply dependencies in the component dependency graph, traversing the energy supply paths associated with the first-level affected components, and identifying the second-level affected components indirectly triggered by the energy supply interruption, can be achieved using either Depth-First Search (DFS) or Breadth-First Search (BFS) algorithms. Taking DFS as an example, it first starts with the first-level affected components and marks them as visited. Then, based on the energy supply dependencies in the component dependency graph, it searches for all upstream and downstream components of that component. For each unvisited component, it recursively performs a DFS until all related components have been traversed. During the traversal, it determines whether a component will malfunction due to the energy supply interruption of the first-level affected component; if so, it is identified as a second-level affected component. For example, in a power network, the first-level affected component is a transformer. By traversing its energy supply path using DFS, it is found that a downstream capacitor malfunctions due to the transformer's energy supply interruption, and this capacitor is identified as a second-level affected component.

[0078] Step S324: Based on the effective environmental association strength index in the spatial association feature set, locate the environmental monitoring area that overlaps with the physical deployment areas of the first-level affected components and the second-level affected components.

[0079] The effective environmental correlation strength index in the spatial correlation feature set reflects the degree of correlation between environmental parameters in different regions and the degree of synergistic impact on the operation of power network equipment. These indicators allow us to understand the impact of environmental changes in different regions on equipment components. Locating environmental monitoring areas that overlap with the physical deployment areas of the first-level and second-level affected components involves identifying environmental monitoring areas with strong environmental correlations to the regions where the affected components are located, based on the physical location of the components and the spatial correlation feature set.

[0080] Based on the effective environmental association strength index in the spatial association feature set, locating the environmental monitoring area overlapping with the physical deployment areas of the first-level and second-level affected components can be achieved by: acquiring the physical deployment location information of the first-level and second-level affected components, such as latitude and longitude coordinates or their positions on the physical layout topology map; then, determining the area range with strong environmental association with the regions where these components are located based on the effective environmental association strength index in the spatial association feature set; this can be achieved by setting an environmental association strength threshold, whereby an area is considered to have a strong environmental association with the affected components if the environmental association strength exceeds this threshold; finally, finding areas overlapping with the determined area range within the environmental monitoring area, and locating these areas as the environmental monitoring area overlapping with the physical deployment areas of the affected components.

[0081] Step S325: Extract records of environmental parameter mutations in the environmental monitoring area during the period when the abnormal behavior pattern occurred, and mark the monitoring areas with parameter mutations as associated environmental areas.

[0082] Environmental parameter mutation records are records of sudden changes in environmental parameters (such as temperature, humidity, electromagnetic interference intensity, etc.) within the environmental monitoring area during the period of abnormal behavior patterns. Extracting these records allows us to understand the impact of abnormal behavior patterns on the environment. Associated environmental areas are environmental monitoring areas where environmental parameter mutations occur. These areas are closely related to the affected equipment components and may have further impacts on equipment operation.

[0083] Extracting records of environmental parameter mutations in an environmental monitoring area during the period of an abnormal behavior pattern and marking monitoring areas with parameter mutations as associated environmental areas can be implemented as follows: First, determine the time period during which the abnormal behavior pattern occurred, for example, from time t1 to time t2. Then, extract environmental parameter data for the monitoring area during this time period from the environmental monitoring data. Next, perform mutation detection on the extracted environmental parameter data, using statistical methods such as the Z-score method or machine learning methods such as the Isolation Forest algorithm. If the change in environmental parameters of a certain monitoring area exceeds a preset mutation threshold during this time period, the area is considered to have an environmental parameter mutation. Finally, marking monitoring areas with environmental parameter mutations as associated environmental areas.

[0084] Step S326: Perform topological integration of the first-level affected components, the second-level affected components and their corresponding associated environmental regions to generate a vulnerability impact scope mapping table containing component identifiers and region identifiers. The vulnerability impact scope mapping table is used to describe the collaborative effect path of abnormal behavior patterns on device components and the external environment.

[0085] Topology integration involves combining the first-level affected components, second-level affected components, and their corresponding associated environmental areas according to their physical connections and spatial relationships, forming a complete description of the vulnerability's impact scope. Component identifiers are unique identifiers for each device component, used to distinguish different device components. Area identifiers are unique identifiers for each environmental monitoring area, used to distinguish different environmental areas. The vulnerability impact scope mapping table is a table that records the impact scope and synergistic paths of anomalous behavior patterns on device components and the external environment. This table provides a clear understanding of the propagation and impact of anomalous behavior patterns on devices and the environment.

[0086] The vulnerability impact scope mapping table, which includes component identifiers and region identifiers, is generated by topologically integrating the first-level affected components, second-level affected components, and their corresponding associated environmental regions. Specifically, this can be achieved as follows: First, the component identifiers of the first-level and second-level affected components are organized into a component identifier list. Then, the region identifiers of the associated environmental regions are organized into a region identifier list. Next, based on the physical connections and spatial relationships between components and regions, a mapping relationship between component identifiers and region identifiers is established. This mapping relationship can be represented using matrices or graphs. Finally, the component identifiers, region identifiers, and mapping relationships are compiled into the vulnerability impact scope mapping table.

[0087] Step S330: Based on the component type of the device component set and the environmental parameters of the associated environmental area, select target repair instructions that meet the repair condition constraints from the candidate repair strategy set.

[0088] The device component set refers to the different types of device components, such as transformers, switches, and capacitors. Different types of components have different characteristics and failure modes. The environmental parameters of the associated environment area include parameters such as temperature, humidity, and electromagnetic interference intensity. These parameters affect the operation and repair effectiveness of the device components. The candidate repair strategy set is a collection of repair strategies matched from a pre-defined vulnerability repair knowledge base based on the dominant anomaly type in the previous step. Each strategy contains multiple candidate repair instructions, and each candidate repair instruction has its corresponding repair condition constraints. The target repair instructions are the repair instructions that meet the repair condition constraints and are selected from the candidate repair strategy set. These instructions can be used to repair the affected device components.

[0089] Based on the component types of the device component set and the environmental parameters of the associated environmental region, the selection of target repair instructions that meet the repair condition constraints from the candidate repair strategy set can be implemented as follows: Iterate through each candidate repair instruction in the candidate repair strategy set and obtain its corresponding repair condition constraints. Repair condition constraints can be combinations of conditions such as device component type and environmental parameter range. Then, for each candidate repair instruction, check whether there is a component in the device component set that meets its component type requirements, and whether the environmental parameters of the associated environmental region meet its environmental parameter range requirements. If both are met, the candidate repair instruction is determined as the target repair instruction.

[0090] Step S340: Based on the execution resource consumption parameters and repair timeliness parameters of the target repair instructions, calculate the comprehensive execution priority of each target repair instruction, and sort the target repair instructions from high to low according to the comprehensive execution priority to generate a set of vulnerability repair strategies.

[0091] The execution resource consumption parameter refers to the resources required to execute each target remediation instruction, such as manpower, material resources, and financial resources. The remediation timeliness parameter specifies the remediation time requirement for each target remediation instruction, such as urgent remediation, short-term remediation, or long-term remediation. The overall execution priority is a comprehensive index calculated based on the execution resource consumption parameter and the remediation timeliness parameter, used to measure the importance and urgency of each target remediation instruction. The vulnerability remediation strategy set is a collection obtained by sorting the target remediation instructions from high to low overall execution priority. This set contains multiple remediation instructions and their corresponding execution priorities and execution condition parameters.

[0092] Based on the resource consumption parameters and repair timeliness parameters of the target repair instructions, the overall execution priority of each target repair instruction is calculated, and the target repair instructions are sorted from high to low according to their overall execution priority to generate a set of vulnerability repair strategies. Specifically, this can be achieved by assigning weights to the resource consumption parameters and repair timeliness parameters, for example, a weight of 0.4 for the resource consumption parameter and a weight of 0.6 for the repair timeliness parameter. Then, the resource consumption parameters and repair timeliness parameters of each target repair instruction are quantified. For example, the resource consumption parameter is quantified into three levels: high, medium, and low, each corresponding to a different value; the repair timeliness parameter is quantified into three levels: urgent, important, and general, each corresponding to a different value. Next, based on the set weights and the quantified parameter values, the overall execution priority of each target repair instruction is calculated using the formula: Overall Execution Priority = Execution Resource Consumption Parameter Value * Execution Resource Consumption Parameter Weight + Repair Timeliness Parameter Value * Repair Timeliness Parameter Weight. Finally, the target repair instructions are sorted from high to low according to their overall execution priority to generate a set of vulnerability repair strategies.

[0093] Step S400: Based on the execution priority and execution condition parameters in the vulnerability remediation strategy set, trigger the vulnerability remediation operation of the power network equipment and obtain the remediated equipment operation verification data.

[0094] The execution priority in the vulnerability remediation strategy set determines the execution order of the remediation instructions, while the execution condition parameters specify the preconditions for each remediation instruction. Triggering a vulnerability remediation operation on power network equipment involves executing the remediation instructions in the vulnerability remediation strategy set sequentially according to their execution priority. When the execution condition parameters are met, a corresponding control signal is sent through the power network equipment's control interface to initiate the remediation operation. The post-remediation equipment operation verification data consists of equipment operating status parameters and external environment parameters collected and monitored after the vulnerability remediation operation is completed. This data is used to verify whether the vulnerability remediation operation achieved the expected remediation effect.

[0095] Based on the execution priority and condition parameters in the vulnerability remediation strategy set, the vulnerability remediation operation of the power network equipment is triggered, and the remediated equipment operation verification data is obtained. Specifically, this can be achieved by: retrieving remediation instructions from the vulnerability remediation strategy set in descending order of execution priority; for each remediation instruction, checking whether the current equipment operating status and external environment parameters meet its execution condition parameters; if so, sending the corresponding control signal through the power network equipment's control interface to trigger the remediation operation; during the remediation operation, real-time monitoring of the equipment's operating status and environmental parameters to ensure smooth operation; and after all remediation instructions have been executed, comprehensive operational monitoring of the power network equipment is performed, collecting the remediated equipment operating status parameters and external environment parameters as the remediated equipment operation verification data.

[0096] As one implementation method, in step S400, the vulnerability remediation operation of the power network equipment is triggered according to the execution priority and execution condition parameters in the vulnerability remediation strategy set, which may specifically include the following steps S410 to S430:

[0097] Step S410: Execute the target repair instructions in descending order of execution priority, and before executing each target repair instruction, check whether the current device operating status meets the environmental constraints and device resource conditions in the execution condition parameters.

[0098] The target remediation instructions are those selected and sorted from the vulnerability remediation strategy set, with execution priority determining their execution order. Environmental constraints are the requirements for external environmental parameters in the execution condition parameters, such as ambient temperature, humidity, and electromagnetic interference intensity. Device resource conditions are the requirements for the device's own resources in the execution condition parameters, such as device load, memory, and bandwidth. Checking whether the current device operating status meets the environmental constraints and device resource conditions in the execution condition parameters ensures the safe and effective execution of the remediation instructions, avoiding device failure or poor remediation results caused by executing remediation instructions under unmet conditions.

[0099] Target repair instructions are executed sequentially in descending order of execution priority. Before executing each instruction, the current device operating status is checked to ensure it meets the environmental constraints and device resource conditions specified in the execution condition parameters. Specifically, this can be implemented as follows: The highest-priority target repair instruction is retrieved from the vulnerability repair strategy set. Then, the current device operating status data, including device operating status parameters and external environment parameters, is obtained. Next, the obtained device operating status data is compared with the environmental constraints and device resource conditions specified in the execution condition parameters of the target repair instruction. If the current device operating status meets the environmental constraints and device resource conditions, the target repair instruction is prepared for execution; otherwise, it is not executed, and the process waits for the conditions to be met or makes appropriate adjustments.

[0100] Step S420: If both environmental constraints and equipment resource conditions are met, the repair operation corresponding to the target repair command is triggered through the control interface of the power network equipment.

[0101] The control interface of power network equipment is used for communication and control with the equipment. Through this interface, control signals can be sent to the equipment to initiate corresponding repair operations. When both environmental constraints and equipment resource conditions are met, it indicates that the conditions for executing the target repair command are mature, and the repair operation can be executed safely and effectively. The repair operation corresponding to the target repair command is initiated by sending corresponding control signals to the equipment through the control interface, based on the specific content of the target repair command.

[0102] If both environmental constraints and equipment resource conditions are met, the repair operation corresponding to the target repair command is triggered through the power network equipment's control interface. Specifically, this involves: determining the control signal corresponding to the target repair command. Different target repair commands may correspond to different control signals; for example, the control signal for "restarting the device" might be a preset command code. Then, the control signal is sent to the device through the power network equipment's control interface. The control interface can be a serial port, Ethernet port, USB interface, etc., selected appropriately based on the specific device. Finally, the device responds to the control signal and executes the repair operation. During execution, the device's operating status can be monitored in real time to ensure the smooth progress of the repair operation.

[0103] Step S430: If environmental constraints or equipment resource conditions are not met, the execution of the current target repair instruction is suspended, and a condition optimization strategy is generated based on the unmet condition parameters. The condition optimization strategy is used to adjust the resource allocation or environmental parameters of the power network equipment to re-meet the execution condition parameters.

[0104] When environmental constraints or equipment resource conditions are not met, continuing to execute the current target repair instruction may lead to equipment failure or poor repair results. Therefore, it is necessary to suspend the execution of the target repair instruction. Condition optimization strategies are a series of strategies generated based on unmet condition parameters. These strategies are used to adjust the resource allocation or environmental parameters of power network equipment, so that the equipment operating state once again meets the execution condition parameters. By implementing condition optimization strategies, favorable conditions can be created for the execution of target repair instructions, improving the success rate of repair operations.

[0105] If environmental constraints or equipment resource conditions are detected as unmet, the execution of the current target repair instruction is paused, and a condition optimization strategy is generated based on the unmet condition parameters. Specifically, this can be implemented as follows: First, determine whether the unmet condition parameter is an environmental constraint or a equipment resource condition, and its specific value. Then, analyze possible optimization measures based on the unmet condition parameters. For environmental constraints, the ambient temperature can be adjusted by regulating air conditioning or ventilation equipment; for equipment resource conditions, equipment resources can be optimized by adjusting equipment load or releasing memory. Next, generate a condition optimization strategy based on the analyzed optimization measures. The condition optimization strategy can be a series of operation instructions or control parameters used to guide the equipment in resource allocation or environmental parameter adjustment. Finally, execute the condition optimization strategy, monitor the equipment's operating status, and continue executing the current target repair instruction only after the execution condition parameters are met.

[0106] As one implementation method, step S400, obtaining the repaired equipment operation verification data, may specifically include the following steps S440 to S470:

[0107] Step S440: After completing the vulnerability remediation operation, perform full-dimensional operational monitoring of the power network equipment and collect the remediated equipment operation status parameters and external environment parameters.

[0108] Comprehensive operational monitoring involves real-time monitoring of all aspects of power network equipment, including its electrical, mechanical, and thermal performance. Equipment operating status parameters are various data describing the equipment's operating status, such as voltage, current, power, temperature, and frequency. External environmental parameters are relevant data about the external environment in which the equipment operates, such as ambient temperature, humidity, air pressure, and electromagnetic interference intensity. Collecting and remediating equipment operating status parameters and external environmental parameters is crucial for evaluating the effectiveness of vulnerability remediation operations and determining whether the equipment has returned to normal operating conditions.

[0109] After completing the vulnerability remediation, comprehensive operational monitoring of the power network equipment is performed, collecting post-remediation equipment operating status parameters and external environmental parameters. Specifically, this can be achieved by deploying various sensors on the power network equipment to collect these parameters in real time. Then, after the vulnerability remediation is complete, the sensors are activated to collect data. The data collected by the sensors can be transmitted to a data acquisition center via wired or wireless communication. Finally, the collected data is stored and managed for subsequent analysis and processing.

[0110] Step S450: Extract features from the repaired equipment operating status parameters to generate a repair verification feature set.

[0111] Feature extraction involves extracting key information reflecting the device's operational characteristics and performance from the repaired device's operational status parameters. The remediation verification feature set is a collection of features obtained after feature extraction; these features are used to verify whether the vulnerability remediation operation achieved the expected results. Analysis of the remediation verification feature set can determine whether the device has returned to normal operation and whether any potential problems still exist.

[0112] Various methods can be used to extract features from the repaired equipment's operating status parameters to generate a repair verification feature set. For example, statistical analysis methods can be used to calculate statistical characteristics such as the mean, standard deviation, and variance of the equipment's operating status parameters; time-domain analysis methods can be used to extract time-domain features such as peak values, valley values, rise time, and fall time; and frequency-domain analysis methods can be used to perform Fourier transforms on the parameters to extract their spectral features. Machine learning algorithms, such as Principal Component Analysis (PCA) and autoencoders, can also be combined to reduce the dimensionality of the equipment's operating status parameters and extract their main features. For example, for repaired voltage data, statistical analysis methods can be used to calculate its mean and standard deviation, and time-domain analysis methods can be used to extract its peak values ​​and valley values. These features can then be combined to form a repair verification feature set.

[0113] Step S460: Compare the set of repair verification features with the preset security operation standards item by item, and generate a list of verification results containing the comparison differences.

[0114] The preset safe operation standards are a series of pre-defined criteria and indicators used to measure the normal operating status of equipment. These standards and indicators are determined based on the equipment's design requirements, historical operating data, and safety specifications. Item-by-item comparison involves comparing each feature in the repair verification feature set with its corresponding indicator in the preset safe operation standards, calculating the difference between them. The verification result list records the difference values ​​for each feature comparison, providing a clear understanding of the gap between the repaired equipment's operating status and the safe operation standards.

[0115] The process of comparing the repair verification feature set with the preset safety operation standards item by item to generate a verification result list containing the comparison difference values ​​can be implemented as follows: First, organize the repair verification feature set and the preset safety operation standards, ensuring a one-to-one correspondence between their feature dimensions and indicators. Then, for each feature in the repair verification feature set, calculate the difference value between it and the corresponding indicator in the preset safety operation standards. The difference value can be an absolute difference, a relative difference, etc., and an appropriate calculation method should be selected according to the specific situation. Finally, compile the comparison difference values ​​of each feature into a verification result list. For example, the repair verification feature set may include features such as the mean voltage and the standard deviation of current, while the corresponding indicators in the preset safety operation standards are the standard value of the mean voltage and the standard value of the standard deviation of current. Calculate the difference between the mean voltage and the standard value of the mean voltage, and the difference between the standard deviation of current and the standard deviation of current, and compile these difference values ​​into a verification result list.

[0116] Step S470: Determine whether the vulnerability remediation operation has achieved the expected remediation effect based on whether all the comparison difference values ​​in the verification result list are within the preset security tolerance range.

[0117] The preset security tolerance range is a pre-defined range used to determine whether the comparison difference values ​​are acceptable. This range is determined based on the device's security requirements and performance indicators. If all the comparison difference values ​​in the verification result list are within the preset security tolerance range, it means that the gap between the device's post-repair operating state and the security operating standard is within an acceptable range, and the vulnerability repair operation has achieved the expected repair effect; otherwise, it means that the device still has some problems, and the vulnerability repair operation has not achieved the expected effect.

[0118] Determining whether the vulnerability remediation operation has achieved the expected remediation effect by checking whether all comparison differences in the verification result list are within the preset security tolerance range can be implemented as follows: Iterate through each comparison difference value in the verification result list. Then, check whether each comparison difference value is within the preset security tolerance range. Conditional statements can be used for this check; for example, if the comparison difference value is greater than the upper limit of the security tolerance range or less than the lower limit, then the difference value is considered to have exceeded the security tolerance range. Finally, determine whether the vulnerability remediation operation has achieved the expected remediation effect based on the check results. If all comparison differences are within the security tolerance range, the vulnerability remediation operation is considered to have achieved the expected remediation effect; otherwise, it is considered not to have achieved the expected remediation effect.

[0119] Step S500: Based on the difference parameters between the equipment operation verification data and the preset safety operation standards, generate the repair effect evaluation results, and adjust the dynamic strategy matching rules according to the difference parameters.

[0120] Device operation verification data consists of device operation status parameters and external environment parameters collected after vulnerability remediation operations are completed. Preset security operation standards are a series of pre-defined standards and indicators used to measure the normal operating status of the device. Difference parameters are the differences between the device operation verification data and the preset security operation standards; these differences reflect the gap between the device's post-remediation operation status and the security operation standards. The remediation effectiveness evaluation result is obtained by assessing the effectiveness of the vulnerability remediation operation based on the difference parameters. This result can be a qualitative evaluation (e.g., successful remediation, partial remediation, remediation failure, etc.) or a quantitative indicator (e.g., remediation success rate, remediation deviation rate, etc.). Dynamic policy matching rules are rules used to match dynamic behavioral feature sets with vulnerability remediation strategies. Adjusting the dynamic policy matching rules based on the difference parameters can improve the accuracy and adaptability of the rules, making subsequent vulnerability remediation more effective.

[0121] Based on the difference parameters between equipment operation verification data and preset security operation standards, a remediation effectiveness evaluation result is generated, and the dynamic policy matching rules are adjusted according to the difference parameters. Specifically, this can be achieved by: calculating remediation effectiveness evaluation indicators based on the difference parameters. Various methods can be used to calculate these indicators, such as calculating the mean, standard deviation, and other statistical measures of the difference parameters, and determining the evaluation level of the remediation effectiveness based on these statistical measures. Then, based on the remediation effectiveness evaluation results, the causes of the difference parameters are analyzed to determine whether adjustments to the dynamic policy matching rules are necessary. If the remediation effect is poor, it may be due to inaccurate or incomplete dynamic policy matching rules, requiring rule adjustment. Next, based on the difference parameters and analysis results, the policy matching conditions and weight coefficients in the dynamic policy matching rules are modified and optimized. For example, if a large difference parameter is found in a certain feature dimension, the weight of that feature dimension in the policy matching conditions can be increased. Finally, the adjusted dynamic policy matching rules are applied to subsequent vulnerability remediation processes to improve the effectiveness of vulnerability remediation.

[0122] As one implementation method, in step S500, a repair effect evaluation result is generated based on the difference parameters between the equipment operation verification data and the preset safety operation standard, which may specifically include the following steps S510 to S540:

[0123] Step S510: Extract abnormal difference values ​​that exceed the safety tolerance range from the verification result list and determine the device operation dimension corresponding to the abnormal difference values.

[0124] The verification results list is a list generated in the previous step containing comparisons between the set of repair verification features and the preset safe operating standards. The safety tolerance range is a pre-defined range used to determine whether the comparison differences are acceptable. Abnormal differences are comparison differences in the verification results list that exceed the safety tolerance range. These differences indicate significant discrepancies between the device's state and the safe operating standards in certain operating dimensions. Device operating dimensions describe various aspects of the device's operating state, such as voltage, current, power, and temperature. Identifying the device operating dimensions corresponding to abnormal differences helps pinpoint the problems in the device and provides a basis for subsequent analysis and repair.

[0125] Extracting abnormal difference values ​​that exceed the safety tolerance range from the verification result list and determining the corresponding device operation dimension for each abnormal difference value can be implemented as follows: Iterate through each comparison difference value in the verification result list. Then, check whether each comparison difference value exceeds the safety tolerance range. Conditional statements can be used for this check; for example, if the comparison difference value is greater than the upper limit of the safety tolerance range or less than the lower limit, then the difference value is considered to exceed the safety tolerance range. For abnormal difference values ​​that exceed the safety tolerance range, record their corresponding device operation dimension. The device operation dimension can be determined using the feature name or index in the verification result list.

[0126] Step S520: Based on the device operation dimension, backtrack the executed target repair instructions from the vulnerability repair strategy set and analyze the contribution of the target repair instructions to the repair of the device operation dimension.

[0127] The device operation dimension refers to the device operation dimension corresponding to the abnormal difference value determined in the previous step, such as the average voltage and the standard deviation of current. The vulnerability remediation strategy set is a collection generated during the vulnerability remediation process, containing multiple remediation instructions along with their execution priority and execution condition parameters. Backtracking the executed target remediation instructions involves identifying the remediation instructions executed for this device operation dimension from the vulnerability remediation strategy set. The remediation contribution is the degree to which the target remediation instruction contributes to the remediation effect of the device operation dimension. By analyzing the remediation contribution, the effectiveness of the target remediation instruction can be evaluated, and it can be determined whether the remediation strategy needs to be adjusted.

[0128] Analyzing the contribution of target remediation instructions to the repair of a device's operational dimension by backtracking the executed target remediation instructions from the vulnerability remediation strategy set can be achieved as follows: First, select target remediation instructions for that specific device operational dimension from the vulnerability remediation strategy set. The description or execution conditions of the target remediation instruction can be used to determine if it targets that dimension. Then, analyze the changes in the device operational dimension before and after the execution of each target remediation instruction. The measured values ​​of the device operational dimension before and after remediation can be compared, and the change can be calculated. Next, evaluate the contribution of the target remediation instruction to the repair of the device operational dimension based on the change. Quantitative methods can be used, such as calculating the percentage contribution. For example, for the device operational dimension of average voltage, select the target remediation instruction "adjust the transformer tap" for average voltage from the vulnerability remediation strategy set. Analyze the change in average voltage before and after the execution of this instruction. Before execution, the average voltage was 225V; after execution, the average voltage was 222V, a change of 3V. Assuming the average voltage of the safe operating standard is 220V, the difference between the standard and the voltage before the repair is 5V, and the difference between the standard and the voltage after the repair is 2V, then the contribution of the target repair instruction to the repair of the average voltage is (5-2) / 5*100%=60%.

[0129] Step S530: If the repair contribution is lower than the preset contribution threshold, it is determined that the target repair instruction has not effectively repaired the corresponding vulnerability, and a policy adjustment instruction is generated.

[0130] The preset contribution threshold is a pre-defined standard value used to determine the effectiveness of a target remediation command. This threshold is determined based on the device's security requirements and the expected remediation effect. If the remediation contribution of a target remediation command is lower than the preset contribution threshold, it indicates that the command's remediation effect on the device's operational dimension is poor, and it has not effectively remediated the corresponding vulnerability. Policy adjustment commands are a series of commands generated to improve vulnerability remediation effectiveness. These commands are used to adjust the remediation commands, execution priorities, or execution conditions within the vulnerability remediation policy set.

[0131] If the repair contribution is lower than a preset contribution threshold, the target repair instruction is deemed to have failed to effectively repair the corresponding vulnerability, and a policy adjustment instruction is generated. Specifically, this can be implemented by comparing the repair contribution of the target repair instruction with the preset contribution threshold. Conditional statements can be used for this comparison; for example, if the repair contribution is less than the contribution threshold, the target repair instruction is considered to have failed to effectively repair the corresponding vulnerability. Then, a policy adjustment instruction is generated based on the determination result. The policy adjustment instruction may include reselecting a repair instruction, adjusting the execution priority, or modifying execution conditions.

[0132] Step S540: The policy adjustment instruction is used to re-match supplementary repair instructions associated with the device operation dimension from the vulnerability remediation knowledge base, and add the supplementary repair instructions to the vulnerability remediation policy set.

[0133] The policy adjustment instruction is the instruction generated in the previous step used to adjust the vulnerability remediation policy. The vulnerability remediation knowledge base is a database that stores various vulnerability types and their corresponding remediation policies. Rematching supplementary remediation instructions associated with the device's operational dimension involves searching the vulnerability remediation knowledge base for new remediation instructions specific to that device's operational dimension based on the policy adjustment instruction. Supplementary remediation instructions are rematched instructions used to supplement the vulnerability remediation policy set; these instructions can improve the effectiveness of vulnerability remediation. Adding supplementary remediation instructions to the vulnerability remediation policy set involves integrating the new remediation instructions into the existing vulnerability remediation policy set, adjusting the execution priority and conditions of the remediation instructions, and forming a new vulnerability remediation policy set.

[0134] The policy adjustment instruction is used to re-match supplementary remediation instructions associated with the device operation dimension from the vulnerability remediation knowledge base and add these supplementary remediation instructions to the vulnerability remediation policy set. Specifically, this can be implemented as follows: Based on the device operation dimension information in the policy adjustment instruction, search the vulnerability remediation knowledge base for remediation instructions associated with that dimension. Keyword matching or rule matching methods can be used for the search. Then, the searched remediation instructions are filtered and evaluated, and suitable supplementary remediation instructions are selected. The evaluation can consider factors such as the effectiveness, feasibility, and resource consumption of the remediation instructions. Next, the selected supplementary remediation instructions are added to the vulnerability remediation policy set. Their execution priority and execution conditions can be adjusted according to the characteristics and requirements of the supplementary remediation instructions. Finally, the vulnerability remediation policy set is updated to form a new remediation policy.

[0135] As one implementation method, step S500, adjusting the dynamic strategy matching rules according to the difference parameters, may specifically include the following steps S550 to S590:

[0136] Step S550: Obtain the execution log data of the supplementary repair instructions corresponding to the strategy adjustment instructions recorded in the repair effect evaluation results.

[0137] The remediation effectiveness evaluation result is an assessment of the effectiveness of the vulnerability remediation operation obtained during the generation process. It records relevant information about the supplementary remediation instructions corresponding to the policy adjustment instructions. Execution log data consists of various records generated during the execution of the supplementary remediation instructions, including execution time, execution status, and execution results. Obtaining execution log data helps understand the execution status of the supplementary remediation instructions, providing a basis for subsequent analysis and adjustments.

[0138] Obtaining the execution log data of the supplementary repair instructions corresponding to the strategy adjustment instructions recorded in the repair effect evaluation results can be implemented as follows: Extract the identification information of the supplementary repair instructions corresponding to the strategy adjustment instructions from the repair effect evaluation results, such as instruction name and number. Then, search for the corresponding execution log data in the log database based on the identification information. The log database is used to store various instruction execution logs and can be a relational database, non-relational database, etc. Finally, the found execution log data is organized and filtered to extract useful information, such as execution time, execution status, and execution results.

[0139] Step S560: Extract the actual impact parameters of the supplementary repair instructions on the device operation dimension during the repair process from the execution log data. The actual impact parameters include the magnitude of the abnormal difference value change of the device operation dimension and the duration of the repair operation.

[0140] The actual impact parameter is a quantitative indicator of the actual impact of the supplementary repair command on the equipment operation dimension during the repair process, including the magnitude of the change in abnormal difference values ​​of the equipment operation dimension and the duration of the repair operation. The magnitude of the change in abnormal difference values ​​of the equipment operation dimension is the amount of change in the abnormal difference values ​​of the equipment operation dimension before and after the execution of the supplementary repair command; this indicator reflects the repair effect of the supplementary repair command on the equipment operation dimension. The duration of the repair operation is the time taken from the start to the end of the execution of the supplementary repair command; this indicator reflects the execution efficiency of the supplementary repair command.

[0141] Extracting the actual impact parameters of supplementary repair instructions on device operation dimensions during the repair process from execution log data can be implemented as follows: Obtain the measured values ​​of the device operation dimension before and after the execution of the supplementary repair instruction from the execution log data. For example, for the device operation dimension of average voltage, obtain the average voltage before execution as 222V and the average voltage after execution as 221V. Then, calculate the magnitude of the abnormal difference value change in the device operation dimension. The magnitude of the abnormal difference value change can be calculated by the difference between the abnormal difference values ​​before and after execution. Assuming the average voltage of the safe operating standard is 220V, the abnormal difference value before execution is 2V, and the abnormal difference value after execution is 1V, then the magnitude of the abnormal difference value change is 2-1=1V. Next, extract the duration of the repair operation from the execution log data. The duration of the repair operation can be calculated by the difference between the execution start time and the execution end time.

[0142] Step S570: Compare the actual impact parameters with the expected impact parameters of the supplementary repair instructions recorded in the vulnerability remediation knowledge base to generate the instruction effectiveness deviation value of the supplementary repair instructions.

[0143] The expected impact parameters are the parameters that, under ideal conditions, will affect the device's operational dimensions according to the supplementary remediation instructions recorded in the vulnerability remediation knowledge base. These include the expected magnitude of changes in abnormal difference values ​​and the expected duration of the remediation operation. The instruction effectiveness deviation value is the difference between the actual impact parameters and the expected impact parameters. This metric reflects the gap between the actual execution effect and the expected effect of the supplementary remediation instruction. By generating instruction effectiveness deviation values, the effectiveness of supplementary remediation instructions can be evaluated, providing a basis for adjusting dynamic policy matching rules.

[0144] The method of generating an instruction effectiveness deviation value for supplementary repair instructions by comparing the actual impact parameters with the expected impact parameters of the supplementary repair instructions recorded in the vulnerability remediation knowledge base can be implemented as follows: Obtain the expected impact parameters of the supplementary repair instructions from the vulnerability remediation knowledge base, including the expected magnitude of abnormal difference value changes and the expected duration of the repair operation. Then, compare the actual impact parameters with the expected impact parameters and calculate the difference between them. For the magnitude of abnormal difference value changes, calculate the difference between the actual and expected magnitude; for the duration of the repair operation, calculate the difference between the actual and expected duration. Finally, generate the instruction effectiveness deviation value based on the calculated difference values. A weighted average method can be used to combine the two difference values ​​to obtain a comprehensive instruction effectiveness deviation value.

[0145] Step S580: If the instruction effectiveness deviation value exceeds the preset deviation tolerance range, the policy matching conditions in the dynamic policy matching rules are expanded, and the actual impact parameters are integrated into the policy matching conditions as new matching conditions.

[0146] The preset deviation tolerance range is a pre-defined range used to determine whether the deviation value of the instruction effectiveness is acceptable. This range is determined based on the equipment's safety requirements and the expected repair effect. If the instruction effectiveness deviation value exceeds the preset deviation tolerance range, it indicates that there is a significant gap between the actual execution effect and the expected effect of the supplementary repair instruction, requiring adjustment of the dynamic strategy matching rules. Expanding the strategy matching conditions involves adding new matching conditions to the existing ones to improve the accuracy and adaptability of the rules. Integrating actual impact parameters as new matching conditions into the strategy matching conditions means incorporating actual impact parameters (such as the magnitude of abnormal difference value changes, repair operation duration, etc.) into the strategy matching conditions, enabling the rules to better consider the actual execution effect of the supplementary repair instruction.

[0147] If the instruction effectiveness deviation exceeds the preset deviation tolerance range, the policy matching conditions in the dynamic policy matching rules are expanded by integrating the actual impact parameters as new matching conditions. Specifically, this can be achieved by comparing the instruction effectiveness deviation with the preset deviation tolerance range. Conditional statements can be used for comparison; for example, if the instruction effectiveness deviation is greater than the upper limit of the deviation tolerance range or less than the lower limit, it is considered that the instruction effectiveness deviation exceeds the deviation tolerance range. Then, new matching conditions are generated based on the actual impact parameters. These new matching conditions can be restrictions on parameters such as the magnitude of abnormal difference value changes or the duration of repair operations. For example, the magnitude of abnormal difference value changes must be within a certain range, and the duration of repair operations must not exceed a certain value. Next, the new matching conditions are integrated into the policy matching conditions in the dynamic policy matching rules. Logical operators (such as AND and OR) can be used to combine the new matching conditions with the original conditions. Finally, the dynamic policy matching rules are updated to make the new policy matching conditions effective.

[0148] Step S590: Recalculate the matching fit of each candidate repair instruction in the candidate repair strategy set according to the expanded strategy matching conditions, and update the priority sorting rules of the candidate repair strategy set according to the matching fit.

[0149] The expanded policy matching conditions are the new matching conditions obtained by expanding the policy matching conditions in the dynamic policy matching rules in the previous step. Match fit is the degree of matching between the candidate repair instructions and the expanded policy matching conditions; this indicator reflects the applicability of the candidate repair instructions under the new matching conditions. Recalculating the match fit of each candidate repair instruction in the candidate repair policy set involves evaluating each candidate repair instruction in the set based on the expanded policy matching conditions and calculating its degree of matching with the new conditions. Updating the priority ranking rules of the candidate repair policy set involves adjusting the priority ranking of the candidate repair instructions in the set based on the recalculated match fit, making the priority ranking more reasonable and improving the effectiveness of vulnerability repair.

[0150] The process of recalculating the matching fit of each candidate repair instruction in the candidate repair strategy set based on the expanded strategy matching conditions, and updating the priority ranking rule of the candidate repair strategy set according to the matching fit, can be implemented as follows: For each candidate repair instruction in the candidate repair strategy set, its feature information is compared with the expanded strategy matching conditions. Feature information may include the applicable scenario, repair effect, resource consumption, etc., of the repair instruction. Then, the matching fit is calculated based on the comparison results. Fuzzy matching, similarity calculation, or other methods can be used to calculate the matching fit. For example, cosine similarity can be used to calculate the similarity between the feature vector of the candidate repair instruction and the feature vector of the strategy matching conditions. Next, the candidate repair instructions in the candidate repair strategy set are ranked according to the recalculated matching fit. They can be ranked from high to low matching fit, placing candidate repair instructions with higher matching fit at the top and giving them higher priority. Finally, the priority ranking rule of the candidate repair strategy set is updated to make the new ranking rule effective.

[0151] As one implementation method, when a change in the operating configuration of power network equipment is detected, the embodiments of the present invention may further include a process of performing dynamic analysis rule adaptation processing, which may specifically include the following steps S600 to S1000:

[0152] Step S600: Obtain the new set of device operating status parameters and the new set of external environment parameters corresponding to the changed operating configuration.

[0153] Operating configuration refers to the various settings and parameters of power network equipment, such as operating mode, rated power, and voltage level. When the operating configuration changes, the operating status of the equipment and the external environment may change accordingly. The new equipment operating status parameter set is the set of various operating status parameters of the power network equipment after the operating configuration change, such as voltage, current, power, and temperature. The new external environment parameter set is the set of relevant parameters of the external environment in which the equipment is located after the operating configuration change, such as ambient temperature, humidity, air pressure, and electromagnetic interference intensity. Obtaining the new equipment operating status parameter set and the new external environment parameter set corresponding to the changed operating configuration is for real-time monitoring and analysis of the equipment's operating status, ensuring that the equipment can operate normally under the new operating configuration, and providing a data foundation for subsequent dynamic analysis rule adaptation processing.

[0154] Obtaining the new set of equipment operating status parameters and the new set of external environmental parameters corresponding to the changed operating configuration can be achieved using various sensors deployed in the power network. These sensors can collect relevant data on equipment operating status and the external environment in real time. For example, voltage parameters can be collected using voltage sensors, and ambient temperature can be measured using temperature sensors. After the operating configuration changes, the sensors continuously record the new equipment operating status parameters and external environmental parameters, and transmit this data to the data acquisition system. The data acquisition system performs preliminary processing and storage on this data for subsequent analysis.

[0155] Step S700: Perform coverage verification between the new equipment operating status parameter set and the standard feature dimensions in the standard behavior feature set to determine the newly added feature dimensions and failure feature dimensions.

[0156] The standard behavioral feature set is a collection of features obtained by analyzing and statistically processing historical operating cycle data of power network equipment under vulnerability-free conditions. It includes multiple standard feature dimensions and their corresponding standard fluctuation ranges. Coverage verification involves comparing each feature dimension in the new equipment operating state parameter set with the standard feature dimensions in the standard behavioral feature set to check their coverage relationship. Newly added feature dimensions are those present in the new equipment operating state parameter set but not in the standard behavioral feature set. These feature dimensions may be due to new operating states or environmental factors introduced by changes in operating configuration. Failure feature dimensions are those present in the standard behavioral feature set but no longer appear or have lost meaning in the new equipment operating state parameter set. These feature dimensions may be due to changes in operating configuration causing certain operating states or environmental factors to become inapplicable.

[0157] To determine the new and failure feature dimensions, a coverage verification process is performed between the new equipment operating status parameter set and the standard feature dimensions in the standard behavioral feature set. This can be achieved by: organizing and labeling the feature dimensions in both sets, clearly defining the name and meaning of each dimension; then, iterating through each feature dimension in the new equipment operating status parameter set and checking if it exists in the standard behavioral feature set; if not, identifying it as a new feature dimension; and finally, iterating through each standard feature dimension in the standard behavioral feature set and checking if it appears in the new equipment operating status parameter set; if not, identifying it as a failure feature dimension.

[0158] Step S800: Adjust the feature fusion weight distribution in the multidimensional fusion process according to the newly added feature dimension, so that the weight values ​​of the failed feature dimension are redistributed to the newly added feature dimension.

[0159] Multidimensional fusion processing is a process of comprehensively processing feature data from different dimensions (such as the temporal dimension of equipment operating status parameters and the spatial dimension of external environmental parameters) during the previous dynamic behavior analysis. The feature fusion weight distribution determines the importance of each feature dimension in the fusion process. New feature dimensions are those identified in the previous step that appear in the new set of equipment operating status parameters, while failed feature dimensions are those that are no longer applicable. Adjusting the feature fusion weight distribution is to enable multidimensional fusion processing to better adapt to the new operating configuration, fully consider the impact of new feature dimensions, and reduce the interference of failed feature dimensions.

[0160] Adjusting the feature fusion weight distribution in multidimensional fusion processing based on newly added feature dimensions, so that the weight values ​​of failed feature dimensions are redistributed to the newly added feature dimensions, can be implemented as follows: First, determine the original feature fusion weight distribution in the multidimensional fusion processing, i.e., the weight value corresponding to each feature dimension. Then, calculate the total weight value of the failed feature dimensions. Add the weight values ​​of all failed feature dimensions to obtain the total weight value of the failed feature dimensions. Next, according to the number and importance of the newly added feature dimensions, distribute the total weight value of the failed feature dimensions to the newly added feature dimensions. Methods such as average distribution or distribution according to importance ratio can be used for weight allocation.

[0161] Step S900: Based on the adjusted feature fusion weight distribution, perform fusion processing on the new set of device operating status parameters and the new set of external environment parameters to generate a fusion behavior feature vector under the new configuration.

[0162] Fusion processing involves comprehensively calculating different feature dimensions from the new set of equipment operating status parameters and the new set of external environment parameters according to an adjusted feature fusion weight distribution, in order to extract more comprehensive and valuable feature information. The fused behavior feature vector under the new configuration is a vector obtained after fusion processing. It contains the comprehensive features of the new equipment operating status parameters and the new external environment parameters, and can more accurately describe the behavior characteristics of power network equipment under the new operating configuration.

[0163] The fusion of the new device operating state parameter set and the new external environment parameter set based on the adjusted feature fusion weight distribution can be achieved using a linear combination method to generate the fused behavior feature vector under the new configuration. The specific implementation process is as follows: Each feature dimension in the new device operating state parameter set and the new external environment parameter set is standardized to have the same scale and range. Then, according to the adjusted feature fusion weight distribution, the standardized feature dimensions are weighted and summed. The value of each feature dimension is multiplied by its corresponding weight value, and all products are summed to obtain the value of each dimension of the fused behavior feature vector. Finally, the calculated values ​​of each dimension are combined to form the fused behavior feature vector under the new configuration.

[0164] Step S1000: Input the fusion behavior feature vector under the new configuration into the abnormal pattern recognition process, and update the generation logic of the abnormal weight distribution map according to the data fluctuation characteristics of the newly added feature dimension.

[0165] Anomaly pattern recognition processing is used to identify abnormal behavior patterns during the operation of power network equipment. By inputting the fused behavioral feature vector under the new configuration into this process, it is possible to detect whether the equipment exhibits abnormal behavior under the new operating configuration. The anomaly weight distribution map is a graphical or data structure used to display the deviation parameters of all anomaly feature dimensions and their corresponding weight values. It reflects the importance of each anomaly feature dimension in the abnormal behavior pattern. The logic for updating the anomaly weight distribution map based on the data fluctuation characteristics of the newly added feature dimensions is to ensure that the anomaly weight distribution map more accurately reflects the abnormal behavior patterns of the equipment under the new configuration, fully considering the impact of the newly added feature dimensions.

[0166] The logic for generating the anomaly weight distribution map by inputting the fused behavior feature vector under the new configuration into the anomaly pattern recognition processing and updating the anomaly weight distribution map based on the data fluctuation characteristics of the newly added feature dimensions can be implemented as follows: The fused behavior feature vector under the new configuration is input into the anomaly detection algorithm used by the anomaly pattern recognition processing, such as the Isolation Forest algorithm or the Gaussian distribution-based anomaly detection algorithm. The anomaly detection algorithm determines whether the device exhibits abnormal behavior based on the feature values ​​of the fused behavior feature vector and outputs the anomaly feature dimension and its deviation parameters. Then, the data fluctuation characteristics of the newly added feature dimension are analyzed, such as fluctuation range, fluctuation frequency, and fluctuation trend. Based on these data fluctuation characteristics, the weight calculation method for the newly added feature dimension in the anomaly weight distribution map is determined. For example, if the data fluctuation range of the newly added feature dimension is large and the fluctuation frequency is high, it indicates that this feature dimension has a significant impact on abnormal behavior and can be assigned a higher weight. Next, the generation logic of the anomaly weight distribution map is updated to include the weight calculation method of the newly added feature dimension. When generating the anomaly weight distribution map, the weight value of each anomaly feature dimension is calculated according to the updated logic. Finally, a new anomaly weight distribution map is generated based on the calculated weight values. For example, under the new configuration, the data for the newly added feature dimension "harmonic content" fluctuates significantly and is strongly correlated with the device's abnormal behavior. When updating the generation logic of the abnormal weight distribution map, a higher weight calculation coefficient is set for the "harmonic content" feature dimension. After the fused behavioral feature vector under the new configuration is input into the abnormal pattern recognition processing, a new abnormal weight distribution map is generated based on the updated logic, more accurately reflecting the device's abnormal behavior patterns under the new configuration.

[0167] As one implementation method, the method provided in this embodiment of the invention may further include a closed-loop optimization process for the vulnerability remediation knowledge base, specifically including the following steps S1100 to S1500:

[0168] Step S1100: Within a preset period, obtain the set of repair verification features and the corresponding repair effect evaluation results for all target repair instructions in the vulnerability repair strategy set.

[0169] The preset period is a pre-defined time interval, such as one week or one month, during which the target remediation instructions in the vulnerability remediation strategy set are evaluated and optimized. The remediation verification feature set is a collection of features extracted from the device's operational status parameters after the vulnerability remediation operation is completed. These features are used to verify whether the vulnerability remediation operation achieved the expected results. The remediation effect evaluation result is obtained by comparing the remediation verification feature set with the preset security operation standards. This result can be a qualitative evaluation (e.g., successful remediation, partial remediation, remediation failure) or a quantitative indicator (e.g., remediation success rate, remediation deviation rate).

[0170] Obtaining the set of repair verification features and corresponding repair effect evaluation results for all target repair instructions in the vulnerability repair strategy set within a preset period can be implemented as follows: First, determine the start and end times of the preset period. Then, select all target repair instructions to be executed within the preset period from the vulnerability repair strategy set. Next, for each target repair instruction, obtain its corresponding set of repair verification features and repair effect evaluation results from the data storage system. The data storage system can be a database, file system, etc., used to store various data during the vulnerability repair process. Finally, organize and summarize the obtained set of repair verification features and repair effect evaluation results for subsequent analysis and processing.

[0171] Step S1200: Reconstruct the remediation condition constraints in the vulnerability remediation knowledge base based on the remediation verification feature set, so that the reconstructed remediation condition constraints include the dynamic change range of environmental parameters in the device operation verification data.

[0172] The remediation condition constraints are the execution conditions corresponding to each remediation strategy in the vulnerability remediation knowledge base, specifying under what circumstances the remediation strategy can be executed. Device operation verification data consists of device operating status parameters and external environment parameters collected after the vulnerability remediation operation is completed. The dynamic range of environmental parameters reflects the changes in external environment parameters during device operation. Restructuring the remediation condition constraints in the vulnerability remediation knowledge base aims to make the remediation conditions more realistic, fully consider the dynamic changes in environmental parameters during device operation, and improve the effectiveness and adaptability of remediation strategies.

[0173] The remediation condition constraints in the vulnerability remediation knowledge base are reconstructed based on the remediation verification feature set. This reconstruction includes the dynamic range of environmental parameters from the device operation verification data. Specifically, this can be achieved by extracting relevant features of environmental parameters from the remediation verification feature set, such as the maximum, minimum, average, and standard deviation of parameters like ambient temperature, humidity, and electromagnetic interference intensity. These statistical features reflect the dynamic range of environmental parameters. Then, the remediation condition constraints for each remediation strategy in the vulnerability remediation knowledge base are analyzed to identify conditions related to environmental parameters. Finally, the extracted information on the dynamic range of environmental parameter changes is incorporated into the remediation condition constraints, modifying and improving the original remediation conditions.

[0174] Step S1300: Based on the frequency of policy adjustment instructions in the remediation effect evaluation results, dynamically sort and optimize the matching order of the candidate remediation policy set in the vulnerability remediation knowledge base.

[0175] Policy adjustment instructions are generated during the remediation effectiveness evaluation process when a target remediation instruction fails to effectively fix the corresponding vulnerability. These instructions are used to adjust the vulnerability remediation strategy. The frequency of policy adjustment instructions is the number of times they occur within a preset period. The candidate remediation strategy set is a collection of candidate remediation strategies stored in the vulnerability remediation knowledge base. The matching order determines the order in which these candidate remediation strategies are matched and selected during vulnerability remediation. Dynamic sorting optimization adjusts the matching order of the candidate remediation strategy set based on the frequency of policy adjustment instructions, making the matching order more reasonable and improving the success rate of vulnerability remediation.

[0176] Based on the frequency of policy adjustment instructions in the remediation effectiveness evaluation results, the dynamic sorting and optimization of the matching order of candidate remediation strategies in the vulnerability remediation knowledge base can be implemented as follows: First, the frequency of policy adjustment instructions corresponding to each candidate remediation strategy in the remediation effectiveness evaluation results can be statistically analyzed. This can be done by analyzing the records of policy adjustment instructions to count the number of times each candidate remediation strategy triggers a policy adjustment instruction within a preset period. Then, the candidate remediation strategy set is sorted according to the frequency of policy adjustment instructions. Candidate remediation strategies with lower policy adjustment instruction frequencies indicate better performance in practical applications and should be ranked higher, with higher matching priority; candidate remediation strategies with higher policy adjustment instruction frequencies indicate poorer performance and should be ranked lower. Sorting algorithms such as bubble sort and quicksort can be used for sorting. Finally, the matching order of the candidate remediation strategy set in the vulnerability remediation knowledge base is updated to make the new sorting effective.

[0177] Step S1400: Associate and bind the dynamically sorted and optimized candidate repair strategy set with the expanded strategy matching conditions to generate optimized dynamic strategy matching rules.

[0178] The dynamically sorted and optimized candidate remediation strategy set is the new set obtained by adjusting the matching order of the candidate remediation strategy set according to the frequency of policy adjustment instructions in the previous step. The expanded policy matching conditions are new matching conditions obtained by expanding the policy matching conditions in the dynamic policy matching rules according to the actual impact parameters of supplementary remediation instructions in previous steps. Association binding involves mapping and combining the dynamically sorted and optimized candidate remediation strategy set with the expanded policy matching conditions, so that each candidate remediation strategy is associated with the corresponding matching condition. The optimized dynamic policy matching rule is a new matching rule generated after associating and binding the dynamically sorted and optimized candidate remediation strategy set with the expanded policy matching conditions. This rule can more accurately match the dynamic behavioral feature set with the vulnerability remediation strategy, improving the effectiveness of vulnerability remediation.

[0179] The process of associating and binding the dynamically sorted and optimized candidate repair strategy set with the expanded strategy matching conditions to generate optimized dynamic strategy matching rules can be implemented as follows: The optimized candidate repair strategy set is traversed, and for each candidate repair strategy, its applicable scenarios and conditions are analyzed. Then, conditions matching the candidate repair strategy are found from the expanded strategy matching conditions. Rule-based matching algorithms, such as pattern matching and condition judgment methods, can be used for matching. Next, the candidate repair strategies are associated and bound with the matching conditions to establish a correspondence. Data structures, such as dictionaries and lists, can be used to store this correspondence. Finally, all associations are organized into optimized dynamic strategy matching rules.

[0180] Step S1500: Extract vulnerability features from the subsequently received dynamic behavior feature set using the optimized dynamic policy matching rules, and output an updated vulnerability remediation policy set.

[0181] The optimized dynamic policy matching rule is a new matching rule generated in the previous step. It combines the dynamically sorted and optimized candidate remediation policy set with the expanded policy matching conditions, enabling more accurate matching of the dynamic behavioral feature set with vulnerability remediation policies. The subsequently received dynamic behavioral feature set is a collection of features obtained through dynamic behavioral analysis of operational data during the operation of power network equipment. These features are used to identify abnormal behavior patterns of the equipment. Vulnerability feature extraction processing extracts vulnerability-related feature information from the dynamic behavioral feature set based on the optimized dynamic policy matching rule, providing a basis for subsequent vulnerability remediation policy generation. The updated vulnerability remediation policy set is a collection of remediation policies generated based on the vulnerability feature extraction processing results, containing multiple remediation instructions and their corresponding execution priorities and execution condition parameters.

[0182] The optimized dynamic policy matching rules are used to extract vulnerability features from subsequently received dynamic behavior feature sets and output an updated set of vulnerability remediation policies. Specifically, this can be achieved by: inputting the subsequently received dynamic behavior feature sets into the optimized dynamic policy matching rules; the optimized dynamic policy matching rules then match candidate remediation policies sequentially according to the feature information in the feature set; for each successfully matched candidate remediation policy, extracting its corresponding remediation instructions and execution condition parameters; next, calculating the overall execution priority of each remediation instruction based on its execution resource consumption parameters and remediation timeliness parameters; using previously mentioned methods, such as the weighted average method, to calculate the overall execution priority; and finally, sorting the extracted remediation instructions from high to low overall execution priority to generate the updated set of vulnerability remediation policies.

[0183] It is understood that the various algorithms involved in the above descriptions of the embodiments of the present invention, such as the isolated forest algorithm, sorting algorithms, etc., can all be obtained from relevant content in the prior art. To save space, they will not be elaborated on in the embodiments of the present invention. In addition, those skilled in the art can supplement the details based on common knowledge in the art when implementing the solution of the present invention. For example, they can use normalization to eliminate dimensional conflicts before feature fusion, use interpolation to eliminate dimensional differences, reasonably set thresholds based on historical data, experience or business scenario requirements, train the model based on a general model training method, etc. The present invention will not provide redundant descriptions of overly detailed implementation processes here.

[0184] Please see Figure 2 , Figure 2This is a schematic diagram of a computer system provided in an embodiment of the present invention. The computer system includes at least a processor 101, a communication interface 102, and a memory 103. The processor 101, communication interface 102, and memory 103 can be connected via a bus or other means. The processor 101 (or Central Processing Unit, CPU) is the computing and control core of the computer system, capable of parsing various instructions and processing various data within the computer system. The communication interface 102 may optionally include a standard wired interface or a wireless interface (such as Wi-Fi, mobile communication interface, etc.), and can be used to send and receive data under the control of the processor 101; the communication interface 102 can also be used for data transmission and interaction within the computer system. The memory 103 is a storage device in the computer system used to store programs and data. It is understood that the memory 103 here can include the computer system's built-in memory, or it can include extended memory supported by the computer system. The memory 103 provides storage space, which stores the computer system's operating system; this invention does not limit this storage space.

[0185] In one embodiment, the processor 101 executes the power network equipment vulnerability repair method based on dynamic behavior analysis provided above in the embodiments of the present invention by running a computer program in the memory 103.

Claims

1. A method for patching vulnerabilities in power network equipment based on dynamic behavior analysis, characterized in that, include: Acquire a set of operational data for power network equipment, the set of operational data including multiple operational cycle data, each operational cycle data including at least one equipment operational status parameter and a corresponding external environment parameter; Dynamic behavior analysis processing is performed on the set of running data to obtain a set of dynamic behavior features of the multiple running cycle data; The dynamic behavior feature set is used to characterize the abnormal behavior patterns of the power network equipment during its operating cycle; Based on preset dynamic policy matching rules, vulnerability feature extraction processing is performed on the dynamic behavior feature set to generate a vulnerability remediation policy set corresponding to the abnormal behavior pattern; the vulnerability remediation policy set includes the execution priority and execution condition parameters of multiple remediation instructions. Based on the execution priority and execution condition parameters in the vulnerability remediation strategy set, the vulnerability remediation operation of the power network equipment is triggered, and the remediated equipment operation verification data is obtained; Based on the difference parameters between the equipment operation verification data and the preset safety operation standards, a repair effect evaluation result is generated, and the dynamic strategy matching rules are adjusted according to the difference parameters. The step of performing dynamic behavior analysis on the set of running data to obtain a set of dynamic behavior features for the multiple running cycle data includes: Perform time-series correlation analysis on the equipment operating status parameters in each operating cycle data to generate a first-behavior feature sequence related to the time dimension; Spatial distribution analysis of the external environmental parameters is performed to determine the spatial correlation feature set of the environment in which the power network equipment is located. Specifically, this includes: acquiring a set of real-time environmental parameters collected by multiple environmental monitoring nodes deployed in the environment in which the power network equipment is located, the real-time environmental parameter set including temperature distribution data, humidity distribution data, and electromagnetic interference intensity data; mapping the deployment locations of the environmental monitoring nodes to the corresponding regional division results of the physical layout topology map of the power network equipment, generating an environmental parameter distribution map containing regional identifiers; and performing fluctuation consistency checks on the temperature distribution data, humidity data, and electromagnetic interference intensity data corresponding to the same regional identifier in the environmental parameter distribution map. The method involves measuring and extracting parameter change trend features that satisfy the fluctuation consistency condition; generating an environmental correlation strength index between adjacent regions based on the parameter change trend features, which characterizes the degree of synergistic impact of environmental parameter changes in different regions on the operation of the power network equipment; verifying the environmental correlation strength index through topology propagation based on the equipment connection relationship in the physical layout topology diagram, and selecting effective environmental correlation strength indices that match the signal transmission path of the equipment connection relationship; combining the effective environmental correlation strength indices and their corresponding region identifiers into a spatial correlation feature set, which indicates the spatial dependency of the external environmental parameters of the power network equipment. The first behavioral feature sequence is fused with the spatial association feature set in a multidimensional manner to obtain the fused behavioral feature vector of each running cycle data. Anomaly pattern recognition processing is performed on the fused behavior feature vector to extract the feature dimensions that exceed a preset safety threshold, and the abnormal fluctuation data corresponding to the feature dimensions are determined as abnormal behavior patterns in the dynamic behavior feature set.

2. The method according to claim 1, characterized in that, The abnormal pattern recognition processing of the fused behavioral feature vector includes: Obtain a set of standard behavioral features of the power network equipment during its historical operating cycle. The set of standard behavioral features includes multiple standard feature dimensions of the power network equipment in a vulnerability-free state and their corresponding standard fluctuation ranges. Each feature dimension in the fused behavior feature vector is matched with the standard feature dimension to determine the target feature dimension in the fused behavior feature vector that matches the standard feature dimension; Calculate the deviation parameter between the current fluctuation data of the target feature dimension and the standard fluctuation range. If the deviation parameter exceeds a preset deviation threshold, mark the target feature dimension as an abnormal feature dimension. An anomaly weight distribution map is generated based on the deviation parameters of all anomaly feature dimensions, and the dominant anomaly type of the anomaly behavior pattern is determined by the anomaly feature dimension with the largest weight value in the anomaly weight distribution map.

3. The method according to claim 2, characterized in that, The method, based on preset dynamic policy matching rules, performs vulnerability feature extraction processing on the dynamic behavior feature set to generate a vulnerability remediation policy set corresponding to the abnormal behavior pattern, including: Based on the dominant anomaly type, a set of candidate remediation strategies is matched from a preset vulnerability remediation knowledge base. The set of candidate remediation strategies includes multiple candidate remediation instructions and their corresponding remediation condition constraints. The vulnerability impact range analysis is performed on the dynamic behavior feature set to determine the set of device components and associated environmental areas affected by the abnormal behavior pattern; Based on the component types of the device component set and the environmental parameters of the associated environmental region, target repair instructions that meet the repair condition constraints are selected from the candidate repair strategy set; Based on the execution resource consumption parameters and repair timeliness parameters of the target repair instructions, the comprehensive execution priority of each target repair instruction is calculated, and the target repair instructions are sorted from high to low according to the comprehensive execution priority to generate the vulnerability repair strategy set.

4. The method according to claim 3, characterized in that, The step of triggering the vulnerability remediation operation of the power network equipment according to the execution priority and execution condition parameters in the vulnerability remediation strategy set includes: The target repair instructions are executed sequentially in descending order of execution priority. Before executing each target repair instruction, it is checked whether the current device operating status meets the environmental constraints and device resource conditions in the execution condition parameters. If the environmental constraints and equipment resource conditions are both met, the repair operation corresponding to the target repair instruction is triggered through the control interface of the power network equipment. If the environmental constraints or equipment resource conditions are not met, the execution of the current target repair instruction is suspended, and a condition optimization strategy is generated based on the unmet condition parameters. The condition optimization strategy is used to adjust the resource allocation or environmental parameters of the power network equipment to re-meet the execution condition parameters.

5. The method according to claim 4, characterized in that, The acquisition of the repaired device operation verification data includes: After the vulnerability remediation operation is completed, the power network equipment is monitored in all dimensions, and the equipment operation status parameters and external environment parameters after the remediation are collected. Feature extraction is performed on the operating status parameters of the repaired equipment to generate a repair verification feature set; The repair verification feature set is compared with the preset safe operation standard item by item to generate a verification result list containing the comparison difference values; Based on whether all the comparison differences in the verification result list are within the preset security tolerance range, it is determined whether the vulnerability repair operation has achieved the expected repair effect.

6. The method according to claim 5, characterized in that, The method of generating a repair effectiveness evaluation result based on the difference parameters between the equipment operation verification data and the preset safety operation standards includes: Extract abnormal difference values ​​that exceed the security tolerance range from the verification result list, and determine the device operation dimension corresponding to the abnormal difference values; Based on the device operation dimension, backtrack the executed target repair instructions from the vulnerability repair strategy set, and analyze the contribution of the target repair instructions to the repair of the device operation dimension. If the repair contribution is lower than a preset contribution threshold, it is determined that the target repair instruction has not effectively repaired the corresponding vulnerability, and a strategy adjustment instruction is generated. The policy adjustment instruction is used to re-match supplementary repair instructions associated with the device operation dimension from the vulnerability repair knowledge base, and add the supplementary repair instructions to the vulnerability repair policy set.

7. The method according to claim 6, characterized in that, The step of adjusting the dynamic strategy matching rule according to the difference parameter includes: Obtain the execution log data of the supplementary repair instructions corresponding to the strategy adjustment instructions recorded in the repair effect evaluation results; Extract the actual impact parameters of the supplementary repair instruction on the device operation dimension during the repair process from the execution log data. The actual impact parameters include the magnitude of the abnormal difference value change of the device operation dimension and the duration of the repair operation. The actual impact parameters are compared with the expected impact parameters of the supplementary repair instructions recorded in the vulnerability repair knowledge base to generate the instruction effectiveness deviation value of the supplementary repair instructions. If the deviation value of the instruction effectiveness exceeds the preset deviation tolerance range, the strategy matching conditions in the dynamic strategy matching rules are expanded, and the actual impact parameter is integrated into the strategy matching conditions as a new matching condition. The matching fit of each candidate repair instruction in the candidate repair strategy set is recalculated based on the expanded strategy matching conditions, and the priority sorting rules of the candidate repair strategy set are updated according to the matching fit.

8. The method according to claim 2, characterized in that, When a change in the operating configuration of the power network equipment is detected, the method further includes a process of performing dynamic analysis rule adaptation, including: Obtain the new set of device operating status parameters and the new set of external environment parameters corresponding to the changed operating configuration; The new equipment operating status parameter set is compared with the standard feature dimensions in the standard behavior feature set to verify coverage and determine the newly added feature dimensions and failure feature dimensions. The feature fusion weight distribution in the multidimensional fusion process is adjusted according to the newly added feature dimension, so that the weight value of the failed feature dimension is redistributed to the newly added feature dimension. Based on the adjusted feature fusion weight distribution, the new device operating status parameter set and the new external environment parameter set are fused to generate a fusion behavior feature vector under the new configuration. The fusion behavior feature vector under the new configuration is input into the abnormal pattern recognition process, and the generation logic of the abnormal weight distribution map is updated according to the data fluctuation characteristics of the newly added feature dimension.

9. A computer system, characterized in that, include: A memory, wherein a computer program is stored; A processor is configured to load the computer program to implement the power network equipment vulnerability repair method based on dynamic behavior analysis as described in any one of claims 1-8.

Citation Information

Patent Citations

  • Network security vulnerability position detection system and method based on artificial intelligence

    CN118316722A