Method and system for optimizing safety operation and maintenance service and inspection management of power monitoring system
By constructing equipment operation feature vectors and fault propagation link diagrams, planning dynamic inspection paths, and deploying communication protection strategies, the problems of lagging fault identification and low inspection efficiency in power monitoring systems have been solved. This has enabled accurate location of fault sources and proactive prevention by the system, thereby improving the security and stability of power monitoring systems.
Patent Information
- Application Number
- CN202511134030.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-14
- Publication Date
- 2025-10-31
AI Technical Summary
Existing power monitoring systems suffer from problems such as delayed diagnosis of equipment anomalies, low inspection efficiency, and difficulty in identifying potential security risks in fault identification and inspection management. They lack dynamic inspection priority determination and abnormal communication identification based on behavioral characteristics, resulting in slow response to attack events and low protection accuracy.
By collecting equipment operation information, constructing equipment operation feature vectors, generating equipment operation trajectories and performing time-series analysis, identifying trajectory deviation points, calculating state correlation, generating fault propagation link diagrams, planning inspection paths, establishing equipment safety isolation domains and communication matrices, deploying communication protection strategies, and matching equipment status parameters with features to locate safety hazards.
It enables accurate identification and rapid response to fault source nodes, improves system operation and maintenance efficiency, enhances the refined management of communication behavior, reduces network security risks, optimizes inspection paths and resource allocation, and improves the safety, reliability and stability of the power monitoring system.
Smart Images

Figure CN120875446A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power system safety operation and maintenance, and particularly to a method and system for optimizing the safety operation and maintenance service and patrol management of a power monitoring system. Background Art
[0002] With the continuous expansion of the scale of the power system and the improvement of the intelligent level, the power monitoring system plays a core role in ensuring the safe and stable operation of the power grid. However, continuous monitoring of the operating states of a large number of devices in the system, identification of fault sources, operation and maintenance task scheduling, and network communication security rely on manual or static rules, making it difficult to promptly respond to the fault correlation and spread among multiple devices, resulting in lagged abnormal diagnosis of devices, low patrol efficiency, and difficulty in identifying potential security risks.
[0003] In the prior art, it mainly adopts single-device or fixed-path patrol methods, lacking a dynamic patrol priority determination mechanism for fault propagation paths; at the communication level, a unified access control strategy is usually adopted, which cannot flexibly adjust protection measures according to the communication dependency relationship between devices, and it is also difficult to accurately identify abnormal communication based on behavior characteristics, resulting in problems such as slow response to attack events and low protection accuracy in the system. In addition, the operating states of devices and communication behaviors are often processed separately, lacking cross-level linkage analysis means, and it is difficult to identify potential attack paths or security hazards through the matching of abnormal behaviors and device state parameters. Therefore, there is an urgent need for a power monitoring system safety operation and maintenance optimization method that integrates operation trajectory analysis, fault link modeling, dynamic patrol planning, and communication security protection to improve the overall operation safety and patrol efficiency of the system. Summary of the Invention
[0004] Embodiments of the present invention provide a method and system for optimizing the safety operation and maintenance service and patrol management of a power monitoring system, which can solve the problems in the prior art.
[0005] In the first aspect of the embodiments of the present invention, a method for optimizing the safety operation and maintenance service and patrol management of a power monitoring system is provided, including:
[0006] Collect the device operation information of the power monitoring system, construct a device operation feature vector, map the device operation feature vector to the state space, generate a device operation trajectory, perform time series analysis on the device operation trajectory, identify trajectory offset points, determine the abnormal operation interval of the device, calculate the state correlation degree between devices based on the abnormal operation interval, and generate a device fault propagation link diagram;
[0007] According to the state correlation degree values in the device fault propagation link diagram, identify the fault source node, determine the affected devices based on the position of the fault source node, establish the device patrol order among the affected devices, plan the patrol path according to the patrol order, and generate a patrol task list;
[0008] Based on the topology of the equipment failure propagation link diagram, a device security isolation domain is constructed. Within the security isolation domain, a device communication matrix is established. The shortest communication path between devices is calculated based on the device communication matrix. Communication protection strategies are deployed using the shortest communication path, and the operation status of the communication protection strategies is monitored, and abnormal communication behaviors are marked.
[0009] Perform inspections according to the inspection task list, collect equipment status parameters, match equipment status parameters with abnormal communication behaviors, locate equipment safety hazards, and output early warning information.
[0010] In one alternative embodiment,
[0011] Collect equipment operation information from the power monitoring system, construct equipment operation feature vectors, map these feature vectors to the state space, and generate equipment operation trajectories, including:
[0012] Collect equipment operation information from a power monitoring system, calculate the rate of change of the equipment operation information within multiple preset time windows, adjust the sampling time interval according to the rate of change, and obtain a sequence of equipment operation information.
[0013] The device operation information sequence is subjected to trend separation to obtain fluctuation components and trend components. Wavelet decomposition is then performed on the fluctuation components and trend components respectively to obtain feature components.
[0014] Calculate the information entropy value of the feature component, determine the discrimination index of the feature component based on the information entropy value, select feature components with a discrimination index greater than a preset threshold to form a feature subset, calculate the correlation coefficient between each feature component in the feature subset, construct a weight matrix, and perform weighted superposition of the feature components based on the weight matrix to generate a device operation feature vector.
[0015] Calculate the similarity value between adjacent vectors in the device operation feature vector sequence, determine the vector mapping parameters based on the similarity value, map the device operation feature vectors to the state space using the vector mapping parameters to obtain state points, calculate the transition probability between adjacent state points, and connect the state points sequentially based on the transition probability to generate the device operation trajectory.
[0016] In one alternative embodiment,
[0017] Time-series analysis of equipment operating trajectories is performed to identify trajectory deviation points, determine abnormal operating intervals, calculate the state correlation between equipment based on abnormal operating intervals, and generate an equipment fault propagation link diagram, including:
[0018] The fluctuation intensity of the equipment's operating trajectory at different time scales is calculated. Based on the distribution of the fluctuation intensity, the time scale corresponding to the maximum fluctuation intensity is selected as the reference window. The local complexity coefficient of the equipment's operating trajectory is calculated, and the reference window is dynamically adjusted to obtain the time series analysis window sequence.
[0019] Within the time-series analysis window sequence, the shape feature value and distribution feature value of the device's running trajectory are calculated, and they are combined in time order to form a feature vector sequence. The local density value and distance value of each vector in the feature vector sequence are calculated, and the position of the trajectory offset point is identified based on the changing pattern of the local density value and distance value.
[0020] The device's operating trajectory is divided into multiple intervals using the trajectory offset point as the boundary. The deviation coefficient between each interval and the standard trajectory is calculated. Intervals with deviation coefficients exceeding the judgment threshold are marked as abnormal operating intervals. The duration and abnormal amplitude of the abnormal operating intervals are extracted.
[0021] Calculate the weighted combination value of duration and abnormal amplitude to generate equipment status features. Calculate the status correlation degree with adjacent equipment based on the equipment status features. Construct a status correlation matrix based on the status correlation degree. Obtain the physical connection relationship of the equipment to generate a constraint matrix. Map and fuse the constraint matrix with the status correlation matrix to obtain a propagation relationship matrix. Extract the maximum weighted connected subgraph from the propagation relationship matrix to generate a device fault propagation link graph.
[0022] In one alternative embodiment,
[0023] Based on the state correlation values in the equipment fault propagation chain diagram, the fault source node is identified. Based on the location of the fault source node, the affected equipment is determined. An inspection sequence is established among the affected equipment, and inspection paths are planned according to this sequence. An inspection task table is generated, including:
[0024] Extract the state correlation values of device nodes in the fault propagation link graph, calculate the degree of propagation influence of each device node on adjacent nodes, count the propagation range and propagation intensity of each node, and select the node with the largest propagation range and the strongest propagation intensity as the candidate fault source node.
[0025] Establish a propagation path tree with the candidate fault source node as the root node, identify the propagation convergence point in the propagation path tree, calculate the state correlation change of the propagation convergence point, and select the node with the largest state correlation change as the fault source node.
[0026] The fault-affected devices are determined with the fault source node as the center, the affected levels are divided according to the attenuation ratio of the state correlation value, state monitoring points are set between each affected level, and the devices covered by the state monitoring points are determined as the fault-affected devices.
[0027] Obtain the state change trend of the equipment affected by the fault, divide the inspection area according to the state change trend and spatial distribution, and sort the equipment in each inspection area according to the state change amplitude to determine the equipment inspection order.
[0028] Collect operational status data of equipment affected by the fault, formulate inspection strategies based on operational status data and inspection sequence, plan inspection paths according to the inspection strategies, and generate inspection task tables.
[0029] In one alternative embodiment,
[0030] Based on the topology of the equipment fault propagation link diagram, a device security isolation domain is constructed. Within the security isolation domain, a device communication matrix is established. Based on the device communication matrix, the shortest communication path between devices is calculated, including:
[0031] Extract the topological connection relationship of nodes in the fault propagation link graph of the equipment, calculate the input propagation strength and output propagation strength of each equipment node, use the ratio of the input propagation strength to the output propagation strength as the fault propagation attenuation coefficient, and select the node with the largest fault propagation attenuation coefficient as the candidate fault propagation bottleneck point.
[0032] A fixed-intensity fault propagation signal is injected at the input end of the candidate fault propagation bottleneck point. The output fault signal intensity is collected, and the signal attenuation ratio is calculated by the ratio of the output fault signal intensity to the input fault signal intensity. The number of downstream adjacent nodes in a fault state is recorded, and the time interval between the fault signal propagation to each downstream node is measured. The fault suppression index is calculated based on the signal attenuation ratio, the number of fault nodes, and the propagation time interval.
[0033] The node with the largest fault suppression index is selected as the main fault propagation bottleneck point. An observation area is set up around it and the fault propagation status of the node is collected to verify the fault isolation effect. When the isolation effect meets the requirements, it is determined as the fault propagation bottleneck point and used as the boundary node to determine the range of the equipment safety isolation domain using breadth-first search.
[0034] Within the secure isolation domain, communication data packets are collected, communication feature parameters are extracted to construct a device communication matrix, the strength of direct communication links is analyzed, and indirect communication paths are traced and their transmission strength is calculated. The weighted sum of direct communication strength and indirect transmission strength is used as the communication path weight, and the shortest communication path between devices is calculated based on the communication path weight.
[0035] In one alternative embodiment,
[0036] Deploy communication protection strategies using the shortest communication path and monitor the operational status of these strategies, marking abnormal communication behaviors, including:
[0037] Analyze the data forwarding volume and processing load of each node in the shortest communication path, determine the criticality of the node location based on the load distribution, calculate the communication dependency between nodes, and classify the protection priority level of each node based on the communication dependency.
[0038] Configure corresponding authentication mechanisms, access control rules, traffic limit thresholds, and session management methods for nodes of different levels, and combine these mechanisms into differentiated communication protection strategies.
[0039] According to the node protection priority level, deploy communication protection strategies on the shortest communication path, and set up monitoring probes to collect the execution data of the protection strategies of each node. Statistical analysis is performed on the execution data within a preset time period according to the protection priority level to obtain statistical analysis results including the identity authentication frequency range of each node, access control rule matching rate, traffic change range and session state distribution. The statistical analysis results are used as the communication benchmark parameters of the nodes.
[0040] The monitoring probe collects the protection execution data of the node in real time, compares the real-time collected protection execution data with the communication benchmark parameters, sets a deviation threshold based on the protection priority level of the node, and marks it as abnormal communication behavior when the real-time collected protection execution data exceeds the deviation threshold.
[0041] In one alternative embodiment,
[0042] Perform inspections according to the inspection task list, collect equipment status parameters, match equipment status parameters with abnormal communication behaviors to locate potential equipment safety hazards, and output early warning information including:
[0043] Collect equipment status parameters of the inspected objects, construct a time-series acquisition queue of the equipment status parameters, calculate the changing trend of adjacent equipment status parameters in the time-series acquisition queue, generate a status baseline threshold, mark the fluctuation level of the equipment status parameters based on the status baseline threshold, and combine the fluctuation level with the acquisition timestamp to form status feature data.
[0044] Extract the feature identifier and occurrence timestamp of abnormal communication behavior, obtain state feature data within a preset time range before and after the occurrence timestamp, and calculate the fluctuation trend value, fluctuation amplitude value and fluctuation duration in the state feature data to form the device state change feature;
[0045] The device state change characteristics are matched with a preset attack feature library, and the attack feature type is determined based on the matching result. The attack feature library stores abnormal change characteristics of device state parameters, and the device security risks are located based on the attack feature type.
[0046] Based on the location of security risks, early warning information is generated and output to the security management platform. At the same time, the attack features corresponding to the changes in device status are updated to the attack feature database.
[0047] A second aspect of this invention provides a power monitoring system security operation and maintenance service and inspection management optimization system, comprising:
[0048] The first unit is used to collect equipment operation information of the power monitoring system, construct equipment operation feature vectors, map the equipment operation feature vectors to the state space, generate equipment operation trajectories, perform time-series analysis on the equipment operation trajectories, identify trajectory deviation points, determine abnormal operation intervals of equipment, calculate the state correlation between equipment based on the abnormal operation intervals, and generate equipment fault propagation link diagrams.
[0049] The second unit is used to identify the fault source node based on the state correlation value in the equipment fault propagation link diagram, determine the fault-affected equipment based on the location of the fault source node, establish the equipment inspection sequence among the fault-affected equipment, plan the inspection path according to the inspection sequence, and generate the inspection task table.
[0050] The third unit is used to construct a device security isolation domain based on the topology of the device fault propagation link diagram, establish a device communication matrix within the security isolation domain, calculate the shortest communication path between devices based on the device communication matrix, deploy communication protection strategies using the shortest communication path, monitor the operation status of the communication protection strategies, and mark abnormal communication behaviors.
[0051] The fourth unit is used to perform inspections according to the inspection task list, collect equipment status parameters, match the equipment status parameters with abnormal communication behaviors, locate potential equipment safety hazards, and output early warning information.
[0052] A third aspect of the present invention provides an electronic device, comprising:
[0053] processor;
[0054] Memory used to store processor-executable instructions;
[0055] The processor is configured to invoke instructions stored in the memory to execute the aforementioned method.
[0056] A fourth aspect of the present invention provides a computer-readable storage medium having stored thereon computer program instructions that, when executed by a processor, implement the aforementioned method.
[0057] In this embodiment, by collecting operational information from power monitoring system equipment and constructing a fault propagation chain diagram, the fault source node and affected equipment can be accurately identified, enabling precise fault location and rapid response, thus improving system operation and maintenance efficiency and fault handling capabilities. By establishing equipment security isolation domains and communication matrices, refined management of system communication behavior is achieved, allowing for timely identification of abnormal communication and deployment of corresponding protection strategies, effectively enhancing the security protection capabilities of the power monitoring system and reducing network security risks. By organically combining equipment inspection with communication monitoring, feature matching analysis is used to locate security risks and output early warning information, optimizing inspection paths and resource allocation, transforming system operation and maintenance from passive response to proactive prevention, and improving the overall security, reliability, and operational stability of the power monitoring system. Attached Figure Description
[0058] Figure 1 This is a flowchart illustrating the optimization method for the security operation and maintenance service and inspection management of the power monitoring system according to an embodiment of the present invention.
[0059] Figure 2 This is a logic flowchart of the equipment safety monitoring and early warning system according to an embodiment of the present invention. Detailed Implementation
[0060] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0061] The technical solution of the present invention will be described in detail below with reference to specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.
[0062] Figure 1 This is a flowchart illustrating the optimization method for the security operation and maintenance service and inspection management of the power monitoring system according to an embodiment of the present invention. Figure 1 As shown, the method includes:
[0063] Collect equipment operation information from the power monitoring system, construct equipment operation feature vectors, map the equipment operation feature vectors to the state space, generate equipment operation trajectories, perform time-series analysis on the equipment operation trajectories, identify trajectory deviation points, determine abnormal operation intervals of equipment, calculate the state correlation degree between equipment based on the abnormal operation intervals, and generate equipment fault propagation link diagrams.
[0064] Based on the state correlation value in the equipment fault propagation link diagram, identify the fault source node, determine the fault-affected equipment based on the location of the fault source node, establish the equipment inspection sequence among the fault-affected equipment, plan the inspection path according to the inspection sequence, and generate the inspection task table.
[0065] Based on the topology of the equipment failure propagation link diagram, a device security isolation domain is constructed. Within the security isolation domain, a device communication matrix is established. The shortest communication path between devices is calculated based on the device communication matrix. Communication protection strategies are deployed using the shortest communication path, and the operation status of the communication protection strategies is monitored, and abnormal communication behaviors are marked.
[0066] Perform inspections according to the inspection task list, collect equipment status parameters, match equipment status parameters with abnormal communication behaviors, locate equipment safety hazards, and output early warning information.
[0067] In one optional implementation, the process of collecting equipment operation information from the power monitoring system, constructing equipment operation feature vectors, mapping these feature vectors to the state space, and generating equipment operation trajectories includes:
[0068] Collect equipment operation information from a power monitoring system, calculate the rate of change of the equipment operation information within multiple preset time windows, adjust the sampling time interval according to the rate of change, and obtain a sequence of equipment operation information.
[0069] The device operation information sequence is subjected to trend separation to obtain fluctuation components and trend components. Wavelet decomposition is then performed on the fluctuation components and trend components respectively to obtain feature components.
[0070] Calculate the information entropy value of the feature component, determine the discrimination index of the feature component based on the information entropy value, select feature components with a discrimination index greater than a preset threshold to form a feature subset, calculate the correlation coefficient between each feature component in the feature subset, construct a weight matrix, and perform weighted superposition of the feature components based on the weight matrix to generate a device operation feature vector.
[0071] Calculate the similarity value between adjacent vectors in the device operation feature vector sequence, determine the vector mapping parameters based on the similarity value, map the device operation feature vectors to the state space using the vector mapping parameters to obtain state points, calculate the transition probability between adjacent state points, and connect the state points sequentially based on the transition probability to generate the device operation trajectory.
[0072] In one implementation, the equipment operation information of the power monitoring system is first collected, including parameters such as voltage, current, temperature, and vibration. For the main transformer in a substation, parameters such as active power, reactive power, and winding temperature can be collected; for transmission lines, parameters such as conductor temperature and tower tilt angle can be collected. After collection, the rate of change of these parameters within multiple preset time windows needs to be calculated. The preset time windows can be set to 10 seconds, 30 seconds, 1 minute, 5 minutes, and 10 minutes. Taking the main transformer winding temperature as an example, its rate of change within each time window is calculated. If the rate of change exceeds 0.5℃ / second within a 10-second window, the sampling interval is adjusted to 1 second; if the rate of change is between 0.1℃ / second and 0.5℃ / second, the sampling interval is adjusted to 5 seconds; if the rate of change is less than 0.1℃ / second, the sampling interval is adjusted to 10 seconds. By dynamically adjusting the sampling frequency in this way, sufficient data points can be captured when the equipment status changes rapidly, while reducing the amount of data stored when the equipment status is stable.
[0073] The collected equipment operation information sequence needs to undergo trend separation processing, splitting it into fluctuation components and trend components. For main transformer oil temperature data, the moving average method can be used for trend separation, using the moving average of a 24-hour window as the trend component, and the difference between the original data and the trend component as the fluctuation component. The separated fluctuation and trend components are then subjected to wavelet decomposition. Wavelet decomposition uses Haar wavelet basis functions, performing a 5-level decomposition on the fluctuation component to obtain 5 detail components and 1 approximate component; and a 3-level decomposition on the trend component to obtain 3 detail components and 1 approximate component. These components together constitute the feature component set.
[0074] For the obtained feature components, their information entropy values are calculated to assess their discriminative ability. Taking the first-level detail coefficient of the main transformer oil temperature fluctuation component as an example, its numerical range is divided into 20 equally spaced intervals, and the frequency of data points in each interval is statistically analyzed. The calculated information entropy value is 1.83. Similarly, the information entropy values of all feature components are calculated. The discriminative ability index is defined as the ratio of the information entropy value to the background noise entropy, with the background noise entropy value set to 2.5. When the discriminative ability index is greater than 0.6, the feature component is considered to have strong discriminative ability and is included in the feature subset. Through screening, five feature components are retained: the second, third, and fourth-level detail coefficients of the fluctuation component, and the first and second-level detail coefficients of the trend component.
[0075] Calculate the correlation coefficients between the feature components in the feature subset and construct a 5×5 weight matrix. Taking the correlation coefficient between the second-level detail coefficient of the fluctuation component and the first-level detail coefficient of the trend component as an example, the calculated value is 0.21, indicating a weak correlation. Invert the correlation coefficient and normalize it to obtain a weight value of 0.17. Calculate the weight values between all feature components in a similar way to form a complete weight matrix. Based on the weight matrix, weighted summation of the feature components generates the equipment operation feature vector. For a certain time point of the main transformer, its operation feature vector has a dimension of 5, corresponding to the weighted values of the 5 retained feature components.
[0076] The similarity value between adjacent vectors in the sequence of feature vectors for equipment operation is calculated. Using the cosine similarity method, for feature vectors at two adjacent time points, their dot product is calculated and divided by the product of their respective moduli. If the similarity value is higher than 0.95, it indicates slow equipment state changes, and the vector mapping parameter is set to 0.8; if the similarity value is between 0.9 and 0.95, the vector mapping parameter is set to 0.6; if the similarity value is lower than 0.9, the vector mapping parameter is set to 0.4. These mapping parameters are used to map the equipment operation feature vectors to a three-dimensional state space, obtaining a sequence of state points. The three dimensions of the state space can be understood as the main representation directions of the equipment's operating state.
[0077] The transition probability between adjacent state points is calculated, using the inverse ratio of the Euclidean distance between the state points as the transition probability value. When the distance between two state points is 0.5 units, the transition probability is 0.87; when the distance is 1.0 unit, the transition probability is 0.63; and when the distance is 2.0 units, the transition probability is 0.38. Based on these transition probabilities, the state points are sequentially connected to generate the equipment operating trajectory. For a normally operating main transformer, its operating trajectory exhibits a regular closed loop; however, for a main transformer with an anomaly, its operating trajectory will show significant deviations or abrupt changes, possibly manifesting as a sudden elongation or sharp angles. By observing the morphological characteristics of the equipment operating trajectory, abnormal changes in the equipment's operating status can be effectively identified, providing a basis for decision-making in the safe operation and maintenance of the power monitoring system.
[0078] In this embodiment, by introducing multi-time-window rate of change analysis, dynamic sampling optimization of equipment operation data is achieved, effectively improving the timeliness and accuracy of data acquisition. Through trend separation and wavelet decomposition, local changes and long-term trends in equipment operation status can be precisely extracted. Combining this with information entropy indicators to screen key features enhances the discriminative power and representativeness of feature vectors. By using a weighted fusion feature component matrix, high-quality operation feature vectors are constructed, improving the accuracy of subsequent state modeling. Furthermore, through similarity-driven vector mapping and transition probability calculation, dynamic evolution modeling of equipment operation status in the state space is achieved, constructing a time-series trajectory reflecting actual operation status changes. This helps to accurately identify equipment operation trends and potential abnormal behaviors, providing an efficient data foundation and modeling support for subsequent fault diagnosis and risk prediction.
[0079] In one optional implementation, time-series analysis is performed on the equipment's operating trajectory to identify trajectory deviation points, determine abnormal operating intervals of the equipment, calculate the state correlation between equipment based on the abnormal operating intervals, and generate an equipment fault propagation link diagram, including:
[0080] The fluctuation intensity of the equipment's operating trajectory at different time scales is calculated. Based on the distribution of the fluctuation intensity, the time scale corresponding to the maximum fluctuation intensity is selected as the reference window. The local complexity coefficient of the equipment's operating trajectory is calculated, and the reference window is dynamically adjusted to obtain the time series analysis window sequence.
[0081] Within the time-series analysis window sequence, the shape feature value and distribution feature value of the device's running trajectory are calculated, and they are combined in time order to form a feature vector sequence. The local density value and distance value of each vector in the feature vector sequence are calculated, and the position of the trajectory offset point is identified based on the changing pattern of the local density value and distance value.
[0082] The device's operating trajectory is divided into multiple intervals using the trajectory offset point as the boundary. The deviation coefficient between each interval and the standard trajectory is calculated. Intervals with deviation coefficients exceeding the judgment threshold are marked as abnormal operating intervals. The duration and abnormal amplitude of the abnormal operating intervals are extracted.
[0083] Calculate the weighted combination value of duration and abnormal amplitude to generate equipment status features. Calculate the status correlation degree with adjacent equipment based on the equipment status features. Construct a status correlation matrix based on the status correlation degree. Obtain the physical connection relationship of the equipment to generate a constraint matrix. Map and fuse the constraint matrix with the status correlation matrix to obtain a propagation relationship matrix. Extract the maximum weighted connected subgraph from the propagation relationship matrix to generate a device fault propagation link graph.
[0084] In this embodiment, time-series analysis of the equipment's operating trajectory is achieved by calculating the fluctuation intensity of the trajectory at different time scales. The fluctuation intensity can be measured by the magnitude of change in the trajectory within a specific time window. Specifically, seven time scales are selected: 5 minutes, 15 minutes, 30 minutes, 1 hour, 2 hours, 4 hours, and 8 hours. The standard deviation of the trajectory points at each scale is calculated as the fluctuation intensity. Taking the main transformer of a 110kV substation as an example, the fluctuation intensity is 0.12 at the 5-minute scale, 0.17 at the 15-minute scale, 0.28 at the 30-minute scale, 0.35 at the 1-hour scale, 0.41 at the 2-hour scale, 0.29 at the 4-hour scale, and 0.21 at the 8-hour scale. Analysis of the fluctuation intensity distribution shows that the fluctuation intensity is highest at the 2-hour scale, with a value of 0.41; therefore, 2 hours is selected as the baseline window. The local complexity coefficient of the equipment's operating trajectory is calculated, reflecting the complexity of the trajectory in a local region. Specifically, this is obtained by calculating the ratio of the number of turning points within the baseline window to the window length. When the local complexity coefficient is greater than 0.5, the baseline window is reduced to 1 hour; when the local complexity coefficient is less than 0.2, the baseline window is expanded to 4 hours; when the local complexity coefficient is between 0.2 and 0.5, the baseline window remains unchanged. Through this dynamic adjustment mechanism, a series of time series analysis window sequences that adapt to changes in trajectory complexity are obtained.
[0085] Within the obtained time-series analysis window, the shape and distribution characteristics of the equipment's operating trajectory are calculated. Shape characteristics include parameters such as trajectory curvature, trajectory length, and trajectory closure. Taking the main transformer's operating trajectory as an example, within a 2-hour window, the average trajectory curvature is 0.23, the trajectory length is 17.8 units, and the trajectory closure is 0.85. Distribution characteristics include parameters such as the density distribution and direction distribution of trajectory points. Within the same window, the variance of trajectory point density is 0.15, and the direction consistency is 0.72. These characteristic values are combined in chronological order to form a sequence of feature vectors. For each feature vector, its local density and distance values are calculated. The local density value represents the similarity between the feature vector and its surrounding vectors, and can be obtained by calculating the number of vectors whose Euclidean distance to their neighbors is less than a preset threshold of 0.3. The distance value represents the minimum distance between the feature vector and a vector with higher density. By plotting scatter plots of local density values and distance values, it was found that when the local density value is less than 5 and the distance value is greater than 2.5, or when the local density value is greater than 15 and the distance value is greater than 3.0, the corresponding vector usually represents the offset point of the trajectory.
[0086] Using the identified trajectory deviation points as boundaries, the equipment's operating trajectory is divided into multiple intervals. For the main transformer's operating trajectory, it can be divided into three intervals: the normal operating interval before 10:35, the transition interval from 10:35 to 14:20, and the recovery interval after 14:20. The deviation coefficient between each interval and the standard trajectory is calculated. The standard trajectory is usually selected from historical trajectory data during normal equipment operation. The deviation coefficient is calculated using the average Euclidean distance between the interval trajectory and the standard trajectory. The deviation coefficient for the normal operating interval is 0.18, for the transition interval it is 0.76, and for the recovery interval it is 0.25. A judgment threshold of 0.5 is set. When the deviation coefficient exceeds this threshold, the corresponding interval is marked as an abnormal operating interval. In this example, the transition interval is marked as an abnormal operating interval, lasting for 3 hours and 45 minutes, with an abnormal amplitude of 0.76.
[0087] The weighted combination of duration and abnormal amplitude is calculated to generate equipment state characteristics. The weighting method is duration with a weight of 0.4 and abnormal amplitude with a weight of 0.6. For the abnormal operating range of the main transformer, the state characteristic value is (3.75×0.4)+(0.76×0.6)=1.956. Based on this equipment state characteristic, the state correlation degree with adjacent equipment is calculated. The state correlation degree is obtained through time series correlation analysis of equipment state characteristics. Taking the main transformer and the connected circuit breaker as an example, the lag correlation coefficient of their state characteristic time series is calculated, with the lag time ranging from 0 minutes to 30 minutes and a step size of 5 minutes. When the lag time is 10 minutes, the correlation coefficient reaches its maximum value of 0.83, indicating that the circuit breaker state change lags behind the main transformer by 10 minutes, and the state correlation degree between the two is 0.83. Similarly, the state correlation degree of the main transformer with other adjacent equipment is calculated, and a state correlation matrix is constructed.
[0088] The physical connection relationships of the devices are obtained, generating a constraint matrix. These physical connections are obtained from the power system wiring diagram, recording whether there are direct electrical connections between devices. The main transformer has direct connections with devices such as circuit breakers, current transformers, and voltage transformers; the corresponding elements in the constraint matrix are set to 1, otherwise to 0. The constraint matrix is mapped and fused with the state association matrix to obtain the propagation relationship matrix. The fusion method is the product of corresponding elements of the two matrices, ensuring that fault propagation relationships exist only between physically connected and state-related devices. The maximum weight connected subgraph is extracted from the propagation relationship matrix; this subgraph contains the device connection relationships with the largest total weight. The extraction method uses the Kruskal algorithm, adding edges starting from the edge with the largest weight until all devices are connected. Finally, a device fault propagation link graph is generated, showing how a fault propagates from the main transformer to devices such as circuit breakers and current transformers, and the propagation strength. By analyzing the propagation link graph, key devices and weak points in the power monitoring system can be identified, providing precise inspection guidance for maintenance personnel, optimizing the inspection sequence and frequency, and improving the safety and maintenance efficiency of the power monitoring system.
[0089] In this embodiment, dynamic window decomposition and temporal feature extraction of equipment operating trajectories are achieved through multi-timescale fluctuation intensity analysis and local complexity modeling. This enables accurate identification of deviation points in abnormal changes within the trajectory and effective division of abnormal operating intervals. The construction of vector sequences based on shape and distribution features allows for fine-grained characterization of trajectory change trends, enhancing the robustness of anomaly identification. Weighted fusion of deviation coefficient determination with duration and anomaly amplitude forms equipment state features that reflect the degree of anomaly and stability. Furthermore, by combining physical connections and state correlations, a propagation relationship matrix is constructed, and the maximum weighted connected subgraph is extracted. This accurately simulates potential fault propagation paths between equipment, generating a practically instructive equipment fault propagation link diagram. This provides a structured and dynamic decision-making basis for subsequent source fault identification, inspection optimization, and risk control.
[0090] In one optional implementation, the fault source node is identified based on the state correlation value in the equipment fault propagation link diagram. Based on the location of the fault source node, the affected equipment is determined. An inspection sequence is established among the affected equipment. Inspection paths are planned according to the inspection sequence, and an inspection task table is generated, including:
[0091] Extract the state correlation values of device nodes in the fault propagation link graph, calculate the degree of propagation influence of each device node on adjacent nodes, count the propagation range and propagation intensity of each node, and select the node with the largest propagation range and the strongest propagation intensity as the candidate fault source node.
[0092] Establish a propagation path tree with the candidate fault source node as the root node, identify the propagation convergence point in the propagation path tree, calculate the state correlation change of the propagation convergence point, and select the node with the largest state correlation change as the fault source node.
[0093] The fault-affected devices are determined with the fault source node as the center, the affected levels are divided according to the attenuation ratio of the state correlation value, state monitoring points are set between each affected level, and the devices covered by the state monitoring points are determined as the fault-affected devices.
[0094] Obtain the state change trend of the equipment affected by the fault, divide the inspection area according to the state change trend and spatial distribution, and sort the equipment in each inspection area according to the state change amplitude to determine the equipment inspection order.
[0095] Collect operational status data of equipment affected by the fault, formulate inspection strategies based on operational status data and inspection sequence, plan inspection paths according to the inspection strategies, and generate inspection task tables.
[0096] For example, in the fault propagation path diagram of a 110kV substation, the state correlation coefficient values of equipment nodes including the main transformer, circuit breaker, current transformer, and surge arrester were extracted. When calculating the propagation influence of each equipment node on its adjacent nodes, the product of the state correlation coefficient and the node's out-degree was used as a quantitative indicator. For instance, the state correlation coefficients of the main transformer with its five adjacent devices are 0.83, 0.76, 0.65, 0.58, and 0.47, respectively, and its propagation influence is the sum of these values multiplied by 5, resulting in 16.45. A similar calculation was performed on the circuit breaker node; its state correlation coefficients with its four adjacent devices are 0.78, 0.72, 0.59, and 0.43, and its propagation influence is 10.08. The propagation range of each node was statistically analyzed, and determined by calculating the number of connected nodes with a state correlation coefficient greater than 0.4 originating from that node. The propagation range of the main transformer is 12 nodes, the circuit breaker is 8 nodes, and the current transformer is 5 nodes. Propagation intensity is defined as the average state correlation degree of the nodes. The propagation intensity of the main transformer is 0.66, that of the circuit breaker is 0.63, and that of the current transformer is 0.52. By comparing the propagation range and propagation intensity of each node, the main transformer is selected as the candidate fault source node because it has the largest propagation range and the strongest propagation intensity.
[0097] A propagation path tree was established with the main transformer as the root node, using a breadth-first search method with state correlation as the path weight. Starting from the main transformer, primary connected devices include circuit breakers, current transformers, and surge arresters, while secondary connected devices include disconnect switches and voltage transformers, forming a complete propagation path tree. Propagation convergence points, i.e., the nodes where multiple propagation paths intersect, were identified within this tree. By calculating the in-degree of each node, it was found that the circuit breaker had an in-degree of 3, and the voltage transformer had an in-degree of 4, both being propagation convergence points. The change in state correlation at the propagation convergence points was calculated by comparing the difference in state correlation before and after the fault. The state correlation of the circuit breaker increased from 0.38 to 0.78, a change of 0.40; the state correlation of the voltage transformer increased from 0.25 to 0.59, a change of 0.34. The circuit breaker was selected as the fault source node because its state correlation changed the most.
[0098] The affected equipment is determined with the circuit breaker as the center, and the impact level is divided according to the attenuation ratio of the state correlation degree value. The state correlation degree attenuation ratio is defined as the ratio of the state correlation degree of the equipment node to the state correlation degree of the fault source node. Three thresholds are set for the impact level division: 0.8, 0.6, and 0.4. When the attenuation ratio is greater than 0.8, the equipment belongs to the first-level impact layer; when the attenuation ratio is between 0.6 and 0.8, the equipment belongs to the second-level impact layer; and when the attenuation ratio is between 0.4 and 0.6, the equipment belongs to the third-level impact layer. The calculated first-level impact layer includes the main transformer and disconnector A, with attenuation ratios of 0.87 and 0.82, respectively; the second-level impact layer includes the current transformer, surge arrester, and disconnector B, with attenuation ratios of 0.76, 0.68, and 0.63, respectively; and the third-level impact layer includes the voltage transformer, surge arrester B, and capacitor, with attenuation ratios of 0.59, 0.52, and 0.45, respectively. Status monitoring points are set up between each affected level. Monitoring point M1 is set between the first-level affected level and the second-level affected level, and monitoring point M2 is set between the second-level affected level and the third-level affected level. The monitoring points are set up on the connection path with the largest state correlation gradient. M1 is set between the circuit breaker and the current transformer, and M2 is set between the surge arrester and the voltage transformer. The equipment covered by the status monitoring points together constitute the set of equipment affected by the fault.
[0099] The system acquires the state change trends of equipment affected by the fault, recording the rate and magnitude of change of equipment state parameters before and after the fault. For example, the number of circuit breaker operations increased from 3 times in the 24 hours before the fault to 8 times in the 12 hours after the fault, a rate of change of 0.42 times / hour; the oil temperature of the main transformer was 55℃ before the fault and rose to 68℃ after the fault, a change of 13℃. Inspection areas are divided based on state change trends and spatial distribution. Spatial clustering is used to group geographically close equipment with similar state change trends into the same inspection area. The division results in Area A including circuit breakers, main transformers, and disconnector A; Area B including current transformers, surge arresters, and disconnector B; and Area C including voltage transformers, surge arresters, and capacitors. Within each inspection area, equipment is ranked based on the magnitude of state change; the greater the magnitude of the state change, the higher the inspection priority. The inspection sequence for equipment in area A is: circuit breaker, main transformer, disconnector A; the inspection sequence for equipment in area B is: current transformer, surge arrester, disconnector B; the inspection sequence for equipment in area C is: voltage transformer, capacitor, surge arrester B.
[0100] Data on the operational status of equipment affected by the fault is collected, including electrical, mechanical, and environmental parameters. Electrical parameters include a circuit breaker contact temperature of 87℃ and a contact resistance of 120 microohms; mechanical parameters include a spring pressure of 280 Newtons in the operating mechanism; and environmental parameters include a cabinet humidity of 65%. An inspection strategy is developed based on the operational status data and inspection sequence. For equipment with large status changes and operating parameters close to alarm thresholds, a focused inspection strategy is adopted, increasing the inspection frequency and extending the inspection time. For equipment with small status changes and normal operating parameters, a routine inspection strategy is used. Inspection routes are planned according to the inspection strategy, optimizing the walking routes of inspection personnel and reducing duplicate paths and ineffective inspections. A modified ant colony algorithm is used for the planning method, with the shortest path and least time as the optimization objectives. The resulting inspection route is: substation control room → circuit breaker → main transformer → disconnector A → current transformer → surge arrester → disconnector B → voltage transformer → capacitor → surge arrester B → substation control room, with a total path length of 560 meters and an estimated inspection time of 95 minutes. An inspection task sheet is generated, including fields such as the name of the equipment to be inspected, location number, inspection content, inspection method, estimated duration, precautions, and completion confirmation. Taking a circuit breaker as an example, the inspection content includes contact temperature detection, contact resistance measurement, confirmation of operation count, and mechanical characteristic inspection; the inspection methods include infrared thermometry, use of a contact resistance tester, and mechanical operation testing; the estimated duration is 15 minutes; and the precaution is to check the spring pressure of the operating mechanism and record the value. By executing this inspection task sheet, power monitoring system maintenance personnel can conduct targeted inspections, improve inspection efficiency, promptly identify and handle potential faults, and ensure the safe and stable operation of the power system.
[0101] In this embodiment, by analyzing the fault propagation path diagram through state correlation, fault source nodes can be accurately identified, avoiding misjudgment or omission of initial anomaly locations and improving the accuracy of fault location. Constructing a propagation path tree and analyzing the state changes at the propagation convergence point further verifies and optimizes the fault source determination results. Dividing the impact levels based on the attenuation of state correlation and setting state monitoring points helps to comprehensively cover potentially affected equipment areas. Dividing inspection areas by combining equipment state change trends and spatial distribution, and setting inspection priorities based on state fluctuation amplitude, enables differentiated and precise inspections under fault impact. Finally, by jointly formulating inspection strategies based on operating status and inspection sequence, the inspection path is ensured to have high efficiency and risk response capabilities, thereby effectively improving the operation and maintenance response speed and resource scheduling rationality of the power monitoring system under fault conditions.
[0102] In one optional implementation, a device security isolation domain is constructed based on the topology of the device fault propagation link graph. A device communication matrix is then established within the security isolation domain. The shortest communication path between devices is calculated based on the device communication matrix, including:
[0103] Extract the topological connection relationship of nodes in the fault propagation link graph of the equipment, calculate the input propagation strength and output propagation strength of each equipment node, use the ratio of the input propagation strength to the output propagation strength as the fault propagation attenuation coefficient, and select the node with the largest fault propagation attenuation coefficient as the candidate fault propagation bottleneck point.
[0104] A fixed-intensity fault propagation signal is injected at the input end of the candidate fault propagation bottleneck point. The output fault signal intensity is collected, and the signal attenuation ratio is calculated by the ratio of the output fault signal intensity to the input fault signal intensity. The number of downstream adjacent nodes in a fault state is recorded, and the time interval between the fault signal propagation to each downstream node is measured. The fault suppression index is calculated based on the signal attenuation ratio, the number of fault nodes, and the propagation time interval.
[0105] The node with the largest fault suppression index is selected as the main fault propagation bottleneck point. An observation area is set up around it and the fault propagation status of the node is collected to verify the fault isolation effect. When the isolation effect meets the requirements, it is determined as the fault propagation bottleneck point and used as the boundary node to determine the range of the equipment safety isolation domain using breadth-first search.
[0106] Within the secure isolation domain, communication data packets are collected, communication feature parameters are extracted to construct a device communication matrix, the strength of direct communication links is analyzed, and indirect communication paths are traced and their transmission strength is calculated. The weighted sum of direct communication strength and indirect transmission strength is used as the communication path weight, and the shortest communication path between devices is calculated based on the communication path weight.
[0107] In the implementation process, the topological connections of the equipment fault propagation link graph are first extracted. For example, the equipment fault propagation link graph contains 32 equipment nodes, including 3 main transformers, 12 circuit breakers, 16 disconnecting switches, 8 current transformers, and 5 voltage transformers. The connection relationships between each node can be obtained by analyzing the adjacency matrix of the link graph. The input propagation strength of each equipment node is calculated by adding the weights of all connection edges pointing to that node. For circuit breaker No. 2, its input propagation strength is 2.37, and the propagation contributions from the three upstream nodes are 0.82, 0.76, and 0.79, respectively. The output propagation strength of each equipment node is calculated by adding the weights of all connection edges originating from that node. The output propagation strength of the same circuit breaker is 1.85, distributed across four downstream nodes with propagation strengths of 0.65, 0.52, 0.38, and 0.30, respectively. The fault propagation attenuation coefficient is obtained by calculating the ratio of the input propagation strength to the output propagation strength. The fault propagation attenuation coefficient of circuit breaker No. 2 is 2.37 / 1.85 = 1.28, indicating that this node has a certain inhibitory effect on fault propagation. Similarly, the fault propagation attenuation coefficients of all equipment nodes are calculated. The attenuation coefficient of disconnector No. 3 is 1.76, that of current transformer No. 1 is 1.42, and that of voltage transformer No. 2 is 1.33. Disconnector No. 3 is selected as the candidate fault propagation bottleneck point because it has the largest fault propagation attenuation coefficient.
[0108] A fixed-strength fault propagation signal is injected at the input of the candidate fault propagation bottleneck point to simulate an abnormal state in the upstream equipment. The signal strength is set to 1.0 unit. The output fault signal strength is collected by monitoring changes in the status parameters of the downstream equipment. For disconnector switch No. 3, the output fault signal strength is 0.57 units, and the calculated signal attenuation ratio is 0.57 / 1.0 = 0.57, indicating that this node can attenuate 43% of the fault propagation signal. The number of downstream adjacent nodes experiencing a fault state is recorded, with the criterion being that the equipment status parameters exceed the normal range by 20%. There are 5 adjacent nodes downstream of disconnector switch No. 3, of which 3 are experiencing a fault state, for a total of 3 fault nodes. The time interval for the fault signal to propagate to each downstream node is measured, and the time difference between the occurrence of the fault state in the upstream equipment and the abnormal parameters in the downstream equipment is recorded. For the downstream nodes of disconnector switch No. 3, the propagation time intervals are 3.5 seconds, 5.2 seconds, 6.8 seconds, 7.4 seconds, and 8.1 seconds, respectively, with an average propagation time of 6.2 seconds. The fault suppression index is calculated based on the signal attenuation ratio, the number of faulty nodes, and the propagation time interval. The calculation method is the signal attenuation ratio multiplied by the ratio of the propagation time interval to the number of faulty nodes. The fault suppression index for disconnector switch No. 3 is 0.57 × (6.2 / 3) = 1.18.
[0109] The node with the highest fault suppression index was selected as the main fault propagation bottleneck. Comparing the fault suppression indices of all candidate bottlenecks, it was found that the fault suppression index of voltage transformer No. 2 was 1.32, higher than that of disconnector switch No. 3 (1.18). Therefore, voltage transformer No. 2 was selected as the main fault propagation bottleneck. An observation area was set up around it, encompassing all equipment nodes with a topological distance not exceeding 2 digits from voltage transformer No. 2, totaling 12 devices. Fault propagation status of the nodes was collected by injecting various types of fault signals outside the observation area and recording whether the fault signals could propagate through the main fault propagation bottleneck into the observation area. The fault isolation effect was verified, with the verification standard set at no more than 10% of the normal range for the change in equipment state parameters within the observation area. After 50 fault injection tests, the average change in equipment state parameters within the observation area was 8.3%, meeting the isolation effect requirement. Therefore, voltage transformer No. 2 was determined as the fault propagation bottleneck. Using this bottleneck as the boundary node, a breadth-first search was used to determine the equipment safety isolation domain. The search process begins with voltage transformer No. 2 and expands outward along the propagation path diagram until the next fault propagation bottleneck is encountered or the propagation strength drops below 0.2. The final determined safety isolation domain contains 16 device nodes, forming a relatively independent area in terms of fault propagation.
[0110] Communication data packets were collected within the safety isolation zone over a 24-hour period with a 5-minute sampling interval, totaling 288 data points. Communication characteristic parameters were extracted, including communication frequency, data packet size, and communication protocol type. Communication frequency represents the number of communications between the two devices per unit time, data packet size represents the average number of bytes in the communication data, and the communication protocol type reflects the degree of structure in the data interaction. Taking the communication between voltage transformer No. 2 and circuit breaker No. 3 as an example, the communication frequency was 8.5 times per minute, the average data packet size was 256 bytes, and the IEC61850 protocol was primarily used. After normalizing these characteristic parameters, a device communication matrix was constructed with a dimension of 16×16, corresponding to the 16 device nodes within the safety isolation zone. The direct communication link strength was analyzed using a weighted product of communication frequency and data packet size, with weights of 0.7 and 0.3, respectively. The direct communication strength between voltage transformer No. 2 and circuit breaker No. 3 was (8.5×0.7)+(256 / 1024×0.3)=6.55. Simultaneously, the indirect communication path is traced and its transmission strength is calculated. Indirect communication refers to data exchange between two devices through an intermediate node. The transmission strength is calculated as the product of the strengths of all direct communication along the path multiplied by an attenuation coefficient. There is no direct communication between voltage transformer No. 2 and disconnector switch No. 5, but indirect communication is established through circuit breaker No. 3, with a transmission strength of 6.55 × 5.28 × 0.8 = 27.67. The weighted sum of the direct and indirect transmission strengths is used as the communication path weight, with a direct communication weight of 0.8 and an indirect communication weight of 0.2. The shortest communication path between devices is calculated based on the communication path weights using Dijkstra's algorithm, with the reciprocal of the communication path weight as the distance metric; a larger weight indicates a shorter distance. Within the safety isolation domain, the shortest communication path from main transformer No. 2 to current transformer No. 4 is: main transformer No. 2 → circuit breaker No. 1 → disconnector switch No. 3 → current transformer No. 4, with a total communication path weight of 18.76.
[0111] In this embodiment, by analyzing the fault propagation path diagram through state correlation, fault source nodes can be accurately identified, avoiding misjudgment or omission of initial anomaly locations and improving the accuracy of fault location. Constructing a propagation path tree and analyzing the state changes at the propagation convergence point further verifies and optimizes the fault source determination results. Dividing the impact levels based on the attenuation of state correlation and setting state monitoring points helps to comprehensively cover potentially affected equipment areas. Dividing inspection areas by combining equipment state change trends and spatial distribution, and setting inspection priorities based on state fluctuation amplitude, enables differentiated and precise inspections under fault impact. Finally, by jointly formulating inspection strategies based on operating status and inspection sequence, the inspection path is ensured to have high efficiency and risk response capabilities, thereby effectively improving the operation and maintenance response speed and resource scheduling rationality of the power monitoring system under fault conditions.
[0112] In one optional implementation, a communication protection strategy is deployed using the shortest communication path, and the operational status of the communication protection strategy is monitored. Abnormal communication behaviors are marked, including:
[0113] Analyze the data forwarding volume and processing load of each node in the shortest communication path, determine the criticality of the node location based on the load distribution, calculate the communication dependency between nodes, and classify the protection priority level of each node based on the communication dependency.
[0114] Configure corresponding authentication mechanisms, access control rules, traffic limit thresholds, and session management methods for nodes of different levels, and combine these mechanisms into differentiated communication protection strategies.
[0115] According to the node protection priority level, deploy communication protection strategies on the shortest communication path, and set up monitoring probes to collect the execution data of the protection strategies of each node. Statistical analysis is performed on the execution data within a preset time period according to the protection priority level to obtain statistical analysis results including the identity authentication frequency range of each node, access control rule matching rate, traffic change range and session state distribution. The statistical analysis results are used as the communication benchmark parameters of the nodes.
[0116] The monitoring probe collects the protection execution data of the node in real time, compares the real-time collected protection execution data with the communication benchmark parameters, sets a deviation threshold based on the protection priority level of the node, and marks it as abnormal communication behavior when the real-time collected protection execution data exceeds the deviation threshold.
[0117] For example, the shortest communication path is first analyzed, which includes seven nodes: a main server, network switch A, a firewall, network switch B, a front-end processor, a communication gateway, and a smart terminal. By deploying traffic acquisition probes at each node, data forwarding volume was collected over a week. The main server's average data forwarding volume was 245 MB / hour, with a peak of 387 MB / hour; network switch A's average data forwarding volume was 683 MB / hour, with a peak of 925 MB / hour; the firewall's average data forwarding volume was 412 MB / hour, with a peak of 675 MB / hour; and the data forwarding volumes of the remaining nodes were 362 MB / hour, 186 MB / hour, 94 MB / hour, and 42 MB / hour, respectively. Processing load was evaluated by combining node CPU utilization and memory usage. The firewall's average CPU utilization was 43%, with a peak of 68%; the main server's average CPU utilization was 56%, with a peak of 72%; and the CPU utilization of the remaining nodes ranged from 15% to 35%. The criticality of node locations was determined based on load distribution and quantified using the node betweenness centrality index. This index is calculated as the proportion of the shortest paths passing through a given node to the total number of shortest paths. The betweenness centrality of the firewall was 0.83, network switch A was 0.76, the main server was 0.62, the communication gateway was 0.47, and the betweenness centrality of other nodes was below 0.4. Communication dependencies between nodes were calculated, and the degree of dependency was assessed through connection disconnection tests. When the connection between the communication gateway and the smart terminal was disconnected, the monitoring system function was completely lost, with a dependency level of 1.0. When the connection between the front-end server and the communication gateway was disconnected, the data acquisition function was lost, but the control function was retained, with a dependency level of 0.8. The dependency levels for other connection disconnections ranged from 0.4 to 0.7. Based on communication dependencies, each node was assigned a protection priority level, with four levels: critical, high, medium, and general. The firewall and the main server were classified as critical, network switch A and the communication gateway as high, the front-end server and network switch B as medium, and the smart terminal as general.
[0118] Differentiated communication protection strategies are configured for nodes of different levels. Critical nodes are configured with a two-factor authentication mechanism, including digital certificate verification and dynamic password authentication, with an authentication timeout of 10 minutes. Access control rules use a whitelist approach, allowing only predefined IP addresses and ports to access the network, and rejecting all other requests by default. Traffic limits are set at 1.2 times the normal peak traffic, i.e., 810MB / hour for the firewall and 464MB / hour for the main server. Session management uses state tracking technology, with a maximum session duration of 30 minutes and an idle timeout of 5 minutes. Advanced nodes are configured with a single-factor certificate authentication mechanism with an authentication timeout of 30 minutes. Access control rules use a role-based access control model, granting different access permissions based on the access subject's role. Traffic limits are set at 1.5 times the normal peak traffic. Session management uses simplified state checks, with a maximum session duration of 60 minutes and an idle timeout of 10 minutes. Intermediate nodes are configured with password authentication, with an authentication timeout of 60 minutes; access control uses ACL rule sets to explicitly specify allowed and denied access modes; traffic limit thresholds are set to twice the normal peak value; session management uses timeout control with a session timeout of 120 minutes. General-level nodes are configured with basic authentication; access control uses port filtering; traffic limit thresholds are set to three times the normal peak value; session management only performs basic connection state maintenance.
[0119] Deploy communication protection policies along the shortest communication path according to node protection priority levels. Deploy critical-level protection policies on the firewall, configure a two-factor authentication server, set up certificate verification and OTP services, and write strict access control rule sets, such as "Allow the 192.168.1.0 / 24 network segment to access the main server through TCP port 443, requiring two-factor authentication and a 30-minute session timeout." Deploy advanced protection policies on network switch A, configure certificate verification services, and set up a role-based access control matrix, such as "Operator roles are allowed to view device status but are prohibited from modifying configurations." Deploy monitoring probes to collect protection policy execution data. Deploy dedicated security monitoring agents on critical-level nodes, collecting data every 10 seconds; deploy lightweight monitoring agents on high-level nodes, collecting data every 30 seconds; and obtain execution data through log analysis on medium and general-level nodes, collecting data every 60 seconds. Perform statistical analysis on the execution data according to protection priority levels. The analysis period is 24 hours for critical-level nodes, 48 hours for high-level nodes, 72 hours for medium-level nodes, and 168 hours for general-level nodes. The analysis revealed the authentication frequency range for each node: the firewall's authentication frequency was 85-120 times / hour, and the main server's was 62-95 times / hour. The access control rule matching rate was 98.7% for the firewall, meaning 98.7% of access requests matched predefined rules. Traffic variation ranged from 350-450 MB / hour for the firewall, with a standard deviation of 37 MB / hour. Session state distribution showed 15-28 active sessions with an average session duration of 18 minutes. These statistical analysis results were used as baseline communication parameters for the nodes and stored in the security baseline database.
[0120] Real-time monitoring probes collect node protection execution data, including authentication attempt count, authentication success rate, access control rule hit rate, traffic volume, and number of sessions. For the firewall, data collected at a certain moment shows: 145 authentication attempts / hour, authentication success rate of 92%, access control whitelist hit rate of 97.3%, traffic volume of 432MB / hour, and 25 active sessions. The real-time collected protection execution data is compared with communication baseline parameters, and deviation thresholds are set based on the node's protection priority level. For critical nodes, the deviation thresholds are 20% for authentication frequency, 2% for access control rule match rate, 15% for traffic, and 25% for session state; for high-level nodes, the thresholds are 30%, 5%, 25%, and 40%; for mid-level nodes, the thresholds are 50%, 10%, 40%, and 60%; and for general-level nodes, the thresholds are 100%, 20%, 60%, and 80%. When the real-time collected protection execution data exceeds the deviation thresholds, it is marked as abnormal communication behavior. Taking the firewall as an example, a real-time authentication attempt count of 145 times / hour exceeds the baseline parameter limit of 120 times / hour by 20.8%, and exceeds the deviation threshold of 20%. The system marks this as an abnormal authentication frequency. Other parameters do not exceed the deviation threshold and are not marked as abnormal. Similarly, the real-time execution data of all nodes are compared and anomaly marked to form a complete abnormal communication behavior identification result.
[0121] In this embodiment, by analyzing the load and communication dependencies of nodes in the shortest communication path, protection priority levels are rationally divided, enabling hierarchical deployment of protection resources and enhancing the security protection strength of critical nodes. Through differentiated configuration of identity authentication, access control, traffic limiting, and session management mechanisms, targeted communication protection strategies can be formulated for different risk levels, enhancing the overall communication link's resistance to attacks. Introducing monitoring probes and combining them with real-time comparative analysis of protection execution data and communication baseline parameters allows for timely detection of abnormal communication behavior, enabling rapid identification and response to communication anomalies. This improves the system's detection accuracy and processing efficiency for network attacks, unauthorized access, and communication hijacking, thereby effectively ensuring the secure and stable operation of critical communication links.
[0122] In one optional implementation, inspections are performed according to the inspection task list, equipment status parameters are collected, and the equipment status parameters are matched with abnormal communication behaviors to locate potential equipment safety hazards. Early warning information is then output, including:
[0123] Collect equipment status parameters of the inspected objects, construct a time-series acquisition queue of the equipment status parameters, calculate the changing trend of adjacent equipment status parameters in the time-series acquisition queue, generate a status baseline threshold, mark the fluctuation level of the equipment status parameters based on the status baseline threshold, and combine the fluctuation level with the acquisition timestamp to form status feature data.
[0124] Extract the feature identifier and occurrence timestamp of abnormal communication behavior, obtain state feature data within a preset time range before and after the occurrence timestamp, and calculate the fluctuation trend value, fluctuation amplitude value and fluctuation duration in the state feature data to form the device state change feature;
[0125] The device state change characteristics are matched with a preset attack feature library, and the attack feature type is determined based on the matching result. The attack feature library stores abnormal change characteristics of device state parameters, and the device security risks are located based on the attack feature type.
[0126] Based on the location of security risks, early warning information is generated and output to the security management platform. At the same time, the attack features corresponding to the changes in device status are updated to the attack feature database.
[0127] like Figure 2 The diagram illustrates the logical flow of the equipment safety monitoring and early warning system in this embodiment.
[0128] In practical applications, inspection personnel perform inspections according to a pre-set inspection task list. During on-site inspections of smart substations, the collected equipment status parameters fall into three main categories: electrical parameters, mechanical parameters, and environmental parameters. Electrical parameters include voltage, current, power, and frequency; mechanical parameters include temperature, vibration, noise, and air pressure; and environmental parameters include humidity, dust concentration, and gas concentration. Taking the main transformer of a substation as an example, the collected status parameters include oil temperature, winding temperature, active power, reactive power, voltage, current, noise, and vibration. The collection frequency is set to once every 5 minutes, continuously collected for 72 hours, forming a time-series collection queue. Each collection point contains parameter values and corresponding timestamp information. The changing trends of adjacent equipment status parameters in the time-series collection queue are calculated, and the parameter change rate is calculated using the sliding window method. For the main transformer oil temperature parameter, a 30-minute window is selected, and the average change rate within the window is calculated. Under normal circumstances, the average change rate of oil temperature fluctuates within the range of ±0.5℃ / hour. A baseline threshold for the status parameters is generated using the 3σ principle. The mean and standard deviation of historical parameter data are calculated, with an upper threshold set at the mean plus three times the standard deviation and a lower threshold at the mean minus three times the standard deviation. The mean of the main transformer oil temperature is 65℃, with a standard deviation of 2.3℃. The upper threshold is 71.9℃, and the lower threshold is 58.1℃. Based on the baseline threshold, the fluctuation levels of the equipment status parameters are marked, with four levels: normal, slight fluctuation, moderate fluctuation, and severe fluctuation. Parameter values within ±1 standard deviation of the mean are marked as normal; within ±1 to 2 standard deviations of the mean are marked as slight fluctuation; within ±2 to 3 standard deviations of the mean are marked as moderate fluctuation; and exceeding ±3 standard deviations of the mean are marked as severe fluctuation. The fluctuation level and the data acquisition timestamp are combined to form status feature data, which is stored in the status feature database.
[0129] The system extracts the feature identifiers and timestamps of abnormal communication behaviors. These behaviors are generated by the communication protection strategy monitoring module, and the feature identifiers include information such as the anomaly type, anomaly level, involved nodes, and communication flow direction. For example, the feature identifier for a particular abnormal communication behavior might be "Authentication frequency anomaly - high risk - firewall - main station to front-end server direction," with a timestamp of October 5, 2023, at 14:32:18. Status feature data is acquired within a preset time window before and after the timestamp: a forward range of 30 minutes and a backward range of 60 minutes, for a total of 90 minutes. The system calculates the fluctuation trend value in the status feature data and uses linear regression to fit the parameter change trend. The main transformer oil temperature shows an upward trend within this time window, with a slope of 1.8℃ / hour, significantly higher than the normal rate of change of 0.5℃ / hour. The fluctuation amplitude value is calculated as the difference between the maximum and minimum parameter values within the time window. The oil temperature fluctuation amplitude is 7.2℃, exceeding the normal fluctuation range. The fluctuation duration is calculated, representing the cumulative duration the parameter remains in an abnormal state. The duration of oil temperature fluctuations at or above the moderate level is 45 minutes. The fluctuation trend value, fluctuation amplitude value, and fluctuation duration are combined to form the equipment status change characteristics, which are expressed as "rise -7.2℃ - 45 minutes".
[0130] The device state change characteristics are matched against a pre-defined attack feature database, which stores typical abnormal changes in device state parameters caused by different types of network attacks. A fuzzy matching algorithm is used to calculate the similarity between the feature to be matched and the features in the database. The similarity calculation considers three dimensions: trend similarity, amplitude similarity, and time similarity, with weights of 0.4, 0.4, and 0.2, respectively. For the main transformer oil temperature state change characteristic "rise -7.2℃ - 45 minutes", the similarity calculation result with the "transformer overload attack" characteristic "rise -6.5℃~8.0℃ - 40~60 minutes" in the attack feature database is 0.92, and the similarity with the "transformer cooling system attack" characteristic "rise -5.0℃~10.0℃ - 30~90 minutes" is 0.88. The similarity with other attack features is all below 0.6. Based on the matching results, the attack feature type is determined, and the attack feature with the highest similarity is selected as the matching result. In this example, the "transformer overload attack" feature type is determined. The attack signature database stores potential security vulnerabilities caused by this type of attack, including accelerated transformer insulation aging, cooling system overload, and malfunction of protection devices. Security vulnerabilities in equipment are located based on attack signature types, and the load control system and cooling system of the main transformer are checked for tampering or attacks.
[0131] Based on the location of safety hazards, early warning information is generated. This information includes fields such as the hazard equipment identifier, hazard type, severity, discovery time, estimated impact, and handling recommendations. For the main transformer overload attack hazard, the early warning information is: "Equipment Identifier: Main Transformer No. 1; Hazard Type: Overload Attack; Severity: High Risk; Discovery Time: October 5, 2023, 14:48; Estimated Impact: May cause transformer overheat protection activation, resulting in a large-scale power outage in the station area; Handling Recommendation: Immediately check the load control system, isolate suspicious control commands, activate the backup cooling system, and reduce the transformer load to below 70%." The early warning information is output to the safety management platform and pushed to relevant maintenance and safety management personnel through a preset notification mechanism. Notification methods include system interface prompts, SMS, telephone, and mobile application push notifications to ensure timely delivery of early warning information. Simultaneously, the attack characteristics corresponding to the equipment status change features are updated to the attack characteristic database, including the latest observed characteristic parameters and detection time. For transformer overload attack characteristics, the updated fluctuation range is 6.5℃~8.0℃, and the duration is 40~60 minutes, with the detection time recorded. The attack characteristic database employs an incremental learning mechanism to continuously accumulate and optimize characteristic patterns, improving the accuracy of subsequent detections.
[0132] Based on the above technical solutions, dynamic correlation analysis between equipment operating status and communication security can be achieved, enhancing the intelligent identification capability of potential attack behaviors during inspections. By establishing a temporal baseline of equipment status parameters and a temporal correlation with abnormal communication behavior, it is possible to accurately capture equipment status fluctuations caused or accompanied by communication anomalies, enabling the modeling of the causal chain before and after an attack event. Simultaneously, by combining fluctuation trends, amplitudes, and durations to form state change characteristics and matching them with an attack signature database, it is possible to effectively identify highly concealed and progressively evolving attack behaviors, thereby locating equipment security vulnerabilities and generating timely warnings, significantly improving the system's detection coverage and response time for unknown attacks.
[0133] A second aspect of this invention provides a power monitoring system security operation and maintenance service and inspection management optimization system, the system comprising:
[0134] The first unit is used to collect equipment operation information of the power monitoring system, construct equipment operation feature vectors, map the equipment operation feature vectors to the state space, generate equipment operation trajectories, perform time-series analysis on the equipment operation trajectories, identify trajectory deviation points, determine abnormal operation intervals of equipment, calculate the state correlation between equipment based on the abnormal operation intervals, and generate equipment fault propagation link diagrams.
[0135] The second unit is used to identify the fault source node based on the state correlation value in the equipment fault propagation link diagram, determine the fault-affected equipment based on the location of the fault source node, establish the equipment inspection sequence among the fault-affected equipment, plan the inspection path according to the inspection sequence, and generate the inspection task table.
[0136] The third unit is used to construct a device security isolation domain based on the topology of the device fault propagation link diagram, establish a device communication matrix within the security isolation domain, calculate the shortest communication path between devices based on the device communication matrix, deploy communication protection strategies using the shortest communication path, monitor the operation status of the communication protection strategies, and mark abnormal communication behaviors.
[0137] The fourth unit is used to perform inspections according to the inspection task list, collect equipment status parameters, match the equipment status parameters with abnormal communication behaviors, locate potential equipment safety hazards, and output early warning information.
[0138] A third aspect of the present invention provides an electronic device, comprising:
[0139] processor;
[0140] Memory used to store processor-executable instructions;
[0141] The processor is configured to invoke instructions stored in the memory to execute the aforementioned method.
[0142] A fourth aspect of the present invention provides a computer-readable storage medium having stored thereon computer program instructions that, when executed by a processor, implement the aforementioned method.
[0143] This invention can be a method, apparatus, system, and / or computer program product. The computer program product may include a computer-readable storage medium having computer-readable program instructions loaded thereon for performing various aspects of the invention.
[0144] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. An optimization method for the safety operation and maintenance service and inspection management of power monitoring systems, characterized in that, include: Collect equipment operation information from the power monitoring system, construct equipment operation feature vectors, map the equipment operation feature vectors to the state space, generate equipment operation trajectories, perform time-series analysis on the equipment operation trajectories, identify trajectory deviation points, determine abnormal operation intervals of equipment, calculate the state correlation degree between equipment based on the abnormal operation intervals, and generate equipment fault propagation link diagrams. Based on the state correlation value in the equipment fault propagation link diagram, identify the fault source node, determine the fault-affected equipment based on the location of the fault source node, establish the equipment inspection sequence among the fault-affected equipment, plan the inspection path according to the inspection sequence, and generate the inspection task table. Based on the topology of the equipment failure propagation link diagram, a device security isolation domain is constructed. Within the security isolation domain, a device communication matrix is established. The shortest communication path between devices is calculated based on the device communication matrix. Communication protection strategies are deployed using the shortest communication path, and the operation status of the communication protection strategies is monitored, and abnormal communication behaviors are marked. Perform inspections according to the inspection task list, collect equipment status parameters, match equipment status parameters with abnormal communication behaviors, locate equipment safety hazards, and output early warning information.
2. The method according to claim 1, characterized in that, Collect equipment operation information from the power monitoring system, construct equipment operation feature vectors, map these feature vectors to the state space, and generate equipment operation trajectories, including: Collect equipment operation information from a power monitoring system, calculate the rate of change of the equipment operation information within multiple preset time windows, adjust the sampling time interval according to the rate of change, and obtain a sequence of equipment operation information. The device operation information sequence is subjected to trend separation to obtain fluctuation components and trend components. Wavelet decomposition is then performed on the fluctuation components and trend components respectively to obtain feature components. Calculate the information entropy value of the feature component, determine the discrimination index of the feature component based on the information entropy value, select feature components with a discrimination index greater than a preset threshold to form a feature subset, calculate the correlation coefficient between each feature component in the feature subset, construct a weight matrix, and perform weighted superposition of the feature components based on the weight matrix to generate a device operation feature vector. Calculate the similarity value between adjacent vectors in the device operation feature vector sequence, determine the vector mapping parameters based on the similarity value, map the device operation feature vectors to the state space using the vector mapping parameters to obtain state points, calculate the transition probability between adjacent state points, and connect the state points sequentially based on the transition probability to generate the device operation trajectory.
3. The method according to claim 1, characterized in that, Time-series analysis of equipment operating trajectories is performed to identify trajectory deviation points, determine abnormal operating intervals, calculate the state correlation between equipment based on abnormal operating intervals, and generate an equipment fault propagation link diagram, including: The fluctuation intensity of the equipment's operating trajectory at different time scales is calculated. Based on the distribution of the fluctuation intensity, the time scale corresponding to the maximum fluctuation intensity is selected as the reference window. The local complexity coefficient of the equipment's operating trajectory is calculated, and the reference window is dynamically adjusted to obtain the time series analysis window sequence. Within the time-series analysis window sequence, the shape feature value and distribution feature value of the device's running trajectory are calculated, and they are combined in time order to form a feature vector sequence. The local density value and distance value of each vector in the feature vector sequence are calculated, and the position of the trajectory offset point is identified based on the changing pattern of the local density value and distance value. The device's operating trajectory is divided into multiple intervals using the trajectory offset point as the boundary. The deviation coefficient between each interval and the standard trajectory is calculated. Intervals with deviation coefficients exceeding the judgment threshold are marked as abnormal operating intervals. The duration and abnormal amplitude of the abnormal operating intervals are extracted. Calculate the weighted combination value of duration and abnormal amplitude to generate equipment status features. Calculate the status correlation degree with adjacent equipment based on the equipment status features. Construct a status correlation matrix based on the status correlation degree. Obtain the physical connection relationship of the equipment to generate a constraint matrix. Map and fuse the constraint matrix with the status correlation matrix to obtain a propagation relationship matrix. Extract the maximum weighted connected subgraph from the propagation relationship matrix to generate a device fault propagation link graph.
4. The method according to claim 1, characterized in that, Based on the state correlation values in the equipment fault propagation chain diagram, the fault source node is identified. Based on the location of the fault source node, the affected equipment is determined. An inspection sequence is established among the affected equipment, and inspection paths are planned according to this sequence. An inspection task table is generated, including: Extract the state correlation values of device nodes in the fault propagation link graph, calculate the degree of propagation influence of each device node on adjacent nodes, count the propagation range and propagation intensity of each node, and select the node with the largest propagation range and the strongest propagation intensity as the candidate fault source node. Establish a propagation path tree with the candidate fault source node as the root node, identify the propagation convergence point in the propagation path tree, calculate the state correlation change of the propagation convergence point, and select the node with the largest state correlation change as the fault source node. The fault-affected devices are determined with the fault source node as the center, the affected levels are divided according to the attenuation ratio of the state correlation value, state monitoring points are set between each affected level, and the devices covered by the state monitoring points are determined as the fault-affected devices. Obtain the state change trend of the equipment affected by the fault, divide the inspection area according to the state change trend and spatial distribution, and sort the equipment in each inspection area according to the state change amplitude to determine the equipment inspection order. Collect operational status data of equipment affected by the fault, formulate inspection strategies based on operational status data and inspection sequence, plan inspection paths according to the inspection strategies, and generate inspection task tables.
5. The method according to claim 1, characterized in that, Based on the topology of the equipment fault propagation link diagram, a device security isolation domain is constructed. Within this domain, a device communication matrix is established. Based on this matrix, the shortest communication path between devices is calculated, including: Extract the topological connection relationship of nodes in the fault propagation link graph of the equipment, calculate the input propagation strength and output propagation strength of each equipment node, use the ratio of the input propagation strength to the output propagation strength as the fault propagation attenuation coefficient, and select the node with the largest fault propagation attenuation coefficient as the candidate fault propagation bottleneck point. A fixed-intensity fault propagation signal is injected at the input end of the candidate fault propagation bottleneck point. The output fault signal intensity is collected, and the signal attenuation ratio is calculated by the ratio of the output fault signal intensity to the input fault signal intensity. The number of downstream adjacent nodes in a fault state is recorded, and the time interval between the fault signal propagation to each downstream node is measured. The fault suppression index is calculated based on the signal attenuation ratio, the number of fault nodes, and the propagation time interval. The node with the largest fault suppression index is selected as the main fault propagation bottleneck point. An observation area is set up around it and the fault propagation status of the node is collected to verify the fault isolation effect. When the isolation effect meets the requirements, it is determined as the fault propagation bottleneck point and used as the boundary node to determine the range of the equipment safety isolation domain using breadth-first search. Within the secure isolation domain, communication data packets are collected, communication feature parameters are extracted to construct a device communication matrix, the strength of direct communication links is analyzed, and indirect communication paths are traced and their transmission strength is calculated. The weighted sum of direct communication strength and indirect transmission strength is used as the communication path weight, and the shortest communication path between devices is calculated based on the communication path weight.
6. The method according to claim 1, characterized in that, Deploy communication protection strategies using the shortest communication path and monitor the operational status of these strategies, marking abnormal communication behaviors, including: Analyze the data forwarding volume and processing load of each node in the shortest communication path, determine the criticality of the node location based on the load distribution, calculate the communication dependency between nodes, and classify the protection priority level of each node based on the communication dependency. Configure corresponding authentication mechanisms, access control rules, traffic limit thresholds, and session management methods for nodes of different levels, and combine these mechanisms into differentiated communication protection strategies. According to the node protection priority level, deploy communication protection strategies on the shortest communication path, and set up monitoring probes to collect the execution data of the protection strategies of each node. Statistical analysis is performed on the execution data within a preset time period according to the protection priority level to obtain statistical analysis results including the identity authentication frequency range of each node, access control rule matching rate, traffic change range and session state distribution. The statistical analysis results are used as the communication benchmark parameters of the nodes. The monitoring probe collects the protection execution data of the node in real time, compares the real-time collected protection execution data with the communication benchmark parameters, sets a deviation threshold based on the protection priority level of the node, and marks it as abnormal communication behavior when the real-time collected protection execution data exceeds the deviation threshold.
7. The method according to claim 1, characterized in that, Perform inspections according to the inspection task list, collect equipment status parameters, match equipment status parameters with abnormal communication behaviors to locate potential equipment safety hazards, and output early warning information including: Collect equipment status parameters of the inspected objects, construct a time-series acquisition queue of the equipment status parameters, calculate the changing trend of adjacent equipment status parameters in the time-series acquisition queue, generate a status baseline threshold, mark the fluctuation level of the equipment status parameters based on the status baseline threshold, and combine the fluctuation level with the acquisition timestamp to form status feature data. Extract the feature identifier and occurrence timestamp of abnormal communication behavior, obtain state feature data within a preset time range before and after the occurrence timestamp, and calculate the fluctuation trend value, fluctuation amplitude value and fluctuation duration in the state feature data to form the device state change feature; The device state change characteristics are matched with a preset attack feature library, and the attack feature type is determined based on the matching result. The attack feature library stores abnormal change characteristics of device state parameters, and the device security risks are located based on the attack feature type. Based on the location of security risks, early warning information is generated and output to the security management platform. At the same time, the attack features corresponding to the changes in device status are updated to the attack feature database.
8. A power monitoring system safety operation and maintenance service and inspection management optimization system, used to implement the method of any one of claims 1-7, characterized in that, include: The first unit is used to collect equipment operation information of the power monitoring system, construct equipment operation feature vectors, map the equipment operation feature vectors to the state space, generate equipment operation trajectories, perform time-series analysis on the equipment operation trajectories, identify trajectory deviation points, determine abnormal operation intervals of equipment, calculate the state correlation between equipment based on the abnormal operation intervals, and generate equipment fault propagation link diagrams. The second unit is used to identify the fault source node based on the state correlation value in the equipment fault propagation link diagram, determine the fault-affected equipment based on the location of the fault source node, establish the equipment inspection sequence among the fault-affected equipment, plan the inspection path according to the inspection sequence, and generate the inspection task table. The third unit is used to construct a device security isolation domain based on the topology of the device fault propagation link diagram, establish a device communication matrix within the security isolation domain, calculate the shortest communication path between devices based on the device communication matrix, deploy communication protection strategies using the shortest communication path, monitor the operation status of the communication protection strategies, and mark abnormal communication behaviors. The fourth unit is used to perform inspections according to the inspection task list, collect equipment status parameters, match the equipment status parameters with abnormal communication behaviors, locate potential equipment safety hazards, and output early warning information.
9. An electronic device, characterized in that, include: processor; Memory used to store processor-executable instructions; The processor is configured to invoke instructions stored in the memory to execute the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having computer program instructions stored thereon, characterized in that, When the computer program instructions are executed by the processor, they implement the method described in any one of claims 1 to 7.
Citation Information
Cited By
Fault diagnosis method and fault diagnosis system for CAN bus communication failure
CN121187275A
Automatic inspection and fault processing method and system for video conference
CN121792723A