Method and system for identifying network boundary of power monitoring system
By merging the network topology information of the power monitoring system to form a security partition IP address range, and combining the device type and communication IP list to identify boundary devices, the problem of unclear network boundary management in the power monitoring system is solved, accurate identification and classification management are achieved, and the network security protection effect is improved.
Patent Information
- Application Number
- CN202511091729.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-05
- Publication Date
- 2025-11-11
AI Technical Summary
The lack of clear network boundary management and effective means of detecting boundary changes in power monitoring systems renders boundary protection ineffective, hindering the overall effective management of network security boundaries and impacting the security protection effectiveness of power monitoring systems.
By merging subnet information within a security partition based on the network topology information of a single power monitoring system to form a security partition IP address range, data packets are obtained and the partition communication IP list of each communication link in the system subnet is filled in. By combining the device type and the partition communication IP list, different types of boundary devices and low-isolation-strength non-compliant boundary devices are identified.
It enables accurate identification and classification management of network boundaries in power monitoring systems, automatically discovers cross-regional communication nodes, reduces the risk of missed boundary detection, dynamically tracks network topology changes, identifies non-compliant boundary devices with low protection strength, and improves the overall network security protection level.
Smart Images

Figure CN120934816A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology in the power generation industry, specifically to a method and system for identifying the network boundary of a power monitoring system. Background Technology
[0002] As a critical information infrastructure ensuring a stable and reliable power supply, the network security of power monitoring systems is of paramount importance. Currently, the network security of power monitoring systems mainly relies on the isolation and protection of boundary devices, but this approach suffers from numerous problems in actual operation. First, operation and maintenance personnel typically focus only on the connectivity of physical links and the normal functioning of the system, lacking a clear understanding of the network boundary and effective means of detecting boundary changes. Second, the fragmented operations of different system maintenance personnel create management vacuums, hindering effective overall management of the network security boundary. Furthermore, in the context of open interconnection, the number of external interfaces of power monitoring systems is increasing, blurring the network boundary and rendering boundary protection ineffective, directly exposing the system to network security threats.
[0003] Even more serious is the fact that power monitoring systems require continuous, uninterrupted operation, making traditional active network scanning techniques inapplicable, and enterprises lack effective network boundary detection methods. Furthermore, the power industry suffers from a relative shortage of cybersecurity professionals, leading to inadequate management of information assets and network boundaries during daily operations and slow responses to boundary changes, resulting in a mismatch between the actual network boundary and the security protection configuration. These problems severely impact the security protection effectiveness of power monitoring systems, causing significant challenges to network security operations and maintenance, and potentially even triggering major power safety incidents. Therefore, there is an urgent need to develop a technical solution that can accurately identify the network boundaries of power monitoring systems without affecting normal system operation.
[0004] To address the aforementioned issues, existing technologies urgently need improvement. Summary of the Invention
[0005] The purpose of this invention is to provide a method and system for identifying the network boundary of a power monitoring system, so as to overcome the shortcomings of the prior art.
[0006] To achieve the above objectives, the technical solution adopted by the present invention is as follows: A method for identifying the network boundary of a power monitoring system includes the following steps: The IP address range of a security partition is formed by merging subnet information within a security partition based on the network topology information of a single power monitoring system. Retrieve data packets within the power monitoring system subnet and populate the partition communication IP list for each communication link in the system subnet; Based on the IP address range of the security partition, different types of boundary devices and low-isolation-strength non-compliant boundary devices are obtained according to the device type and the partition communication IP list.
[0007] Preferably, for the power monitoring system in the production control area, the topology information of each system subnet is compiled according to the system operation and maintenance documents, specifically including the subnet partition number and IP address range. The subnet partition number is in the format of "security partition_serial number". The security partition includes security zone I, security zone II and security zone III, and the serial number is a three-digit number.
[0008] Preferably, for subnets belonging to the same security partition, the IP address range and MAC address range are merged, and then the device list information is organized, including device number, device type, isolation strength, IP address, and MAC address. The device type includes host devices, industrial control devices, network devices, and security devices, and the isolation strength includes NULL, physical isolation, and logical isolation.
[0009] Preferably, for a single power monitoring system, a communication link table is established for all host devices within the subnet. Each link includes IP address, MAC address, subnet partition number, device ID, and a list of communication IPs.
[0010] Preferably, the traffic of the host and network devices is filtered to ensure that the connection is established and the complete data communication is completed. According to the above-mentioned merged security partition IP address range, data packets whose source IP address or target IP address is the IP address of the communication link and whose target IP address or source IP address is outside the system subnet IP address range are captured.
[0011] Preferably, the communication IP list of the communication link is filled according to the acquired data packets, including the communication IP lists of Security Zone I, Security Zone II, Security Zone III and the four communication IP lists of the unknown external partition. Specifically, if there is no such list, it is filled with NULL. For data packets whose source IP address and destination IP address are not within the range of IP addresses of all partitions, the communication link table is supplemented according to the device to which they belong.
[0012] Preferably, the IP address and the communication IP list are in the same security partition, there is a system subnet boundary, the device in the communication link belongs to the subnet boundary device, and the output device ID is used; If the IP address and the communication IP list are not in the same security zone, and the device type is a host device, it belongs to a cross-zone network boundary. The output device ID is a cross-zone interconnection type of illegal network boundary device.
[0013] Preferably, devices whose IP addresses and communication IP lists are not in the same security partition, whose device type is a security device, whose communication IP list belongs to the IP address range of Security Zone I or Security Zone II, have a boundary between Security Zone I and Security Zone II, whose isolation strength is logical isolation, output device ID, and whose isolation strength is not empty are compliant boundary devices; specifically, devices whose device type is not a security device or whose isolation strength is empty are low-isolation-strength non-compliant boundary devices. If the IP address and communication IP list are not in the same security partition, the device type is a security device, the communication IP list includes Security Zone III or an unknown range, there is a network boundary between the production control area and the management information area, the isolation strength is physical isolation, and the output device ID has physical isolation strength, then it is a compliant network boundary device. For those with non-physical isolation strength, this type of network boundary belongs to the low isolation strength category of non-compliant network boundary devices.
[0014] A system for identifying the network boundary of a power monitoring system includes the following steps: The IP address range of a security partition is formed by merging subnet information within a security partition based on the network topology information of a single power monitoring system. Retrieve data packets within the power monitoring system subnet and populate the partition communication IP list for each communication link in the system subnet; Based on the IP address range of the security partition, different types of boundary devices and low-isolation-strength non-compliant boundary devices are obtained according to the device type and the partition communication IP list.
[0015] Preferably, for the power monitoring system in the production control area, the topology information of each system subnet is compiled according to the system operation and maintenance documents, specifically including the subnet partition number and IP address range. The subnet partition number is in the format of "security partition_serial number". The security partition includes security zone I, security zone II and security zone III, and the serial number is a three-digit number.
[0016] Compared with the prior art, the present invention has the following beneficial technical effects: This invention discloses a method for identifying network boundaries in a power monitoring system. It involves merging subnet information within a security partition based on the network topology information of a single power monitoring system to form a security partition IP address range; acquiring data packets within the power monitoring system subnet and filling the partition communication IP list for each communication link of the system subnet; and based on the security partition IP address range, identifying different types of boundary devices and low-isolation-strength non-compliant boundary devices according to device type and the partition communication IP list. This application achieves accurate identification and classification management of power monitoring system network boundaries. It can automatically discover cross-regional communication nodes and distinguish device attributes, reducing the risk of missed boundary detection. By updating the communication IP list in real time, it dynamically tracks network topology changes, solving the information lag problem of traditional methods. Combined with an isolation strength verification mechanism, it effectively identifies low-protection-strength non-compliant boundary devices, improving the overall network security protection level. Attached Figure Description
[0017] Figure 1 This is a schematic diagram of a method for identifying the network boundary of a power monitoring system according to an embodiment of the present invention. Detailed Implementation
[0018] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0019] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion, specifically, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0020] Current technologies for network security boundary management in power monitoring systems have significant shortcomings. Maintenance personnel typically focus only on physical link connectivity, lacking effective means of network boundary detection. Management blind spots exist between different systems, leading to a disconnect between boundary protection measures and actual conditions. As the number of external interfaces increases, traditional manual methods are insufficient to handle dynamically changing network topologies, resulting in blurred boundaries and protection failures, creating significant security vulnerabilities.
[0021] To address the aforementioned issues, this invention proposes an identification approach based on IP address range aggregation and traffic feature matching by analyzing the correlation between network topology and communication behavior. The focus is on why security partition features are extracted from dispersed subnet information and why a mapping relationship between communication links and device types is established to construct an automated identification mechanism.
[0022] Specifically Figure 1 As shown, this invention provides a method for identifying the network boundary of a power monitoring system, specifically including the following steps: The IP address range of a security partition is formed by merging subnet information within a security partition based on the network topology information of a single power monitoring system. Retrieve data packets within the power monitoring system subnet and populate the partition communication IP list for each communication link in the system subnet; Based on the IP address range of the security partition, different types of boundary devices and low-isolation-strength non-compliant boundary devices are obtained according to the device type and the partition communication IP list.
[0023] In a specific embodiment of this application, the topology information of a single system subnet is obtained for the power monitoring system of the production control area based on the system operation and maintenance documents. Specifically, this includes the subnet partition number and IP address range. The subnet partition number is in the format of "security partition_serial number". The security partition includes security zone I, security zone II, and security zone III. The serial number is a three-digit number.
[0024] Security Zone I and Security Zone II both belong to the production control zone, while Security Zone III belongs to the management information zone. For subnets belonging to the same security zone, the IP address range and MAC address range are merged, and then the device list information is organized, including device number, device type, isolation strength, IP address, and MAC address. The device type includes host devices, industrial control devices, network devices, and security devices, and the isolation strength includes NULL, physical isolation, and logical isolation.
[0025] In a specific embodiment of this application, the security partition is specifically shown in Table 1 below: Table 1. Security Zones Corresponding to Power Monitoring Systems
[0026] For a single power monitoring system, a communication link table is established for all host devices within the subnet. Each link includes IP address, MAC address, subnet partition number, device ID, and a list of communication IPs. By filtering the traffic of hosts and network devices, it is ensured that a connection is established and complete data communication is achieved. Based on the aforementioned merged security partition IP address range, data packets whose source IP address or destination IP address is the IP address of the communication link and whose destination IP address or source IP address is outside the system subnet IP address range are captured. The communication IP list of the communication link is filled according to the captured data packets, including the communication IP lists of Security Zone I, Security Zone II, Security Zone III, and four communication IP lists of external unknown partitions. Specifically, if there is no such list, it is filled with NULL. For data packets whose source IP address and destination IP address are not within the IP address range of all partitions, the communication link table is supplemented according to the device to which they belong.
[0027] For each communication link in the power monitoring system, check the list of 4 communication IPs. If all 4 communication IPs are NULL, the device belongs to the internal device of the system. For links where not all 4 communication IPs are NULL, output the boundary device according to the security zone and device type to which the communication IPs belong. If the IP address and the communication IP list are in the same security partition, there is a system subnet boundary. The device in the communication link belongs to the subnet boundary device, and the device ID is output. If the IP address and the communication IP list are not in the same security zone, and the device type is a host device, it belongs to the cross-zone network boundary and outputs the device ID. This type of network boundary belongs to the cross-zone interconnection type of illegal network boundary device. If the IP address and the communication IP list are not in the same security partition, the device type is a security device, the communication IP list belongs to the IP address range of Security Zone I or Security Zone II, there is a boundary between Security Zone I and Security Zone II, the isolation strength is logical isolation, output device ID, and the isolation strength is not empty, it is a compliant boundary device. Specifically, if the device type is not a security device or the isolation strength is empty, it belongs to the low isolation strength category of non-compliant boundary devices. If the IP address and communication IP list are not in the same security partition, the device type is a security device, the communication IP list includes Security Zone III or an unknown range, there is a network boundary between the production control area and the management information area, the isolation strength is physical isolation, and the output device ID has physical isolation strength, then it is a compliant network boundary device. For those with non-physical isolation strength, this type of network boundary belongs to the low isolation strength category of non-compliant network boundary devices.
[0028] For low-isolation-strength non-compliant boundary devices at the boundaries of Security Zone I and Security Zone II, replace them with industrial firewalls. For low-isolation-strength non-compliant boundary devices at the network boundaries of the production control area and management information area, replace them with forward-type physical network isolation gateways. For cross-zone interconnection boundary devices, manual inspection of device configuration is required, and network disconnection procedures must be performed. This invention, based on passive traffic analysis, can detect abnormal communication links in the system without affecting system operation. If the communication IP lists for all four sub-security zones in the communication link are NULL, it indicates communication within the subnet.
[0029] Therefore, this application proposes a technical solution based on network topology merging to form a security partition IP range, constructing a communication IP list by capturing subnet data packets, and combining device type to achieve boundary device classification and identification.
[0030] Specifically, the IP address range of a security partition refers to a set of consecutive or non-consecutive addresses formed by merging multiple subnet IP addresses within the same security partition. This is achieved by extracting the IP segments of each subnet from the subnet topology document and using an address merging algorithm to eliminate overlapping areas. This feature solves the problem of unified management of scattered subnet information and provides a benchmark range for subsequent boundary determination.
[0031] Specifically, the partition communication IP list is a set of IP addresses that record cross-partition interactions in the communication link. This is achieved by capturing data packets using network traffic mirroring technology and filtering out valid communication records between source and destination addresses across partitions. This feature effectively captures actual communication behavior and avoids identification biases caused by relying on static configuration information.
[0032] Specifically, the first step is to integrate the subnet topology information and merge the IP addresses of subnets belonging to the same security zone. Specifically, the three subnets 192.168.1.0 / 24, 192.168.2.0 / 24, and 192.168.5.0 / 26 in Security Zone I are merged into the address range 192.168.0.0-192.168.5.127. Then, traffic acquisition devices are deployed within the subnets to capture all communication data packets. For each communication link, the IP addresses involved are recorded and categorized and stored in the corresponding partition's communication list. When a device IP and a communication IP are detected to belong to different security zones, the boundary attributes are determined based on the device type. Specifically, cross-zone communication by network devices is marked as a potential boundary point, while cross-zone communication by security devices requires further verification of isolation strength.
[0033] Through the above technical solutions, this application achieves accurate identification and classification management of network boundaries in power monitoring systems. It can automatically discover cross-regional communication nodes and distinguish device attributes, reducing the risk of missed boundary detections. By updating the communication IP list in real time, it dynamically tracks network topology changes, solving the information lag problem of traditional methods. Combined with an isolation strength verification mechanism, it effectively identifies illegal boundary devices with low protection strength, improving the overall network security protection level.
[0034] This application further proposes a power monitoring system for the production control area, which compiles the topology information of individual system subnets based on system operation and maintenance documents. Specifically, this includes subnet partition numbers and IP address ranges. The subnet partition numbers are in the format of "security partition_serial number". Security partitions include Security Zone I, Security Zone II, and Security Zone III, and the serial number is a three-digit number.
[0035] The subnet partition number is a unique identifier for each subnet using a pre-defined format. Specifically, it can be implemented using a combination of "security partition_three-digit serial number," where "security zone I_001" indicates that the subnet is the first subnet belonging to security zone I. This encoding rule standardizes the naming conventions for subnets used by different maintenance personnel, preventing boundary management vulnerabilities caused by naming confusion.
[0036] Specifically, security zoning refers to the classification of areas based on the functions and security levels of the power monitoring system. This can be achieved using a classification standard of Security Zone I, Security Zone II, and Security Zone III. Security Zone I corresponds to real-time control services, Security Zone II to non-real-time monitoring services, and Security Zone III to management information services. This classification method clarifies the security attributes of different subnets, providing fundamental data support for subsequent boundary identification.
[0037] The IP address range specifically refers to the set of IP addresses used by devices within the subnet. This can be obtained by extracting device configuration information recorded in the operation and maintenance documentation. Specifically, 192.168.1.0 / 24 represents the IP address range of this subnet. This information is used to define the network space range of the subnet and provides a data basis for subsequent merging of subnets within the security partition.
[0038] Specifically, during implementation, the configuration information of each subnet, including device IP addresses and their respective security zones, is first extracted from the power monitoring system's operation and maintenance documents. Each subnet is then numbered according to a predefined "security zone_serial number" format; for example, Security Zone I_002 represents the second subnet in Security Zone I. By associating subnet numbers within the same security zone with IP address ranges, a structured topology information table is formed. Specifically, the subnet number in Security Zone II is Security Zone II_003, and its IP address range is 10.0.3.0 / 24. This standardized process allows subnet information, previously scattered among different maintenance personnel, to be uniformly integrated, eliminating blind spots in boundary management caused by information silos.
[0039] This application achieves structured storage of subnet topology information by forcibly adopting a standardized subnet partition numbering format and combining security partition attributes with IP address ranges, providing an accurate data foundation for subsequent merging of subnets within security partitions and boundary identification.
[0040] Through the above technical solution, this application solves the problems of scattered subnet information and chaotic naming rules in the prior art, enabling different operation and maintenance personnel to organize subnet data based on a unified standard and avoiding boundary identification errors caused by inconsistent information formats. At the same time, by clarifying the correspondence between security partitions and subnet numbers, a scalable data framework is provided for the automated identification of cross-system boundaries.
[0041] This application further proposes to merge the IP address range and MAC address range of subnets belonging to the same security partition, and then organize the device list information, including device number, device type, isolation strength, IP address, and MAC address. The device type includes host devices, industrial control devices, network devices, and security devices, and the isolation strength includes NULL, physical isolation, and logical isolation.
[0042] Specifically, IP address range merging involves consolidating IP address ranges from multiple subnets within the same security zone into a continuous address range. This can be achieved using CIDR notation or address range merging algorithms; for example, merging 192.168.1.0 / 24 and 192.168.2.0 / 24 into 192.168.0.0 / 16. MAC address range merging involves classifying and consolidating the physical addresses of devices within the same security zone. This can be achieved by extracting MAC address prefixes or vendor identifiers. Device type classification categorizes devices into host devices, industrial control devices, network devices, and security devices based on their functional attributes. This can be achieved through device fingerprinting or protocol feature matching. The isolation strength attribute identifies the isolation method for communication between devices. Physical isolation indicates the presence of physical layer isolation devices, while logical isolation indicates that communication is restricted only by firewall rules.
[0043] Specifically, after merging the subnet IP and MAC addresses for security partitioning, the device list information is structured and stored in a database containing device numbers, types, isolation strengths, and network identifiers. Specifically, when two subnets belong to Security Zone I, their IP address ranges 192.168.1.1-192.168.1.254 and 192.168.2.1-192.168.2.254 are merged into 192.168.0.0 / 16. Simultaneously, devices are categorized by type, and their communication isolation methods are recorded. For devices without effective isolation measures, the isolation strength field is marked as NULL. This structured data provides the foundation for subsequent boundary device identification, specifically by matching device type and isolation strength to determine if any unauthorized boundaries exist.
[0044] This application eliminates redundant data by address merging and combines multi-dimensional attribute association between device type and isolation strength, enabling rapid determination of the security zone to which a device belongs and its isolation compliance when identifying boundary devices.
[0045] The above technical solution effectively addresses the difficulty of boundary identification caused by the dispersion of subnet information within the same security zone. Through structured records of device type and isolation strength, boundary devices without compliant isolation measures can be quickly identified. Specifically, if a network device is detected connecting to two merged IP address ranges but with an isolation strength of NULL, it can be determined that the device poses a risk of low isolation strength violation. This solution provides a standardized data foundation for automated network boundary identification, avoiding omissions or misjudgments that may occur during manual verification.
[0046] This application further proposes to establish a communication link table for all host devices within a subnet for a single power monitoring system. Each link includes IP address, MAC address, subnet partition number, device ID, and a list of communication IPs.
[0047] The communication link table is a structured collection of data recording the communication paths of all host devices within the subnet. It can be implemented using a database table or spreadsheet, and is used to systematically store the communication relationships between devices. IP addresses and MAC addresses, as unique network identifiers for devices, can be obtained by capturing the protocol header information of network data packets, and are used to accurately identify communication endpoints. The subnet partition number uses the format "security partition_serial number", specifically security zone I_001, and can be automatically generated by parsing network topology documents, used to distinguish communication links in different security zones. The device ID is a unique code for the device in the system, specifically generated by combining the device serial number and installation location, used for quickly locating the device entity. The communication IP list is formed by collecting target addresses from communication data packets, specifically recording all external IP addresses that a host device has connected to within a specific time period, used to analyze the device's external communication behavior.
[0048] Specifically, during the operation of the power monitoring system, network traffic data from host devices within the subnet is continuously collected, and the source IP address, destination IP address, and corresponding MAC address of each communication link are extracted. Combined with pre-organized security partition information, each link is associated with a specific subnet partition number. For example, if a host device has an IP address of 192.168.1.10, and its communication destination addresses include 192.168.2.20 and 10.0.0.5, these are recorded as two separate communication links. The device ID is generated using a hash algorithm to encrypt the device hardware information, ensuring uniqueness. The communication IP list is a dynamic list formed by the destination addresses of communication data packets within a statistical period. Specifically, if a host device establishes connections with five external IP addresses within 24 hours, the communication IP list records these five addresses and the communication frequency.
[0049] This application establishes a communication link table containing multi-dimensional information, which can accurately reflect the actual communication behavior of devices. Specifically, if a device in Security Zone I frequently communicates with addresses in Security Zone III, the system can automatically mark the abnormal link, while traditional manual inspection methods are difficult to detect such covert cross-zone communication.
[0050] Through the above technical solution, this application achieves refined recording of network communication behavior in power monitoring systems, solving the inefficiency problem caused by relying on manual investigation for boundary device identification. By storing communication endpoint information in a structured manner, cross-regional communication devices can be quickly located. Specifically, when an address from another security zone appears in the communication IP list of a host device, the system can automatically trigger an alarm. It also supports dynamic updates of communication links, specifically automatically supplementing the communication IP list when a new external connection is added, effectively addressing security risks arising from changes in network boundaries.
[0051] This application further proposes filtering the traffic of hosts and network devices to ensure that a connection is established and complete data communication is achieved. It captures data packets whose source IP address or destination IP address is the IP address of the communication link and whose destination IP address or source IP address is outside the system subnet IP address range, according to the merged security partition IP address range.
[0052] Traffic filtering specifically involves selecting data packets that meet certain criteria by setting rules. This can be achieved using deep packet inspection (DPI) or stateful firewalls to exclude interference data from incomplete communication connections, ensuring that the analyzed data represents valid communication behavior. The security partition IP address range is a set of continuous or discrete addresses formed by merging subnet IP addresses within the same security partition. This can be generated using address segment aggregation algorithms and is used to define the boundary conditions between internal and external communication within the subnet. The communication link IP address is the actual address identifier used by the host or network device during communication. This can be obtained by parsing the network layer protocol header and is used to associate the device with its communication behavior.
[0053] Specifically, IP addresses outside the system subnet IP address range are those that do not belong to the address set after the current subnet is merged. This can be determined through an address matching algorithm to identify communication behavior across subnets or partitions.
[0054] Specifically, after merging the IP address ranges of the security partitions, traffic acquisition devices are deployed to capture the communication traffic of hosts and network devices. The traffic filtering module first filters out sessions that have completed the three-way handshake and are transmitting data, specifically sessions in the ESTABLISHED state of TCP connections. Then, based on the merged security partition IP address range, it extracts data packets whose source or destination IP address belongs to the communication link IP list, and further determines whether the address at the other end of the data packet exceeds the current subnet IP address range. Specifically, when a host's communication link IP address is 192.168.1.10, and it communicates with the external address 10.0.0.5, if 10.0.0.5 is not within the merged subnet address range, the data packet will be captured and marked as boundary communication behavior.
[0055] This application effectively avoids data interference from temporary connections or incomplete handshakes by screening complete communication sessions. Through the above technical solution, this application can accurately identify the actual communication boundary between the subnet and the external network, reducing misjudgments caused by temporary connections or invalid sessions. Simultaneously, it provides a high-confidence data foundation for subsequent analysis of devices violating boundary rules, improving the reliability of cross-zone communication compliance checks.
[0056] This application further proposes to fill the communication IP list of the communication link according to the acquired data packet, including the communication IP lists of Security Zone I, Security Zone II, Security Zone III and four communication IP lists of external unknown partitions. Specifically, if there is no such list, it is filled with NULL. For data packets whose source IP address and destination IP address are not within the range of IP addresses of all partitions, the communication link table is supplemented according to the device to which they belong.
[0057] The communication IP list specifically records all IP addresses involved in device communication. This can be achieved by capturing the source and destination IP addresses in data packets using network traffic capture tools. This list is used to analyze the device's communication behavior between different security zones. The communication IP lists for Security Zone I, Security Zone II, and Security Zone III are data structures that categorize and store communication IPs according to predefined security zone IP address ranges. This can be managed using hash tables or database tables. This categorization clearly distinguishes legitimate communication behavior within a security zone. The communication IP list for unknown external zones is a set of IP addresses that do not belong to any known security zone. This can be achieved by setting filtering rules to include IP addresses in data packets that do not match the security zone range. This list is used to identify potential abnormal external communication. The communication link table supplementation based on the device's ownership is implemented when both the source and destination IP addresses of a data packet are outside the known zone range. The communication IP is added to the corresponding communication link table of the device to which the data packet belongs by associating it with the device ID. This can be achieved using a mapping relationship between device identifiers and communication IPs. This mechanism effectively handles abnormal communication scenarios in undefined zones.
[0058] Specifically, during the packet capture phase, all communication traffic within the subnet is acquired using traffic mirroring technology, and the source IP, destination IP, and associated device information of each packet are extracted. Based on the pre-merged security partition IP address range, the communication IPs are automatically categorized into the corresponding security zone I, II, III communication lists or external unknown partition lists. When it is detected that neither the source IP nor the destination IP matches any known partition, the communication IP is associated with the corresponding device's communication link table by parsing the device identification information of the packet. Specifically, if a packet generated by an industrial control device contains both an unknown source IP (specifically 192.168.1.100) and a destination IP (specifically 10.0.0.50), the system will automatically add this communication record to the device's communication link table and mark it as external unknown partition communication.
[0059] This application establishes a multi-dimensional communication IP classification system, which not only covers communication records of standard security partitions but also adds communication tracking functionality for external unknown partitions. Simultaneously, a device association mechanism ensures that all communication activities are accurately recorded, resolving the problem of communication data omissions caused by changes in partition ranges or the addition of new devices in existing technologies.
[0060] Through the above technical solution, this application achieves complete recording and intelligent classification of all communication behaviors of the power monitoring system, enabling accurate identification of cross-regional communication and abnormal external communication behaviors. Especially when dealing with communication scenarios where no partitions are defined, the device association mechanism ensures the integrity of communication link information, providing a reliable data foundation for subsequent boundary device identification and effectively avoiding boundary identification errors caused by missing communication data.
[0061] This application further proposes a method to identify different types of boundary devices and low-isolation-strength non-compliant boundary devices based on the IP address range of a security partition, according to the device type and the partition's communication IP list. When the IP address and the communication IP list are in the same security partition, a system subnet boundary exists, and the device in the communication link is a subnet boundary device, with the device ID output. When the IP address and the communication IP list are not in the same security partition, and the device type is a host device, it belongs to a cross-regional network boundary, with the device ID output. This type of network boundary belongs to the cross-regional interconnection type of non-compliant network boundary device.
[0062] Specifically, security zoning divides the power monitoring system network into logical zones with different security levels: Security Zone I, Security Zone II, and Security Zone III. This is achieved by configuring subnet partition numbers and is used to isolate network traffic at different security levels. Device type refers to the functional classification of network devices: host devices, industrial control devices, network devices, and security devices. This is categorized using device attribute fields and is used to differentiate the processing logic of different devices in boundary identification. The communication IP list records the set of IP addresses involved in device communication. This is generated by capturing source and destination IPs from data packets and is used to analyze cross-zone communication behavior. Isolation strength refers to the security isolation level of the network boundary: physical isolation or logical isolation. This is obtained through device configuration parameters and is used to assess the compliance of boundary protection.
[0063] Specifically, when a device's IP address is detected to belong to the same security zone as an address in its communication IP list, it indicates that the device is within the same security domain and only needs to be marked as a subnet boundary device. If the device's IP address and communication IP list span different security zones, the determination must be made based on the device type: for host devices, their cross-zone communication behavior directly triggers a cross-zone interconnection violation flag; for security devices, it is necessary to further verify whether their isolation strength parameters meet the corresponding zone-to-zone isolation requirements. Specifically, if the boundary device between Security Zone I and Security Zone II uses logical isolation and has complete isolation strength parameters, it is determined to be a compliant boundary; if the isolation strength parameters are missing or the device type is inconsistent, it is determined to be a low isolation strength violation.
[0064] This application, through automated analysis of the matching relationship between device communication data and partitioning rules, can accurately identify unauthorized cross-partition connections, especially targeting covert host device violations. Existing technologies lack clear verification mechanisms for judging the compliance of security devices. This application establishes a quantitative evaluation standard for inter-partition security boundaries by introducing dual verification of isolation strength parameters and device type.
[0065] Through the above technical solution, this application can effectively identify illegal cross-regional interconnection devices in the power monitoring system, especially for host device communication links that lack compliant isolation measures. By automatically distinguishing between compliant boundary devices and illegal devices with low isolation strength, it solves the problems of low efficiency and high missed detection rate of traditional manual inspections, providing an accurate list of boundary devices for network security operation and maintenance, and avoiding the risk of security protection failure due to ambiguous boundaries.
[0066] This application further proposes that when the IP address and the communication IP list are not in the same security zone and the device type is a security device, if the communication IP list belongs to the IP address range of Security Zone I or Security Zone II, then there is a boundary between Security Zone I and Security Zone II, with logical isolation strength. The output device ID is used. Devices with non-empty isolation strength are compliant boundary devices. If the device type is not a security device or the isolation strength is empty, then it belongs to the low isolation strength category of non-compliant boundary devices. When the communication IP list includes Security Zone III or an unknown range, there is a network boundary between the production control area and the management information area, with physical isolation strength. The output device ID is used. Devices with physical isolation strength are compliant network boundary devices. Devices with non-physical isolation strength are low isolation strength category of non-compliant network boundary devices.
[0067] Among them, security devices are specifically deployed at the network boundary to implement access control or security protection, specifically firewalls or intrusion detection systems, whose function is to determine the compliance of the boundary through isolation strength parameters.
[0068] Isolation strength refers to the isolation method provided by the device between two network areas. Physical isolation can be achieved through dedicated hardware, while logical isolation can be achieved through access control policies. This parameter is used to distinguish between compliance and non-compliance boundaries.
[0069] The communication IP list is a set of IP addresses that the device interacts with in the communication link. It is generated by capturing the source IP or destination IP of cross-regional data packets and is used to identify the actual communication range of the device.
[0070] Specifically, when a security device's communication IP list belongs to Security Zone I or Security Zone II, the system automatically matches the logical isolation strength requirements. If the device's isolation strength parameter is set to logical isolation, it is determined to be a compliant boundary device, specifically a firewall configured with an access control list but not physically disconnected. If the device does not have an isolation strength parameter set or is not a security device (specifically, a regular switch without access control), it is determined to be a low-isolation, non-compliant device. When the communication IP list involves Security Zone III or an unknown range, the system requires the isolation strength to be physical isolation, specifically through a separate hardware device to physically disconnect the network. If the device's isolation strength parameter is set to physical isolation, it is compliant; otherwise, it is determined to be non-compliant.
[0071] This application can accurately identify the compliance status of cross-regional boundary devices by automatically analyzing the matching relationship between device type, communication IP list and isolation strength parameters, thereby reducing human error.
[0072] Through the above technical solution, this application can automatically distinguish the compliance of security devices in different zone boundaries. Specifically, it can accurately identify security zone III boundary devices that are not configured with physical isolation, avoid cross-zone illegal communication problems caused by insufficient isolation strength, and complete boundary identification without interrupting system operation, adapting to the characteristics of continuous operation of power monitoring systems.
[0073] This application further proposes a network boundary identification system for power monitoring systems, comprising the following steps: merging subnet information within a security partition based on the network topology information of a single power monitoring system to form a security partition IP address range; obtaining data packets within the power monitoring system subnet and filling the partition communication IP list for each communication link of the system subnet; and based on the security partition IP address range, identifying different types of boundary devices and low-isolation-strength non-compliant boundary devices according to device type and the partition communication IP list.
[0074] Specifically, the IP address range of a security partition is a contiguous address segment formed by merging subnet IP addresses within the same security partition. This can be achieved using the CIDR format for address aggregation, specifically merging 192.168.1.0 / 24 and 192.168.2.0 / 24 into 192.168.0.0 / 16. This feature eliminates address fragmentation caused by subnetting, providing a unified reference standard for subsequent boundary determination.
[0075] The partition communication IP list is specifically a set of IP addresses that record cross-partition or cross-subnet communication behavior in each communication link. This can be achieved by capturing network traffic and extracting the mapping relationship between source and destination addresses. This list is used to quantitatively analyze device communication behavior and identify abnormal cross-partition access behavior.
[0076] The boundary device classification is specifically based on the correlation between device type and communication IP list to determine device attributes. Specifically, when a security device's communication IP list contains unknown partition addresses, a physical isolation strength verification mechanism can be triggered. This classification logic can distinguish between compliant and non-compliant devices, achieving precise boundary control.
[0077] Specifically, the system first parses the network topology configuration file to merge subnet IP addresses within the same security zone. Specifically, the three subnet addresses 192.168.1.0 / 24, 192.168.2.0 / 24, and 192.168.3.0 / 24 in Security Zone I can be merged into the address range 192.168.0.0 / 16. Then, network traffic mirroring technology is used to capture data packets within the subnet, extracting and classifying IP addresses involved in cross-zone communication in each communication link, forming a communication IP list encompassing four dimensions: Security Zone I, II, III, and an unknown external area. Finally, based on preset device type determination rules, when a cross-security zone address is detected in the network device's communication IP list, it is automatically marked as a potentially illegal boundary device.
[0078] In some specific implementations, packet capture by security devices can employ deep packet inspection (DPI) technology, specifically by parsing application layer protocol characteristics using DPI devices. For communication behavior analysis of industrial control equipment, a whitelist mechanism can be set up to allow only packets of specific protocol types to enter the analysis process. Address merging algorithms can use a binary tree structure for fast address segment aggregation, specifically by expanding scattered IP addresses into 32-bit binary representations and constructing a prefix tree for merging.
[0079] This system, through automated address merging and traffic analysis, can reflect network boundary changes in real time. Existing technologies for boundary device identification are mostly based on static configuration information; this application, by dynamically capturing communication behavior data, can discover hidden, unauthorized cross-regional access links. Compared to conventional solutions that only detect physical connections, this system further combines device type and isolation strength parameters to achieve multi-dimensional boundary risk assessment.
[0080] Through the above technical solution, this application can automatically identify boundary devices with potential security risks in power monitoring systems. Specifically, it can promptly issue alarms when it detects logically isolated security devices communicating with unknown areas. The system solves the problem of chaotic address management in multi-subnet environments by establishing standardized address merging rules. Based on the dynamic analysis of communication behavior, it effectively addresses the boundary ambiguity caused by frequent network topology changes, providing accurate data support for security policy configuration.
[0081] This application further proposes a power monitoring system for the production control area, which compiles the topology information of individual system subnets based on system operation and maintenance documents. Specifically, this includes subnet partition numbers and IP address ranges. The subnet partition numbers are in the format of "security partition_serial number". Security partitions include Security Zone I, Security Zone II, and Security Zone III, and the serial number is a three-digit number.
[0082] The system operation and maintenance documentation specifically includes configuration records, network architecture diagrams, and equipment lists generated during the operation and maintenance of the power monitoring system. Text parsing tools can be used to extract subnetting rules and device connection relationships, providing foundational data for subsequent boundary identification. The subnet partition number is a unique identifier generated using the format "security partition_serial number." An automated script can be used to combine the security partition name with a three-digit serial number, specifically Security I_001, Security II_002, etc., using standardized naming rules to avoid manual numbering errors. Security partitions are logical areas divided according to the security protection requirements of the power monitoring system. They can be categorized based on device functional attributes and data flow direction: Security I for real-time control services, Security II for non-real-time monitoring services, and Security III for management information services. The three-digit serial number is an incremental number used to distinguish different subnets within the same security partition. It can be generated using a three-digit encoding rule, specifically from 001 to 999, with a fixed number of digits ensuring a consistent numbering format.
[0083] Specifically, by parsing the network topology information in the system operation and maintenance documents, the security zone attributes and IP address ranges of the subnets are extracted, and subnet partition numbers are generated according to preset naming rules. For example, a power monitoring system in a production control area contains three subnets located in Security Zone I, Security Zone II, and Security Zone III, respectively. The IP address ranges recorded in its operation and maintenance documents are 192.168.1.0 / 24, 10.0.2.0 / 24, and 172.16.3.0 / 24. The system then automatically generates subnet partition numbers Security Zone I_001, Security Zone II_002, and Security Zone III_003, and stores the IP address ranges associated with these numbers. The resulting structured data provides standardized input for subsequent merging of subnet information within security zones and identification of network boundaries.
[0084] This application eliminates the uncertainty of human operation by forcibly constraining the format of subnet partition numbers and security partition types, so that subnet information within the same security partition can be accurately classified, thereby laying the data foundation for IP address range merging and boundary device identification.
[0085] Through the above technical solution, this application can transform the subnet topology information scattered in the operation and maintenance documents into structured standard data, solve the problem of network boundary identification errors caused by low efficiency and chaotic format due to manual sorting, and thus improve the automation level and accuracy of network boundary management of power monitoring system.
[0086] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. A method for identifying the network boundary of a power monitoring system, characterized in that, Includes the following steps: The IP address range of a security partition is formed by merging subnet information within a security partition based on the network topology information of a single power monitoring system. Retrieve data packets within the power monitoring system subnet and populate the partition communication IP list for each communication link in the system subnet; Based on the IP address range of the security partition, different types of boundary devices and low-isolation-strength non-compliant boundary devices are obtained according to the device type and the partition communication IP list.
2. The method for identifying the network boundary of a power monitoring system according to claim 1, characterized in that, For the power monitoring system in the production control area, the topology information of each system subnet is compiled according to the system operation and maintenance documents. Specifically, this includes the subnet partition number and IP address range. The subnet partition number is in the format of "security partition_serial number". The security partitions include Security Zone I, Security Zone II, and Security Zone III, and the serial number is a three-digit number.
3. The method for identifying the network boundary of a power monitoring system according to claim 2, characterized in that, For subnets belonging to the same security zone, merge the IP address range and MAC address range, and then organize the device list information, including device number, device type, isolation strength, IP address, and MAC address. The device type includes host devices, industrial control devices, network devices, and security devices, and the isolation strength includes NULL, physical isolation, and logical isolation.
4. The method for identifying the network boundary of a power monitoring system according to claim 1, characterized in that, For a single power monitoring system, establish a communication link table for all host devices within the subnet. Each link includes IP address, MAC address, subnet partition number, device ID, and a list of communication IPs.
5. The method for identifying the network boundary of a power monitoring system according to claim 4, characterized in that, Traffic from hosts and network devices is filtered to ensure that connections are established and complete data communication is achieved. Based on the aforementioned merged security partition IP address range, data packets whose source IP address or destination IP address is the IP address of the communication link and whose destination IP address or source IP address is outside the system subnet IP address range are captured.
6. The method for identifying the network boundary of a power monitoring system according to claim 5, characterized in that, Fill the communication IP list of the communication link according to the acquired data packets, including the communication IP lists of Security Zone I, Security Zone II, Security Zone III, and the four communication IP lists of the external unknown partition. Specifically, if there is no such list, fill it with NULL. For data packets whose source IP address and destination IP address are not within the range of IP addresses of all partitions, supplement the communication link table according to the device to which they belong.
7. The method for identifying the network boundary of a power monitoring system according to claim 6, characterized in that, If the IP address and the communication IP list are in the same security partition, there is a system subnet boundary. The device in the communication link belongs to the subnet boundary device, and the output device ID is used. If the IP address and the communication IP list are not in the same security zone, and the device type is a host device, it belongs to a cross-zone network boundary. The output device ID is a cross-zone interconnection type of illegal network boundary device.
8. The method for identifying the network boundary of a power monitoring system according to claim 7, characterized in that, If the IP address and the communication IP list are not in the same security partition, the device type is a security device, the communication IP list belongs to the IP address range of Security Zone I or Security Zone II, there is a boundary between Security Zone I and Security Zone II, the isolation strength is logical isolation, output device ID, and the isolation strength is not empty, it is a compliant boundary device. Specifically, if the device type is not a security device or the isolation strength is empty, it belongs to the low isolation strength category of non-compliant boundary devices. If the IP address and communication IP list are not in the same security partition, the device type is a security device, the communication IP list includes Security Zone III or an unknown range, there is a network boundary between the production control area and the management information area, the isolation strength is physical isolation, and the output device ID has physical isolation strength, then it is a compliant network boundary device. For those with non-physical isolation strength, this type of network boundary belongs to the low isolation strength category of non-compliant network boundary devices.
9. A network boundary identification system for a power monitoring system, characterized in that, Includes the following steps: The IP address range of a security partition is formed by merging subnet information within a security partition based on the network topology information of a single power monitoring system. Retrieve data packets within the power monitoring system subnet and populate the partition communication IP list for each communication link in the system subnet; Based on the IP address range of the security partition, different types of boundary devices and low-isolation-strength non-compliant boundary devices are obtained according to the device type and the partition communication IP list.
10. The power monitoring system network boundary identification system according to claim 1, characterized in that, For the power monitoring system in the production control area, the topology information of each system subnet is compiled according to the system operation and maintenance documents. Specifically, this includes the subnet partition number and IP address range. The subnet partition number is in the format of "security partition_serial number". The security partitions include Security Zone I, Security Zone II, and Security Zone III, and the serial number is a three-digit number.