Power monitoring system mimicry defense architecture based on dynamic heterogeneous redundancy

By constructing a mimicry defense architecture for power monitoring systems based on dynamic heterogeneous redundancy and utilizing digital twin technology to achieve precise mapping between the virtual environment and the physical system, the problems of identifying unknown threats and cross-regional collaboration in power monitoring systems are solved, thereby improving the efficiency of defense strategies and the security of the system.

CN120979731APending Publication Date: 2025-11-18GUIZHOU POWER GRID CO LTD
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202511158711.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-19
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

Power monitoring systems face challenges such as difficulty in identifying unknown threats, time-consuming verification of defense strategies, insufficient cross-regional collaboration capabilities, and low success rates in attack tracing. Traditional defense technologies are unable to effectively address increasingly complex and covert network threats.

Method used

A mimicry defense architecture for power monitoring systems based on dynamic heterogeneous redundancy is constructed, including a physical layer, a twin layer, and a simulation layer. Digital twin technology is used to achieve accurate mapping between the virtual environment and the physical system, supporting the parsing and simulation of power-specific protocols. Combined with anomaly detection and cross-regional collaborative defense mechanisms, the defense strategy is optimized.

Benefits of technology

It improves the identification rate of unknown threats, reduces the cost of verifying defense strategies, shortens the attack propagation time, increases the success rate of tracing the source, and ensures the security and business continuity of the power system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979731A_ABST
    Figure CN120979731A_ABST
Patent Text Reader

Abstract

The invention discloses a power monitoring system mimicry defense architecture based on dynamic heterogeneous redundancy, which relates to the field of smart grid network security protection and comprises a physical layer, a twinborn layer and a simulation layer. All the layers communicate through encryption channels, a collaborative architecture of a physical layer, a twinborn layer, a simulation layer and an application layer is constructed, accurate mapping of a virtual environment and a physical power monitoring system is achieved by means of the digital twinborn technology, and a virtual carrier fitting the reality is provided for anomaly detection and attack simulation. The adaptability of the defense architecture to the power business logic is improved through analysis and simulation support on the power dedicated protocol; each layer ensures that the normal operation of the power monitoring system is not interfered through encryption communication and reasonable resource control; meanwhile, the digital twinborn body is used for replacing the traditional physical test environment, so that the construction, operation and maintenance cost of a defense system is reduced, the management efficiency is improved, and an adaptive service, efficient and reliable basic framework is laid for the safety protection of the power monitoring system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of smart grid network security protection technology, and in particular to a biomimetic defense architecture, system, equipment, and medium for power monitoring systems based on dynamic heterogeneous redundancy. Background Technology

[0002] With the increasing demand for security protection of critical information infrastructure, power monitoring systems, as a core component of critical information infrastructure in the energy sector, face increasingly complex, covert, and targeted cyber threats. Their security protection is crucial to ensuring the stable operation of the power system.

[0003] Currently, traditional defense technologies for power monitoring systems have significant limitations: On the one hand, traditional intrusion detection systems and firewalls, which rely on known threat signature databases (such as virus databases and vulnerability databases), operate based on the principle of "feature matching." They require prior acquisition of threat signatures such as attack code snippets and malicious traffic characteristics, making it difficult to identify threats using unknown attack vectors (such as malformed packet attacks targeting power-specific protocols). This results in a large number of unknown threats and advanced threats such as APT attacks being able to bypass defense mechanisms with a high success rate. On the other hand, due to the "physical isolation + logical partitioning" architecture of power monitoring systems, new defense strategies (such as firewall rules and intrusion prevention strategies) cannot be directly tested in a real environment. Traditionally, physical test environments need to be built, which is time-consuming, has high hardware costs, and the differences from the real environment can lead to strategy failures.

[0004] Meanwhile, in a microgrid isolation environment, the defense equipment in each region (such as headquarters, regional dispatch, and substations) operates independently, lacking a global coordination mechanism. When an attack occurs in one region, other regions cannot quickly synchronize their defense strategies, which can easily lead to the horizontal spread of the attack. Furthermore, the power monitoring system has high business continuity requirements, and it is difficult to pause the system for source tracing analysis after an attack. In the traditional log auditing method, some attacks may tamper with the logs, resulting in a low success rate of source tracing and seriously affecting fault diagnosis and system recovery.

[0005] Furthermore, while existing technologies such as digital twins are applied to power systems (e.g., equipment status monitoring), they have not penetrated into the field of security defense. Specifically, this manifests in the following ways: the lack of a dynamic correlation model between attack behavior and defense strategies makes it impossible to simulate unknown threats; the absence of a collaborative mechanism for cross-regional twins makes it difficult to support global defense; and the failure to design simulation logic in conjunction with the characteristics of power business (e.g., real-time data transmission and control command priority) results in poor adaptability between defense strategies and business needs.

[0006] Therefore, there is an urgent need for a power monitoring system security defense architecture that can effectively respond to unknown threats, improve the efficiency of defense strategy verification, and enhance cross-regional collaboration capabilities. Summary of the Invention

[0007] In view of the above-mentioned problems, the present invention is proposed.

[0008] To address the aforementioned technical problems, this invention provides the following technical solution: a biomimetic defense architecture for a power monitoring system based on dynamic heterogeneous redundancy, comprising,

[0009] It includes the physical layer, twin layer, and simulation layer;

[0010] The physical layer includes the actual equipment and defense equipment of the power monitoring system, and the actual equipment is distributed in multiple isolated areas;

[0011] The twin layer is deployed on computing nodes in each region and runs digital twin software. The digital twin is built based on the topology, device parameters and business processes of the physical layer, and achieves state synchronization by collecting physical layer operation data in real time through sensors.

[0012] The simulation layer is deployed on a cloud platform and runs an attack scenario simulation engine to reproduce the attack process, test and optimize defense strategies in a digital twin.

[0013] Each layer communicates through an encrypted channel and includes an application layer, which comprises an anomaly detection platform, a policy management platform, and a collaborative defense center for parameter configuration, alarm viewing, and policy optimization.

[0014] As a preferred embodiment of the biomimetic defense architecture for a power monitoring system based on dynamic heterogeneous redundancy described in this invention, the construction of the digital twin includes:

[0015] Three-dimensional modeling technology is used to recreate the hardware parameters, network topology, and business logic of physical devices;

[0016] It supports the parsing and simulation of power-specific protocols to simulate the protocol interaction process of physical systems;

[0017] The system collects real-time operational data from the physical system using sensors and synchronizes it to the twin to ensure consistency with the physical device's state.

[0018] As a preferred embodiment of the biomimetic defense architecture for a power monitoring system based on dynamic heterogeneous redundancy described in this invention, the twin layer further includes an anomaly detection mechanism based on behavioral baselines, the anomaly detection mechanism comprising:

[0019] Establish equipment behavior baselines and statistically analyze the normal range of operating parameters for individual devices;

[0020] Establish a network behavior baseline and analyze the normal patterns of traffic characteristics, protocol distribution, and communication frequencies within the region;

[0021] Establish a baseline for business behavior and record the patterns of control command transmission and normal rules for data modification permissions;

[0022] When the behavior of the physical system deviates from the baseline threshold, it is marked as an abnormal event and an alarm is triggered.

[0023] As a preferred embodiment of the biomimetic defense architecture for a power monitoring system based on dynamic heterogeneous redundancy as described in this invention, the attack scenario simulation and defense strategy optimization of the simulation layer includes:

[0024] It has a built-in attack scenario library of typical attack scenarios in the power industry, and also supports custom attack scenarios;

[0025] Inject attack traffic into the digital twin, observe the system response and record the attack path and scope of impact; adjust the defense strategy based on the simulation results, and determine the optimal strategy through multiple rounds of simulation;

[0026] The optimized strategy is synchronized to the physical layer defense devices via an encrypted channel and deployed.

[0027] As a preferred embodiment of the biomimetic defense architecture for a power monitoring system based on dynamic heterogeneous redundancy as described in this invention, it further includes a cross-regional twin collaborative defense mechanism.

[0028] The collaborative defense mechanism includes:

[0029] A twin registration center is set up at headquarters to record the network address, coverage area and online status of twins in each region;

[0030] When a regional twin detects an anomaly, it pushes an early warning message to the associated regional twins through the registry center;

[0031] The headquarters twin generates a unified defense strategy template based on the overall threat situation and distributes it to regional twins. The regional twins then fine-tune the templates based on local characteristics and synchronize them to the physical devices.

[0032] Multi-region twins share attack logs, and the entire attack path can be reconstructed through correlation analysis.

[0033] As a preferred embodiment of the biomimetic defense architecture for a power monitoring system based on dynamic heterogeneous redundancy described in this invention, it further includes an anomaly handling mechanism, which includes:

[0034] When communication between the physical layer and the twin layer is interrupted, the twin uses locally cached historical data to predict the system state, and automatically calibrates after communication is restored.

[0035] When the deviation between the twin simulation results and the physical system exceeds the preset range, model optimization is automatically initiated; when the defense strategy fails to be synchronized to the physical device, a manual intervention process is triggered, and the strategy status is marked in the twin.

[0036] When multiple abnormal events are detected simultaneously, an "area isolation" simulation is automatically initiated to assess the feasibility of severing the area link in order to prevent the attack from spreading.

[0037] As a preferred embodiment of the biomimetic defense architecture for a power monitoring system based on dynamic heterogeneous redundancy as described in this invention, the anomaly detection mechanism based on behavioral baselines can improve the identification rate of unknown threats.

[0038] The digital twin simulation environment can reduce the cost of verifying defense strategies;

[0039] The aforementioned abnormal event synchronization and strategy coordination mechanism can shorten the attack propagation time;

[0040] Cross-region log sharing can improve the success rate of attack attribution.

[0041] To solve the above-mentioned technical problems, the present invention provides the following technical solution: a mimicry defense system for power monitoring systems based on dynamic heterogeneous redundancy, which is constructed using the aforementioned mimicry defense architecture for power monitoring systems based on dynamic heterogeneous redundancy.

[0042] A computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the steps of a dynamic heterogeneous redundancy-based power monitoring system mimicry defense architecture as described above.

[0043] A computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of a biomimetic defense architecture for a power monitoring system based on dynamic heterogeneous redundancy as described above.

[0044] The beneficial effects of this invention are as follows: By constructing a collaborative architecture of physical layer, twin layer, simulation layer, and application layer, and leveraging digital twin technology, a precise mapping between the virtual environment and the physical power monitoring system is achieved, providing a realistic virtual carrier for anomaly detection and attack simulation; its parsing and simulation support for power-specific protocols improves the adaptability of the defense architecture to power business logic; each layer ensures the normal operation of the power monitoring system is undisturbed through encrypted communication and reasonable resource control; at the same time, replacing the traditional physical testing environment with a digital twin reduces the cost of building and maintaining the defense system, improves management efficiency, and lays a business-adaptive, efficient, and reliable foundation framework for the security protection of the power monitoring system. Attached Figure Description

[0045] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0046] Figure 1 This is a schematic diagram of a mimicry defense architecture for a power monitoring system based on dynamic heterogeneous redundancy, as shown in Example 1. Detailed Implementation

[0047] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0048] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.

[0049] Example 1, referring to Figure 1 This is the first embodiment of the present invention, which provides a mimicry defense architecture for a power monitoring system based on dynamic heterogeneous redundancy, including:

[0050] It includes a physical layer, a twin layer, and a simulation layer; each layer interacts with data through an encrypted channel.

[0051] The physical layer includes the actual equipment and defense equipment of the power monitoring system. The actual equipment is distributed in multiple isolated areas. The actual equipment includes servers (such as SCADA servers), switches, RTU devices, PLCs, etc., distributed in isolated areas such as headquarters, dispatching stations, and substations. The defense equipment includes IDS (Intrusion Detection System), firewalls, etc., for the initial interception of known threats.

[0052] The twin layer is deployed on computing nodes in various regions, preferably configured with 8C16G to meet real-time synchronization requirements. It runs digital twin software, which is developed based on C++ (integrating OSIsoft PI real-time database). The digital twin is built based on the physical layer topology, device parameters and business processes, and achieves state synchronization by collecting physical layer operation data in real time through sensors.

[0053] The simulation layer is deployed on a cloud platform (preferably with a 16C32G configuration) and runs an attack scenario simulation engine to reproduce the attack process, test and optimize defense strategies in a digital twin.

[0054] Each layer communicates through an encrypted channel and includes an application layer, which comprises an anomaly detection platform, a policy management platform, and a collaborative defense center, used for parameter configuration, alarm viewing, and policy optimization.

[0055] The construction of a digital twin includes:

[0056] Using 3D modeling technology (preferably using the Unity engine) to recreate the hardware parameters of physical devices (such as the number of CPU cores, memory capacity, and port configuration), network topology (link bandwidth, routing strategy), and business logic (such as the telemetry / telecommunications process of the SCADA system) reduces the error rate of static modeling.

[0057] It supports the parsing and simulation of power-specific protocols to simulate the protocol interaction process of physical systems; it supports the parsing and simulation of power-specific protocols (IEC61850, Modbus, DL / T645), and can simulate processes such as MMS message sending and receiving, and Modbus command interaction.

[0058] Real-time data collection of physical system operation is achieved through sensors and synchronized to the twin to ensure consistency with the physical device's state. Real-time data collection of physical system operation (CPU utilization, network traffic, control commands, etc.) is achieved through industrial sensors (such as network traffic probes and device status sensors) and synchronized to the twin every 100ms to ensure that the state deviation between the twin and the physical device is ≤2% (e.g., if the server CPU utilization is 40% in the physical system, it is 39%-41% in the twin).

[0059] In summary, by constructing a collaborative architecture encompassing the physical layer, twin layer, simulation layer, and application layer, and leveraging digital twin technology, a precise mapping between the virtual environment and the physical power monitoring system is achieved, providing a realistic virtual platform for anomaly detection and attack simulation. Its support for parsing and simulating power-specific protocols enhances the adaptability of the defense architecture to power business logic. Encrypted communication and reasonable resource control at each layer ensure the uninterrupted operation of the power monitoring system. Furthermore, replacing the traditional physical testing environment with a digital twin reduces the cost of building and maintaining the defense system, improves management efficiency, and lays a business-adaptive, efficient, and reliable foundation for the security protection of the power monitoring system.

[0060] Example 2 is the second embodiment of the present invention, which differs from the first embodiment in that: the twin layer further includes an anomaly detection mechanism based on behavioral baselines, the anomaly detection mechanism including:

[0061] Establish a baseline for device behavior and statistically analyze the normal range of operating parameters for a single device; statistically analyze the normal operating parameters for a single device, such as the baseline CPU utilization of a SCADA server being 30%-50%, memory usage ≤80%, and the number of connections on port 80 ≤10; and the number of connections on port 502 (Modbus protocol) of an RTU device being ≤5.

[0062] Establish a network behavior baseline and analyze the normal patterns of traffic characteristics, protocol distribution, and communication frequency within the region; analyze the traffic characteristics within the region, such as the average daily traffic in the production area and test area being ≤10GB, the proportion of IEC61850 messages being ≥80%, and the RTU device sending telemetry data once every 5 seconds.

[0063] Establish a baseline for business behavior, record the sending patterns of control commands and the normal rules for data modification permissions; record the patterns of control commands, for example, scheduling commands are mostly sent between 9:00 and 17:00, and only the administrator IP can modify the set parameters.

[0064] When the behavior of the physical system deviates from the baseline threshold, it is marked as an abnormal event and an alarm is triggered. For example, when the CPU utilization suddenly increases by 30% or when an unauthorized IP sends control commands, it is immediately marked as an abnormal event and an alarm is triggered, which is then pushed to the application layer anomaly detection platform.

[0065] In an optional embodiment, the attack scenario simulation and defense strategy optimization of the simulation layer includes:

[0066] The simulation layer has a built-in library of typical attack scenarios in the power industry (such as Modbus protocol tampering, IEC61850 message forgery, and PLC firmware implantation), and supports custom scenarios (such as attack chains targeting new zero-day vulnerabilities).

[0067] Inject attack traffic (such as sending malformed MMS packets) into the twin, observe the system response (such as whether it triggers circuit breaker malfunction), and record the attack path and scope of impact; adjust the defense strategy based on the simulation results. For example, in the initial strategy, the firewall only blocks Modbus packets with a length >1024 bytes, with an interception rate of only 30%; through multiple rounds of simulation, the threshold is adjusted to 256 bytes, and unauthorized IPs are blocked, increasing the interception rate to 99%.

[0068] The optimized strategy is synchronized to the physical layer defense devices via an encrypted channel and deployed.

[0069] In an optional embodiment, taking "a substation SCADA system suffering a Modbus protocol tampering attack" as an example, the process is as follows:

[0070] The attack source (unauthorized IP 192.168.1.200) sent a malformed Modbus message of 512 bytes to the RTU in an attempt to tamper with telemetry data;

[0071] After the twin synchronized the traffic, it detected a sudden increase in the number of connections on port 502 to 15 (exceeding the baseline threshold of 5), a packet length exceeding 256 bytes (exceeding the baseline threshold), and unauthorized IP sending commands (violating the business baseline), triggering a "high-risk anomaly" alarm;

[0072] The attack was reproduced at the simulation layer. After testing and optimizing the strategy, it was synchronized to the physical firewall and deployed within 2 hours, successfully blocking subsequent attacks.

[0073] Technical Effects: This embodiment overcomes the limitations of traditional feature matching technology in identifying unknown threats, improving the detection rate, especially for zero-day vulnerability exploits and protocol malformation attacks. Applying this architecture to substations can prevent power outages caused by circuit breaker malfunctions.

[0074] Example 3 is the third embodiment of the present invention, which differs from the previous two embodiments in that it also includes a cross-regional twin cooperative defense mechanism;

[0075] Coordinated defense mechanisms include:

[0076] A twin registration center is set up at the headquarters to record the network address, coverage area and online status of twins in each region. The registration center is also set up at the headquarters to record the IP address, coverage area (e.g., the regional dispatch twin A covers 10 substations) and online status of twins in each region, serving as a hub for collaborative communication.

[0077] When a regional twin detects an anomaly (such as APT attack signatures), it pushes early warning information (such as attack IP address and signature) to related regional twins through the registry center. For example, if a regional dispatch SCADA system is attacked, the attack signature will be synchronized to three related substations within one hour to prevent the attack from spreading.

[0078] The headquarters twin generates a unified defense strategy template based on the overall threat situation and distributes it to regional twins. The regional twins then fine-tune the templates based on local characteristics (such as device models and protocol types within the region) and synchronize them to the physical devices.

[0079] Multi-region twins share attack logs (such as traffic records and login logs), and reconstruct the entire attack path (such as the penetration process from the external network → DMZ area → production area) through correlation analysis.

[0080] It also includes an exception handling mechanism, which includes:

[0081] When communication between the physical layer and the twin layer is interrupted, the twin uses locally cached historical data to predict the system state, and automatically calibrates after communication is restored.

[0082] When the deviation between the twin simulation results and the physical system exceeds the preset range, model optimization is automatically initiated; when the defense strategy fails to be synchronized to the physical device, a manual intervention process is triggered, and the strategy status is marked in the twin.

[0083] When multiple abnormal events are detected simultaneously, an "area isolation" simulation is automatically initiated to assess the feasibility of severing the area link in order to prevent the attack from spreading.

[0084] In an optional embodiment, after a dispatch center is attacked, a cross-regional coordination mechanism is used:

[0085] The three associated substations implemented a synchronized defense strategy within one hour, with only one substation being slightly affected (in the traditional approach, the impact would spread to all three within 24 hours).

[0086] Multi-region twins share logs, allowing attack paths to be reconstructed within 2 hours (traditional log auditing has a success rate of less than 50% due to log tampering), avoiding a complete system shutdown (traditional handling methods caused losses of over 1 million yuan).

[0087] Anomaly detection mechanisms based on behavioral baselines can improve the identification rate of unknown threats;

[0088] Digital twin simulation environments can reduce the cost of verifying defense strategies;

[0089] Anomaly synchronization and policy coordination mechanisms can shorten attack propagation time;

[0090] Cross-region log sharing can improve the success rate of attack attribution.

[0091] Technical effects: This embodiment reduces the attack propagation time from 24 hours to 1 hour and increases the source tracing success rate from 50% to 90% through global collaboration and anomaly handling mechanisms, significantly improving the anti-attack capability and business continuity of the power monitoring system.

[0092] Example 4 is the fourth embodiment of the present invention, which differs from the previous three embodiments in that: a power monitoring system mimicking defense system based on dynamic heterogeneous redundancy is constructed using a power monitoring system mimicking defense architecture based on dynamic heterogeneous redundancy.

[0093] This embodiment also provides a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the biomimetic defense architecture of the power monitoring system based on dynamic heterogeneous redundancy proposed in the above embodiment.

[0094] This embodiment also provides a computer-readable storage medium storing a computer program thereon. When the computer program is executed by a processor, it implements the biomimetic defense architecture of the power monitoring system based on dynamic heterogeneous redundancy proposed in the above embodiment.

[0095] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0096] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device.

[0097] More specific examples of computer-readable media (a non-exhaustive list) include: electrical connections (electronic devices) having one or more wires, portable computer disk drives (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.

[0098] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented in combination with any of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0099] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

Claims

1. A mimicry defense architecture for a power monitoring system based on dynamic heterogeneous redundancy, characterized in that: include, It includes the physical layer, twin layer, and simulation layer; The physical layer includes the actual equipment and defense equipment of the power monitoring system, and the actual equipment is distributed in multiple isolated areas; The twin layer is deployed on computing nodes in each region and runs digital twin software. The digital twin is built based on the topology, device parameters and business processes of the physical layer, and achieves state synchronization by collecting physical layer operation data in real time through sensors. The simulation layer is deployed on a cloud platform and runs an attack scenario simulation engine to reproduce the attack process, test and optimize defense strategies in a digital twin. Each layer communicates through an encrypted channel and includes an application layer, which comprises an anomaly detection platform, a policy management platform, and a collaborative defense center for parameter configuration, alarm viewing, and policy optimization.

2. The biomimetic defense architecture for a power monitoring system based on dynamic heterogeneous redundancy as described in claim 1, characterized in that: The construction of the digital twin includes: Three-dimensional modeling technology is used to recreate the hardware parameters, network topology, and business logic of physical devices; It supports the parsing and simulation of power-specific protocols to simulate the protocol interaction process of physical systems; The system collects real-time operational data from the physical system using sensors and synchronizes it to the twin to ensure consistency with the physical device's state.

3. The biomimetic defense architecture for a power monitoring system based on dynamic heterogeneous redundancy as described in claim 2, characterized in that: The twin layer also includes an anomaly detection mechanism based on behavioral baselines, the anomaly detection mechanism comprising: Establish equipment behavior baselines and statistically analyze the normal range of operating parameters for individual devices; Establish a network behavior baseline and analyze the normal patterns of traffic characteristics, protocol distribution, and communication frequencies within the region; Establish a baseline for business behavior and record the patterns of control command transmission and normal rules for data modification permissions; When the behavior of the physical system deviates from the baseline threshold, it is marked as an abnormal event and an alarm is triggered.

4. The biomimetic defense architecture for a power monitoring system based on dynamic heterogeneous redundancy as described in claim 3, characterized in that: The attack scenario simulation and defense strategy optimization of the simulation layer include: It has a built-in attack scenario library of typical attack scenarios in the power industry, and also supports custom attack scenarios; Inject attack traffic into the digital twin, observe the system response and record the attack path and scope of impact; adjust the defense strategy based on the simulation results, and determine the optimal strategy through multiple rounds of simulation; The optimized strategy is synchronized to the physical layer defense devices via an encrypted channel and deployed.

5. The biomimetic defense architecture for a power monitoring system based on dynamic heterogeneous redundancy as described in claim 4, characterized in that: It also includes cross-regional twin collaborative defense mechanisms; The collaborative defense mechanism includes: A twin registration center is set up at headquarters to record the network address, coverage area and online status of twins in each region; When an anomaly is detected in a certain region's twin, an early warning message is pushed to the twins in related regions through the registry center; The headquarters twin generates a unified defense strategy template based on the overall threat situation and distributes it to regional twins. The regional twins then fine-tune the templates based on local characteristics and synchronize them to the physical devices. Multi-region twins share attack logs, and the entire attack path can be reconstructed through correlation analysis.

6. The biomimetic defense architecture for a power monitoring system based on dynamic heterogeneous redundancy as described in claim 5, characterized in that: It also includes an exception handling mechanism, which includes: When communication between the physical layer and the twin layer is interrupted, the twin uses locally cached historical data to predict the system state, and automatically calibrates after communication is restored. When the deviation between the twin simulation results and the physical system exceeds the preset range, model optimization is automatically initiated; when the defense strategy fails to be synchronized to the physical device, a manual intervention process is triggered, and the strategy status is marked in the twin. When multiple abnormal events are detected simultaneously, an "area isolation" simulation is automatically initiated to assess the feasibility of severing the area link in order to prevent the attack from spreading.

7. The biomimetic defense architecture for a power monitoring system based on dynamic heterogeneous redundancy as described in claim 6, characterized in that: The aforementioned anomaly detection mechanism based on behavioral baselines can improve the identification rate of unknown threats; The digital twin simulation environment can reduce the cost of verifying defense strategies; The aforementioned abnormal event synchronization and strategy coordination mechanism can shorten the attack propagation time; Cross-region log sharing can improve the success rate of attack attribution.

8. A mimicry defense system for power monitoring systems based on dynamic heterogeneous redundancy, characterized in that: The system is constructed using a dynamic heterogeneous redundancy-based mimicry defense architecture for power monitoring systems, as described in any one of claims 1 to 7.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, it implements the steps of the biomimetic defense architecture for a power monitoring system based on dynamic heterogeneous redundancy as described in any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, it implements the steps of the biomimetic defense architecture for a power monitoring system based on dynamic heterogeneous redundancy as described in any one of claims 1 to 7.

Citation Information

Cited By

  • Mine intelligent ventilation control method and system

    CN121184171A

  • Mine intelligent ventilation management method and system

    CN121184171B

  • Ship network security target range simulation device based on digital twinning and experimental platform

    CN121690732A