Gateway machine state evaluation method and device, terminal equipment and storage medium
By analyzing the operation data of gateway equipment and constructing membership and weight matrices for fuzzy operations, the problem of low efficiency in gateway status assessment is solved and efficient security status assessment is achieved.
Patent Information
- Application Number
- CN202510750589.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-09-19
AI Technical Summary
The existing technology has low efficiency in evaluating the state of gateway machines and cannot effectively perform security state evaluation.
By obtaining the equipment operation data of the gateway machine, calculating the degradation degree and membership of the unit function, constructing the membership matrix and weight matrix, and performing fuzzy operations to evaluate the security status of modules and equipment.
The automation of gateway machine status assessment is realized, which improves the assessment efficiency and can quickly and accurately determine the security status of the device.
Smart Images

Figure CN120675906A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of substation operation and maintenance, and in particular to a gateway machine status assessment method, device, terminal equipment and storage medium. Background Art
[0002] In recent years, existing technologies have conducted extensive research and practice on the security protection of substation operation and maintenance systems. These efforts attempt to develop comprehensive, closed-loop technical and management measures, while meeting network security constraints. These measures aim to ensure that human error, equipment failure, system defects, and environmental risks do not cause safety incidents during remote system operation and maintenance. This approach ensures technical safety in all aspects of personnel, equipment, systems, environment, and management, severing the causal chain of safety incidents and ultimately effectively ensuring the safety and reliability of remote maintenance. As the core automation equipment in substations, the security of gateways is crucial to their safe and stable operation. Therefore, it is necessary to study the security status assessment of gateway devices.
[0003] However, existing technologies can only enable operation and maintenance personnel to analyze the operation of the gateway machine based on their experience and thus evaluate the status of the gateway machine. However, the operation-related data of the gateway machine is very large, and manual evaluation of the gateway machine status is inefficient. Summary of the Invention
[0004] The present invention provides a gateway machine status evaluation method, apparatus, terminal equipment and storage medium, which can solve the problem of low efficiency in gateway machine status evaluation in the prior art.
[0005] The gateway machine status evaluation method of the present invention includes:
[0006] Obtain device operation data of the gateway machine;
[0007] Calculating the degradation degree of each unit function of the gateway machine based on the device operation data, and calculating the membership degree of each unit function under different security states based on the degradation degree of each unit function;
[0008] Obtaining the variable weight value of each unit function, and according to the module function to which each unit function belongs, combining the corresponding membership degrees of the unit functions of the same module function into a membership matrix corresponding to the current module function, and combining the corresponding variable weight values of the unit functions of the same module function into a weight matrix corresponding to the current module function; wherein each module function includes a plurality of unit functions, and the unit functions corresponding to each module function are different from each other;
[0009] Calculating a module security membership matrix for each module function based on the membership matrix and weight matrix of each module function; wherein the module security membership matrix includes: the membership of each module function under different security states;
[0010] Obtain the variable weight value of each module function, calculate the device security membership matrix based on the module security membership matrix and variable weight value of each module function, and select the security state corresponding to the maximum membership value as the security assessment result of the device; wherein the device security membership matrix includes: the membership of the device in different security states.
[0011] Furthermore, the calculating of the degradation degree of each unit function of the gateway machine according to the device operation data includes:
[0012] Calculate the failure rate of each unit function of the gateway machine based on the equipment operation data;
[0013] For each unit function of the gateway machine, the security level of the current unit function is retrieved, the security level limit corresponding to the security level is determined, and the degradation degree of the current unit function is calculated based on the security level limit and failure rate corresponding to the current unit function.
[0014] Furthermore, the calculating of the failure rate of each unit function of the gateway machine based on the device operation data includes:
[0015] In the device operation data, the device operation time of each unit function of the gateway machine is screened; wherein the device operation time includes: failure time and normal operation time;
[0016] Substitute the device operating time of each unit function into the failure rate calculation formula to obtain the failure rate of each unit function of the gateway machine; wherein the failure rate calculation formula satisfies the following conditions:
[0017]
[0018] Where f is the failure rate, T fault is the failure time of each unit function, T normal The functional uptime of each unit.
[0019] Furthermore, the calculation of the degradation degree of the current unit function according to the safety level limit and failure rate corresponding to the current unit function includes:
[0020] Substitute the safety level limit and failure rate of the current unit function into the degradation degree calculation formula to calculate the degradation degree of the current unit function. The degradation degree calculation formula satisfies the following conditions:
[0021]
[0022] Where x is the failure rate of the current unit function, g2(x) is the degradation degree of the current unit function, and α and β are the upper limit and good upper limit of the safety level.
[0023] Furthermore, the safety status includes: safe, alert, emergency and critical; the calculation of the membership of each unit function in different safety statuses according to the degradation degree of each unit function includes:
[0024] Substitute the degradation degree of each unit function into the normal distribution membership function to calculate the membership degree of each unit function under different safety states; wherein the normal distribution membership function satisfies the following conditions:
[0025]
[0026] Where d is the degradation degree, σ1, σ 21 , σ 22 , σ 31 , σ 32 , σ4 is a constant value, r v1 (d) is the membership degree of the security state as safe, r v2 (d) is the membership degree of the safety state as alert, r v3 (d) is the membership degree of the safety status as emergency, r v4 (d) is the membership degree of the security status being critical.
[0027] Furthermore, obtaining the variable weight value of each unit function includes:
[0028] The constant weight of each unit function is calculated using a preset importance algorithm, and the constant weight and degradation degree of each unit function are substituted into a variable weight calculation formula to determine the variable weight of each unit function; wherein the variable weight calculation formula satisfies the following conditions:
[0029]
[0030] Where A it is the variable weight corresponding to the t-th unit function in the i-th module function, m is the number of unit functions in the i-th module function; ω is (0) (s=1,2,3,…,m) is the constant weight corresponding to the sth unit function in the i-th module function, d is (s=1, 2, 3, ..., m) represents the degradation degree of the sth unit function under the i-th module function; v is the variable weight coefficient.
[0031] Furthermore, the unit functions include: functional module security, software security, trusted verification security, network detection security and malicious code prevention security, and the module functions include: entity inherent attribute security and operation monitoring security; among them, entity inherent attribute security includes: functional module security, software security and trusted verification security; operation monitoring security includes: network detection security and malicious code prevention security.
[0032] Another embodiment of the present invention further provides a gateway machine state evaluation device, comprising: a data acquisition module, a first calculation module, a matrix composition module, a second calculation module, and a result generation module;
[0033] The data acquisition module is used to obtain device operation data of the gateway machine;
[0034] The first calculation module is configured to calculate the degradation degree of each unit function of the gateway machine according to the device operation data, and calculate the membership degree of each unit function under different security states according to the degradation degree of each unit function;
[0035] The matrix composition module is used to obtain the variable weight value of each unit function, and according to the module function to which each unit function belongs, the membership corresponding to the unit functions of the same module function is composed into a membership matrix corresponding to the current module function, and the variable weight values corresponding to the unit functions of the same module function are composed into a weight matrix corresponding to the current module function; wherein each module function includes a plurality of unit functions, and the unit functions corresponding to each module function are different from each other;
[0036] The second calculation module is used to calculate the module security membership matrix of each module function based on the membership matrix and weight matrix of each module function; wherein the module security membership matrix includes: the membership of each module function in different security states;
[0037] The result generation module is used to obtain the variable weight value of each module function, calculate the device security membership matrix based on the module security membership matrix and the variable weight value of each module function, and select the security state corresponding to the maximum membership as the security assessment result of the device; wherein the device security membership matrix includes: the membership of the device in different security states.
[0038] Another embodiment of the present invention further provides a terminal device, comprising: a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, the steps of the gateway machine status evaluation method of the present invention are implemented.
[0039] Another embodiment of the present invention further provides a computer-readable storage medium item, comprising: a stored computer program, which controls the device where the computer-readable storage medium is located to execute the steps of the gateway machine status assessment method of the present invention when the computer program is running.
[0040] The following beneficial effects are achieved by implementing the present invention:
[0041] The present invention analyzes the device operation data of the gateway machine, calculates the degradation degree of each unit function of the gateway machine, determines the membership degree of each unit function under different security states based on the degradation degree, and performs a primary assessment of the security state of the unit function dimension; obtains the variable weight value of each unit function, divides the membership degree and variable weight value of each unit function according to the module function to which each unit function belongs, and forms a membership matrix and a weight matrix corresponding to the current module function, thereby calculating the module security membership matrix of the module function based on the membership matrix and the weight matrix, and calculating the security membership matrix of each module function based on the variable weight value of each module function, thereby performing a secondary assessment of the security state of the module function dimension, and selects the security state with the maximum membership value as the security assessment result of the device based on the result of the secondary assessment, thereby realizing the automation of gateway machine status assessment and improving the efficiency of gateway machine status assessment. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In order to more clearly illustrate the technical solution of the present application, the following is a brief introduction to the drawings required for use in the implementation. Obviously, the drawings described below are only some implementation methods of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0043] Figure 1 1 is a flow chart of a method for evaluating the state of a gateway provided by an embodiment of the present invention;
[0044] Figure 2 1 is a schematic diagram of the structure of a gateway state evaluation device provided by an embodiment of the present invention;
[0045] Figure 3 It is a flowchart of a gateway machine status evaluation method provided by another embodiment of the present invention. DETAILED DESCRIPTION
[0046] To make the objectives, technical solutions, and advantages of this application more clear, the technical solutions in this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of this application.
[0047] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application belongs; the terms used herein are only for the purpose of describing specific embodiments and are not intended to limit this application; the terms "including" and "having" and any variations thereof in the specification and claims of this application and the above-mentioned figure descriptions are intended to cover non-exclusive inclusions.
[0048] In the description of the embodiments of this application, the technical terms "first" and "second" are used only to distinguish different objects and should not be understood to indicate or imply relative importance or implicitly specify the quantity, specific order, or primary and secondary relationship of the indicated technical features. In the description of the embodiments of this application, the meaning of "plurality" is more than two, unless otherwise clearly and specifically defined.
[0049] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute an independent or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.
[0050] In the description of the embodiments of this application, the term "and / or" is simply a description of the association relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent the following three situations: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this document generally indicates that the associated objects are in an "or" relationship.
[0051] In the description of the embodiments of the present application, the term "multiple" refers to more than two (including two). Similarly, "multiple groups" refers to more than two groups (including two groups), and "multiple pieces" refers to more than two pieces (including two pieces).
[0052] In the description of the embodiments of the present application, unless otherwise expressly specified or limited, technical terms such as "installed," "connected," "connected," and "fixed" should be understood in a broad sense. For example, they can refer to fixed connections, detachable connections, or integration; mechanical connections or electrical connections; direct connections or indirect connections through an intermediate medium; internal connections between two components or interactions between two components. Those skilled in the art can understand the specific meanings of the above terms in the embodiments of the present application based on specific circumstances.
[0053] See also Figure 1 To solve the problem of low efficiency in gateway machine status assessment in the prior art, an embodiment of the present invention provides a gateway machine status assessment method, comprising:
[0054] S1. Obtain device operation data of the gateway machine;
[0055] S2. Calculate the degradation degree of each unit function of the gateway machine based on the device operation data, and calculate the membership degree of each unit function under different security states based on the degradation degree of each unit function;
[0056] Furthermore, the unit functions include: functional module security, software security, trusted verification security, network detection security and malicious code prevention security, and the module functions include: entity inherent attribute security and operation monitoring security; among them, entity inherent attribute security includes: functional module security, software security and trusted verification security; operation monitoring security includes: network detection security and malicious code prevention security.
[0057] In a specific embodiment, the security status evaluation index is constructed by the unit function and the module function, wherein the unit function corresponds to the secondary index and the module function corresponds to the primary index. The security status evaluation index is shown in Table 1.
[0058] Table 1
[0059]
[0060] Furthermore, the calculating of the degradation degree of each unit function of the gateway machine according to the device operation data includes:
[0061] Calculate the failure rate of each unit function of the gateway machine based on the equipment operation data;
[0062] For each unit function of the gateway machine, the security level of the current unit function is retrieved, the security level limit corresponding to the security level is determined, and the degradation degree of the current unit function is calculated based on the security level limit and failure rate corresponding to the current unit function.
[0063] In a specific embodiment, taking the failure time and normal working time of each security function module of a gateway machine of a certain manufacturer as an example, based on the requirements of technical regulations such as comprehensive level protection, the allowable range of the required security level of each indicator is determined, and the degradation value of each indicator is calculated. The degradation degree of each indicator of a certain gateway machine device is shown in Table 2.
[0064] Table 2
[0065]
[0066] In a specific embodiment, the security level required for each unit function is one of the three levels I, II, and III, and each security level has a corresponding security level limit, as shown in Table 3.
[0067] Table 3
[0068]
[0069] In a specific embodiment, when the security level is I, the upper limit of the indicator is 10 -4 , a good upper limit value for the indicator is 10 -5 ; When the safety level is II, the upper limit of the index is 10 -5 , a good upper limit value for the indicator is 10 -6 ; When the safety level is Ⅰ, the upper limit of the index is 10 -6 , a good upper limit value for the indicator is 10 -7 .
[0070] Furthermore, the calculating of the failure rate of each unit function of the gateway machine based on the device operation data includes:
[0071] In the device operation data, the device operation time of each unit function of the gateway machine is screened; wherein the device operation time includes: failure time and normal operation time;
[0072] Substitute the device operating time of each unit function into the failure rate calculation formula to obtain the failure rate of each unit function of the gateway machine; wherein the failure rate calculation formula satisfies the following conditions:
[0073]
[0074] Where f is the failure rate, T fault is the failure time of each unit function, T normal The functional uptime of each unit.
[0075] Furthermore, the calculation of the degradation degree of the current unit function according to the safety level limit and failure rate corresponding to the current unit function includes:
[0076] Substitute the safety level limit and failure rate of the current unit function into the degradation degree calculation formula to calculate the degradation degree of the current unit function. The degradation degree calculation formula satisfies the following conditions:
[0077]
[0078] Where x is the failure rate of the current unit function, g2(x) is the degradation degree of the current unit function, and α and β are the upper limit and good upper limit of the safety level.
[0079] Furthermore, the safety status includes: safe, alert, emergency and critical; the calculation of the membership of each unit function in different safety statuses according to the degradation degree of each unit function includes:
[0080] Substitute the degradation degree of each unit function into the normal distribution membership function to calculate the membership degree of each unit function under different safety states; wherein the normal distribution membership function satisfies the following conditions:
[0081]
[0082] Where d is the degradation degree, σ1, σ 21 , σ 22 , σ 31 , σ 32 , σ4 is a constant value, r v1 (d) is the membership degree of the security state as safe, r v2 (d) is the membership degree of the safety state as alert, r v3 (d) is the membership degree of the safety status as emergency, r v4 (d) is the membership degree of the security status being critical.
[0083] In a specific embodiment, the security status is divided into four levels: "safe", "alert", "emergency" and "critical", and the standards for the device to belong to different statuses are defined.
[0084] A. "Safe" means that all indicators of the equipment operating condition are within the ideal range, the equipment can operate normally, and no obvious degradation is observed. The test results show that all status parameters are far away from the threshold, which can ensure safety and no operation is required;
[0085] B. "Alert" means that all indicators of the equipment operating condition are fluctuating within a certain range near the standard limit, have not exceeded the threshold, and will not affect the safety of the equipment, but require close monitoring and adjustment to avoid entering an emergency state;
[0086] C. "Emergency" means that the various indicators of the equipment operating conditions have deviated from or slightly exceeded the indicator thresholds. The equipment should be monitored and safety inspections and maintenance should be arranged in a timely manner;
[0087] D. "Critical" means that certain status indicators of the equipment operating condition have seriously exceeded the threshold, and the equipment has safety issues. It is necessary to block the equipment's command operations, etc., and arrange safety inspections and maintenance as soon as possible to ensure that it does not affect the safety of the entire chain.
[0088] S3. Obtaining a variable weight value for each unit function, and based on the module function to which each unit function belongs, combining the membership degrees corresponding to the unit functions of the same module function into a membership matrix corresponding to the current module function, and combining the variable weight values corresponding to the unit functions of the same module function into a weight matrix corresponding to the current module function; wherein each module function includes a plurality of unit functions, and the unit functions corresponding to each module function are different from each other;
[0089] Furthermore, obtaining the variable weight value of each unit function includes:
[0090] The constant weight of each unit function is calculated using a preset importance algorithm, and the constant weight and degradation degree of each unit function are substituted into a variable weight calculation formula to determine the variable weight of each unit function; wherein the variable weight calculation formula satisfies the following conditions:
[0091]
[0092] Where A it is the variable weight corresponding to the t-th unit function in the i-th module function, m is the number of unit functions in the i-th module function; ω is (0) (s=1,2,3,…,m) is the constant weight corresponding to the sth unit function in the i-th module function, d is (s=1, 2, 3, ..., m) represents the degradation degree of the sth unit function under the i-th module function; v is the variable weight coefficient.
[0093] In a specific embodiment, the variable weight coefficient may be 3.
[0094] In a specific embodiment, the importance algorithm can be the G1 method, which is used to determine the constant weights of indicators at each level of the equipment. Ten experts are asked to score the importance ranking of indicators at each level, and the importance ranking results of each indicator are obtained based on the score. The results are shown in Table 4.
[0095] Table 4
[0096]
[0097] For better explanation, the weights obtained by calculating the variable weight method are shown in Table 5, combined with relevant monitoring data.
[0098] Table 5
[0099]
[0100] Among them, the G1 method is as follows: experts standardize the index factor set {E1, E2, ... E m}, sorted by importance, first let the experts in the indicator set {E1, E2, ... E m}Select the most important indicator and label it as E1 * , then select the most important one among the remaining m-1 indicators and label it as E2 * , and so on, after m-1 selections, the remaining evaluation index is marked as This uniquely determines an order relationship:
[0101]
[0102] Experts on evaluation indicators and The importance ratio The rational judgment is shown in Table 6 below:
[0103] Table 6
[0104]
[0105] in: (k=m,m-1,…3,2) is the evaluation index and The importance ratio.
[0106] If the experts give The rational assignment of the indicator weight for:
[0107]
[0108] Calculate the weight coefficient ω:
[0109]
[0110] ω k-1 =r k ω k ,k=m,m-1,m-2,…,3,2
[0111] S4. Calculating a module security membership matrix for each module function based on the membership matrix and weight matrix of each module function; wherein the module security membership matrix includes: the membership of each module function under different security states;
[0112] In a specific embodiment, the weight matrix ARij And the membership matrix V Rij By performing fuzzy operations, we can obtain the evaluation results of each indicator of the upper level:
[0113] B ij =A Rij &V Rij
[0114] Where A Rij =(a ij1 ,...,a ijn ) is its corresponding weight matrix, & is a generalized fuzzy operator. This paper adopts a weighted average operator with a strong degree of comprehensiveness. Right now:
[0115] In a specific embodiment, taking the functional module safety as an example, after substituting the degradation degree of the functional module safety into the normal distribution membership function, the membership degree of the functional module safety is obtained:
[0116] V R211 =[0.01880.99090.26270], based on the normal distribution membership function, determine the membership of software security and the membership of trusted verification security; construct a membership matrix through the membership of functional module security, software security, and trusted verification security:
[0117]
[0118] After calculating the constant weights and variable weights, we can obtain the variable weights of functional module security, software security, and trusted verification security to construct the weight matrix: A R21 =[0.08040.21600.4025].
[0119] The membership matrix V R21 , weight matrix A R21 Perform fuzzy operations to obtain the module security membership matrix B of the inherent attribute security of the entity 21 , B R21 =[0.00150.28950.12320.2441].
[0120] S5. Obtain the variable weight value of each module function, calculate the device security membership matrix based on the module security membership matrix and the variable weight value of each module function, and select the security state corresponding to the maximum membership value as the security assessment result of the device; wherein the device security membership matrix includes: the membership of the device in different security states.
[0121] In a specific embodiment, the degradation degree of a module function is the maximum degradation degree of the corresponding unit function. Then, the variable weight of each module function is calculated according to the variable weight calculation formula.
[0122] In a specific embodiment, the security membership matrix of each module function is combined into a device membership matrix; the variable weight value of each module function is combined into a device weight matrix, and the device membership matrix and the device weight matrix are fuzzy calculated to obtain the device security membership matrix;
[0123] In a specific embodiment, the results of the device security membership matrix of the gateway device are shown in Table 7.
[0124] Table 7 Gateway machine security membership results
[0125]
[0126] After fuzzy comprehensive evaluation of the gateway equipment, the membership degree b of each security state is obtained. j (j=1,2,3,4), the maximum membership principle is adopted to take the maximum evaluation value b max =max(b j |j=1, 2, 3, 4) as the evaluation result, that is, in this specific embodiment, the evaluation result of the gateway device status is warning.
[0127] For a better explanation, see Figure 3 , Figure 3 A flowchart of a method for evaluating the state of a gateway machine provided in another embodiment of the present invention.
[0128] like Figure 2 As shown, based on the above method embodiment, a corresponding device embodiment is provided;
[0129] An embodiment of the present invention provides a gateway machine status evaluation device, comprising: a data acquisition module 201, a first calculation module 202, a matrix composition module 203, a second calculation module 204, and a result generation module 205;
[0130] The data acquisition module is used to obtain device operation data of the gateway machine;
[0131] The first calculation module is configured to calculate the degradation degree of each unit function of the gateway machine according to the device operation data, and calculate the membership degree of each unit function under different security states according to the degradation degree of each unit function;
[0132] The matrix composition module is used to obtain the variable weight value of each unit function, and according to the module function to which each unit function belongs, the membership corresponding to the unit functions of the same module function is composed into a membership matrix corresponding to the current module function, and the variable weight values corresponding to the unit functions of the same module function are composed into a weight matrix corresponding to the current module function; wherein each module function includes a plurality of unit functions, and the unit functions corresponding to each module function are different from each other;
[0133] The second calculation module is used to calculate the module security membership matrix of each module function based on the membership matrix and weight matrix of each module function; wherein the module security membership matrix includes: the membership of each module function in different security states;
[0134] The result generation module is used to obtain the variable weight value of each module function, calculate the device security membership matrix based on the module security membership matrix and the variable weight value of each module function, and select the security state corresponding to the maximum membership as the security assessment result of the device; wherein the device security membership matrix includes: the membership of the device in different security states.
[0135] It can be understood that the above-mentioned device embodiment corresponds to the method embodiment of the present invention, and can implement the gateway machine status evaluation method provided by any of the above-mentioned method embodiments of the present invention.
[0136] It should be noted that the device embodiments described above are merely illustrative, and some or all of the modules may be selected according to actual needs to achieve the purpose of the present embodiment. Furthermore, in the drawings of the device embodiments provided by the present invention, the connection relationship between modules indicates that they have a communication connection, which may be implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement the present invention without inventive effort.
[0137] Based on the above-mentioned embodiment of the gateway machine status evaluation method, another embodiment of the present invention provides a terminal device, which includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, the gateway machine status evaluation method of any embodiment of the present invention is implemented.
[0138] For example, in this embodiment, the computer program may be divided into one or more modules, which are stored in the memory and executed by the processor to implement the present invention. The one or more module elements may be a series of computer program instruction segments capable of performing specific functions, and the instruction segments are used to describe the execution process of the computer program in the terminal device.
[0139] The terminal device may be a computing device such as a desktop computer, a notebook computer, a PDA, a cloud server, etc. The terminal device may include, but is not limited to, a processor and a memory.
[0140] The processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. The processor is the control center of the terminal device, connecting various parts of the entire terminal device using various interfaces and lines.
[0141] Based on the above-mentioned method embodiments, another embodiment of the present invention provides a computer-readable storage medium, including a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the gateway machine status evaluation method described in any one of the above-mentioned method embodiments of the present invention.
[0142] Wherein, the module / unit integrated in the device / terminal equipment, if implemented in the form of a software functional unit and sold or used as an independent product, can be stored in a computer-readable storage medium. Based on this understanding, the present invention implements all or part of the process in the above-mentioned embodiment method, and can also be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and when the computer program is executed by the processor, it can implement the steps of the above-mentioned various method embodiments. Wherein, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may include: any entity or device that can carry the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal and software distribution medium, etc.
[0143] The above is a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications are also considered to be within the scope of protection of the present invention.
Claims
1. A method for evaluating the state of a gateway, characterized in that: include: Obtain device operation data of the gateway machine; Calculating the degradation degree of each unit function of the gateway machine based on the device operation data, and calculating the membership degree of each unit function under different security states based on the degradation degree of each unit function; Obtaining the variable weight value of each unit function, and according to the module function to which each unit function belongs, combining the corresponding membership degrees of the unit functions of the same module function into a membership matrix corresponding to the current module function, and combining the corresponding variable weight values of the unit functions of the same module function into a weight matrix corresponding to the current module function; wherein each module function includes a plurality of unit functions, and the unit functions corresponding to each module function are different from each other; Calculating a module security membership matrix for each module function based on the membership matrix and weight matrix of each module function; wherein the module security membership matrix includes: the membership of each module function under different security states; Obtain the variable weight value of each module function, calculate the device security membership matrix based on the module security membership matrix and variable weight value of each module function, and select the security state corresponding to the maximum membership value as the security assessment result of the device; wherein the device security membership matrix includes: the membership of the device in different security states.
2. The method for evaluating the state of a gateway machine according to claim 1, wherein: The calculating, based on the device operation data, the degradation degree of each unit function of the gateway machine includes: Calculate the failure rate of each unit function of the gateway machine based on the equipment operation data; For each unit function of the gateway machine, the security level of the current unit function is retrieved, the security level limit corresponding to the security level is determined, and the degradation degree of the current unit function is calculated based on the security level limit and failure rate corresponding to the current unit function.
3. The method for evaluating the state of a gateway machine according to claim 2, wherein: Calculating the failure rate of each unit function of the gateway machine based on the device operation data includes: In the device operation data, the device operation time of each unit function of the gateway machine is screened; wherein the device operation time includes: failure time and normal operation time; Substitute the device operating time of each unit function into the failure rate calculation formula to obtain the failure rate of each unit function of the gateway machine; wherein the failure rate calculation formula satisfies the following conditions: Where f is the failure rate, T fault is the failure time of each unit function, T normal The functional uptime of each unit.
4. The method for evaluating the state of a gateway machine according to claim 3, wherein: Calculating the degradation degree of the current unit function according to the safety level limit and failure rate corresponding to the current unit function includes: Substitute the safety level limit and failure rate of the current unit function into the degradation degree calculation formula to calculate the degradation degree of the current unit function. The degradation degree calculation formula satisfies the following conditions: Where x is the failure rate of the current unit function, g2(x) is the degradation degree of the current unit function, and α and β are the upper limit and good upper limit of the safety level.
5. The method for evaluating the state of a gateway machine according to claim 4, wherein: The safety status includes: safe, alert, emergency and critical; the calculation of the membership of each unit function in different safety statuses according to the degradation degree of each unit function includes: Substitute the degradation degree of each unit function into the normal distribution membership function to calculate the membership degree of each unit function under different safety states; wherein the normal distribution membership function satisfies the following conditions: Where d is the degradation degree, σ1, σ 21 , σ 22 , σ 31 , σ 32 , σ4 is a constant value, r v1 (d) is the membership degree of the security state as safe, r v2 (d) is the membership degree of the safety state as alert, r v3 (d) is the membership degree of the safety status as emergency, r v4 (d) is the membership degree of the security status being critical.
6. The method for evaluating the state of a gateway machine according to claim 5, wherein: The step of obtaining the variable weight value of each unit function includes: The constant weight of each unit function is calculated using a preset importance algorithm, and the constant weight and degradation degree of each unit function are substituted into a variable weight calculation formula to determine the variable weight of each unit function; wherein the variable weight calculation formula satisfies the following conditions: Where A it is the variable weight corresponding to the t-th unit function in the i-th module function, m is the number of unit functions in the i-th module function; ω is (0) (s=1,2,3,…,m) is the constant weight corresponding to the sth unit function in the i-th module function, d is (s=1, 2, 3, ..., m) represents the degradation degree of the sth unit function under the i-th module function; v is the variable weight coefficient.
7. The method for evaluating the state of a gateway machine according to claim 6, wherein: The unit functions include: functional module security, software security, trusted verification security, network detection security and malicious code prevention security; the module functions include: entity inherent attribute security and operation monitoring security; among them, entity inherent attribute security includes: functional module security, software security and trusted verification security; operation monitoring security includes: network detection security and malicious code prevention security.
8. A gateway machine status evaluation device, characterized in that: include: Data acquisition module, first calculation module, matrix composition module, second calculation module and result generation module; The data acquisition module is used to obtain device operation data of the gateway machine; The first calculation module is configured to calculate the degradation degree of each unit function of the gateway machine according to the device operation data, and calculate the membership degree of each unit function under different security states according to the degradation degree of each unit function; The matrix composition module is used to obtain the variable weight value of each unit function, and according to the module function to which each unit function belongs, the membership corresponding to the unit functions of the same module function is composed into a membership matrix corresponding to the current module function, and the variable weight values corresponding to the unit functions of the same module function are composed into a weight matrix corresponding to the current module function; wherein each module function includes a plurality of unit functions, and the unit functions corresponding to each module function are different from each other; The second calculation module is used to calculate the module security membership matrix of each module function based on the membership matrix and weight matrix of each module function; wherein the module security membership matrix includes: the membership of each module function in different security states; The result generation module is used to obtain the variable weight value of each module function, calculate the device security membership matrix based on the module security membership matrix and the variable weight value of each module function, and select the security state corresponding to the maximum membership as the security assessment result of the device; wherein the device security membership matrix includes: the membership of the device in different security states.
9. A terminal device, characterized in that: The method comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, the method for evaluating the state of a gateway machine according to any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium, characterized in that include: A stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the gateway machine status evaluation method according to any one of claims 1 to 7.