Edge side power grid situation awareness analysis model and method

By using the edge-side power grid situational awareness analysis model, the problems of data source, reliability, and readability in power grid situational awareness have been solved, enabling a comprehensive assessment and prediction of power grid security status, avoiding large-scale accidents, and improving the power grid's security management capabilities.

CN120933898APending Publication Date: 2025-11-11SHENZHEN MINGSHENG STARLIGHT TECH DEV CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510840931.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-23
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Existing technologies are not yet able to effectively conduct situational awareness in the power grid, and cannot fully consider the security threats under the current state of the network in the smart grid. This makes it difficult to conduct accurate situational assessment and prediction, which may lead to large-scale power grid safety and operation accidents.

Method used

An edge-side power grid situational awareness analysis model is adopted, including a network security situational awareness system, a power grid situational awareness system, and a power grid network assessment system. Data issues are addressed by considering data source, credibility, and readability. Situational identification and prediction are performed using technologies such as feature matching, behavior analysis, and machine learning. Combined with data calibration, format standardization, and response and early warning mechanisms, a comprehensive assessment and prediction of the power grid security situation is achieved.

Benefits of technology

It enables accurate situational assessment of the current state of the network in the smart grid, avoids large-scale power grid security and operational accidents, improves the security monitoring and intrusion prevention capabilities of the power information network, and supports proactive prevention in the power grid.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The invention discloses an edge side power grid situation awareness analysis model and method, and relates to the field of power grid situation awareness analysis. The system comprises a network security situation awareness system, a power grid situation awareness system, a power grid network evaluation system and a power grid situation awareness application system. The method has the beneficial effects that the model can comprehensively consider the security threat faced by the network in the current state in the smart power grid, provides accurate situation assessment for the current network state, lays a good foundation for making accurate situation prediction, and strives to avoid the occurrence of large-scale power grid security and operation accidents. The above doubts have positive significance for the development of current complex, integrated and highly-new smart power grids.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power grid situational awareness analysis, and specifically to an edge-side power grid situational awareness analysis model and method. Background Technology

[0002] Situational awareness is a dynamic and holistic ability to understand security risks based on the environment. It is a way to improve the ability to discover, identify, understand, analyze, and respond to security threats from a global perspective, based on security big data. Ultimately, it is for decision-making and action, and is the implementation of security capabilities.

[0003] The power grid represents the mainstream development trend of the future power grid. The future power grid can be viewed as a massive, complex network where information networks and physical (electrical) networks are interdependent. However, with the integration of numerous public networks into the power grid, many new challenges arise for its stable operation, such as hacker attacks, virus intrusions, and employee misoperation or malicious actions. As a crucial technological means to monitor the power grid's operational trajectory, situational awareness technology is particularly important in the power grid. It can collect, understand, and predict various factors related to changes in power grid operation over a wide spatial and temporal area, striving to accurately and effectively grasp the power grid's security situation, thus shifting power grid security management from passive repair to proactive prevention. While situational awareness technology has relatively mature applications in computer networks, transportation, and the military, its application in the power grid is still in its early stages. Summary of the Invention

[0004] The purpose of this invention is to address the shortcomings and defects of existing technologies by providing an edge-side power grid situational awareness analysis model and method. This model comprehensively considers the security threats faced by the smart grid network under its current state, providing an accurate situational assessment of the current network status. This lays a solid foundation for accurate situational prediction and aims to avoid large-scale power grid safety and operational accidents. These advancements will undoubtedly have a positive impact on the development of today's increasingly complex, integrated, and technologically advanced smart grids.

[0005] To achieve the above objectives, the present invention adopts the following technical solution: an edge-side power grid situational awareness analysis model and method, which includes a network security situational awareness system, a power grid situational awareness system, a power grid network assessment system, and a power grid situational awareness application system.

[0006] More specifically, the network security situation awareness system can solve the problems of data source, data credibility, and data readability required for situation awareness.

[0007] More specifically, the network security situation awareness system has the following functions: identification and confirmation of the current situation; assessment of potential impacts; analysis of attacker intent; accuracy of the situation awareness data and decisions made; and situation prediction.

[0008] More specifically, the network security situation awareness system also includes functions such as data calibration, data format unification, data simplification, and response and early warning.

[0009] More specifically, the power grid situation awareness system can solve the problems of "what is happening," "why it is happening and how it is happening," and "what will happen," namely, situation element extraction, real-time situation understanding, and future situation prediction.

[0010] More specifically, the situation element extraction is the most basic and fundamental step in situation awareness. Its purpose is to acquire information from the perceived object, especially important information elements. With the advancement of power grid technology, the scope of situation element acquisition has been continuously expanded. Currently, the types of information that can be acquired mainly include topology, real-time operation information, equipment status information, power grid stability / dynamic data information, power grid transient fault information, and power grid operating environment information.

[0011] More specifically, the real-time situational understanding involves analyzing and processing the extracted important information and elements, conducting situational assessments, and forming a comprehensive evaluation of the power grid's security status through integrated analysis and judgment.

[0012] More specifically, the future situation prediction is based on the perception, understanding, evaluation, and comprehensive analysis of important information and elements of the situation. The development and change patterns of the network situation in the power grid are summarized and reasoned, thereby predicting the future situation. The prediction results will be submitted to the decision-making and execution stage for the regulation and control of the power grid.

[0013] More specifically, the power grid network assessment system, based on an understanding of computer network situational awareness, recognizes that when a power grid connects to numerous public networks, it faces various security threats related to equipment, networks, and data. To enhance the security monitoring and intrusion prevention capabilities of the power information network, a series of analyses and processing of the collected information are necessary. This necessitates a situational assessment of the network information within the power grid. Power grid situational assessment can be understood as, in a large-scale, highly complex network environment, based on the fusion and acquisition of various types of network monitoring data from the power grid and simple processing, using domain knowledge and historical data, and aided by certain mathematical tools and models, through analysis and reasoning, providing reasonable explanations for various possible network attacks, and finally assessing the current situation. The assessment data is then used for situational prediction to prevent large-scale security incidents.

[0014] The beneficial effects of adopting the above technical solution are as follows: This model can comprehensively consider the security threats faced by the network in the current state of the smart grid, providing an accurate situation assessment of the current network state, laying a solid foundation for accurate situation prediction, and striving to avoid large-scale power grid safety and operational accidents. These will undoubtedly have a positive impact on the development of today's complex, integrated, and technologically advanced smart grids. Detailed Implementation

[0015] The technical solution adopted in this specific implementation is as follows: it includes a network security situation awareness system, a power grid situation awareness system, a power grid network assessment system, and a power grid situation awareness application system.

[0016] The network security situational awareness system addresses the issues of data source, data credibility, and data readability required for situational awareness. In this application, data sources include various channels such as network device logs (including firewalls, intrusion detection systems, etc.), server system logs, and application runtime logs. Dedicated sensors can also be deployed at key network nodes to collect network traffic data and user behavior data. Credibility is addressed by employing data verification mechanisms, such as authenticating data sources, to ensure the legitimacy of the data origin. Simultaneously, data integrity verification algorithms, such as hash functions, are used to check whether data has been tampered with during transmission. For conflicting data, credibility can be improved through multi-source data comparison and fusion, such as combining sensor data from multiple locations to determine if a network attack actually exists. Readability is addressed by formatting the collected data according to a unified data model. For example, standardized XML or JSON formats can be used to encapsulate different types of data, adding clear semantic tags to each data field for easier subsequent processing and understanding.

[0017] The network security situation awareness system has the following functions:

[0018] The identification and confirmation of the current situation is based on feature matching and behavioral analysis. A feature database of known network attacks and abnormal behaviors is established, and the collected data is compared with this database. Simultaneously, behavioral patterns such as network traffic and system resource usage are analyzed to identify whether the current network status is normal, subject to minor interference, or under severe attack. The process is as follows: First, the data acquisition module collects various network data. Then, the analysis engine matches this data with predefined attack features and normal behavior models. For newly emerging unknown patterns, cluster analysis can be performed using machine learning algorithms to determine if they are abnormal. If an attack feature or abnormal behavior pattern is matched, a security threat is confirmed to exist in the current network, and the type and severity of the threat are further determined.

[0019] The potential impact assessment is based on vulnerability databases and network topology. It involves understanding the vulnerability status of various devices and systems within the network, and analyzing the potential spread paths and scope of the attack, considering the type and location of the current attack. Simultaneously, the importance and relevance of business operations are taken into account to assess the impact on business continuity.

[0020] The process is as follows: First, query the vulnerability management system to obtain vulnerability information for network devices and systems. Second, determine the attack source and possible propagation direction based on the network topology diagram. Third, for critical business systems, analyze their correlation with the attacked parts, and calculate potential impact indicators such as business interruption time and data loss by simulating attack propagation and combining it with a business impact weighting model.

[0021] Attacker intent analysis starts with the seriality and targeting of attack behaviors. It analyzes the attacker's attack steps, such as port scanning followed by vulnerability exploitation attempts, to infer whether their goal is to acquire data, damage the system, or conduct other malicious activities. Simultaneously, it combines this with the distribution of valuable information within the target network to determine the attacker's most likely intent. The process involves recording and analyzing each of the attacker's operational steps and attack action sequences. By analyzing the attack targets (such as specific ports, services, databases, etc.) and mapping them to high-value assets in the network, behavioral analysis algorithms and expert system rules are used to infer the attacker's intent, such as stealing sensitive information or launching a denial-of-service attack.

[0022] The accuracy of situational awareness and decision-making is assessed using feedback mechanisms and confidence level evaluation. By collecting network feedback after decision execution—such as whether attacks were effectively prevented and whether the system returned to normal—the accuracy of previous situational awareness and decision-making is evaluated. Simultaneously, confidence levels are assigned to the data and analysis results used to support each decision, comprehensively considering multiple factors to determine the reliability of the decisions.

[0023] The process is as follows: After making a decision (such as activating firewall rules, isolating suspicious devices, etc.), the network status is continuously monitored. The actual network response is compared with the expected result, and the situational awareness model and decision-making algorithm are adjusted according to the differences. For the results of each situational analysis, the confidence level is determined based on factors such as the credibility of the data source and the maturity of the analysis method. The confidence levels of different results are comprehensively weighed when making decisions.

[0024] Situation prediction is based on time series analysis and machine learning prediction models. It analyzes the changing trends of historical cybersecurity situation data, uses machine learning algorithms (such as neural networks and support vector machines) to learn patterns in the data, and predicts future cybersecurity situations. Simultaneously, it considers the impact of external factors (such as emerging cyber threat intelligence). The process involves: collecting historical cybersecurity data, including attack frequency, type, and intensity information; preprocessing this data, such as normalization and feature extraction; selecting an appropriate prediction model and training it using training data; and inputting current cybersecurity situation data into the trained model to obtain situation prediction results for a future period, such as predicting possible new attack types and their probabilities.

[0025] The network security situation awareness system also includes functions such as data calibration, data format standardization, data simplification, and response and early warning. Specifically, the data calibration principle is as follows: by synchronizing with a standard time source, the timestamps of different data sources are ensured to be consistent, enabling accurate analysis of the sequence of events. Measurement values ​​and other information in the data can be corrected based on known calibration parameters.

[0026] Data calibration process: Time synchronization is achieved using technologies such as Network Time Protocol (NTP). For data values ​​requiring calibration, adjustments are made according to pre-set calibration formulas and parameters.

[0027] The principle of data format standardization involves defining a unified data structure and format specification to convert data from different sources into a format that conforms to the specification. For example, a unified log format template can be developed, requiring all devices and systems to output logs according to this template.

[0028] Data format standardization process: Develop a data conversion module to identify data formats from different data sources, and parse and repackage them according to a unified format specification. For data that does not conform to the specification, perform error handling or format conversion and repair.

[0029] Data simplification principle: Employing data compression and feature selection techniques. Redundant data, such as duplicate log entries and information with minimal impact on situational analysis, is removed. Feature selection algorithms identify the most valuable features for situational awareness, reducing the amount of data.

[0030] Data simplification process: Data compression algorithms (such as ZIP, GZIP, etc.) are used to compress and store large amounts of repetitive data. Feature selection algorithms (such as principal component analysis, information gain, etc.) are used to filter data features, retaining only key features.

[0031] Response and early warning principle: Based on predefined strategies and thresholds. When the situational awareness system detects an anomaly that reaches or exceeds the set threshold, it triggers response measures according to the corresponding strategy, such as sending an alarm to notify the administrator or automatically initiating the emergency response process.

[0032] Response and Early Warning Process: Configure response policies and threshold parameters in the system, such as when the number of attacks of a specific type exceeds a certain limit or when abnormal network bandwidth usage reaches a certain threshold. When the analysis results meet these conditions, activate the corresponding response mechanism, such as sending early warning information to security administrators via SMS or email, and automatically performing emergency operations according to the policy, such as closing specific ports or isolating suspicious network segments.

[0033] The power grid situational awareness system addresses the questions of "what is happening," "why it is happening and how it is happening," and "what will happen," which are essentially situational element extraction, real-time situational understanding, and future situational prediction. Situational element extraction is the most fundamental and basic step in situational awareness, aiming to acquire information from the perceived object, especially important information elements. With advancements in power grid technology, the scope of situational element collection has continuously expanded. Currently, the types of information that can be collected mainly include topology, real-time operational information, equipment status information, power grid stability / dynamic data, power grid transient fault information, and power grid operating environment information. Real-time situational understanding analyzes and processes the extracted important information and elements, performs situational assessment, and forms a comprehensive evaluation of the power grid's security status through comprehensive analysis and judgment. Future situational prediction, based on the perception, understanding, assessment, and comprehensive analysis of important situational information and elements, summarizes and infers the development and change patterns of the network situation in the power grid, thereby predicting future situational changes. The prediction results are submitted to the decision-making and execution stage for power grid regulation and control.

[0034] The power grid network assessment system, based on an understanding of computer network situational awareness, recognizes that when a power grid connects to numerous public networks, it faces various security threats related to equipment, networks, and data. To enhance the security monitoring and intrusion prevention capabilities of the power information network, a series of analyses and processing of the collected information are necessary. This necessitates situational assessment of the network information within the power grid. Power grid situational assessment can be understood as, in a large-scale, highly complex network environment, integrating and processing various types of network monitoring data from the power grid, and using domain knowledge and historical data, along with certain mathematical tools and models, analyzing and reasoning to provide reasonable explanations for various possible network attacks, ultimately assessing the current situation, using the assessment data to predict the situation, and preventing large-scale security incidents.

[0035] The beneficial effects of adopting the above technical solution are as follows: This model can comprehensively consider the security threats faced by the network in the current state of the smart grid, providing an accurate situation assessment of the current network state, laying a solid foundation for accurate situation prediction, and striving to avoid large-scale power grid safety and operational accidents. These will undoubtedly have a positive impact on the development of today's complex, integrated, and technologically advanced smart grids.

[0036] The above description is only used to illustrate the technical solution of the present invention and is not intended to limit it. Any other modifications or equivalent substitutions made by those skilled in the art to the technical solution of the present invention, as long as they do not depart from the spirit and scope of the technical solution of the present invention, should be covered within the scope of the claims of the present invention.

Claims

1. A situational awareness analysis model and method for edge-side power grids, characterized in that: It includes a network security situation awareness system, a power grid situation awareness system, a power grid network assessment system, and a power grid situation awareness application system.

2. The edge-side power grid situational awareness analysis model and method according to claim 1, characterized in that: The network security situation awareness system can solve the problems of data source, data credibility, and data readability required for situation awareness.

3. The edge-side power grid situational awareness analysis model and method according to claim 1, characterized in that: The network security situation awareness system has the following functions: 1) Identification and confirmation of the current situation; 2) Assessment of potential impacts; 3) Attacker intent analysis; 4) The accuracy of the situational awareness data collected and the decisions made; 5) Situation forecasting.

4. The edge-side power grid situational awareness analysis model and method according to claim 1, characterized in that: The network security situation awareness system also includes functions such as data calibration, data format standardization, data simplification, and response and early warning.

5. The edge-side power grid situational awareness analysis model and method according to claim 1, characterized in that: The power grid situation awareness system can solve the problems of "what is happening now", "why it is happening and how it is happening" and "what will happen", which are situation element extraction, real-time situation understanding and future situation prediction.

6. The edge-side power grid situational awareness analysis model and method according to claim 5, characterized in that: Situation element extraction is the most basic and fundamental step in situation awareness. Its purpose is to obtain information from the perceived object, especially important information elements. With the advancement of power grid technology, the scope of situation element collection has been continuously expanded. Currently, the types of information that can be collected mainly include topology, real-time operation information, equipment status information, power grid stability / dynamic data information, power grid transient fault information, and power grid operating environment information.

7. The edge-side power grid situational awareness analysis model and method according to claim 5, characterized in that: The real-time situational understanding involves analyzing and processing the extracted key information and elements, conducting situational assessments, and forming a comprehensive evaluation of the power grid's security status through integrated analysis and judgment.

8. The edge-side power grid situational awareness analysis model and method according to claim 5, characterized in that: The future situation prediction is based on the perception, understanding, assessment, and comprehensive analysis of important information and elements of the situation. It summarizes and infers the development and change patterns of the network situation in the power grid, thereby predicting the future situation. The prediction results will be submitted to the decision-making and execution stage for the regulation and control of the power grid.

9. The edge-side power grid situational awareness analysis model and method according to claim 1, characterized in that: The power grid network assessment system, based on an understanding of computer network situational awareness, recognizes that when a power grid connects to numerous public networks, it faces various security threats related to equipment, networks, and data. To enhance the security monitoring and intrusion prevention capabilities of the power information network, a series of analyses and processing of the collected information are necessary. This necessitates situational assessment of the network information within the power grid. Power grid situational assessment can be understood as, in a large-scale, highly complex network environment, integrating and processing various types of network monitoring data from the power grid, and using domain knowledge and historical data, along with certain mathematical tools and models, analyzing and reasoning to provide reasonable explanations for various possible network attacks, ultimately assessing the current situation, using the assessment data to predict the situation, and preventing large-scale security incidents.