Security policy adjustment method and device of power system, equipment, medium and product
By monitoring the power system's operational data in real time and dynamically adjusting security strategies using deep learning neural network models, the problem of power systems being unable to adapt to complex security threats in existing technologies has been solved, thus achieving the safe and stable operation of the power grid.
Patent Information
- Application Number
- CN202510881464.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-27
- Publication Date
- 2025-10-28
AI Technical Summary
Existing technologies are unable to adjust security strategies by real-time monitoring of the operating status and security threats of the power system, making it difficult to adapt to the complex and changing security threat environment. They also fail to utilize technical means such as machine learning and big data analysis, making it difficult to ensure the information security of the power system.
By monitoring real-time operating data of the power system, a deep learning neural network model is used to dynamically adjust security strategies, and a pre-set operation security assessment model is combined to predict and respond to security events, thereby improving the power system's adaptability and defense capabilities.
It enables dynamic adjustment of the power system's security strategy, improves the ability to defend against new security threats, and ensures the safe and stable operation of the power grid.
Smart Images

Figure CN120851644A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power system technology, and in particular to a method, apparatus, equipment, medium and product for adjusting the security strategy of a power system. Background Art
[0002] As a critical national infrastructure, the security of the power system is directly related to the national economy, people's livelihood, and national security. In recent years, with the rapid development of network technology and the continuous upgrading of cyberattack methods, the cybersecurity threats faced by the power system have become increasingly severe. For example, malicious code such as "Stuxnet" and "Flame," designed specifically for the power system, launches organized cross-network attacks through covert channels or social engineering, which traditional protection measures are ineffective in defending against. The computer network operating environment of the power system has multiple security vulnerabilities, and traditional firewall technology is insufficient to deal with professional-level security threats. At the same time, traditional firewalls are logical entities, making them vulnerable to attack themselves, and they are not applicable to the special communication protocols of the power system, making it difficult to guarantee the information security of the power system.
[0003] Therefore, existing technologies typically configure multiple security strategies for power grid systems, with these strategies adjusting each other to protect the power grid system's security. However, existing technologies cannot adjust the system's security strategies by monitoring the system's operating status and security threats in real time, making it difficult to adapt to complex and ever-changing security threat environments. At the same time, existing technologies do not utilize machine learning, big data analysis, and other technologies, resulting in insufficient prediction and response capabilities for security events, making it impossible to effectively defend against new security threats and ensure the safe and stable operation of the power grid. Summary of the Invention
[0004] This invention provides a method, apparatus, equipment, medium, and product for adjusting the security strategy of a power system. By monitoring the real-time operating data of the power system and using a deep learning neural network model, the security strategy of the power system is dynamically adjusted. At the same time, a preset operation security assessment model is used to predict and respond to security events, thereby improving the adaptive and defensive capabilities of the power system, as well as its ability to defend against new security threats, so as to ensure the safe and stable operation of the power grid.
[0005] To achieve the above objectives, embodiments of the present invention provide a method for adjusting the security strategy of a power system, comprising:
[0006] Obtain real-time operating data for each operating node of the power system at the current moment;
[0007] A preset operational security assessment model is used to perform an operational security assessment on the real-time operational data to obtain the operational security assessment result for each operational node; based on the operational security assessment result, the target operational nodes that require operational security policies are determined.
[0008] Based on the operational security assessment results of each target running node and the trained deep learning neural network model, the target security strategy corresponding to each target running node is obtained.
[0009] The target security policy is adapted to the corresponding target running node for security protection.
[0010] As an improvement to the above scheme, the method for obtaining the trained deep learning neural network model includes:
[0011] Obtain historical operational data of power system operating nodes before and after the implementation of security policies;
[0012] The historical operation data is calculated using a preset formula for calculating the operation status anomaly coefficient to obtain the operation status anomaly coefficient of the operation node before and after the operation history security policy.
[0013] The deep learning neural network model is trained using the aforementioned operational state anomaly coefficient until the operational state anomaly coefficient output by the deep learning neural network model reaches the highest prediction accuracy, thus obtaining the trained deep learning neural network model.
[0014] As an improvement to the above scheme, if the expression of the preset operation safety assessment model is a preset operation state anomaly coefficient calculation formula;
[0015] The process involves using a preset operational security assessment model to perform an operational security assessment on the real-time operational data, obtaining the operational security assessment result for each operational node; and determining the target operational nodes requiring operational security policies based on the operational security assessment results, including:
[0016] The real-time operating data is calculated using a preset formula for calculating the abnormal operating status coefficient to obtain the abnormal operating status coefficient of each operating node.
[0017] If the abnormal operation status coefficient is greater than or equal to the set abnormal operation status coefficient threshold, then the operation node corresponding to the abnormal operation status coefficient is determined to be the target operation node that needs to run the security policy.
[0018] As an improvement to the above scheme, the step of obtaining the target security strategy corresponding to each target running node based on the operational security assessment results of each target running node and the trained deep learning neural network model includes:
[0019] The operational security assessment results of each target running node and the data of each security policy type are input into the trained deep learning neural network model to obtain the operational status anomaly coefficient after the security policy is run for each security policy type data.
[0020] Select the security policy corresponding to the smallest abnormal operation state coefficient and set it as the target security policy for each target running node.
[0021] As an improvement to the above solution, the step of adapting the target security policy to the corresponding target running node for security protection includes:
[0022] The target security policy is adapted to the corresponding target running node, and the target security policy is executed to provide security protection.
[0023] To achieve the above objectives, embodiments of the present invention provide a power system security strategy adjustment device, comprising:
[0024] The data acquisition module is used to acquire real-time operating data of each operating node in the power system at the current moment;
[0025] The target node determination module is used to perform an operational security assessment on the real-time operational data using a preset operational security assessment model to obtain the operational security assessment result for each operational node; and to determine the target operational nodes that require operational security policies based on the operational security assessment results.
[0026] The security policy acquisition module is used to obtain the target security policy corresponding to each target running node based on the running security assessment results of each target running node and the trained deep learning neural network model.
[0027] The target node protection module is used to adapt the target security policy to the corresponding target running node for security protection.
[0028] To achieve the above objectives, embodiments of the present invention provide a power system security policy adjustment device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the above-described power system security policy adjustment method.
[0029] To achieve the above objectives, embodiments of the present invention also provide a computer-readable storage medium, the computer-readable storage medium including a stored computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to execute the above-described power system security policy adjustment method.
[0030] To achieve the above objectives, embodiments of the present invention also provide a computer program product, which is stored in a storage medium and executed by at least one processor to implement the steps of the above-described power system security policy adjustment method.
[0031] Compared with existing technologies, the present invention discloses a method, apparatus, device, medium, and product for adjusting the security strategy of a power system. This involves acquiring real-time operational data of each operating node in the power system at the current moment; performing an operational security assessment on the real-time operational data using a preset operational security assessment model to obtain the operational security assessment result for each operating node; determining the target operating node requiring the operational security strategy based on the operational security assessment result; obtaining the target security strategy corresponding to each target operating node based on the operational security assessment result of each target operating node and a trained deep learning neural network model; and adapting the target security strategy to the corresponding target operating node for security protection. This method enables dynamic adjustment of the power system's security strategy by real-time monitoring of the power system's operational data and deep learning neural network model, while simultaneously using a preset operational security assessment model to predict and respond to security events. This improves the power system's adaptability and defense capabilities, as well as its ability to defend against new security threats, thereby ensuring the safe and stable operation of the power grid. Attached Figure Description
[0032] Figure 1 This is a flowchart illustrating a method for adjusting the security strategy of a power system according to an embodiment of the present invention;
[0033] Figure 2 This is a schematic diagram of the structure of a power system security strategy adjustment device provided in an embodiment of the present invention;
[0034] Figure 3 This is a structural block diagram of a power system security strategy adjustment device provided in an embodiment of the present invention. Detailed Implementation
[0035] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0036] It should be noted that the terms "comprising" and "specific" in this invention, and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to such process, method, product, or device.
[0037] Please see Figure 1 , Figure 1This is a flowchart illustrating a method for adjusting the security strategy of a power system according to an embodiment of the present invention. The method includes:
[0038] S1, obtain the real-time operating data of each operating node of the power system at the current moment;
[0039] S2, The real-time operation data is evaluated using a preset operation security assessment model to obtain the operation security assessment result for each operation node; the target operation node requiring an operation security strategy is determined based on the operation security assessment result.
[0040] S3. Based on the operational security assessment results of each target running node and the trained deep learning neural network model, obtain the target security strategy corresponding to each target running node.
[0041] S4, adapt the target security policy to the corresponding target running node for security protection.
[0042] For example, the power system security strategy adjustment method described in this embodiment of the invention is implemented by a power system security management server, which is capable of information interaction with target users and with the power system. The power system security management server acquires real-time operating data (including operating current, operating voltage, and operating temperature, etc., which reflect the operational safety of the operating node) of each operating node in the power system at the current moment; it uses a preset operational safety assessment model to perform an operational safety assessment on the real-time operating data, obtaining the operational safety assessment result for each operating node; it determines the target operating node requiring an operational safety strategy based on the operational safety assessment result; it obtains the target security strategy corresponding to each target operating node based on the operational safety assessment result of each target operating node and the trained deep learning neural network model; and it adapts the target security strategy to the corresponding target operating node for security protection. This embodiment of the invention can dynamically adjust the power system's security strategy by real-time monitoring of the power system's real-time operating data and deep learning neural network model, while simultaneously using a preset operational safety assessment model to predict and respond to security events, improving the power system's adaptability and defense capabilities, as well as its defense capabilities against new security threats, thereby ensuring the safe and stable operation of the power grid.
[0043] It is worth noting that operating nodes refer to various equipment nodes in the power system that need to be monitored for their operating status, such as servers, terminal equipment, and communication devices in the power monitoring system. They are the specific targets of security policy adjustments.
[0044] Specifically, the method for obtaining the trained deep learning neural network model includes:
[0045] S101, Obtain historical operating data of power system operating nodes before and after the historical security policy;
[0046] S102, the historical operation data is calculated using a preset formula for calculating the operation status anomaly coefficient to obtain the operation status anomaly coefficient of the operation node before and after the operation history security policy.
[0047] S103, the deep learning neural network model is trained using the aforementioned operational state anomaly coefficient until the operational state anomaly coefficient output by the deep learning neural network model reaches the highest prediction accuracy, thus obtaining the trained deep learning neural network model.
[0048] For example, the historical operating data includes the first operating data of the power system operating nodes before the implementation of the historical security policy and the second operating data of the power system operating nodes after the implementation of the historical security policy.
[0049] The method for obtaining the trained deep learning neural network model includes: importing the first and second running data into a preset formula for calculating the running state anomaly coefficient to calculate the running state anomaly coefficient of the first and second running data; taking the running state anomaly coefficient of the first running data and security policy type data as input, and the running state anomaly coefficient of the second running data as output, to construct a deep learning neural network model.
[0050] The abnormal operation status coefficients and security policy type data of the first and second operation data are divided into a 70% parameter training set and a 30% parameter test set. The 70% parameter training set is input into the deep learning neural network model for training to obtain the initial deep learning neural network model. The initial deep learning neural network model is tested using the 30% parameter test set, and the initial deep learning neural network model with the highest accuracy in predicting the abnormal operation status coefficients is output as the trained deep learning neural network model.
[0051] The expression in the deep learning neural network model is:
[0052]
[0053] In the formula, The output of the s-term neuron in layer q+1. The connection weights are the connection weights between the b-th neuron in layer q and the s-th neuron in layer q+1. This represents the input to the b-th neuron in the q-th layer. represents the bias of the linear relationship between the b-th neuron in layer q and the s-th neuron in layer q+1, sig() represents the Sigmoid activation function, and W is the number of neurons in the q-th deep learning neural network model.
[0054] In practice, the basic process of model building can be carried out according to the following steps:
[0055] Collect operational data before and after implementing the security policy, including but not limited to CPU usage, memory usage, network traffic, and error logs. Handle missing and outlier values, and standardize or normalize the operational data. Extract useful features from the processed operational data, such as operational status anomaly coefficients (e.g., standard deviation, variance, etc.). Calculate the operational status anomaly coefficients according to a pre-defined formula, which may involve multiple statistics from the original operational data, such as the anomaly coefficient, current statistics, and baseline statistics. Label the collected raw operational data for anomaly coefficients before and after implementing the security policy. Select an appropriate deep learning model based on the problem complexity, such as a fully connected neural network (FCNN), a multiplicative neural network (CNN), or a recurrent neural network (RNN). Construct the neural network model:
[0056] Input layer: Input data includes the anomaly coefficient of the running status before the security policy is executed and the security policy type.
[0057] Hidden layers: Design multiple hidden layers according to the model complexity, and ReLU can be used as the activation function.
[0058] Output layer: The output is the anomaly coefficient of the running status after the security policy is implemented.
[0059] The model is trained using historical data, a suitable loss function (such as mean squared error (MSE)) is selected, and optimization algorithms such as Adam are used for weight optimization. Data augmentation, such as data jittering, is also performed to improve the model's generalization ability. The model performance is evaluated using a validation set, and metrics may include mean squared error, coefficient of determination (R²), etc.
[0060] Understandably, when adjusting power system security strategies for the first time, or when significant changes occur in the power system operating environment (such as adding new equipment types or upgrading communication protocols), it is necessary to build and train a deep learning neural network model to obtain a trained model, eliminating the need for repeated construction. The operational state anomaly coefficient is a core indicator used to assess the security status of power system operating nodes, obtained by quantifying the deviation of operational data from the safe range. Security strategy type data refers to the characteristic data used to identify different security strategy categories. Security strategies are the core protective means to ensure the safe operation of the power system, achieving precise responses to security threats through dynamic adjustments.
[0061] Specifically, if the expression of the preset operation safety assessment model is a preset operation state anomaly coefficient calculation formula;
[0062] Then step S2 includes:
[0063] S21, the real-time running data is calculated using a preset formula for calculating the abnormal running status coefficient to obtain the abnormal running status coefficient of each running node.
[0064] S22, if the abnormal operation status coefficient is greater than or equal to the set abnormal operation status coefficient threshold, then the operation node corresponding to the abnormal operation status coefficient is determined to be the target operation node that needs to run the security policy.
[0065] In an optional embodiment, the real-time running data is calculated using a preset formula for calculating the abnormal running status coefficient to obtain the abnormal running status coefficient of each running node; the abnormal running status coefficient is compared with a set abnormal running status coefficient threshold; if the abnormal running status coefficient is greater than or equal to the set abnormal running status coefficient threshold, it is determined that a security policy needs to be implemented; if the abnormal running status coefficient is less than the set abnormal running status coefficient threshold, it is determined that a security policy does not need to be implemented; the running node corresponding to the abnormal running status coefficient that requires the implementation of a security policy is taken as the target running node.
[0066] The preset formula for calculating the abnormal operating state coefficient is as follows:
[0067]
[0068] Among them, Y r denoted as the abnormal operation status coefficient, m as the type of operation data, aj as the proportion coefficient of the j-th type of operation data, T as the monitoring duration, xjt as the specific value of the j-th type of operation data at time t, xjtm as the median of the safe range of the j-th type of operation data at time t, xjmax as the maximum value of the safe range of the j-th type of operation data, xjmin as the minimum value of the safe range of the j-th type of operation data, and dt as the time integral.
[0069] It should be noted that the proportion coefficient of the j-th type of operating data is set based on the experience of those skilled in the art.
[0070] Specifically, step S3 includes:
[0071] S31, input the operational security assessment results of each target running node and the data of each security policy type into the trained deep learning neural network model to obtain the operational status anomaly coefficient of each security policy type data after the security policy is run;
[0072] S32, select the security policy corresponding to the smallest abnormal operation state coefficient and set it as the target security policy for each target running node.
[0073] For example, the real-time running data of each target running node is substituted into the preset running state anomaly coefficient calculation formula to calculate the running state anomaly coefficient of each target running node. The calculated running state anomaly coefficient and various security policy type data are substituted into the trained deep learning neural network model. The trained deep learning neural network model outputs the running state anomaly coefficient after the security policy is run, corresponding to the security policy data of various security policy types. The security policy corresponding to the smallest running state anomaly coefficient after the security policy is run is selected as the target security policy of each target running node.
[0074] Specifically, step S4 includes:
[0075] S41, adapt the target security policy to the corresponding target running node, and run the target security policy to provide security protection.
[0076] This invention discloses a method for adjusting the security strategy of a power system. The method involves acquiring real-time operational data of each operating node in the power system at the current moment; performing an operational security assessment on the real-time operational data using a preset operational security assessment model to obtain the operational security assessment result for each operating node; determining the target operating node requiring the operational security strategy based on the operational security assessment result; obtaining the target security strategy corresponding to each target operating node based on the operational security assessment result of each target operating node and a trained deep learning neural network model; and adapting the target security strategy to the corresponding target operating node for security protection. This method enables dynamic adjustment of the power system's security strategy by real-time monitoring of the power system's operational data and deep learning neural network model. Simultaneously, it uses a preset operational security assessment model to predict and respond to security events, improving the power system's adaptability and defense capabilities, as well as its ability to defend against new security threats, thereby ensuring the safe and stable operation of the power grid.
[0077] See Figure 2 , Figure 2 This is a schematic diagram of the structure of a power system security strategy adjustment device 10 provided in an embodiment of the present invention. The power system security strategy adjustment device 10 includes:
[0078] The operation data acquisition module 11 is used to acquire the real-time operation data of each operating node of the power system at the current moment;
[0079] The target node determination module 12 is used to perform an operational security assessment on the real-time operational data using a preset operational security assessment model to obtain the operational security assessment result for each operational node; and to determine the target operational nodes that require operational security strategies based on the operational security assessment results.
[0080] The security policy acquisition module 13 is used to obtain the target security policy corresponding to each target running node based on the running security assessment results of each target running node and the trained deep learning neural network model.
[0081] The target node protection module 14 is used to adapt the target security policy to the corresponding target running node for security protection.
[0082] The power system security strategy adjustment device 10 provided in this embodiment of the invention can realize all the processes of the power system security strategy adjustment method of the above embodiment. The functions and technical effects of each module in the device are the same as the functions and technical effects of the power system security strategy adjustment method of the above embodiment, and will not be repeated here.
[0083] See Figure 3 , Figure 3 This is a schematic diagram of the structure of a power system security policy adjustment device 20 provided in an embodiment of the present invention. The power system security policy adjustment device 20 of this embodiment includes: a processor 21, a memory 22, and a computer program stored in the memory 22 and executable on the processor 21. When the processor 21 executes the computer program, it implements the steps in the above-described power system security policy adjustment method embodiment. Alternatively, when the processor 21 executes the computer program, it implements the functions of each module in the above-described power system security policy adjustment device embodiment.
[0084] For example, the computer program may be divided into one or more modules, which are stored in the memory 22 and executed by the processor 21 to complete the present invention. The one or more modules may be a series of computer program instruction segments capable of performing specific functions, which describe the execution process of the computer program in the power system's security policy adjustment device 20.
[0085] The power system security policy adjustment device 20 can be a computing device such as a desktop computer, laptop, handheld computer, or cloud server. The power system security policy adjustment device 20 may include, but is not limited to, a processor 21 and a memory 22. Those skilled in the art will understand that the schematic diagram is merely an example of the power system security policy adjustment device 20 and does not constitute a limitation on the device. It may include more or fewer components than illustrated, or combine certain components, or use different components. For example, the power system security policy adjustment device 20 may also include input / output devices, network access devices, buses, etc.
[0086] The processor 21 may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor. The processor 21 is the control center of the power system's security policy adjustment device 20, connecting various parts of the device through various interfaces and lines.
[0087] The memory 22 can be used to store the computer programs and / or modules. The processor 21 implements various functions of the power system safety policy adjustment device 20 by running or executing the computer programs and / or modules stored in the memory 22 and calling the data stored in the memory 22. The memory 22 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the mobile phone (such as audio data, phonebook, etc.). In addition, the memory 22 may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.
[0088] If the module integrated into the power system security policy adjustment device 20 is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by the processor 21, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content contained in the computer-readable medium may be appropriately added to or subtracted from the content as required by the legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium may not include electrical carrier signals and telecommunication signals.
[0089] It should be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, in the accompanying drawings of the device embodiments provided by this invention, the connection relationships between modules indicate that they have communication connections, which can be specifically implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without any creative effort.
[0090] This invention also provides a computer-readable storage medium, which includes a stored computer program, wherein the computer program, when running, controls the device where the computer-readable storage medium is located to execute the power system security policy adjustment method as described in the above embodiments.
[0091] Furthermore, embodiments of the present invention also provide a computer program product, which is stored in a storage medium and executed by at least one processor to implement the steps of the power system security policy adjustment method described in the above embodiments.
[0092] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications are also considered to be within the scope of protection of the present invention.
Claims
1. A method for adjusting the security strategy of a power system, characterized in that, include: Obtain real-time operating data for each operating node of the power system at the current moment; A preset operational safety assessment model is used to perform an operational safety assessment on the real-time operational data to obtain the operational safety assessment results for each operational node. Based on the operational security assessment results, determine the target operational nodes that require operational security policies; Based on the operational security assessment results of each target running node and the trained deep learning neural network model, the target security strategy corresponding to each target running node is obtained. The target security policy is adapted to the corresponding target running node for security protection.
2. The power system security strategy adjustment method as described in claim 1, characterized in that, The method for obtaining the trained deep learning neural network model includes: Obtain historical operational data of power system operating nodes before and after the implementation of security policies; The historical operation data is calculated using a preset formula for calculating the operation status anomaly coefficient to obtain the operation status anomaly coefficient of the operation node before and after the operation history security policy. The deep learning neural network model is trained using the aforementioned operational state anomaly coefficient until the operational state anomaly coefficient output by the deep learning neural network model reaches the highest prediction accuracy, thus obtaining the trained deep learning neural network model.
3. The power system security strategy adjustment method as described in claim 1, characterized in that, If the expression of the preset operation safety assessment model is a preset formula for calculating the operation state anomaly coefficient; The operation security assessment is then performed on the real-time operation data using a preset operation security assessment model to obtain the operation security assessment result for each operation node. Based on the operational security assessment results, the target operational nodes that require the implementation of security policies are determined, including: The real-time operating data is calculated using a preset formula for calculating the abnormal operating status coefficient to obtain the abnormal operating status coefficient of each operating node. If the abnormal operation status coefficient is greater than or equal to the set abnormal operation status coefficient threshold, then the operation node corresponding to the abnormal operation status coefficient is determined to be the target operation node that needs to run the security policy.
4. The power system security strategy adjustment method as described in claim 1, characterized in that, The step of obtaining the target security strategy corresponding to each target running node based on the operational security assessment results of each target running node and the trained deep learning neural network model includes: The operational security assessment results of each target running node and the data of each security policy type are input into the trained deep learning neural network model to obtain the operational status anomaly coefficient after the security policy is run for each security policy type data. Select the security policy corresponding to the smallest abnormal operation state coefficient and set it as the target security policy for each target running node.
5. The power system security strategy adjustment method as described in claim 1, characterized in that, The step of adapting the target security policy to the corresponding target running node for security protection includes: The target security policy is adapted to the corresponding target running node, and the target security policy is executed to provide security protection.
6. A power system security strategy adjustment device, characterized in that, include: The data acquisition module is used to acquire real-time operating data of each operating node in the power system at the current moment; The target node determination module is used to perform an operational safety assessment on the real-time operational data using a preset operational safety assessment model, and obtain the operational safety assessment result for each operational node. Based on the operational security assessment results, determine the target operational nodes that require operational security policies; The security policy acquisition module is used to obtain the target security policy corresponding to each target running node based on the running security assessment results of each target running node and the trained deep learning neural network model. The target node protection module is used to adapt the target security policy to the corresponding target running node for security protection.
7. A power system security strategy adjustment device, characterized in that, The system includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor, when executing the computer program, implements the power system security policy adjustment method as described in any one of claims 1-5.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to perform the power system security policy adjustment method as described in any one of claims 1-5.
9. A computer program product, characterized in that, The computer program product is stored in a storage medium, and the program product is executed by at least one processor to implement the steps of the power system security policy adjustment method as described in any one of claims 1-5.