A Power Grid Network Security Situation Assessment System Based on Big Data Analysis
The power grid network security situation assessment system, which utilizes big data analytics, enables global data collection, deep semantic analysis, and multi-level risk prediction. It solves the problems of data collection, feature extraction, and assessment in power grid network security situation assessment, improves assessment efficiency and accuracy, and supports real-time protection and decision-making.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-16
- Publication Date
- 2026-04-03
AI Technical Summary
Existing methods for assessing the cybersecurity situation of power grids suffer from problems such as limited data collection dimensions, insufficient feature extraction depth, crude risk prediction and assessment, and static assessment results. These issues result in the inability to fully reconstruct attack chains, high false negative rates, and low assessment efficiency.
The power grid network security situation assessment system, based on big data analytics, enables global data collection, deep semantic analysis, multi-level risk prediction and quantitative assessment. Combined with a historical attack case knowledge base, it identifies potential attack paths and vulnerability distributions to conduct a quantitative assessment of the power grid network security situation.
It improves the efficiency of power grid network security situation assessment, can accurately identify potential attack paths and vulnerabilities, provide a global security situation level, and support real-time protection and decision-making.
Smart Images

Figure CN120915592B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of monitoring and analysis technology, and in particular to a power grid network security situation assessment system based on big data analysis. Background Technology
[0002] With the accelerated integration of new energy sources into the grid and the construction of smart grids, the power grid network is gradually exhibiting characteristics of "multi-node, high coupling, and wide connectivity." Dispatch centers, substations, and distribution terminals are deeply interconnected through the network, facing diverse security threats such as industrial control virus attacks, man-in-the-middle attacks, and internal maintenance errors. Once attacked, these threats could lead to large-scale power outages, threatening energy security and social stability. Currently, power grid security management relies heavily on traditional security methods, such as firewalls and intrusion detection systems. While these can intercept single-point threats, they suffer from data fragmentation, focusing primarily on equipment operating parameters and neglecting critical data such as network communication topology and user behavior logs, making it difficult to integrate comprehensive security information. Furthermore, traditional assessments are mostly static qualitative analyses, lacking the prediction of potential attack paths and the capture of dynamic changes in vulnerabilities, thus failing to form a global security situation awareness. With the widespread application of big data technology in the energy sector, integrating multi-source data, deeply analyzing features, and quantitatively assessing risks to build a global and intelligent security situation assessment system has become a core requirement for power grid network security protection.
[0003] Among related technologies, current methods for assessing the cybersecurity situation of power grid networks have significant shortcomings:
[0004] First, the data collection dimension is too narrow, focusing mainly on device operating parameters and simple network traffic, while ignoring data such as user operation logs and communication node relationships, which makes it impossible to fully reconstruct the attack chain;
[0005] Second, the feature extraction depth is insufficient, only surface statistics of the data are performed, and semantic parsing and temporal correlation are not combined to mine potential threat features;
[0006] Third, risk prediction and assessment are crude, relying heavily on manual experience to match historical cases, lacking dynamic simulation of attack paths and analysis of the linkage between regional vulnerabilities, resulting in a high rate of missed detection of potential threats.
[0007] Fourth, the assessment results are static, only outputting qualitative conclusions (such as the existence of risks), without quantitative grading and dynamic trend prediction, and the degree of visualization is low. It is difficult for managers to quickly grasp the overall risks, delaying the timing of emergency response, and thus reducing the efficiency of power grid network security situation assessment. There are areas for improvement. Summary of the Invention
[0008] To address the shortcomings of existing technologies, this application provides a power grid network security situation assessment system based on big data analysis.
[0009] Firstly, this application provides a power grid network security situation assessment system based on big data analysis, comprising:
[0010] The data acquisition module is used to collect network security data in the power grid network globally, and to aggregate and process the network security status of the power grid based on the results of the global collection to form global security data of the power grid.
[0011] The parsing and extraction module is used to perform feature extraction and deep semantic parsing on the global security data of the power grid, and then determine the comprehensive feature vector of the power grid network based on the results of feature extraction and deep semantic parsing.
[0012] The processing module is used to perform multi-level risk prediction on the network security status of the power grid based on the comprehensive feature vector of the power grid and in combination with a preset historical attack case knowledge base, thereby obtaining the set of potential attack paths and vulnerability distribution data corresponding to the power grid network.
[0013] The assessment module is used to perform a quantitative assessment of the power grid network security situation based on the set of potential attack paths and vulnerability distribution data. Then, based on the assessment results, it confirms the global security situation level of the power grid and sends the global security situation level of the power grid to the terminal device so that the power grid security management personnel can carry out real-time protection and decision-making.
[0014] Preferably, the network security data includes network communication data and power grid operation log information; the network communication data includes network communication nodes and traffic data corresponding to each network communication node, and the power grid operation log information includes equipment operation status data, intrusion detection alarm information, and user behavior data.
[0015] Preferably, feature extraction and deep semantic parsing are performed on the global security data of the power grid, and then the comprehensive feature vector of the power grid corresponding to the power grid network is determined based on the results of feature extraction and deep semantic parsing, specifically including:
[0016] The communication topology of the global power grid security data is reconstructed to confirm the power grid communication node association map;
[0017] Based on the power grid communication node association map, the interaction patterns between each network communication node are extracted using time-series features, and then the network communication node interaction behavior data is confirmed based on the extraction results.
[0018] Deep semantic mining is performed on power grid operation log information to identify key behavioral sequences related to potential attacks, and then key feature data of power grid logs are identified based on the key behavioral sequences.
[0019] By fusing the network communication node interaction behavior data with the key feature data of the power grid log, the comprehensive feature vector of the power grid network can be determined.
[0020] Preferably, after identifying key feature data from the power grid log based on the key behavior sequence, the method further includes:
[0021] Sequence analysis is performed on user behavior data in the power grid operation log information to identify abnormal behavior data, and in-depth analysis is performed on the correlation between the abnormal behavior data and the equipment operation status data in the power grid operation log information to obtain the correlation characteristics between user behavior and equipment status.
[0022] Based on the correlation characteristics between user behavior and device status, and combined with a preset historical attack case knowledge base, behavior pattern matching is performed to identify potential attack intent data.
[0023] Based on the potential attack intent data, key feature data of the power grid logs are labeled to form a set of potential behavioral features.
[0024] Preferably, the set of potential attack paths and vulnerability distribution data corresponding to the power grid network are obtained, specifically including:
[0025] Based on the comprehensive feature vector and potential behavioral feature set of the power grid network, the potential attack paths between communication nodes of the power grid network are simulated and predicted, thereby confirming the set of potential attack paths.
[0026] A risk assessment is performed on the set of potential attack paths to identify the vulnerability distribution data corresponding to each functional area of the power grid network.
[0027] Preferably, a risk assessment is performed on the set of potential attack paths by region to identify the vulnerability distribution data corresponding to each functional area of the power grid network, specifically including:
[0028] The potential attack path set is divided into network topology layers to obtain security risk distribution data between different layers;
[0029] Based on the security risk distribution data between different levels, a differential analysis of the vulnerability indicators of each functional area is conducted to identify the risk differences between functional areas.
[0030] Time series assessment of risk differences among the functional areas is performed to identify vulnerability change trends in each functional area of the power grid network at different time periods.
[0031] Based on the vulnerability change trend data, risk warning classification is carried out for each functional area of the power grid network, thereby forming vulnerability distribution data corresponding to each functional area of the power grid network.
[0032] Preferably, the overall security status level of the power grid is determined based on the assessment results, specifically including:
[0033] The potential attack path set and vulnerability distribution data are globally quantified and fused to obtain the initial assessment results of the overall security situation of the power grid.
[0034] Multi-layer convolution calculation is performed on the initial assessment results of the overall security situation of the power grid to obtain the optimized assessment results of the overall security situation of the power grid.
[0035] Based on the results of the power grid global security situation optimization assessment, a multivariate situation level is assigned to the power grid network, thereby confirming the power grid global security situation level;
[0036] The overall security status level of the power grid is presented in a visual manner and sent to the terminal device so that power grid security management personnel can carry out real-time protection and decision-making.
[0037] Preferably, after obtaining the initial assessment results of the overall security situation of the power grid, the following are also included:
[0038] The initial assessment results of the overall security status of the power grid are reconstructed using spatial coordinates to obtain the reconstructed spatial coordinates of the power grid security status.
[0039] Based on the coordinates of the reconstructed spatial state of the power grid security situation, a coordinate risk linkage analysis is performed on the state status levels of each functional area of the power grid network to obtain state linkage data.
[0040] Based on the aforementioned situational linkage data, a multivariate joint modeling of the set of potential attack paths and vulnerability distribution data of the power grid is performed to obtain a multivariate power grid situational index.
[0041] The initial assessment results of the overall security situation of the power grid are optimized based on the multivariate power grid situation index, and then the optimized assessment results of the overall security situation of the power grid are obtained.
[0042] Secondly, this application provides a method for assessing the cybersecurity situation of power grid networks based on big data analysis, including the following steps:
[0043] Globally collect network security data in the power grid network, and aggregate and process the power grid network security situation based on the results of the global collection to form global power grid security data;
[0044] Feature extraction and deep semantic parsing are performed on the global security data of the power grid, and then the comprehensive feature vector of the power grid corresponding to the power grid network is determined based on the results of feature extraction and deep semantic parsing.
[0045] Based on the comprehensive feature vector of the power grid and combined with a pre-set historical attack case knowledge base, multi-level risk prediction is performed on the network security status of the power grid, thereby obtaining the set of potential attack paths and vulnerability distribution data corresponding to the power grid network.
[0046] Based on the potential attack path set and vulnerability distribution data, a quantitative assessment of the power grid network security situation is conducted. Then, based on the assessment results, the overall security situation level of the power grid is determined, and the overall security situation level of the power grid is sent to the terminal device so that the power grid security management personnel can carry out real-time protection and decision-making.
[0047] Thirdly, this application provides a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to execute any of the above-described power grid network security situation assessment systems based on big data analysis.
[0048] In summary, this application includes the following beneficial technical effects:
[0049] This application provides a power grid network security situation assessment system based on big data analysis. By extracting features and performing deep semantic analysis on global power grid security data, the system identifies the comprehensive feature vector of the power grid network. Based on this comprehensive feature vector and a pre-set historical attack case knowledge base, the system performs multi-level risk prediction of the power grid network security status, obtaining the set of potential attack paths and vulnerability distribution data corresponding to the power grid network. Based on these data, the system performs a quantitative assessment of the power grid network security situation, confirms the global security situation level of the power grid, and sends the global security situation level to terminal devices. This effectively reduces the occurrence of situations where a global security situation understanding cannot be formed due to a lack of prediction of potential attack paths and capture of dynamic changes in vulnerabilities, thus effectively improving the efficiency of power grid network security situation assessment. Attached Figure Description
[0050] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0051] Figure 1 This is a schematic diagram of a power grid network security situation assessment system based on big data analysis, according to an embodiment of this application.
[0052] Figure 2 This is a flowchart of a method for assessing the cybersecurity situation of a power grid based on big data analysis, as described in this application. Detailed Implementation
[0053] The following is in conjunction with the appendix Figure 1-2 This application will be described in further detail.
[0054] Example 1
[0055] This application discloses a power grid network security situation assessment system based on big data analysis.
[0056] Reference Figure 1 A power grid network security situation assessment system based on big data analysis includes a data acquisition module, a parsing and extraction module, a processing module, and an assessment module.
[0057] The data acquisition module is used to collect network security data in the power grid network globally, and to aggregate the network security status of the power grid based on the results of the global collection to form global power grid security data. Specifically, the network security data includes network communication data and power grid operation log information. The network communication data includes network communication nodes and traffic data corresponding to each network communication node, and the power grid operation log information includes equipment operation status data, intrusion detection alarm information, and user behavior data.
[0058] The parsing and extraction module is used to perform feature extraction and deep semantic parsing on the global security data of the power grid, and then determine the comprehensive feature vector of the power grid network based on the results of feature extraction and deep semantic parsing.
[0059] The processing module is used to perform multi-level risk prediction on the network security status of the power grid based on the comprehensive feature vector of the power grid and in combination with the preset historical attack case knowledge base, thereby obtaining the set of potential attack paths and vulnerability distribution data corresponding to the power grid network; wherein, the preset historical attack case knowledge base contains typical power grid attack cases and marks the attack information in the typical power grid attack cases, the attack information including attack path, vulnerability and degree of harm.
[0060] The assessment module is used to quantitatively assess the power grid network security situation based on the set of potential attack paths and vulnerability distribution data. Then, based on the assessment results, it confirms the global security situation level of the power grid and sends the global security situation level of the power grid to the terminal device so that the power grid security management personnel can carry out real-time protection and decision-making.
[0061] Specifically, in this embodiment, the data acquisition module collects power grid network security data through globally deployed acquisition devices. For example, network probes, flow analyzers, and log collectors are deployed at key nodes such as the power grid core dispatch center, substations, and distribution terminals to collect network communication data and power grid operation log information in real time. The collected network security data is aggregated and processed; outliers caused by sensor malfunctions are removed using data cleaning tools; time-series alignment algorithms are used to unify the timestamps of different devices; and the data is categorized and integrated according to "collection time - device number - data type" to form global power grid security data. Next, the parsing and extraction module performs feature extraction and deep semantic parsing on the global power grid security data: key features are extracted from network communication data using principal component analysis; the temporal correlation features of network communication data are captured through long short-term memory networks; semantic features are extracted from power grid operation log information using natural language processing technology; and the extracted communication features are fused with the log semantic features to form a comprehensive power grid feature vector. Finally, the processing module combines preset historical attack cases... The knowledge base conducts multi-level risk prediction: It matches the comprehensive feature vector of the power grid with the features of cases in a pre-set historical attack case knowledge base, selecting historical attack cases with high similarity as reference cases. Based on the attack graph algorithm and the power grid network topology, it predicts the set of potential attack paths that may exist in the current power grid, combined with the attack information of the reference cases. Simultaneously, it uses vulnerability scanning tools to detect vulnerabilities in each communication node of the power grid, and labels the vulnerability level of each communication node based on the prediction results, forming vulnerability distribution data. Finally, the evaluation module quantitatively evaluates the set of potential attack paths and the vulnerability distribution data: it constructs an evaluation index system, including attack path threat level, number of vulnerabilities, and vulnerability repair difficulty, and uses the analytic hierarchy process (AHP) to calculate the weight of each index. Based on the evaluation index system and the weights of each index, it confirms the initial score of the overall security posture of the power grid; it classifies the overall security posture level of the power grid according to the initial score; and it pushes the overall security posture level and corresponding risk details to terminal devices in real time, generating a visual report for managers to formulate protection strategies.
[0062] It should be noted that feature extraction and deep semantic parsing are performed on the global power grid security data, and then the comprehensive feature vector of the power grid corresponding to the power grid network is determined based on the results of feature extraction and deep semantic parsing. Specifically, this includes:
[0063] The communication topology of the global power grid security data is reconstructed to confirm the power grid communication node association map;
[0064] Based on the power grid communication node association map, the interaction patterns between each network communication node are extracted using time-series features, and then the network communication node interaction behavior data is confirmed based on the extraction results.
[0065] Deep semantic mining is performed on power grid operation log information to identify key behavioral sequences related to potential attacks, and then key feature data of power grid logs are identified based on the key behavioral sequences.
[0066] By fusing the network communication node interaction behavior data with the key feature data of the power grid log, the comprehensive feature vector of the power grid network can be determined.
[0067] Specifically, the communication topology is reconstructed as follows: Basic data of each communication node is extracted from network communication data, including IP address, MAC address, port connection relationships, and routing information. A network topology discovery algorithm based on the SNMP protocol is used, combined with the MIB library provided by the equipment manufacturer, to construct a physical topology map of the power grid communication nodes. Deep packet inspection technology is used to analyze the source / destination node information in the data packets to supplement the logical connections between nodes. The physical topology map is dynamically updated, marking newly added / offline nodes to form a power grid communication node association map. Temporal feature extraction is performed: Based on the power grid communication node association map, historical communication data of each communication node pair (e.g., "node A - node B") is selected. A sliding window method is used to extract data segments, and an LSTM neural network is used to extract the temporal features of node interactions. For example, temporal features include the periodicity of communication frequency, abrupt changes in data transmission volume, and the success rate of connection establishment. The extracted time-series features are classified by node pairs to form network communication node interaction behavior data. Log deep semantic mining is then performed: NLP technology is used to process power grid operation log information. First, the logs are structurally split using regular expressions to remove meaningless characters. Then, the log text is semantically encoded to identify key behavioral sequences related to potential attacks. By constructing an attack behavior dictionary, the behaviors in the logs are matched and labeled, and logs containing attack keywords or abnormal behavior sequences are filtered out. The device ID, behavior type, and occurrence time are extracted to form key feature data of the power grid logs. Feature fusion: The network communication node interaction behavior data and the key feature data of the power grid logs are spatially and temporally correlated. For example, matching is performed by node ID and timestamp to ensure that the communication features of the same node and the same time period correspond to the log features. A feature concatenation algorithm is used to merge the feature vectors of the two types of data into a comprehensive power grid feature vector.
[0068] By employing the above technical solution, and through a full-process processing of topology reconstruction, temporal extraction, semantic mining, and feature fusion, the problems of neglecting structural relationships and losing semantic information in traditional feature extraction are solved. Communication topology reconstruction ensures that feature extraction is no longer isolated to node locations, avoiding the situation where the same communication feature is treated equally in core nodes and edge nodes with different risks. Temporal feature extraction captures the dynamic changes in communication data, enabling early identification of potential threats compared to traditional static features. Log semantic mining overcomes the limitations of traditional log analysis, which only matches keywords and ignores behavioral sequences, enabling the identification of covert attack behaviors and improving the accuracy of key behavioral sequences. Feature fusion combines communication and log features, avoiding the feature bias caused by using only single data points, and providing high-precision feature support for subsequent risk prediction.
[0069] It should be noted that after identifying the key feature data of the power grid log based on the key behavior sequence, the process also includes:
[0070] Sequence analysis is performed on user behavior data in the power grid operation log information to identify abnormal behavior data, and in-depth analysis is performed on the correlation between the abnormal behavior data and the equipment operation status data in the power grid operation log information to obtain the correlation characteristics between user behavior and equipment status.
[0071] Based on the correlation characteristics between user behavior and device status, and combined with a preset historical attack case knowledge base, behavior pattern matching is performed to identify potential attack intent data.
[0072] Based on the potential attack intent data, key feature data of the power grid logs are labeled to form a set of potential behavioral features.
[0073] Specifically, after confirming the key characteristic data of the power grid logs, it is necessary to further explore potential attack intentions. The specific steps are as follows: User behavior sequence analysis: Extract the operation sequence of a single user from the user behavior data of the power grid operation logs, and perform anomaly detection on the operation sequence. For example, first, construct a normal operation sequence model, calculate the deviation between the operation sequence and the normal operation sequence model. If the deviation exceeds a preset threshold, it is judged as abnormal behavior data. Abnormal behavior includes, but is not limited to, login outside working hours, cross-regional operation, high-frequency repetitive operation, etc. Record the abnormal user ID, operation sequence, occurrence time and involved equipment. User behavior and equipment status association analysis: Perform time association between abnormal behavior data and equipment operating status data in the power grid operation logs (such as equipment status changes within 10 minutes after abnormal login). Use association rule mining algorithms to analyze the correlation between the two. For example, after the behavior of "abnormal login → parameter modification", if the support of the equipment's "abnormal fluctuation of voltage monitoring value" reaches 80% and the confidence reaches 90%, then it is judged that the user's behavior is abnormal. Abnormal behavior is strongly correlated with abnormal equipment status. This strong correlation is extracted to form a correlation feature between user behavior and equipment status. Historical attack case pattern matching is performed: a pre-defined historical attack case knowledge base is invoked, where each case contains an attack behavior sequence, equipment impact, and attack intent tag. The correlation feature between user behavior and equipment status is matched with the attack behavior sequence-equipment impact of cases in the historical attack case knowledge base, and cases with a similarity ≥70% are selected. Based on the attack intent tag of the matched cases, the potential attack intent of the current abnormal behavior is inferred, forming potential attack intent data. Potential behavior feature annotation is performed: the potential attack intent data is correlated with key feature data from the power grid logs, and the key log features are categorized and annotated according to intent type. For example, interference scheduling intent corresponds to log features such as parameter modification and scheduling command interception, while data theft intent corresponds to log features such as log download and database access. The annotated features form a potential behavior feature set for subsequent risk prediction.
[0074] By employing the above technical solution, and through in-depth analysis of the correlation between user behavior and device status, as well as potential attack intentions, this approach solves the problem that traditional log analysis only focuses on surface features and cannot pinpoint the attack objective. Traditional methods can only identify abnormal logins but cannot determine the login intent. This step, however, by correlating behavioral sequence analysis with device status, can distinguish between normal misoperations and malicious behavior, thereby improving the accuracy of abnormal behavior identification. Historical attack case pattern matching provides a reliable basis for inferring attack intent, avoiding the limitations of traditional methods that rely on human experience to determine intent. The formation of a potential behavioral feature set allows subsequent risk prediction to move beyond blind analysis and instead focus on attack intent, significantly improving prediction efficiency and targeting, and providing intent-level decision-making basis for subsequent precise protection.
[0075] It should be noted that the data obtained includes the set of potential attack paths and vulnerability distribution data corresponding to the power grid network, specifically:
[0076] Based on the comprehensive feature vector and potential behavioral feature set of the power grid network, the potential attack paths between communication nodes of the power grid network are simulated and predicted, thereby confirming the set of potential attack paths.
[0077] A risk assessment is performed on the set of potential attack paths to identify the vulnerability distribution data corresponding to each functional area of the power grid network.
[0078] Specifically, the processing module obtains the potential attack path set and vulnerability distribution data in the following steps: Potential attack path simulation and prediction: Based on the power grid communication node association graph, the power grid comprehensive feature vector and potential behavioral feature set are used as inputs, and an attack graph algorithm is used to construct an attack path model; First, the attack source and attack target are determined, and the attack target is determined according to the attack intent; Then, all possible paths in the power grid communication node association graph are traversed, and the feasible attack paths are selected by combining the abnormal features in the power grid comprehensive feature vector and the attack patterns in the potential behavioral features; Threat assessment is performed on each path, and finally, paths with a threat level ≥ 60% are retained to form a potential attack path set. Each path in the potential attack path set includes attack source-intermediate node-target node-vulnerability type-threat level. Potential attack path partition risk assessment: For example, The power grid network is divided into four functional areas: core dispatch area, substation area, distribution area, and edge access area. For each path in the potential attack path set, the functional area it involves is labeled. For each area, the number of attack paths passing through it, the average threat level of each path, and the number of vulnerabilities in the nodes within the area are statistically analyzed (obtained from vulnerability scanning tools). A weighted summation algorithm is used to calculate the risk value of each area; for example, risk value = number of paths × 0.3 + average threat level × 0.5 + number of vulnerabilities × 0.2. Based on the risk value, the areas are classified into vulnerability levels (high: risk value ≥ 80, medium: risk value between 50 and 80, low: risk value < 50), and the main vulnerabilities in each area are labeled. The vulnerability levels, vulnerabilities, and risk values of each area are integrated to form vulnerability distribution data corresponding to each functional area of the power grid network, stored in the form of tables and heat maps.
[0079] By adopting the above technical solution, the problem of traditional risk assessment being unable to locate specific threat paths and vulnerable areas is solved through accurate prediction of potential attack paths and regional risk assessment. Traditional methods can only determine that there are security risks in the power grid, but cannot explain which paths or areas the risks originate from. However, the attack path prediction in this step can clearly show how an attack travels from its source to its target, helping managers to deploy targeted protection. Functional area division makes risk assessment more targeted, avoiding the waste of resources caused by a unified assessment of the entire area. Vulnerability distribution data marks the specific vulnerability points in each area, enabling maintenance personnel to directly locate the problems that need to be repaired. In addition, combined with the path prediction of attack intent, the path with the greatest harm can be identified first, and managers can sort and deal with them according to their threat level, avoiding the situation of dealing with low-threat paths first and delaying the handling of high-threat paths, thereby effectively improving the efficiency of risk handling.
[0080] It should be noted that a risk assessment is performed on the set of potential attack paths to identify the vulnerability distribution data corresponding to each functional area of the power grid network. Specifically, this includes:
[0081] The potential attack path set is divided into network topology layers to obtain security risk distribution data between different layers;
[0082] Based on the security risk distribution data between different levels, a differential analysis of the vulnerability indicators of each functional area is conducted to identify the risk differences between functional areas.
[0083] Time series assessment of risk differences among the functional areas is performed to identify vulnerability change trends in each functional area of the power grid network at different time periods.
[0084] Based on the vulnerability change trend data, risk warning classification is carried out for each functional area of the power grid network, thereby forming vulnerability distribution data corresponding to each functional area of the power grid network.
[0085] Specifically, the steps for partitioning the potential attack path set to obtain vulnerability distribution data are as follows: Network topology hierarchical division: Based on the power grid communication node association graph, the power grid is divided into three layers according to the network architecture: core layer, aggregation layer, and access layer; Analyze the layers traversed by each path in the potential attack path set (e.g., "access layer → aggregation layer → core layer"), and count the number of nodes stopped at each layer, the communication links used, and the types of vulnerabilities triggered for each path; Use the analytic hierarchy process (AHP) to calculate the security risk weight of each layer (core layer weight 0.5, aggregation layer 0.3, access layer 0.2), and combine this with the path threat level to obtain the security risk distribution data between different layers (e.g., core layer risk value 85, aggregation layer 60, ...). Access Layer 45), Vulnerability Indicator Differentiation Analysis: A vulnerability assessment index system is constructed for the four functional areas of the power grid (core dispatch area, substation area, distribution area, and edge access area), including vulnerability density, vulnerability severity, attack path frequency, and vulnerability remediation rate. The entropy weight method is used to calculate the objective weights of each index, such as vulnerability severity weight 0.4, attack path frequency weight 0.3, vulnerability density weight 0.2, and vulnerability remediation rate weight 0.1. The indicators for each area are quantitatively scored (e.g., core dispatch area: vulnerability severity 9 points, attack path frequency 15 times, remediation rate 60%), and the weighted sum is used to obtain the regional risk value. The risk values of different areas are compared (e.g., core dispatch area 85, substation area 65, distribution area 40). Edge access area 35), forming risk difference data between functional areas, marking the areas with the highest and lowest risks and the reasons for the differences, time series assessment: selecting vulnerability assessment data of the past 7 days, constructing a time series of risk values for each functional area (e.g., 7-day risk values for the core dispatch area: 85→82→80→78→75→73→70); using trend fitting algorithms (e.g., linear regression) to analyze the changing trend of risk values, calculating the trend slope, and identifying trend anomalies, combined with the analysis of the causes of security events during that period; forming vulnerability change trend data for each functional area of the power grid network at different time periods, risk warning classification: based on the vulnerability change trend data and the current regional risk value, setting warning classification rules, for example, when A "red alert" is issued when the current risk value is high (≥80) and trending upward; an "orange alert" is issued when the current risk value is medium (50-80) and trending upward, or when the current risk value is high and trending stable; a "yellow alert" is issued when the current risk value is medium and trending stable, or when the current risk value is low (<50) and trending upward; and a "blue alert" is issued when the current risk value is low and trending stable. Regional risk values and vulnerability change trend data for the four functional areas are acquired separately. Based on the aforementioned alert classification rules, the alert level for each of the four functional areas is determined. The alert levels, regional risk values, and vulnerability change trend data for the four functional areas are then integrated to form vulnerability distribution data for each functional area of the power grid network, presented as a visual heat map.
[0086] By adopting the above technical solution, a refined assessment through hierarchical division, indicator analysis, time-series evaluation, and early warning classification solves the problems of static, undifferentiated, and trendless traditional zonal assessments. Network topology hierarchical division allows risk assessment to focus on the core layer, avoiding resource misallocation caused by treating the core and access layers equally. Differential vulnerability indicator analysis uses multi-dimensional indicators and objective weights, avoiding the one-sidedness of traditional single-indicator assessments. Time-series evaluation captures the dynamic changes in vulnerabilities, enabling early detection of risk escalation trends compared to traditional static assessments. Risk early warning classification makes vulnerability distribution data more decision-oriented, allowing managers to allocate resources according to early warning levels, avoiding inefficiency caused by indiscriminate protection, and shifting power grid safety management from passive response to proactive early warning.
[0087] It should be noted that the overall security status level of the power grid was determined based on the assessment results, specifically including:
[0088] The potential attack path set and vulnerability distribution data are globally quantified and fused to obtain the initial assessment results of the overall security situation of the power grid.
[0089] Multi-layer convolution calculation is performed on the initial assessment results of the overall security situation of the power grid to obtain the optimized assessment results of the overall security situation of the power grid.
[0090] Based on the results of the power grid global security situation optimization assessment, a multivariate situation level is assigned to the power grid network, thereby confirming the power grid global security situation level;
[0091] The overall security status level of the power grid is presented in a visual manner and sent to the terminal device so that power grid security management personnel can carry out real-time protection and decision-making.
[0092] Specifically, the assessment module confirms the overall security status level of the power grid through the following steps: Global quantitative fusion: Obtain the set of potential attack paths (including the threat level of each path) and vulnerability distribution data (including risk values and warning levels for each region). Classify the threat levels of potential attack paths by functional region and weight them with the risk values of the corresponding regions. For example, if the total threat level of paths in the core dispatch area is 90 and the regional risk value is 70, the fused score = 90 × 0.6 + 70 × 0.4 = 82. Take the average of the fused scores for the four functional regions to obtain the initial assessment result of the overall security status of the power grid. Multi-layer... Convolutional computation: The initial global security situation assessment results are combined with the spatial topology data of the power grid network to construct a three-dimensional security situation matrix. A 3×3×3 three-dimensional convolutional kernel is used to perform convolution operations on the three-dimensional security situation matrix. The weights of the convolutional kernels are set according to the "core area - core node - high-risk indicator" (e.g., core area node weight 0.5, edge area node weight 0.1). The convolution operation smooths local outliers and strengthens the influence of core areas and high-risk indicators. After convolution, the optimized assessment result of the global power grid security situation is obtained (e.g., initial 58.25, convolutional 62.1), and the multivariate situation level is obtained. Assignments: Construct a multivariate situational awareness assessment system, with multiple variables including global optimization assessment score, number of high-risk attack paths, and number of red / orange warning areas; set level classification thresholds, for example: a global optimization assessment score ≥80 or ≥5 high-risk attack paths or ≥3 red / orange warning areas is level 5; a global optimization assessment score 60-79 or 3-4 high-risk paths or 2 red / orange warning areas is level 4; a global optimization assessment score 40-59 or 1-2 high-risk paths or 1 red / orange warning area is level 3; a global optimization assessment score 20-39 with no high-risk paths or red / orange warning areas is level 3. Level 2 is defined as having ≤1 domain, and Level 1 is defined as having a global optimization assessment score <20 and no high-risk paths or red / orange warning areas. The current multivariate data of the power grid (e.g., a global optimization assessment score of 62.1, 2 high-risk paths, and 1 red / orange warning area) are substituted into the threshold to determine the overall security status level of the power grid. Visualization and terminal push are then implemented: data visualization tools are used to present the overall security status level in multiple formats, and the visualization results and detailed assessment reports are sent to the management terminal. Upon receiving the data, the terminal automatically pops up a notification, allowing management personnel to click to view details and recording the push time and read status, thus forming a closed-loop management system.
[0093] By adopting the above technical solution, the global quantitative integration of path and regional risks avoids the one-sidedness of traditional assessments based on a single dimension. Multi-layer convolutional computation eliminates the interference of local anomalies on the global assessment. The multi-variable situational classification breaks through the limitations of traditional single-score grading. Combined with path, early warning, etc., the classification is more scientific. Visual presentation and real-time push transform the global situation from abstract numbers into intuitive charts. Managers can quickly grasp the global risks without professional data analysis capabilities, thereby improving decision response time.
[0094] It should be noted that after obtaining the initial assessment results of the overall security situation of the power grid, the following are also included:
[0095] The initial assessment results of the overall security status of the power grid are reconstructed using spatial coordinates to obtain the reconstructed spatial coordinates of the power grid security status.
[0096] Based on the coordinates of the reconstructed spatial state of the power grid security situation, a coordinate risk linkage analysis is performed on the state status levels of each functional area of the power grid network to obtain state linkage data.
[0097] Based on the aforementioned situational linkage data, a multivariate joint modeling of the set of potential attack paths and vulnerability distribution data of the power grid is performed to obtain a multivariate power grid situational index.
[0098] The initial assessment results of the overall security situation of the power grid are optimized based on the multivariate power grid situation index, and then the optimized assessment results of the overall security situation of the power grid are obtained.
[0099] Specifically, the steps for optimizing the initial assessment results of the overall power grid security situation are as follows: Spatial coordinate reconstruction: Obtain geographic information data and network topology data of the power grid network; construct a power grid spatial coordinate system by combining GIS maps and 3D modeling technology; map each functional area and communication node of the power grid to the power grid spatial coordinate system, and label the geographic coordinates and network coordinates of each node; associate the regional risk values and node risk values in the initial assessment results of the overall power grid security situation according to spatial coordinates to form the spatial reconstruction coordinates of the power grid security situation. For example, each coordinate point (X, Y, Z) corresponds to a node or region, and the Z-axis value is the risk value (e.g., node A coordinates (100, 200, 80)). (Z=80 represents a risk value of 80); spatial interpolation algorithms are used to fill in the blank areas between coordinate points, forming a continuous spatial risk distribution surface, which intuitively displays the geographical distribution of risks. Situational linkage analysis: Based on the spatial reconstruction coordinate analysis of power grid security situation, the situational linkage relationship between different functional areas and nodes is analyzed. For example, the correlation of risk values in adjacent areas is calculated to identify risk transmission paths; nodes / areas with strong spatial risk linkages are divided into risk communities, and for each risk community, the risk propagation speed and impact range within the risk community are calculated; the above linkage relationships, propagation speed, and impact range are integrated to form situational linkage data. Multivariate joint modeling: Based on the situational linkage data, potential... A Bayesian network model is constructed using attack path set and vulnerability distribution data as input variables. The nodes of the Bayesian network model include risk communities, attack path threat levels, regional warning levels, and global risk values. Edges between nodes represent causal relationships (e.g., "high attack path threat level → high risk value in risk community → high global risk value"). The model is trained using historical security data to determine the conditional probabilities between nodes. Multivariate data from the current power grid are input into the model, and the posterior probability distribution of the global risk value is calculated using Bayesian inference (e.g., a 75% probability of a global risk value of 60-70, and a 20% probability of 70-80). The midpoint of the risk value interval with the highest probability is taken as the model output value (e.g., the 60-70 interval). (Midpoint 65) to obtain the power grid multivariate situation index, and optimize the evaluation results: compare the power grid multivariate situation index with the initial evaluation results of the power grid global security situation. If the deviation between the two is ≤5 (e.g., initial 58.25, index 65, deviation 6.75>5), then the multivariate situation index is used as the basis, and the regional risk details of the initial evaluation results are combined for correction. For example, if the multivariate situation index is 65 and the risk value of the core dispatch area in the initial evaluation is 82, the high-risk details of the core dispatch area need to be retained, and the global index is adjusted to 68. If the deviation is ≤5, then the multivariate situation index is directly used as the optimization result. Finally, the optimized evaluation result of the power grid global security situation is obtained, and an optimization report is generated. Example
[0100] This application also discloses a method for assessing the cybersecurity situation of power grid networks based on big data analysis.
[0101] Reference Figure 2 A method for assessing the cybersecurity situation of power grid networks based on big data analysis includes the following steps:
[0102] Globally collect network security data in the power grid network, and aggregate and process the power grid network security situation based on the results of the global collection to form global power grid security data;
[0103] Feature extraction and deep semantic parsing are performed on the global security data of the power grid, and then the comprehensive feature vector of the power grid corresponding to the power grid network is determined based on the results of feature extraction and deep semantic parsing.
[0104] Based on the comprehensive feature vector of the power grid and combined with a pre-set historical attack case knowledge base, multi-level risk prediction is performed on the network security status of the power grid, thereby obtaining the set of potential attack paths and vulnerability distribution data corresponding to the power grid network.
[0105] Based on the potential attack path set and vulnerability distribution data, a quantitative assessment of the power grid network security situation is conducted. Then, based on the assessment results, the overall security situation level of the power grid is determined, and the overall security situation level of the power grid is sent to the terminal device so that the power grid security management personnel can carry out real-time protection and decision-making.
[0106] The above content is merely an example and illustration of the concept of the present invention. Those skilled in the art can make various modifications or additions to the specific embodiments described or use similar methods to replace them, as long as they do not deviate from the concept of the invention, they should all fall within the protection scope of the present invention.
[0107] In the description of this specification, references to terms such as "an embodiment," "example," "specific example," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.
[0108] The preferred embodiments of the present invention disclosed above are merely illustrative of the invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the invention to any specific implementation. Clearly, many modifications and variations can be made based on the content of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to better understand and utilize the invention.
Claims
1. A power grid network security situation assessment system based on big data analysis, characterized in that, include: The data acquisition module is used to collect network security data in the power grid network globally, and to aggregate and process the network security status of the power grid based on the results of the global collection to form global security data of the power grid. The parsing and extraction module is used to perform feature extraction and deep semantic parsing on the global security data of the power grid, and then determine the comprehensive feature vector of the power grid network based on the results of feature extraction and deep semantic parsing. The processing module is used to perform multi-level risk prediction on the network security status of the power grid based on the comprehensive feature vector of the power grid and in combination with a preset historical attack case knowledge base, thereby obtaining the set of potential attack paths and vulnerability distribution data corresponding to the power grid network; wherein, the preset historical attack case knowledge base contains typical power grid attack cases and is marked with attack information in the typical power grid attack cases, the attack information including attack path, vulnerability and degree of harm. Obtain the set of potential attack paths and vulnerability distribution data corresponding to the power grid network, specifically including: Based on the comprehensive feature vector and potential behavioral feature set of the power grid network, the potential attack paths between communication nodes of the power grid network are simulated and predicted, thereby confirming the set of potential attack paths. The potential attack path set is partitioned for risk assessment, thereby confirming the vulnerability distribution data corresponding to each functional area of the power grid network; A risk assessment is performed on the set of potential attack paths to identify the vulnerability distribution data for each functional area of the power grid network. Specifically, this includes: The potential attack path set is divided into network topology layers to obtain security risk distribution data between different layers; Based on the security risk distribution data between different levels, a differential analysis of the vulnerability indicators of each functional area is conducted to identify the risk differences between functional areas. Time series assessment of risk differences among the functional areas is performed to identify vulnerability change trends in each functional area of the power grid network at different time periods. Based on the vulnerability change trend data, risk warning classification is carried out for each functional area of the power grid network, thereby forming vulnerability distribution data corresponding to each functional area of the power grid network. The assessment module is used to perform a quantitative assessment of the power grid network security situation based on the set of potential attack paths and vulnerability distribution data. Then, based on the assessment results, it confirms the global security situation level of the power grid and sends the global security situation level of the power grid to the terminal device so that the power grid security management personnel can carry out real-time protection and decision-making.
2. The power grid network security situation assessment system based on big data analysis according to claim 1, characterized in that, The network security data includes network communication data and power grid operation log information; the network communication data includes network communication nodes and traffic data corresponding to each network communication node, and the power grid operation log information includes equipment operation status data, intrusion detection alarm information, and user behavior data.
3. The power grid network security situation assessment system based on big data analysis according to claim 2, characterized in that, Feature extraction and deep semantic parsing are performed on the global security data of the power grid. Based on the results of feature extraction and deep semantic parsing, the comprehensive feature vector of the power grid network is determined, specifically including: The communication topology of the global power grid security data is reconstructed to confirm the power grid communication node association map; Based on the power grid communication node association map, the interaction patterns between each network communication node are extracted using time-series features, and then the network communication node interaction behavior data is confirmed based on the extraction results. Deep semantic mining is performed on power grid operation log information to identify key behavioral sequences related to potential attacks, and then key feature data of power grid logs are identified based on the key behavioral sequences. By fusing the network communication node interaction behavior data with the key feature data of the power grid log, the comprehensive feature vector of the power grid network can be determined.
4. The power grid network security situation assessment system based on big data analysis according to claim 3, characterized in that, After identifying key feature data from the power grid logs based on the key behavioral sequences, the process also includes: Sequence analysis is performed on user behavior data in the power grid operation log information to identify abnormal behavior data, and in-depth analysis is performed on the correlation between the abnormal behavior data and the equipment operation status data in the power grid operation log information to obtain the correlation characteristics between user behavior and equipment status. Based on the correlation characteristics between user behavior and device status, and combined with a preset historical attack case knowledge base, behavior pattern matching is performed to identify potential attack intent data. Based on the potential attack intent data, key feature data of the power grid logs are labeled to form a set of potential behavioral features.
5. The power grid network security situation assessment system based on big data analysis according to claim 1, characterized in that, Based on the assessment results, the overall security status level of the power grid was determined, specifically including: The potential attack path set and vulnerability distribution data are globally quantified and fused to obtain the initial assessment results of the overall security situation of the power grid. Multi-layer convolution calculation is performed on the initial assessment results of the overall security situation of the power grid to obtain the optimized assessment results of the overall security situation of the power grid. Based on the results of the power grid global security situation optimization assessment, a multivariate situation level is assigned to the power grid network, thereby confirming the power grid global security situation level; The overall security status level of the power grid is presented in a visual manner and sent to the terminal device so that power grid security management personnel can carry out real-time protection and decision-making.
6. The power grid network security situation assessment system based on big data analysis according to claim 5, characterized in that, After obtaining the initial assessment results of the overall security situation of the power grid, the specific steps also include: The initial assessment results of the overall security status of the power grid are reconstructed using spatial coordinates to obtain the reconstructed spatial coordinates of the power grid security status. Based on the coordinates of the reconstructed spatial state of the power grid security situation, a coordinate risk linkage analysis is performed on the state status levels of each functional area of the power grid network to obtain state linkage data. Based on the aforementioned situational linkage data, a multivariate joint modeling of the set of potential attack paths and vulnerability distribution data of the power grid is performed to obtain a multivariate power grid situational index. The initial assessment results of the overall security situation of the power grid are optimized based on the multivariate power grid situation index, and then the optimized assessment results of the overall security situation of the power grid are obtained.
7. A method for assessing the cybersecurity situation of a power grid based on big data analysis, applied to the power grid cybersecurity situation assessment system based on big data analysis as described in any one of claims 1-6, characterized in that, Includes the following steps: Globally collect network security data in the power grid network, and aggregate and process the power grid network security situation based on the results of the global collection to form global power grid security data; Feature extraction and deep semantic parsing are performed on the global security data of the power grid, and then the comprehensive feature vector of the power grid corresponding to the power grid network is determined based on the results of feature extraction and deep semantic parsing. Based on the comprehensive feature vector of the power grid and combined with the preset historical attack case knowledge base, multi-level risk prediction is performed on the network security status of the power grid, thereby obtaining the set of potential attack paths and vulnerability distribution data corresponding to the power grid network; wherein, the preset historical attack case knowledge base contains typical power grid attack cases and marks the attack information in the typical power grid attack cases, the attack information including attack path, vulnerability and degree of harm. Obtain the set of potential attack paths and vulnerability distribution data corresponding to the power grid network, specifically including: Based on the comprehensive feature vector and potential behavioral feature set of the power grid network, the potential attack paths between communication nodes of the power grid network are simulated and predicted, thereby confirming the set of potential attack paths. The potential attack path set is partitioned for risk assessment, thereby confirming the vulnerability distribution data corresponding to each functional area of the power grid network; A risk assessment is performed on the set of potential attack paths to identify the vulnerability distribution data for each functional area of the power grid network. Specifically, this includes: The potential attack path set is divided into network topology layers to obtain security risk distribution data between different layers; Based on the security risk distribution data between different levels, a differential analysis of the vulnerability indicators of each functional area is conducted to identify the risk differences between functional areas. Time series assessment of risk differences among the functional areas is performed to identify vulnerability change trends in each functional area of the power grid network at different time periods. Based on the vulnerability change trend data, risk warning classification is carried out for each functional area of the power grid network, thereby forming vulnerability distribution data corresponding to each functional area of the power grid network. Based on the potential attack path set and vulnerability distribution data, a quantitative assessment of the power grid network security situation is conducted. Then, based on the assessment results, the overall security situation level of the power grid is determined, and the overall security situation level of the power grid is sent to the terminal device so that the power grid security management personnel can carry out real-time protection and decision-making.
8. A computer-readable storage medium, characterized in that: The system stores instructions that, when executed on a computer, cause the computer to perform a power grid network security situation assessment system based on big data analysis as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Regional safety state dynamic assessment management and control method and system
CN115630848A
Network security monitoring method and system for hierarchical distribution collaborative supervision system
CN116527380A