Threat alarm database management system
By utilizing the alarm collection and preprocessing, quantitative assessment, and dynamic response modules of the threat alarm database management system, the problem of inaccurate monitoring of access requests in the power grid database was solved, enabling rapid response and sharing, and reducing the risk of repeated attacks.
Patent Information
- Application Number
- CN202510928261.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-07
- Publication Date
- 2025-11-28
AI Technical Summary
Traditional alarm database management systems for power grid databases suffer from inaccurate monitoring of access requests, resulting in massive data volumes, resource waste, and slow response times. Furthermore, the lack of effective dynamic response and sharing mechanisms exposes similar power grid databases to the risk of repeated attacks.
The threat alert database management system includes: an alert collection and preprocessing module, a threat quantification and assessment module, and a dynamic response and sharing module. It can filter and quantify threat access requests in real time, and dynamically respond to and share threat access request addresses.
It effectively filters out normal access requests, reduces data volume, improves response speed, identifies persistent threats through multi-cycle analysis, enables rapid response and sharing, and reduces the risk of repeated attacks.
Smart Images

Figure CN121037005A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of power system network security technology, specifically, it relates to a threat alarm database management system. Background Technology
[0002] With rapid economic development, the power system plays a crucial role in the informatization process. As the core of the power system, the power grid database stores massive amounts of critical data, including the grid's operating status, user information, and equipment parameters. This data is a vital foundation for the safe and stable operation of the power grid and serves as the basis for decisions regarding grid dispatching, fault handling, and operation and maintenance. In the field of cybersecurity, especially in the protection of critical infrastructure such as power grids, traditional alarm database management systems have many shortcomings. Existing technologies, when monitoring and processing access requests, generally perform comprehensive processing, failing to filter out a large amount of legitimate access request data. This results in a massive amount of data to be processed, wasting system resources and affecting the timely detection and response speed to potential threats. Furthermore, existing technologies lack effective dynamic response and sharing mechanisms for power grid databases when facing threatening access request addresses. They cannot quickly share data with other similar power grid databases or database systems, leaving other similar power grid databases or database systems at risk of being repeatedly attacked by the same threat source. To address the aforementioned problems, this invention proposes a threat alert database management system. Summary of the Invention
[0003] To address the shortcomings of existing technologies, this invention provides a threat alert database management system, which solves the problems of insufficient real-time monitoring, accurate quantitative assessment, and rapid response sharing in existing technologies.
[0004] The objective of this invention can be achieved through the following technical solutions: Threat Alert Database Management System. This system includes: The alarm acquisition and preprocessing module interacts with the power grid database, extracts several access request data in real time based on the power grid database, removes normal access request data, and filters and retains alarm access request data. Based on the determined alarm access request data, further extract the alarm access request address associated with the corresponding alarm access request, and extract the access request data requested by this alarm access request address within the backtracking period. The threat quantification and assessment module simultaneously extracts access request data associated with alarm access request addresses within several backtracking periods, and constructs a line graph showing the change in the total number of alarm access request data. And based on the line graph showing the change in the total number of alarm access request data, it is determined whether the alarm access request address is a threat access request address; The dynamic response and sharing module blocks the identified threat access request addresses and extracts several threat access request addresses associated with this power grid database, which are then transmitted to the threat alarm database for storage and sharing.
[0005] As a further aspect of the present invention, in the alarm collection and preprocessing module, the access request data includes the access request address and the number of access request authentication failures.
[0006] As a further aspect of the present invention, the threat alert database is a shared database of several threat alert database management systems; The threat alert database is used to store threat access request addresses and share them with the threat alert database management system that interacts with this threat alert database, so as to perform pre-protection of threat access request addresses.
[0007] As a further aspect of the present invention, the specific method for filtering and retaining alarm access request data in the alarm acquisition and preprocessing module, after removing normal access request data, is as follows: At the current moment, retrieve access request data from several pairs of power grid databases, the total number of which is denoted as . ; By acquisition time Sort the access request data to obtain the access request data sequence. ; Sure Any access request data ,in, For counting index, ; from Separate access request address and the number of times access request authentication failed. ; right An assessment will be conducted, if ,Will Data marked as a normal access request, and in Remove from the middle; like ,Will Access request data marked as a suspected alarm; extract The time interval between authentication failures of any adjacent set of associated access requests; If there is an extracted time interval that is less than the time interval threshold ,Will Record alarm access request data and mark it as And retain, where the time interval threshold Preset by the operator; Conversely, then Record this as normal access request data and discard it.
[0008] As a further aspect of the present invention, the specific method for extracting the access request data requested by the alarm access request address within the backtracking period in the alarm acquisition and preprocessing module is as follows: S51. Extract alarm access request data The associated access request address is denoted as the alarm access request address and marked as... ; S52. Obtain the backtracking cycle and its duration preset by the operator. ; S53. Take the current time as the end time of the backtracking cycle, denoted as... ; S54, in Based on the time spent looking back to the past The start time of this backtracking cycle is obtained and denoted as . ; S55, at to Inside, the access request address is obtained as All access request data are collected and sorted in chronological order, and recorded as the alarm access request data sequence.
[0009] As a further aspect of the present invention, the specific method for constructing the line curve showing the change in the total number of alarm access request data in the threat quantification assessment module is as follows: Extract alarm access request address In the backtracking cycle The sequence of alarm access request data associated with it; Determine the total number of alarm access request data in this alarm access request data sequence, denoted as . ,in, Preset values for operators; Based on the backtracking period determined in steps S53 to S54, continue to retrieve data from the past. -1 backtracking cycle ; Sure -1 backtracking cycle The internal access request address is of -1 alarm access request data sequence; Sure -1 alarm access request data sequence associated with -1 total number of alarm access request data, along with Sort the data according to the timeline to obtain the sequence of the total number of alarm access requests. ; Construct a two-dimensional coordinate system with the timeline as the horizontal axis and the total number of alarm access request data as the vertical axis. In The total number of alarm access request data is marked on a two-dimensional coordinate system. One data point; Connect any two adjacent data points with a short line to obtain a broken line, which can be denoted as the broken line representing the change in the total number of alarm access request data. .
[0010] As a further aspect of the present invention, the specific method for determining whether the alarm access request address is a threat access request address in the threat quantification assessment module is as follows: Linear graph showing the change in the total number of alarm access requests. The slope between adjacent data points, in chronological order along the timeline, is denoted as a slope sequence. ,in, This represents the slope between the first and second data points, and so on for the remaining slopes; extract A slope group is formed by p or more consecutive slopes with a slope greater than 0, where p is a value preset by the operator. Similarly, we can obtain Among all slope groups, extract the slope group with the largest increase in the total number of alarm access request data. If there is no slope group, then determine If the access request address is not a threat, no action will be taken. If the increase in the total number of alarm access request data in this slope group exceeds the threshold for the increase in the total number of alarm access request data preset by the operator, then it is determined that... This is a threat access request address; Conversely, then determine If the access request address is not a threat, no action will be taken.
[0011] As a further aspect of the present invention, the specific method for extracting the increment of the total number of alarm access request data in the threat quantification assessment module is as follows: Extracting the slope sequence Any set of slopes in the set of slopes is denoted as . ; Determine the slope group respectively The minimum and maximum total number of alarm access request data are denoted as follows: as well as ; use To obtain the slope group The total number of associated alarm access request data increments .
[0012] As a further aspect of the present invention, in the dynamic response and sharing module, if the alarm access request address is determined... If the address is a threat requesting access, then add this threat requesting address to the blacklist of this power grid database and block access. All threat access request addresses are extracted and transmitted to the threat alert database for storage and sharing.
[0013] The beneficial effects of this invention are: This invention distinguishes between normal access failures and potential high-frequency malicious attack attempts by analyzing the number of authentication failures and the time interval between adjacent failures. It effectively eliminates a massive amount of interfering "normal failed requests" and retains only the truly suspicious alarm access request data, greatly reducing the amount of data and false alarm interference in subsequent analysis. Secondly, the preset backtracking cycle mechanism allows for the automatic association and extraction of all relevant request data from the same attack source (access request address) within the historical window period after an alarm is confirmed, forming a complete time series. This design supports the correlation analysis and contextual tracing of attack behavior without the need for manual sifting through massive amounts of logs, quickly presenting key information such as the attacker's probing patterns and frequency changes. This invention constructs a historical line chart of the total number of alarm access request data through a multi-cycle backtracking mechanism, expanding alarm data at a single point in time into a visualized behavioral trend trajectory. Combined with a slope group analysis algorithm (identifying intervals with continuously rising slopes > 0), it intelligently filters out abnormal patterns where the attack frequency shows a continuous and accelerating increase, effectively filtering out occasional interference. In particular, by calculating the total jump of the maximum incremental slope group, it directly quantifies the escalation intensity of the attack behavior and compares it with a preset threshold for automated threat classification. This avoids the lag of traditional static threshold alarms and can more proactively detect "gradual attacks" that are still in the planning stages, providing operators with an early warning window. Attached Figure Description
[0014] The invention will now be further described with reference to the accompanying drawings.
[0015] Figure 1 This is a schematic diagram of the system described in this invention; Figure 2 This is a flowchart illustrating the method described in Embodiment 2 of the present invention; Figure 3 This is a flowchart illustrating the method described in Embodiment 3 of the present invention. Detailed Implementation
[0016] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0017] Example 1 Threat alert database management system, such as Figure 1 As shown, it specifically includes the following: This system, the Threat Alarm Database Management System, serves the power grid database and acts as its "antivirus software." Its primary purpose is to intercept and identify threat access requests, and to shield and share these requests. Shielding refers to identifying the threat access request address and directly blocking and denying access when that address attempts to access the power grid database. Sharing refers to sending the threat access request address to the threat alarm database, enabling all threat alarm database management systems interacting with it to promptly extract different threat access request addresses and identify and proactively protect against such requests when they are received by the corresponding power grid database.
[0018] The threat alert database management system mainly includes: an alert collection and preprocessing module, a threat quantification and assessment module, a dynamic response and sharing module, and the threat alert database mentioned above. The threat alert database is a shared database of several threat alert database management systems.
[0019] Specifically, the alarm acquisition and preprocessing module is the entry point of this system. It continuously monitors and connects to the power grid database, that is, it interacts with the power grid database in real time. When the power grid database receives access request data, it extracts and preprocesses it. The purpose of the preprocessing is to remove normal access request data (because it is normal, it does not need to be processed and can be allowed directly) from the extracted access request data, and filter out alarm access request data and retain it.
[0020] Next, in this module, it is also necessary to extract the access request address of the determined alarm access request data, name it alarm access request address (for easy distinction), and obtain the backtracking period preset by the operator for this threat alarm database management system. Within this backtracking period, extract all access request data associated with this alarm access request address. It should be explained here that the access request data includes the access request address and the number of times the access request authentication failed.
[0021] The threat quantification and assessment module receives alarm access request data from the preprocessing module (mainly extracting alarm access request addresses from the alarm access request data). Based on the methods described in the alarm collection and preprocessing module, this module traces back several traceback periods and extracts all access request data associated with this alarm access request address in several traceback periods (grouping and distinguishing the extracted access request data according to their respective traceback periods).
[0022] Determine the total number of alarm access request data associated with each backtracking period (one alarm access request data is considered as the total number of alarm access request data plus one), construct a curve representing the change in the total number of alarm access request data based on the total number of alarm access request data, and then quantify the threat of this alarm access request address based on the slope of the constructed curve representing the change in the total number of alarm access request data, and determine whether this alarm access request address is a threat access request address.
[0023] The dynamic response and sharing module, once it determines that any alarm access request address is a threat access request address, immediately intercepts and blocks the determined threat access request address, directly denying the threat access request address's access request to the power grid database.
[0024] The identified threat access request address is then transmitted to the threat alert database. This database serves as a shared platform for all threat alert database management systems and power grid databases that interact with it, enabling collaborative defense with the principle of "detection in one place, immunity across the entire network."
[0025] This embodiment introduces a threat alarm database management system for a power grid database, which aims to intercept and identify threat access requests, and realize the shielding and sharing of threat requests; it includes an alarm collection and preprocessing module, a threat quantification and assessment module, a dynamic response and sharing module, and a shared threat alarm database.
[0026] Its workflow is as follows: The alarm collection and preprocessing module monitors the power grid database in real time, extracts access request data, removes normal requests, and filters out alarm access request data; then it extracts the access request address and obtains relevant access request data in combination with a preset backtracking period; the threat quantification and assessment module receives alarm data, backtracks multiple periods to extract data and constructs a change line to quantify and assess the threat; the dynamic response and sharing module intercepts threat access requests, denies their access, and transmits the threat address to the threat alarm database for sharing, so as to achieve collaborative defense.
[0027] Example 2 This embodiment, based on Embodiment 1, discloses a method for determining an alarm access request address and obtaining access request data associated with that alarm access request address within a traceback period, such as... Figure 2 As shown, the specific steps include the following: As described in Example 1, the alarm collection and preprocessing module needs to preprocess the acquired access request data: First, determine the current time as the time to extract access request data. At the current time, determine several access request data that initiate access requests to any power grid database (take any power grid database as an example for processing).
[0028] Count the total number of all access request data determined at this current moment, and record it as . and the determined Each access request data is based on the The acquisition time associated with each access request data is sorted, and the result after sorting is denoted as the access request data sequence, as follows: .
[0029] Based on the determined access request data sequence Extract any one of the access request data and mark it as... ,in, This is a counting index, with values ranging from 1 to... .
[0030] As described in Example 1, the access request data includes the access request address and the number of access request authentication failures. From the extracted access request data... Extract access request data from The associated access request address is marked as and the number of times access request authentication failed. .
[0031] Next, the access request data Number of times the associated access request authentication failed The system will assess and determine the number of times the access request authentication failed. Is the value 0? If it is 0, it indicates that data is being requested. If the access is successfully verified on the first visit (the access verification is existing technology and will not be elaborated on in this solution), it can be considered a secure access, and the access request data will be sent to the appropriate location. Data marked as normal access request data, and included in the access request data sequence. Perform a removal operation (on the access request data) The associated access request address Released).
[0032] If there are a number of failed access request authentication attempts A value greater than 0 indicates that this access request data... If the access fails the access verification on the first visit, the access request data will be immediately sent. Data is marked as a suspected alarm access request for further evaluation.
[0033] Extract this access request data Number of times the associated access request authentication failed And determine the time interval when authentication fails for any two adjacent access requests. If the time interval when authentication fails for any two adjacent access requests is less than the time interval threshold, then... (i.e., frequently initiating access requests within a short period of time), then the access request data will be... Data marked as an alarm access request is denoted as , and retain.
[0034] Similarly, if the time interval is greater than or equal to the time interval threshold Then the access request data will be processed. Data marked as normal access request data, and included in the access request data sequence. Perform the removal operation in the middle; The time interval threshold mentioned above The operator shall determine this based on the actual situation.
[0035] At this point, the alarm access request data has been identified. (The following content pertains to alarm access request data) Process it if the access request data is determined. If the request is for normal data access, then the following processing is not required. Extract alarm access request data again The associated access request address is marked as the alarm access request address, denoted as... ; Obtain the backtracking period determined by the operator based on the actual situation, and mark the duration of the determined backtracking period as... .
[0036] Re-determine the current time as the end time of a backtracking cycle, denoted as . At the end of the time Based on the time spent looking back to the past The start time of this backtracking cycle is obtained and denoted as . That is, the time from which this backtracking period begins. Beginning, until the moment Finish.
[0037] Then, at the determined backtracking period, i.e., the start time... Until the end time Within, extract all access request addresses as alarm access request addresses. The access request data is extracted and sorted according to the timeline (that is, the time when each access request data is associated with the initiation time). The sorted result is recorded as the alarm access request data sequence.
[0038] The purpose of this embodiment is to realize real-time monitoring and filtering of power grid database access requests, distinguishing between normal access and suspicious access; accurately filtering potential threat access requests through a preprocessing process to prepare for subsequent threat assessment and protection; and dynamically identifying abnormal behaviors such as frequent access within a short period of time by using parameters such as time interval thresholds, thereby improving the ability to identify threat access and the response speed.
[0039] Example 3 This embodiment discloses a method for determining the address of a threat access request, based on Embodiments 1 and 2. Figure 3 As shown, the specific steps include the following: Based on Example 2, the alarm access request address can be obtained. In a backtracking cycle The associated alarm access request data sequence within this backtracking period It is a backtracking cycle with the current time as the end time, so this backtracking cycle is the one closest to the current time; Determine the total number of alarm access request data in the alarm access request data sequence associated with this backtracking period, and mark it as... ,in, Preset values for operators.
[0040] Next, based on this backtracking cycle, we continue to retrieve data from the past. -1 backtracking cycle Together with the most recent backtracking period total One backtracking cycle.
[0041] Then, following the method described above, extract the newly determined... -1 backtracking cycle The internal access request address is the alarm access request address. The alarm access request data sequence can be obtained in total. -1 alarm access request data sequence, then extract the determined... The total number of alarm access request data associated with each of the -1 alarm access request data sequences can be obtained. -1 Total number of alarm access request data.
[0042] The obtained -1 total number of alarm access request data and total number of alarm access request data The data is summarized and sorted according to the timeline. The sorted result is recorded as the sequence of the total number of alarm access request data, represented as: .
[0043] Next, a two-dimensional coordinate system is constructed with the horizontal axis representing the timeline and the vertical axis representing the total number of alarm access request data. Then, the determined sequence of the total number of alarm access request data is... In The total number of alarm access request data is marked on the constructed two-dimensional coordinate system, which yields... Each data point is used as a starting point, and adjacent data points are connected sequentially with short lines to obtain a broken line, named: "Line Chart of Changes in Total Number of Alarm Access Requests". .
[0044] Linear graph showing the change in the total number of alarm access requests obtained. Calculate the slope of the line segment formed by all adjacent data points (that is, assess the degree of change in the total number of alarm access request data between two adjacent backtracking periods; a slope greater than 0 indicates that the total number of alarm access request data increases compared to the previous backtracking period, and the larger the value, the greater the increase; similarly, a slope less than 0 indicates that the total number of alarm access request data increases compared to the previous backtracking period, and the smaller the value, the greater the decrease; if the slope is equal to 0, it indicates that the total number of alarm access request data remains unchanged compared to the previous backtracking period).
[0045] Next, sort the slopes between all adjacent data points according to the timeline. The sorted result is denoted as a slope sequence, and is represented as follows: ,in, This represents the slope between the first and second data points, and so on for the remaining slopes; Then from the determined slope sequence Extract several continuous slopes with a slope greater than 0 to form a slope group. The total number of slopes in the slope group is greater than or equal to p, where p is a value preset by the operator based on the actual situation.
[0046] Determine the slope sequence using this method. Among all the slope groups, the group with the largest increase in the total number of alarm access request data was further identified; The specific method for determining the increment of the total number of alarm access request data is as follows: Extracting the slope sequence Any one of the slope groups that exists in the equation (taking any one slope group as an example). Determine the total number of alarm access request data in the slope group that has the smallest total number of alarm access request data, and denot it as . ; Next, determine the total number of alarm access request data with the largest total number of alarm access request data in this slope group, and denot it as... ; By adopting: The total number of alarm access request data increments was obtained. .
[0047] Determine whether the increase in the total number of alarm access request data of the slope group with the largest increase in the total number of alarm access request data exceeds the threshold for the total number of alarm access request data increment preset by the operator based on the actual situation. If the increase in the total number of alarm access request data for this slope group exceeds the threshold for the increase in the total number of alarm access request data, then this change in the total number of alarm access request data is identified as a broken line. The associated alarm access request address This is a threat access request address; If the increase in the total number of alarm access request data in this slope group exceeds or does not exceed the threshold for the increase in the total number of alarm access request data, then the change in the total number of alarm access request data is determined as a broken line. The associated alarm access request address If the access request address is not a threat, no action will be taken.
[0048] This embodiment first determines the total number of alarm access request data related to the alarm access request address in the most recent backtracking period. Then, it continues to acquire relevant data from several past backtracking periods to form multiple alarm access request data sequences and total numbers. Next, it constructs a two-dimensional coordinate system, draws a polyline of the change in the total number of alarm access request data, calculates the slope of the line segments between adjacent data points, and forms a slope sequence. Then, it extracts continuous slope groups with a slope greater than 0, finds the slope group with the largest increase in the total number of alarm access request data, and determines whether its increase exceeds a preset threshold, thereby determining whether the alarm access request address is a threat access request address. The purpose of this embodiment is to accurately identify threatening access request addresses by analyzing the changing trends of alarm access request data, thereby achieving effective protection of the power grid database and realizing the technical effect of accurately assessing threatening access request addresses.
[0049] All data in the formulas described above are numerical calculations performed with dimensions removed. Furthermore, any content not described in detail in this specification is existing technology known to those skilled in the art.
[0050] The above description is merely an example and illustration of the present invention. Those skilled in the art can make various modifications or additions to the specific embodiments described, or use similar methods to replace them, as long as they do not deviate from the invention or exceed the scope defined in the claims, all of which should fall within the protection scope of the present invention.
[0051] It should be stated that all user data collected in this application was collected with the user's consent and authorization. Furthermore, the uses of user data are legal and compliant, and the use and processing of user data comply with the relevant laws, regulations, and standards of the relevant regions.
Claims
1. A threat alert database management system, characterized in that, This system includes: The alarm acquisition and preprocessing module interacts with the power grid database, extracts several access request data in real time based on the power grid database, removes normal access request data, and filters and retains alarm access request data. Based on the determined alarm access request data, further extract the alarm access request address associated with the corresponding alarm access request, and extract the access request data requested by this alarm access request address within the backtracking period. The threat quantification and assessment module simultaneously extracts access request data associated with alarm access request addresses within several backtracking periods, and constructs a line graph showing the change in the total number of alarm access request data. And based on the line graph showing the change in the total number of alarm access request data, it is determined whether the alarm access request address is a threat access request address; The dynamic response and sharing module blocks the identified threat access request addresses and extracts several threat access request addresses associated with this power grid database, which are then transmitted to the threat alarm database for storage and sharing.
2. The threat alert database management system according to claim 1, characterized in that, In the alarm collection and preprocessing module, the access request data includes the access request address and the number of access request authentication failures.
3. The threat alert database management system according to claim 1, characterized in that, The threat alert database is a shared database of several threat alert database management systems; The threat alert database is used to store threat access request addresses and share them with the threat alert database management system that interacts with this threat alert database, so as to perform pre-protection of threat access request addresses.
4. The threat alert database management system according to claim 1, characterized in that, In the alarm collection and preprocessing module, the specific method for filtering and retaining alarm access request data after removing normal access request data is as follows: At the current moment, retrieve access request data from several pairs of power grid databases, the total number of which is denoted as . ; By acquisition time Sort the access request data to obtain the access request data sequence. ; Sure Any access request data ,in, For counting index, ; from Separate access request address and the number of times access request authentication failed. ; right An assessment will be conducted, if ,Will Data marked as a normal access request, and in Remove from the middle; like ,Will Access request data marked as a suspected alarm; extract The time interval between authentication failures of any adjacent set of associated access requests; If there is an extracted time interval that is less than the time interval threshold ,Will Record alarm access request data and mark it as And retain, where the time interval threshold Preset by the operator; Conversely, then Record this as normal access request data and discard it.
5. The threat alert database management system according to claim 4, characterized in that, In the alarm acquisition and preprocessing module, the specific method for extracting the access request data requested by this alarm access request address within the backtracking period is as follows: S51. Extract alarm access request data The associated access request address is denoted as the alarm access request address and marked as... ; S52. Obtain the backtracking cycle and its duration preset by the operator. ; S53. Take the current time as the end time of the backtracking cycle, denoted as... ; S54, in Based on the time spent looking back to the past The start time of this backtracking cycle is obtained and denoted as . ; S55, at to Inside, the access request address is obtained as All access request data are collected and sorted in chronological order, and recorded as the alarm access request data sequence.
6. The threat alert database management system according to claim 5, characterized in that, In the threat quantification and assessment module, the specific method for constructing the line graph showing the change in the total number of alarm access request data is as follows: Extract alarm access request address In the backtracking cycle The sequence of alarm access request data associated with it; Determine the total number of alarm access request data in this alarm access request data sequence, denoted as . ,in, Preset values for operators; Based on the backtracking period determined in steps S53 to S54, continue to retrieve data from the past. -1 backtracking cycle ; Sure -1 backtracking cycle The internal access request address is of -1 alarm access request data sequence; Sure -1 alarm access request data sequence associated with -1 total number of alarm access request data, along with Sort the data according to the timeline to obtain the sequence of the total number of alarm access requests. ; Construct a two-dimensional coordinate system with the timeline as the horizontal axis and the total number of alarm access request data as the vertical axis. In The total number of alarm access request data is marked on a two-dimensional coordinate system. One data point; Connect any two adjacent data points with a short line to obtain a broken line, which can be denoted as the broken line representing the change in the total number of alarm access request data. .
7. The threat alert database management system according to claim 6, characterized in that, In the threat quantification and assessment module, the specific method for determining whether this alarm access request address is a threat access request address is as follows: Linear graph showing the change in the total number of alarm access requests. The slope between adjacent data points, in chronological order, is denoted as a slope sequence. ,in, This represents the slope between the first and second data points, and so on for the remaining slopes. extract A slope group is formed by p or more consecutive slopes with a slope greater than 0, where p is a value preset by the operator. Similarly, we can obtain Among all slope groups, extract the slope group with the largest increase in the total number of alarm access request data. If there is no slope group, then determine If the access request address is not a threat, no action will be taken. If the increase in the total number of alarm access request data in this slope group exceeds the threshold for the increase in the total number of alarm access request data preset by the operator, then it is determined that... This is a threat access request address; Conversely, then determine If the access request address is not a threat, no action will be taken.
8. The threat alert database management system according to claim 7, characterized in that, The specific method for extracting the increment of the total number of alarm access request data in the threat quantification and assessment module is as follows: Extracting the slope sequence Any set of slopes in the set of slopes is denoted as . ; Determine the slope group respectively The minimum and maximum total number of alarm access request data are denoted as follows: as well as ; use To obtain the slope group The total number of associated alarm access request data increments .
9. The threat alert database management system according to claim 1, characterized in that, In the dynamic response and sharing module, if the alarm access request address is determined... If the address is a threat requesting access, then add this threat requesting address to the blacklist of this power grid database and block access. All threat access request addresses are extracted and transmitted to the threat alert database for storage and sharing.