Security isolation method and system applied to power monitoring system

By capturing real-time operational interaction links and abnormal behavior trajectories within the power monitoring system, generating isolation start commands, and constructing a cross-domain protection linkage framework, the problem of difficult monitoring and response to abnormal behavior of components in the power monitoring system is solved, achieving dynamic security isolation and stable operation of the system.

CN121125229APending Publication Date: 2025-12-12XINYUAN NETWORK TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511296204.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-11
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

Existing power monitoring systems lack effective security measures to monitor and respond to abnormal behavior among internal components, and are inflexible and lack dynamic adaptability, leading to the exploitation of security vulnerabilities and affecting the stable operation of the system.

Method used

By capturing the real-time operational interaction links and abnormal behavior trajectories of various components within the power monitoring system, isolation start commands are generated, and a cross-domain protection linkage framework is constructed, including device-level isolation mechanisms, communication-level blocking rules, and application-level permission locking strategies. Isolation measures are dynamically adjusted to cope with complex security scenarios.

Benefits of technology

It enables timely and accurate response to abnormal behavior of internal components of the power monitoring system, ensures the system's overall isolation status, dynamically adjusts isolation strategies to deal with real-time security threats, and improves the system's security and stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125229A_ABST
    Figure CN121125229A_ABST
Patent Text Reader

Abstract

The invention provides a security isolation method and system applied to an electric power monitoring system, and belongs to the technical field of electric power system security, and the method comprises the steps: firstly capturing a real-time operation interaction link and an abnormal behavior track of each component in the electric power monitoring system, and then generating an isolation starting instruction including an instruction triggering condition and the like; then, a cross-domain protection linkage framework is constructed based on the isolation starting instruction, and protection strategies of an equipment layer, a communication layer and an application layer are integrated; a hierarchical isolation execution plan is generated by using a cross-domain protection linkage framework, and action sequences of all protection domains and the like are defined; and finally, pushing the hierarchical isolation execution plan to a protection execution component, collecting execution state information, updating framework association logic parameters, and keeping a system global isolation situation, thereby effectively improving the security of the power monitoring system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power system security technology, and more specifically, to a security isolation method and system applied to power monitoring systems. Background Technology

[0002] In the field of power monitoring systems, ensuring system security is crucial for the stable operation of the power system. With the increasing intelligence and complexity of power systems, the number of components within power monitoring systems is growing, and the interactions between these components are becoming more frequent and complex. These components include various sensors, controllers, servers, etc., which exchange data and transmit commands through different communication protocols and connection paths.

[0003] However, existing security measures for power monitoring systems have significant shortcomings. On the one hand, traditional security measures primarily focus on preventing external network attacks, such as setting up firewalls and intrusion detection systems, but lack effective monitoring and response mechanisms for abnormal behavior and potential security threats between internal system components. For example, when a component experiences non-compliant access, unauthorized data transmission, or abnormal command issuance, traditional protection methods often fail to detect and handle it in a timely manner, easily leading to the exploitation of security vulnerabilities and affecting the safe and stable operation of the entire power monitoring system. On the other hand, existing security isolation measures are usually static, lacking flexibility and dynamic adaptability. Once an isolation strategy is set, it is difficult to adjust it in a timely manner according to changes in the system's real-time operating status and security threats, failing to effectively cope with complex and ever-changing security scenarios. Summary of the Invention

[0004] In view of the aforementioned problems, and in conjunction with the first aspect of the present invention, embodiments of the present invention provide a security isolation method applied to a power monitoring system, the method comprising: Capture the real-time operation interaction links and abnormal behavior trajectories of various components within the power monitoring system. The real-time operation interaction links include the connection paths between components, the direction of data flow, and the type of interaction protocol. The abnormal behavior trajectories include non-compliant access trajectories, unauthorized data transmission trajectories, and abnormal command issuance trajectories. An isolation start command is generated based on the real-time operation interaction link and abnormal behavior trajectory. The isolation start command includes the command triggering conditions, the list of associated components and the isolation scope definition information. A cross-domain protection linkage framework is constructed based on the isolation startup command. The cross-domain protection linkage framework includes the associated logic of device-level isolation mechanism, communication-level blocking rules and application-level permission locking strategy. The cross-domain protection linkage framework is used to generate a hierarchical isolation execution plan, which includes the action sequence, startup sequence and coordination method of each protection domain. The hierarchical isolation execution plan is pushed to the corresponding protection execution components, the isolation execution status information of each component is collected, and the associated logic parameters of the cross-domain protection linkage framework are updated according to the isolation execution status information to maintain the full-domain isolation status of the power monitoring system.

[0005] In another aspect, embodiments of the present invention also provide a security isolation system for power monitoring systems, including a processor and a machine-readable storage medium connected to the processor. The machine-readable storage medium is used to store programs, instructions, or code, and the processor is used to execute the programs, instructions, or code in the machine-readable storage medium to implement the above-described method.

[0006] Based on the above, this embodiment of the invention captures the real-time operational interaction links and abnormal behavior trajectories of various components within the power monitoring system. This reveals the connection paths between components, data flow directions, interaction protocol types, and abnormal situations such as non-compliant access, unauthorized data transmission, and abnormal command issuance. Based on this information, an isolation activation command is generated, containing command triggering conditions, a list of associated components, and isolation scope definition information. This allows for timely and accurate triggering of isolation operations based on actual security threats, ensuring the targeted nature and effectiveness of isolation actions. A cross-domain protection linkage framework is constructed based on the isolation activation command, integrating device-level isolation mechanisms, communication-level blocking rules, and application-level permission locking strategies. This framework generates a hierarchical isolation execution plan containing action sequences, activation times, and coordination methods for each protection domain. The hierarchical isolation execution plan is pushed to the corresponding protection execution components, and the isolation execution status information of each component is collected. The associated logical parameters of the cross-domain protection linkage framework are updated based on the isolation execution status information, enabling security isolation measures to dynamically adjust according to changes in the system's real-time operating status and security threats. This maintains the overall isolation status of the power monitoring system, ensuring the system always operates in a safe and reliable environment. Attached Figure Description

[0007] Figure 1 This is a schematic diagram of the execution flow of a security isolation method applied to a power monitoring system provided in an embodiment of the present invention.

[0008] Figure 2 This is a schematic diagram of exemplary hardware and software components of a security isolation system applied to a power monitoring system, provided in an embodiment of the present invention. Detailed Implementation

[0009] The present invention will now be described in detail with reference to the accompanying drawings. Figure 1 This is a flowchart illustrating a security isolation method for a power monitoring system according to an embodiment of the present invention. The following is a detailed description of this security isolation method for a power monitoring system.

[0010] This embodiment uses a power monitoring system for an urban power grid as an application scenario. This system includes monitoring equipment for multiple substations, a regional dispatch server, data relay nodes, communication interface devices, and other components. These components interact with each other and transmit commands through various communication protocols. The following details the implementation process of each step of the security isolation method applied to this power monitoring system.

[0011] Step S110: Capture the real-time operation interaction links and abnormal behavior trajectories of each component in the power monitoring system. The real-time operation interaction links include the connection paths between components, the direction of data flow, and the type of interaction protocol. The abnormal behavior trajectories include non-compliant access trajectories, unauthorized data transmission trajectories, and abnormal command issuance trajectories.

[0012] This step utilizes monitoring modules deployed at key locations within the power monitoring system to achieve real-time capture of component operating status. These modules continuously track the connections between components, recording the path data takes from one component to another, identifying the sender and receiver to determine the flow direction, and recognizing the protocol type used in each interaction, such as specific protocols commonly used in power systems. Simultaneously, the monitoring modules monitor component access behavior, data transmission range, and command issuance. When non-compliant access, data transmission exceeding preset ranges, or command issuance deviating from standard procedures are detected, the modules record the occurrence of these anomalies, creating corresponding trajectories.

[0013] Step S111: Collect the operation logs and communication messages of each component through the distributed sensing component of the power monitoring system, parse the component identifier, interaction time and operation type in the operation log, extract the source component information, target component information and protocol fields in the communication message, and construct the original record of component interaction.

[0014] Distributed sensing components are located on various components or connection nodes of the system, enabling real-time collection of operational logs generated by the components and communication messages transmitted between components. For operational logs, the parsing process separates component identifiers, such as "Substation A Monitoring Terminal" or "Dispatch Server Master Node"; records the time information of interactions, i.e., the interaction time; and determines the type of operation performed by the component, such as data reporting, command reception, or connection initiation. For communication messages, it extracts information about the source component sending the message and the target component receiving the message, as well as protocol-related fields contained in the message. This parsed and extracted information is then organized according to a specific format to generate raw records of component interactions, with each record fully reflecting the key information of a single component interaction.

[0015] Step S112: Arrange the original records of the component interactions in chronological order, extract the connection paths between components, mark the direction of data flow between components, identify the protocol type used in each interaction, and integrate them to form a real-time running interaction link.

[0016] The original records of component interactions are arranged chronologically according to the time of the interactions. From these records, the connection paths between components can be identified, showing which intermediate components data travels through from the source component to the target component. Based on the source and target component information, the direction of data flow between components is marked with arrows or similar methods. The protocol type used in the interaction is extracted from each original record. Then, the connection path, data flow direction, and protocol type information are integrated to form a real-time interaction chain that clearly reflects the real-time interaction status of the components.

[0017] Step S113: Establish a normal behavior baseline for the component, which includes the component's normal access method, data transmission range, and instruction issuance specifications.

[0018] A baseline for normal behavior is established by collecting behavioral data of components during long-term normal operation. For conventional access methods, the allowed access channels and authentication conditions for access are clearly defined. For example, a server may only allow access through a specific interface after authentication. The data transmission scope specifies which other components a component can send data to and which components it can receive data from. For example, a monitoring terminal may only transmit data to the dispatch server in its region. Command issuance specifications include the command format, issuance frequency, and recipients. For example, the dispatch server must follow a specific format when issuing commands to the monitoring terminal, and there are certain restrictions on the issuance frequency to the same terminal.

[0019] Step S114: Compare the real-time collected component behavior with the normal behavior baseline, identify access behaviors that do not conform to the conventional access method, record their access time, access point and access method, and generate non-compliant access trajectory.

[0020] The system collects component access behavior in real time and compares it one by one with the normal access methods in the baseline behavior. When an access behavior is found to be inconsistent with the requirements of the normal access method, such as attempting to access a component without authentication, it is identified as an access behavior that does not conform to the normal access method. At this time, the access time, the access point (such as a specific interface of a component) where the access operation is performed, and the specific access method (such as unauthenticated access, abnormal port access, etc.) are recorded. These records are organized in chronological order to form a non-compliant access trajectory.

[0021] Step S115: Track the data flow process that exceeds the data transmission range, record the data initiating component, relay component and receiving component, and generate a data over-authority transmission trajectory.

[0022] The system monitors data transmission between components. When it detects that the transmission of data exceeds the data transmission range specified in the normal behavior baseline, such as when a component sends data to a component that is not authorized to receive its data, the system tracks the flow of that data. It identifies the initiating component of the data transmission; records the intermediate components the data passes through during transmission; and clarifies the final receiving component. This information is recorded in the order of data flow to generate a data overreach transmission trajectory.

[0023] Step S116: Monitor the instruction delivery path that deviates from the instruction issuance specification, record the instruction generation component, the issuance object and the execution result, and generate an abnormal instruction issuance trajectory.

[0024] The system monitors commands issued by components. When a command's transmission path deviates from the normal behavior baseline, such as when a command is sent to a component that shouldn't receive it, the transmission path of that command is traced. The system records the component that generated the command, the component that received the command, and the execution result after execution, such as whether the command was executed and whether the execution was successful. This information is then compiled to generate an abnormal command delivery trajectory.

[0025] Step S117: Summarize the non-compliant access trajectory, unauthorized data transmission trajectory, and abnormal instruction issuance trajectory into an abnormal behavior trajectory.

[0026] The previously generated non-compliant access tracks, unauthorized data transmission tracks, and abnormal command issuance tracks are integrated in chronological order to form a complete abnormal behavior track. This track contains detailed information on various abnormal behaviors occurring in the system, comprehensively reflecting the abnormal state of the system over a period of time.

[0027] Step S120: Generate an isolation start command based on the real-time operation interaction link and abnormal behavior trajectory. The isolation start command includes command triggering conditions, a list of associated components, and isolation scope definition information.

[0028] Analyze real-time operational interaction links and abnormal behavior trajectories to determine the conditions under which isolation operations should be initiated, i.e., the command triggering conditions, such as when the frequency of abnormal behavior reaches a certain level. Identify all components related to the abnormal behavior from the real-time operational interaction links and abnormal behavior trajectories to form a list of associated components. Based on factors such as the location and importance of associated components in the system, define the scope requiring isolation and clarify the isolation scope definition information. Integrate the command triggering conditions, the list of associated components, and the isolation scope definition information to generate an isolation initiation command.

[0029] Step S121: Perform correlation analysis on the non-compliant access trajectory, unauthorized data transmission trajectory, and abnormal instruction issuance trajectory in the abnormal behavior trajectory to determine the causal relationship and scope of influence between each abnormal trajectory.

[0030] Extract key information from non-compliant access trajectories, unauthorized data transmission trajectories, and abnormal command issuance trajectories, such as the components involved, the time of occurrence, and the content of the behavior. By analyzing this information, identify the connections between different abnormal trajectories and determine whether a causal relationship exists between them, such as whether non-compliant access led to unauthorized data transmission. Simultaneously, based on the components involved in the abnormal trajectories and the connections between components, determine the scope of the impact of the abnormal behavior on the system.

[0031] Step S1211: Extract the access initiation node identifier, access request time, and access target port information from the non-compliant access trajectory to generate a non-compliant access feature set.

[0032] Extract the identifier of the access initiating node from the non-compliant access trajectory, such as "unknown access device A"; record the access request time when the access request occurred; determine the access target port information targeted by the access operation, such as "communication port B of server A". Combine this information to form a non-compliant access feature set, which fully reflects the key characteristics of non-compliant access behavior.

[0033] Step S1212: Extract the data source node, data receiving node, transmission content type and transmission path node sequence from the data unauthorized transmission trajectory to generate a data unauthorized transmission feature set.

[0034] Extract the source node (sending component) and receiving node (receiving component) of the data from the data unauthorized transmission trajectory; the type of transmitted data content, such as "real-time operating parameter data"; and the sequence of nodes along the transmission path, such as [node A, node B, node C]. Integrate this information to generate a data unauthorized transmission feature set.

[0035] Step S1213: Extract the instruction origin, instruction receiving node, instruction execution result and instruction propagation link from the instruction abnormal issuance trajectory to generate an instruction abnormal issuance feature set.

[0036] From the abnormal instruction delivery trajectory, we extract the instruction's origin (the component that generates and delivers the instruction), the instruction's receiving node (the component that receives the instruction), the instruction execution result, and the instruction propagation path from the origin to the receiving node. After organizing this information, we generate a feature set for abnormal instruction delivery.

[0037] Step S1214: Compare the node identifiers of the non-compliant access feature set and the data unauthorized transmission feature set, identify nodes that are the same or have a direct connection relationship, and mark them as the first associated node pair.

[0038] Compare the node identifiers in the non-compliant access feature set and the data unauthorized transmission feature set to see if there are any identical node identifiers or nodes with direct connections, i.e., two nodes can directly interact with each other without going through other nodes. Mark these identified node pairs as the first associated node pair.

[0039] Step S1215: Perform overlap analysis on the transmission path and propagation link of the data unauthorized transmission feature set and the instruction abnormal issuance feature set, identify the path nodes that are traversed in the same way, and mark them as the second associated node pair.

[0040] Analyze the transmission paths in the data unauthorized transmission feature set and the propagation links in the command abnormal issuance feature set, calculate the degree of overlap between them, and identify the path nodes that are traversed in both paths. Mark these common path nodes as the second associated node pair.

[0041] Step S1216: Construct a trajectory association map based on the first and second associated node pairs. Each node in the map corresponds to the device involved in the abnormal behavior, and the lines between nodes represent the association relationship between trajectories.

[0042] Based on the first and second associated node pairs, a trajectory association map is constructed. Each node in the map represents the device involved in the abnormal behavior, and the lines between the nodes represent the association between different abnormal trajectories. The connections between different abnormal trajectories can be seen intuitively through the lines.

[0043] Step S1217: Analyze the order of occurrence of nodes and the direction of connection in the trajectory association map to determine whether non-compliant access trajectory is a prerequisite for unauthorized data transmission trajectory, and whether unauthorized data transmission trajectory is a prerequisite for abnormal instruction issuance trajectory, thereby clarifying the causal relationship between each abnormal trajectory.

[0044] By observing the order in which nodes appear in the trajectory correlation graph and considering the direction of the lines connecting the nodes, the triggering relationships between different abnormal trajectories can be analyzed. If a node in the non-compliant access trajectory appears before a node in the data unauthorized transmission trajectory, and there is a line pointing to a node in the data unauthorized transmission trajectory, then it can be determined that the non-compliant access trajectory is a prerequisite triggering condition for the data unauthorized transmission trajectory. Similarly, analyze the relationship between the data unauthorized transmission trajectory and the abnormal instruction issuance trajectory to clarify their causal relationship.

[0045] Step S1218: Based on causal relationships, trace all nodes involved in each abnormal trajectory, and combine the hierarchical relationship of the nodes in the power monitoring system to determine the scope of the affected equipment cluster.

[0046] Based on the established causal relationships, all nodes involved in each abnormal trajectory are traced. Simultaneously, the hierarchical relationship of these nodes within the power monitoring system is considered; for example, some nodes belong to the core control layer, while others belong to the data transmission layer. Combining this information, the scope of the device clusters affected by the abnormal behavior is determined, i.e., which device clusters may be interfered with or damaged due to the abnormal behavior.

[0047] Step S1219: Based on the function type of the device cluster, determine the system function modules that the abnormal trajectory may affect, and generate a description of the scope of impact.

[0048] Analyze the functional types of the affected device cluster, such as data acquisition, command control, and communication transmission. Based on these functional types, determine which functional modules in the system the abnormal trajectory might affect, such as the data acquisition module, command execution module, and communication module. Organize these findings into a description of the scope of impact, clearly explaining the system functions that the abnormal behavior may affect.

[0049] Step S122: Based on the causal relationship and the scope of influence, set the instruction triggering conditions, which include the frequency of occurrence of abnormal trajectories, the number of components involved, and the duration.

[0050] Based on the causal relationships between abnormal trajectories and the determined scope of their impact, instruction triggering conditions are set. The frequency of an abnormal trajectory occurrence refers to the number of times a certain type of abnormal trajectory occurs within a certain period; the number of components involved refers to the number of components involved in the abnormal trajectory; and the duration refers to the time from the occurrence of the abnormal trajectory to its termination. When these indicators reach preset thresholds, an isolation activation instruction is triggered.

[0051] Step S123: Extract component identifiers related to abnormal behavior trajectories from the real-time operation interaction link, determine directly associated components and indirectly associated components, and generate a list of associated components.

[0052] In the real-time interactive chain, identify components that directly interact with components involved in the abnormal behavior trajectory; these are directly related components. Also identify components that interact with directly related components and may be affected by abnormal behavior; these are indirectly related components. Extract the identifiers of these components and generate a list of related components.

[0053] Step S124: Based on the functional attributes of the associated components and their positions in the power monitoring system, divide the isolation range. The isolation range includes a core isolation zone, a buffer isolation zone, and an outer isolation zone. The core isolation zone includes directly associated components, the buffer isolation zone includes components that interact with the directly associated components, and the outer isolation zone includes components that interact with the components in the buffer isolation zone.

[0054] Isolation zones are defined based on the functional attributes of the associated components, such as whether they are core control components or data storage components, and their physical or logical locations within the power monitoring system. The core isolation zone contains directly related components that are directly associated with the abnormal behavior; the buffer isolation zone contains components that interact with directly related components and may be affected by the abnormal behavior; and the outer isolation zone contains components that interact with components in the buffer isolation zone, which are less likely to be affected but still require monitoring.

[0055] Step S125: Integrate and encapsulate the instruction triggering conditions, the list of associated components, and the isolation scope definition information to generate an isolation start instruction. The isolation start instruction also includes a summary of the abnormal behavior trajectory and the generation time.

[0056] The previously determined command triggering conditions, associated component list, and isolation scope definition information are integrated, and summary information of the abnormal behavior trajectory is added, such as the main type of abnormal behavior, key time points of occurrence, and the generation time of the isolation start command. This information is then encapsulated in a specific format to form the final isolation start command.

[0057] Step S130: Construct a cross-domain protection linkage framework based on the isolation startup command. The cross-domain protection linkage framework includes the associated logic of device-level isolation mechanism, communication-level blocking rules and application-level permission locking strategy.

[0058] The isolation startup command is analyzed to clarify the scope and objectives requiring protection. At the device layer, corresponding isolation mechanisms are established to prevent abnormal devices from impacting the system; at the communication layer, blocking rules are set to prevent the transmission of abnormal data; and at the application layer, access control policies are implemented to restrict the operational permissions of abnormal applications. Simultaneously, the logical connections between these three layers are established to enable them to work collaboratively, forming a cross-domain protection framework.

[0059] Step S131: Parse the isolation range definition information of the isolation start command to determine the protection areas that the device layer, communication layer and application layer need to cover. The protection strength of the core isolation area is higher than that of the buffer isolation area and the outer isolation area.

[0060] The isolation scope definition information in the isolation startup command is parsed to clarify the protection areas that need to be covered at the device layer, communication layer, and application layer. Depending on the type of isolation zone, the core isolation zone, which directly involves abnormal behavior, has a higher protection strength than the buffer isolation zone and the outer isolation zone to ensure the security of the core area.

[0061] Step S132: For the device layer, construct a device layer isolation mechanism based on the component list in the isolation range. The device layer isolation mechanism includes the on / off control of component physical ports, the independent allocation of hardware resources, and the forced switching of device states.

[0062] Based on the component list defined in the isolation scope, a device-level isolation mechanism is constructed for the device layer. This device-level isolation mechanism includes controlling the on / off state of component physical ports, disconnecting specific ports when an anomaly is detected; independently allocating hardware resources to isolate the hardware resources used by different components and avoid mutual interference; and specifying the forced switching method for device states, such as switching the device from the running state to the isolated state in abnormal situations.

[0063] Step S133: For the communication layer, based on the connection path and protocol type in the real-time interactive link, construct communication layer blocking rules. The communication layer blocking rules include communication interception of specified paths, filtering conditions of protocol fields, and handling methods for abnormal messages.

[0064] Based on the connection paths and protocol types recorded in the real-time interactive links, communication layer blocking rules are constructed for the communication layer. These rules include intercepting communication on specified connection paths to prevent data transmission on abnormal paths; setting filtering conditions for protocol fields to intercept packets that do not meet the conditions; and specifying the handling methods for abnormal packets, such as discarding abnormal packets or recording abnormal information.

[0065] Step S134: For the application layer, based on the functional permissions and abnormal behavior trajectories of the associated components, construct an application layer permission locking strategy. The application layer permission locking strategy includes temporary freezing of operation permissions, restriction of data access scope, and revocation of instruction issuance permissions.

[0066] Based on the functional permissions and abnormal behavior patterns of the associated components, an application-layer permission locking strategy is constructed for the application layer. This strategy includes temporarily freezing the application's operational permissions to prevent abnormal operations; restricting the application's data access scope, allowing it to access only specific data; and revoking the application's command-issuing permissions to prevent it from issuing abnormal commands.

[0067] Step S135: Construct the action association logic of the device layer, communication layer, and application layer. When the device layer performs a physical port disconnection operation, the communication layer synchronously starts the interception rules of the corresponding path, and the application layer locks the application permissions on the corresponding device. When the communication layer intercepts an abnormal message, the device layer performs a port check on the component that sent the message, and the application layer checks the application permission status of the component. When the application layer finds abnormal permission usage, the communication layer blocks the communication link of the corresponding application, and the device layer monitors the running status of the corresponding component.

[0068] Establish action association logic between the device layer, communication layer, and application layer to enable the operations of the three layers to cooperate with each other. When the device layer performs a physical port disconnection operation, the communication layer immediately initiates the interception rules for the connection path associated with that port, and the application layer locks the permissions of the application on that device. When the communication layer intercepts an abnormal message, the device layer performs a port check on the component that sent the message, checking whether the component's physical port is in a normal connection state, whether there is any abnormal data flow transmitted through that port, etc.; the application layer checks the permission status of the application running the component, checking whether the application has the permission to send this type of message, whether the permission is within the validity period, and whether there are any signs of permission abuse, etc. When the application layer detects abnormal permission use, such as the application performing a specific operation without the corresponding authorization, the communication layer immediately blocks the communication link corresponding to the application to prevent abnormal data from continuing to be transmitted; the device layer strengthens the monitoring of the component's operating status, collecting information such as the component's CPU usage, memory usage, and network connection status in real time, in order to promptly detect further anomalies that may occur in the component.

[0069] Step S1351: Assign a unique identifier to each physical port in the device layer, associate it with the corresponding communication path identifier in the communication layer and the corresponding application identifier in the application layer, and establish a three-layer association mapping table.

[0070] Assign a unique identifier to each physical port in the device layer. For example, it can be named in the format "Device Identifier-Port Number", such as "Substation A Monitoring Terminal-Port 1" or "Dispatch Server Master Node-Port 3". Then, associate each physical port's unique identifier with the corresponding communication path identifier in the communication layer. The communication path identifier can be a string composed of the source component's physical port identifier and the target component's physical port identifier, such as "Substation A Monitoring Terminal-Port 1 → Data Transfer Node-Port 2". Simultaneously, associate the physical port's unique identifier with the corresponding application identifier in the application layer. The application identifier can be the application's name plus its version number, such as "Power Data Acquisition Program V2.0" or "Command Issuance Program V1.5". After organizing these relationships, establish a three-layer association mapping table. Each record in this table contains the physical port's unique identifier, the corresponding communication path identifier, and the application identifier.

[0071] Step S1352: When the device layer receives a physical port disconnect command, it looks up the corresponding communication path identifier and application identifier through the three-layer association mapping table, sends an interception start command carrying the communication path identifier to the communication layer, and sends a permission lock command carrying the application identifier to the application layer.

[0072] When the device layer receives a physical port disconnect command, the command contains a unique identifier for the physical port to be disconnected. The device layer uses this identifier to look up the corresponding communication path identifier and application identifier in the three-layer association mapping table. Then, the device layer sends an interception start command to the communication layer, which carries the found communication path identifier and explicitly tells the communication layer which communication path to intercept. Simultaneously, it sends a permission lock command to the application layer, carrying the corresponding application identifier and instructing the application layer to lock the permissions for that application.

[0073] Step S1353: After receiving the interception start command, the communication layer immediately activates the blocking rules for the corresponding communication path, returns interception status information to the device layer, and sends an interception event notification to the application layer.

[0074] Upon receiving an interception initiation command carrying a communication path identifier, the communication layer locates the corresponding communication path based on the identifier and immediately activates the blocking rules for that path. These blocking rules may include rejecting all new connection requests on the path, interrupting existing connections on the path, and discarding all packets transmitted on the path. Simultaneously, the communication layer returns interception status information to the device layer, indicating whether the interception operation was successfully initiated and the current blocking status of the communication path. At the same time, it sends an interception event notification to the application layer, containing information such as the communication path identifier and the interception initiation time, enabling the application layer to understand the status changes of the relevant communication path.

[0075] Step S1354: After receiving the permission lock instruction, the application layer freezes the operation permissions of the corresponding application, returns the permission lock result to the device layer, and reports the application status to the communication layer.

[0076] After receiving a permission lock command carrying an application identifier, the application layer locates the corresponding application based on the identifier and then freezes the application's operation permissions. The freezing operation may include preventing the application from initiating new operation requests, suspending unnecessary operations being performed by the application, and restricting the application's access to system resources. After completing the permission lock, the application layer returns the permission lock result to the device layer, indicating whether the permission lock was successful and the current state of the application; simultaneously, it reports the application status to the communication layer, such as whether the application has stopped sending data due to the permission lock.

[0077] Step S1355: When the communication layer intercepts an abnormal message, it extracts the source component identifier of the abnormal message, finds the corresponding physical port identifier and application identifier through the three-layer association mapping table, sends a port check instruction to the device layer, and sends a permission verification instruction to the application layer.

[0078] After intercepting an abnormal packet, the communication layer extracts the source component identifier from the packet. This identifier can be the name or number of the source component. Based on the source component identifier and the port information in the packet, the corresponding physical port identifier and application identifier are searched in the Layer 3 association mapping table. Once found, the communication layer sends a port check command to the device layer, containing the found physical port identifier, requesting the device layer to check the port. Simultaneously, it sends a permission verification command to the application layer, containing the application identifier, requesting the application layer to verify the permissions of the application.

[0079] Step S1356: After receiving the port check command, the device layer detects the connection status and data traffic of the corresponding physical port and feeds back the check results to the communication layer and the application layer.

[0080] After receiving a port check command, the device layer locates the corresponding physical port based on the physical port identifier in the command. It then checks the port's connection status, such as whether the port is connected, whether the connection is stable, and whether there are any physical connection problems like loose connections. Simultaneously, it monitors the port's data traffic, recording information such as the number of data packets passing through the port per unit time, the data transmission rate, and the type of data packets. After processing these check results, the device layer sends feedback to both the communication layer and the application layer, including the physical port identifier, connection status description, and data traffic statistics.

[0081] Step S1357: After receiving the permission verification instruction, the application layer checks the current permission configuration and usage records of the corresponding application and feeds back the verification results to the communication layer and the device layer.

[0082] After receiving a permission verification command, the application layer locates the corresponding application based on the application identifier in the command. It then checks the application's current permission configuration, such as which operation permissions the application possesses, the effective and expiration times of these permissions, and the scope of application. Simultaneously, it reviews the application's permission usage records to view information such as which permissions the application has used over a past period, the times of use, and the objects targeted. After compiling the results of the permission configuration and usage record checks, the application layer sends feedback to both the communication layer and the device layer. This feedback includes the application identifier, permission configuration details, a summary of the permission usage records, and whether any permission anomalies were detected.

[0083] Step S1358: When the application layer detects abnormal use of permissions, it determines the identifier of the abnormal application, finds the corresponding communication path identifier and physical port identifier through the three-layer association mapping table, sends a link blocking command to the communication layer, and sends a status monitoring command to the device layer.

[0084] During routine monitoring of application permissions or responding to permission verification commands, the application layer identifies abnormal permission usage when it detects such as unauthorized permissions, exceeding the scope of permissions, or continuing to use permissions after they have expired. Then, it uses a three-layer association mapping table to look up the communication path identifier and physical port identifier corresponding to this application identifier. Once found, the application layer sends a link blocking command to the communication layer, containing the communication path identifier, requesting the communication layer to block communication along that path. Simultaneously, it sends a status monitoring command to the device layer, containing the physical port identifier, requesting the device layer to strengthen status monitoring of the component containing that port.

[0085] Step S1359: After receiving the link blocking command, the communication layer cuts off the data flow of the corresponding communication path and returns the blocking result to the application layer and the device layer.

[0086] After receiving a link blocking command, the communication layer locates the corresponding communication path based on the communication path identifier in the command, and then takes measures to cut off the data flow along that path, such as closing network connections on that path or configuring firewall rules to block data packets from passing through that path. After completing the link blocking, the communication layer returns the blocking result to the application layer and the device layer, indicating whether the link blocking was successful and the current status of the communication path.

[0087] Step S1360: After receiving the status monitoring command, the device layer monitors the operating parameters of the corresponding physical port in real time and synchronizes the monitoring data to the application layer and communication layer.

[0088] After receiving a status monitoring command, the device layer determines the physical port to be monitored based on the physical port identifier in the command. It then monitors the port's operating parameters in real time, such as port temperature, voltage, data transmission error rate, and connection duration. The device layer aggregates and organizes this monitoring data at regular intervals and simultaneously sends it to the application and communication layers. This allows the application and communication layers to understand the physical port's operational status promptly and make further processing decisions based on the monitoring data.

[0089] Step S140: Generate a hierarchical isolation execution plan using the cross-domain protection linkage framework. The hierarchical isolation execution plan includes the action sequence, startup sequence, and coordination method of each protection domain.

[0090] Based on the isolation mechanisms, blocking rules, access control policies, and interrelationships at the device, communication, and application layers within the cross-domain protection framework, and combined with the isolation scope defined in the isolation initiation command, a hierarchical isolation execution plan is generated. This plan clarifies the sequence of actions to be executed in the core isolation zone, buffer isolation zone, and outer isolation zone, the temporal order of these actions, and the coordination methods between different isolation zones and different layers, ensuring that isolation operations are carried out in an orderly and effective manner.

[0091] Step S141: Extract the device layer isolation mechanism, communication layer blocking rules and application layer permission locking strategy from the cross-domain protection linkage framework, and divide the protection actions into core area action set, buffer zone action set and peripheral area action set according to the isolation scope definition information in the isolation start instruction.

[0092] The cross-domain protection linkage framework extracts various protective actions from device-level isolation mechanisms, communication-level blocking rules, and application-level permission locking policies. These actions include, for example, physical port disconnection and independent allocation of hardware resources at the device level; specified path interception and protocol field filtering at the communication level; and freezing of operation permissions and data access scope restrictions at the application level. Then, based on the isolation scope definition information in the isolation startup command, these protective actions are assigned to the corresponding isolation zone action sets. The core zone action set contains protective actions for core isolation zone components, the buffer zone action set contains protective actions for buffer isolation zone components, and the outer zone action set contains protective actions for outer isolation zone components.

[0093] Step S142: Generate action sequences for the core area action set, buffer area action set, and peripheral area action set respectively. The core area action set primarily includes device layer physical isolation actions, communication layer direct blocking actions, and application layer full-authority locking actions. The buffer area action set includes communication layer restriction actions and application layer partial authorization locking actions. The peripheral area action set includes application layer authorization monitoring actions.

[0094] An action sequence is generated for each action set, determining the execution order of the actions within the set. For the core area action set, since the core isolation zone directly involves abnormal behavior and requires strong protective measures, the action sequence prioritizes physical isolation actions at the device layer, such as disconnecting critical physical ports of core components; direct blocking actions at the communication layer, such as completely blocking communication paths between the core zone and other areas; and full-privilege locking actions at the application layer, such as freezing all operational permissions of applications on core components. The action sequence for the buffer area action set includes communication layer restriction actions, such as limiting the communication bandwidth between components within the buffer and the outside world, and performing stricter filtering on transmitted data; and partial privilege locking actions at the application layer, such as freezing only some high-risk operational permissions of applications. The action sequence for the peripheral area action set mainly includes application layer permission monitoring actions, such as real-time monitoring of permission usage by applications on peripheral components and recording permission usage logs.

[0095] Step S143: Set the startup sequence. The startup time of the core area action set is earlier than that of the buffer action set, the startup time of the buffer action set is earlier than that of the outer area action set, and the startup interval of adjacent action sets is determined according to the spread speed of the abnormal behavior trajectory.

[0096] The startup sequence of each action set is set, with the core area action set starting first because abnormal behavior in the core isolation area may have the most direct and severe impact on the system and needs to be handled first. The buffer area action set starts after the core area action set, and the outer area action set starts after the buffer area action set. The startup interval between adjacent action sets is determined based on the spread rate of the abnormal behavior trajectory. If the abnormal behavior spreads quickly, the interval can be set shorter to quickly curb the spread of the abnormality; if the spread rate is slow, the interval can be appropriately extended to observe the execution effect of the previous action set.

[0097] Step S144: Establish a collaborative mechanism. After the core area device layer action is initiated, it triggers the buffer communication layer action and the peripheral area application layer action. When the buffer communication layer action is executed, it synchronizes the status of the core area application layer action and the preparation status of the peripheral area device layer action. When the peripheral area application layer action detects an anomaly, it feeds back to the corresponding action execution components in the core area and buffer.

[0098] In this embodiment, the collaborative mechanism requires the establishment of a multi-level signal interaction mechanism and a state synchronization protocol to achieve the linkage of actions in each region. The action execution components in the core area, buffer zone, and outer area are all equipped with independent signal transceiver modules to transmit trigger commands and status information.

[0099] Step S1441: Set up an action trigger signal mechanism in the hierarchical isolation execution plan, assign a unique trigger signal to each startup action of the core area device layer, and associate the unique trigger signal with the startup conditions of the buffer communication layer and the startup conditions of the peripheral area application layer.

[0100] Unique identifiers are assigned to physical port disconnection actions and hardware resource isolation actions at the core area device layer. For example, "trigger signal T1" corresponds to a port disconnection action at the core area device layer. "Trigger signal T1" is written into the startup condition list of the buffer communication layer, specifying that when the buffer communication layer receives "trigger signal T1," it immediately initiates a communication restriction action on the specified path. Simultaneously, "trigger signal T1" is associated with the startup conditions of the peripheral area application layer, stipulating that the peripheral area application layer starts the permission monitoring submodule upon detecting "trigger signal T1." The trigger signal format uses a combination of "region identifier-action type-serial number" to ensure the uniqueness and identifiability of the signal.

[0101] Step S1442: When the core area device layer action is initiated, a corresponding trigger signal is generated and sent to the execution components of the buffer communication layer and the peripheral area application layer through the signal transmission channel of the cross-domain protection linkage framework. After receiving the trigger signal, the buffer communication layer component checks its own readiness status. If the conditions are met, the corresponding action is initiated. After receiving the trigger signal, the peripheral area application layer component also checks its readiness status and initiates the action.

[0102] When the port disconnection action is initiated at the core area device layer, its built-in signal generation module generates a "trigger signal T1" based on the action type. This signal is then sent to the signal receiving modules of the buffer communication layer and the peripheral application layer via a dedicated signal transmission channel (using an encrypted transmission protocol) within the framework. Upon receiving the "trigger signal T1," the buffer communication layer component immediately checks its own resource utilization, current connection status, and other readiness parameters. If all parameters are within the preset threshold range, it initiates the communication traffic restriction action for the corresponding path. Upon receiving the "trigger signal T1," the peripheral application layer component checks the running status of the permission monitoring submodule. If it is in a ready state, it initiates the operation log recording and permission usage monitoring actions for the specified application.

[0103] Step S1443: Set up status synchronization nodes for buffer communication layer actions. Each synchronization node corresponds to a time point. At this time point, the buffer communication layer component sends a status query request to the core area application layer component to obtain the current execution progress and results of the core area application layer actions; at the same time, it sends a preparation status query instruction to the peripheral area device layer component to collect the preparation status of the peripheral area device layer actions.

[0104] Multiple status synchronization nodes are set up for the communication protocol filtering actions of the buffer communication layer, such as the first time interval after the action starts, the second time interval, etc. At each synchronization node, the status synchronization module of the buffer communication layer sends a status query request to the status feedback module of the core application layer. The request content includes the identifier of the core application layer action, the expected execution progress parameters (such as completion percentage, current stage), and the result code. After receiving the request, the core application layer component immediately queries the execution log of the corresponding action, extracts the execution progress and result information, encapsulates it into a response message, and returns it to the buffer communication layer component. At the same time, the buffer communication layer component sends a preparation status query instruction to the preparation status monitoring module of the peripheral device layer. The instruction includes a list of actions to be executed by the peripheral device layer and the preparation status items to be checked (such as port ready status, hardware resource allocation status). After receiving the instruction, the peripheral device layer component checks the preparation status of the corresponding action item by item, generates a preparation status report, and feeds it back to the buffer communication layer component.

[0105] Step S1444: The buffer communication layer component collects the core area application layer status and the peripheral area device layer preparation status into a synchronization report, stores it in the plan execution log, and feeds it back to the coordination module of the cross-domain protection linkage framework.

[0106] The status integration module of the buffer communication layer receives the execution progress and result information returned by the core area application layer and summarizes it with the preparation status report returned by the peripheral area device layer. It organizes this information into a synchronization report in the format of "synchronization node time - core area status - peripheral area status". The core area status includes the action identifier, completion percentage, and result code, while the peripheral area status includes the action list, the preparation status of each action (e.g., "ready" or "not ready"), and the reason for not being ready. After the synchronization report is generated, it is first stored in the local planned execution log database and simultaneously sent to the coordination module of the cross-domain protection linkage framework via the data transmission interface. The coordination module compares the synchronization report with the preset expected status values; if there is a discrepancy, it is marked as an item requiring attention.

[0107] Step S1445: Deploy an anomaly monitoring submodule in the application layer component of the peripheral area. This anomaly monitoring submodule analyzes the operation records and data access behavior of the application in real time. When a pattern similar to the abnormal behavior trajectory is identified, anomaly feedback information is generated. The anomaly feedback information includes the time of the anomaly, the application involved, and the operation content.

[0108] An anomaly monitoring submodule is deployed in the application layer components of the peripheral area. This submodule includes an operation log analysis unit and a behavior pattern comparison unit. The operation log analysis unit collects application operation records (such as data queries, command issuance, permission changes, etc.) and data access behaviors (such as accessed data tables, access frequency, data modification operations) in real time, extracting feature parameters such as operation type, object, and timestamp. The behavior pattern comparison unit compares the extracted feature parameters with the pattern features stored in the abnormal behavior trajectory database and calculates the feature matching degree. When the matching degree exceeds a preset threshold, it is determined that a similar abnormal pattern has been identified, and an anomaly feedback information is immediately generated. The anomaly feedback information includes the precise timestamp of the anomaly, the unique identifier of the application involved, the specific operation content (such as "Application A attempted to access unauthorized data table B at time T"), and the feature matching degree value.

[0109] Step S1446: The peripheral application layer component sends the abnormal feedback information to the corresponding device layer and communication layer components in the core area through a dedicated feedback channel, and at the same time sends it to the corresponding communication layer and application layer components in the buffer area. After receiving the abnormal feedback information, the core area and buffer components adjust the execution parameters of their own actions.

[0110] The anomaly feedback module of the peripheral application layer component sends the generated anomaly feedback information through an encrypted dedicated feedback channel (physically isolated from the regular data transmission channel) to the anomaly response module of the core device layer, the anomaly response module of the core communication layer, and the anomaly handling modules of the buffer communication layer and the buffer application layer. Upon receiving the anomaly feedback information, the core device layer component, based on the application involved, associates it with the corresponding physical device and adjusts the port monitoring frequency of that device to improve the sensitivity of anomaly data capture. Upon receiving the information, the core communication layer component strengthens the packet filtering rules of the corresponding communication path, increasing the frequency of checks on specific protocol fields. Upon receiving the information, the buffer communication layer component adjusts the communication traffic limit threshold, narrowing the range of allowed data packets. Upon receiving the information, the buffer application layer component tightens the temporary permission scope of the corresponding application, restricting its access to sensitive data.

[0111] Step S145: Determine the execution conditions and end markers for each action in each action set. The execution conditions include the completion status of the preceding action and real-time monitoring data. The end markers include the duration of the action execution and the achievement of the target status.

[0112] For each action in each action set, define the execution conditions and termination flag. Execution conditions refer to the conditions that must be met for an action to begin execution, including the completion status of preceding actions (i.e., the action can only start after the preceding action has been completed) and real-time monitoring data (e.g., the action can only start when a certain indicator reaches a preset value). Termination flags are the criteria for determining the end of action execution, including the duration of action execution (i.e., the action ends after a preset time) and the achievement of the target state (e.g., when the system reaches a preset target state after the action is executed, such as communication path traffic dropping below a preset threshold or application permission locking being successful), the action can then end.

[0113] Step S146: Integrate the action sequences, start times, coordination methods, execution conditions, and end flags of the core area, buffer zone, and outer area to generate a hierarchical isolation execution plan.

[0114] The action sequences, start times, coordination methods, execution conditions, and end markers of the core area action set, buffer area action set, and outer area action set are integrated and arranged according to a specific format to form a complete hierarchical isolation execution plan. This hierarchical isolation execution plan details the actions to be executed in different isolation zones, the execution order and timing of the actions, the coordination relationships between actions, and the start and end conditions of the actions.

[0115] Step S150: Push the hierarchical isolation execution plan to the corresponding protection execution component, collect the isolation execution status information of each component, update the associated logic parameters of the cross-domain protection linkage framework according to the isolation execution status information, and maintain the full-domain isolation status of the power monitoring system.

[0116] The generated hierarchical isolation execution plan is pushed to the corresponding protection execution components in the power monitoring system. These components may be distributed at the device layer, communication layer, and application layer, and are responsible for executing the isolation actions. During the isolation execution process, the isolation execution status information fed back by each protection execution component is continuously collected, such as whether the action has been executed, the execution progress, and the execution result. Based on this status information, the effectiveness of the isolation operation is analyzed, and the associated logical parameters in the cross-domain protection linkage framework are adjusted and updated, such as adjusting the triggering conditions and coordination methods between actions, to ensure that the power monitoring system can maintain a stable global isolation status and effectively prevent the spread and impact of abnormal behavior.

[0117] Step S151: Distribute the hierarchical isolation execution plan to the protection execution components of the device layer, communication layer and application layer through the secure transmission channel of the power monitoring system. Each protection execution component only receives the action sequence and execution parameters related to itself.

[0118] By utilizing the secure transmission channels of the power monitoring system, such as encrypted dedicated communication links, hierarchical isolation execution plans are distributed to protection execution components at the device, communication, and application layers. During the distribution process, execution plans are filtered according to the responsibilities and areas of each protection execution component, ensuring that each component only receives action sequences and execution parameters relevant to itself. This avoids components receiving irrelevant information, which would increase their processing burden, while simultaneously improving the security and efficiency of information transmission.

[0119] Step S152: Use the protection execution component to parse the action instructions in the hierarchical isolation execution plan, execute them sequentially according to the startup sequence, and record the start time, current status and execution result of the action in real time during the execution process to generate component execution details.

[0120] After receiving action instructions related to itself, the protection execution component parses the instructions to determine the actions to be performed, the execution order, the start time, and the execution conditions. Then, it executes each action sequentially according to the start order. During execution, it records the start time of each action, its current status (e.g., preparing, executing, completed, failed), and the execution result (e.g., successfully disconnecting the physical port, successfully blocking the communication path, permission locking failure). These records are then compiled to generate a component execution detail, reflecting in detail the isolation actions performed by the component.

[0121] Step S153: Set up a status collection node, obtain the component execution details from each protection execution component at fixed time intervals, and summarize them to form isolation execution status information. The isolation execution status information includes a list of completed actions, a list of unexecuted actions, a list of abnormal actions, and the execution time of each action.

[0122] A dedicated status collection node is set up in the power monitoring system. This node retrieves component execution details from each protection execution component at fixed time intervals (e.g., every certain period). The status collection node summarizes and analyzes the collected component execution details, categorizing actions into completed actions, incomplete actions, and abnormal actions, forming lists of completed actions, incomplete actions, and abnormal actions, respectively. Simultaneously, it records the execution duration of each action, i.e., the time spent from the start to the end of execution. This information is then integrated to form isolated execution status information.

[0123] Step S154: Analyze the list of abnormal actions in the isolated execution status information to determine the cause of the abnormality. If it is caused by poor correlation between actions, find the corresponding correlation logic in the cross-domain protection linkage framework and adjust the triggering conditions and timing parameters in the correlation logic. If it is caused by insufficient component execution capability, optimize the action allocation method in the correlation logic and transfer some actions to the backup component.

[0124] Analyze the list of abnormal actions in the isolated execution status information and investigate the cause of each abnormal action one by one. If the abnormality is caused by poor coordination between actions, such as a certain action failing to trigger subsequent actions in a timely manner or deviations in the coordination between actions, then find the corresponding correlation logic in the cross-domain protection linkage framework, adjust the triggering conditions in the correlation logic, such as lowering or raising the trigger threshold or adjusting the order of triggering, and modify the timing parameters, such as extending or shortening the interval between actions, to ensure that actions can be smoothly correlated and executed collaboratively.

[0125] If the anomaly is due to insufficient component execution capacity—for example, a protection execution component receiving too many action instructions in a short period and being unable to process them in time, leading to delays or failures in action execution—then it is necessary to optimize the action allocation method of the related logic in the cross-domain protection linkage framework. Specifically, some actions undertaken by the original component should be transferred to backup components in the system. These backup components have similar functions and processing capabilities to the original component, can share the execution pressure, and ensure that the actions can be completed smoothly as planned.

[0126] Step S155: Based on the completed action list and execution time, evaluate the isolation effect of each protection domain. If the isolation effect in the core area does not meet expectations, strengthen the linkage between the device layer and the communication layer. If the isolation effect in the buffer zone does not meet expectations, increase the frequency of collaboration between the communication layer and the application layer.

[0127] Based on the completed action list, the number of actions completed in the core area, buffer zone, and outer perimeter area are counted. Combined with the execution time of each action, the isolation effectiveness of each protection zone is comprehensively evaluated. Evaluation indicators include the blocking rate of abnormal behavior and the control range of abnormal spread.

[0128] When the isolation effect of the core area fails to meet expectations—for example, if abnormal data continues to flow out of the core area or abnormal commands continue to be issued—it is necessary to strengthen the linkage between the device layer and the communication layer. Specific measures include increasing the number of synchronous triggers of physical port access control at the device layer and path interception rules at the communication layer, shortening the response time between the two, and ensuring that the isolation actions at the device layer and the blocking actions at the communication layer can work more closely together to form a stronger protective barrier.

[0129] When the buffer's isolation effect fails to meet expectations, such as when abnormal behavior tends to spread from the buffer to the core or peripheral areas, the frequency of collaboration between the communication layer and the application layer should be increased. For example, after intercepting abnormal packets, the communication layer should send permission verification requests to the application layer more frequently, and the application layer should also provide timely feedback on permission status to the communication layer. Simultaneously, the frequency of information exchange between the communication layer and the application layer should be increased to ensure that abnormal situations occurring in the buffer can be detected and handled promptly, preventing the spread of anomalies.

[0130] Step S156: Update the adjusted association logic parameters, action allocation method and linkage strength parameters to the cross-domain protection linkage framework, and continuously monitor the isolation status of the power monitoring system. Judge the isolation effect by the changes in the real-time running interaction link and abnormal behavior trajectory. Further optimize the cross-domain protection linkage framework based on the feedback of the isolation effect to maintain the stability of the overall isolation status.

[0131] The triggering conditions and timing parameters of the association logic adjusted in step S154, the optimized action allocation method, and the linkage strength parameters determined in step S155 are uniformly updated into the cross-domain protection linkage framework, so that the framework can run according to the new parameters and methods.

[0132] Subsequently, the isolation status of the power monitoring system is continuously monitored. By re-capturing real-time operational interaction links and abnormal behavior trajectories, changes are observed. If abnormal connection paths in the real-time operational interaction links decrease, data flow returns to normal, and non-compliant access, unauthorized data transmission, and abnormal command issuance in the abnormal behavior trajectories no longer occur or are significantly reduced, it indicates that the isolation effect is good. Conversely, based on the feedback information from these isolation effects, the cross-domain protection linkage framework needs to be optimized again, such as further adjusting the association logic, action allocation, or linkage strength, until the overall isolation status of the power monitoring system remains stable and all components can operate normally in a safe environment.

[0133] Figure 2 The illustration shows exemplary hardware and software components of a security isolation system 100 for a power monitoring system, which can implement the ideas of this application, according to some embodiments of this application. For example, a processor 120 can be used in the security isolation system 100 for a power monitoring system and to perform the functions described in this application.

[0134] The security isolation system 100 applied to the power monitoring system can be a general-purpose server or a special-purpose server; both can be used to implement the security isolation method for the power monitoring system described in this application. Although only one server is shown in this application, for convenience, the functions described in this application can be implemented in a distributed manner on multiple similar platforms to balance the load.

[0135] For example, a security isolation system 100 applied to a power monitoring system may include a network port 110 connected to a network, one or more processors 120 for executing program instructions, a communication bus 130, and various forms of storage media 140, such as a disk, ROM, or RAM, or any combination thereof. Exemplarily, the security isolation system 100 applied to a power monitoring system may also include program instructions stored in ROM, RAM, or other types of non-transitory storage media, or any combination thereof. The methods of this application can be implemented according to these program instructions. The security isolation system 100 applied to a power monitoring system also includes an I / O interface 150 between the computer and other input / output devices.

[0136] For ease of explanation, only one processor is described in the security isolation system 100 applied to a power monitoring system. However, it should be noted that the security isolation system 100 applied to a power monitoring system in this application may also include multiple processors. Therefore, the steps performed by one processor described in this application may also be performed jointly or individually by multiple processors. For example, if the processor of the security isolation system 100 applied to a power monitoring system performs steps A and B, it should be understood that steps A and B may also be performed jointly by two different processors or individually by one processor. For example, the first processor performs step A, the second processor performs step B, or the first processor and the second processor jointly perform steps A and B.

[0137] Furthermore, embodiments of the present invention also provide a readable storage medium, wherein computer-executable instructions are preset in the readable storage medium, and when the processor executes the computer-executable instructions, the above-mentioned security isolation method applied to the power monitoring system is implemented.

[0138] It should be noted that, in order to simplify the description of the present invention and thus help to understand one or more embodiments of the invention, multiple features may sometimes be grouped into one embodiment, drawing or description thereof in the foregoing description of the embodiments of the present invention.

Claims

1. A security isolation method applied to a power monitoring system, characterized in that, The method includes: Capture the real-time operation interaction links and abnormal behavior trajectories of various components within the power monitoring system. The real-time operation interaction links include the connection paths between components, the direction of data flow, and the type of interaction protocol. The abnormal behavior trajectories include non-compliant access trajectories, unauthorized data transmission trajectories, and abnormal command issuance trajectories. An isolation start command is generated based on the real-time operation interaction link and abnormal behavior trajectory. The isolation start command includes the command triggering conditions, the list of associated components and the isolation scope definition information. A cross-domain protection linkage framework is constructed based on the isolation startup command. The cross-domain protection linkage framework includes the associated logic of device-level isolation mechanism, communication-level blocking rules and application-level permission locking strategy. The cross-domain protection linkage framework is used to generate a hierarchical isolation execution plan, which includes the action sequence, startup sequence and coordination method of each protection domain. The hierarchical isolation execution plan is pushed to the corresponding protection execution components, the isolation execution status information of each component is collected, and the associated logic parameters of the cross-domain protection linkage framework are updated according to the isolation execution status information to maintain the full-domain isolation status of the power monitoring system.

2. The security isolation method for power monitoring systems according to claim 1, characterized in that, The real-time operational interaction links and abnormal behavior trajectories of various components within the power monitoring system include: The operation logs and communication messages of each component are collected by the distributed sensing components of the power monitoring system. The component identifier, interaction time and operation type in the operation log are parsed, and the source component information, target component information and protocol fields in the communication message are extracted to construct the original record of component interaction. The original records of the component interactions are arranged in chronological order, the connection paths between components are extracted, the direction of data flow between components is marked, the protocol type used in each interaction is identified, and the data is integrated to form a real-time running interaction link. Establish a baseline for normal component behavior, which includes the component's usual access methods, data transmission range, and command issuance specifications; The real-time collected component behavior is compared with the normal behavior baseline to identify access behaviors that do not conform to the conventional access method, and their access time, access point and access method are recorded to generate non-compliant access trajectories. Track the data flow process that exceeds the data transmission range, record the data initiating component, relay component and receiving component, and generate the data over-authority transmission trajectory; Monitor instruction delivery paths that deviate from the instruction issuance specifications, record the instruction generation components, issuance objects, and execution results, and generate abnormal instruction issuance trajectories; The non-compliant access trajectory, unauthorized data transmission trajectory, and abnormal instruction issuance trajectory are summarized into an abnormal behavior trajectory.

3. The security isolation method applied to a power monitoring system according to claim 1, characterized in that, The step of generating an isolation startup command based on the real-time operational interaction link and abnormal behavior trajectory includes: Correlation analysis is performed on the non-compliant access trajectory, unauthorized data transmission trajectory, and abnormal instruction issuance trajectory in the abnormal behavior trajectory to determine the causal relationship and scope of influence among the abnormal trajectories. Based on the causal relationship and the scope of influence, instruction triggering conditions are set, including the frequency of occurrence of abnormal trajectories, the number of components involved, and the duration. Extract component identifiers related to abnormal behavior trajectories from the real-time interactive chain, determine directly associated components and indirectly associated components, and generate a list of associated components; Based on the functional attributes of the associated components and their positions in the power monitoring system, the isolation range is divided into a core isolation zone, a buffer isolation zone, and an outer isolation zone. The core isolation zone contains directly associated components, the buffer isolation zone contains components that interact with the directly associated components, and the outer isolation zone contains components that interact with the components in the buffer isolation zone. The command triggering conditions, the list of associated components, and the isolation scope definition information are integrated and encapsulated to generate an isolation start command. The isolation start command also includes a summary of the abnormal behavior trajectory and the generation time.

4. The security isolation method for power monitoring systems according to claim 3, characterized in that, The analysis of the correlation between non-compliant access trajectories, unauthorized data transmission trajectories, and abnormal command issuance trajectories in the abnormal behavior trajectories determines the causal relationships and scope of influence among the abnormal trajectories, including: Extract the access initiation node identifier, access request time, and access target port information from the non-compliant access trajectory to generate a non-compliant access feature set; Extract the data source node, data receiving node, transmission content type and transmission path node sequence from the data unauthorized transmission trajectory to generate a data unauthorized transmission feature set; Extract the instruction origin, instruction receiving node, instruction execution result and instruction propagation link from the abnormal instruction issuance trajectory to generate an abnormal instruction issuance feature set; The non-compliant access feature set and the data unauthorized transmission feature set are compared by node identification to identify nodes that are the same or have a direct connection relationship and mark them as the first associated node pair; The overlap of transmission paths and propagation links is analyzed by combining the data unauthorized transmission feature set and the command abnormal issuance feature set to identify the path nodes that are traversed in the same way and mark them as the second associated node pair. A trajectory association map is constructed based on the first and second associated node pairs. Each node in the map corresponds to the device involved in the abnormal behavior, and the lines between nodes represent the association relationship between trajectories. Analyze the order of nodes and the direction of connections in the trajectory association map to determine whether non-compliant access trajectories are the pre-triggering conditions for unauthorized data transmission trajectories, and whether unauthorized data transmission trajectories are the pre-triggering conditions for abnormal instruction issuance trajectories, thereby clarifying the causal relationship between each abnormal trajectory. Based on causal relationships, all nodes involved in each abnormal trajectory are traced, and the scope of the affected equipment cluster is determined by combining the hierarchical relationship of the nodes in the power monitoring system. Based on the functional type of the device cluster, determine the system functional modules that the abnormal trajectory may affect, and generate a description of the scope of impact.

5. The security isolation method for power monitoring systems according to claim 1, characterized in that, The cross-domain protection linkage framework built based on the isolation startup command includes: The isolation scope definition information of the isolation start command is analyzed to determine the protection areas that the device layer, communication layer and application layer need to cover. The protection strength of the core isolation area is higher than that of the buffer isolation area and the outer isolation area. For the device layer, a device layer isolation mechanism is constructed based on the list of components in the isolation range. The device layer isolation mechanism includes the on / off control of component physical ports, the independent allocation of hardware resources, and the forced switching method of device state. For the communication layer, based on the connection path and protocol type in the real-time interactive link, communication layer blocking rules are constructed. The communication layer blocking rules include communication interception of specified paths, filtering conditions for protocol fields, and handling methods for abnormal packets. For the application layer, an application layer permission locking strategy is constructed based on the functional permissions and abnormal behavior trajectories of related components. The application layer permission locking strategy includes temporary freezing of operation permissions, restriction of data access scope, and revocation of instruction issuance permissions. The system establishes action association logic across the device layer, communication layer, and application layer. When the device layer performs a physical port disconnection operation, the communication layer synchronously initiates the corresponding path's interception rules, and the application layer locks the application permissions on the corresponding device. When the communication layer intercepts an abnormal message, the device layer performs a port check on the component that sent the message, and the application layer verifies the application permission status of that component. When the application layer detects abnormal permission usage, the communication layer blocks the communication link of the corresponding application, and the device layer monitors the running status of the corresponding component. By integrating device-level isolation mechanisms, communication-level blocking rules, application-level permission locking strategies, and their interrelationships, a cross-domain protection linkage framework is generated.

6. The security isolation method applied to a power monitoring system according to claim 5, characterized in that, The logic for linking actions of the device layer, communication layer, and application layer is as follows: when the device layer performs a physical port disconnection operation, the communication layer synchronously starts the interception rules for the corresponding path, and the application layer locks the application permissions on the device. When the communication layer intercepts an abnormal message, the device layer performs a port check on the component that sent the message, and the application layer checks the application permission status of that component. When the application layer detects abnormal permission usage, the communication layer blocks the application's communication link, and the device layer monitors the operational status of the corresponding components, including: Assign a unique identifier to each physical port in the device layer, associate it with the corresponding communication path identifier in the communication layer and the corresponding application identifier in the application layer, and establish a three-layer association mapping table; When the device layer receives a physical port disconnect command, it looks up the corresponding communication path identifier and application identifier through the three-layer association mapping table, sends an interception start command carrying the communication path identifier to the communication layer, and sends a permission lock command carrying the application identifier to the application layer. Upon receiving the interception start command, the communication layer immediately activates the blocking rules for the corresponding communication path, returns interception status information to the device layer, and sends an interception event notification to the application layer. After receiving the permission lock command, the application layer freezes the operation permissions of the corresponding application, returns the permission lock result to the device layer, and reports the application status to the communication layer. When the communication layer intercepts an abnormal message, it extracts the source component identifier of the abnormal message, finds the corresponding physical port identifier and application identifier through the three-layer association mapping table, sends a port check instruction to the device layer, and sends a permission verification instruction to the application layer. After receiving the port check command, the device layer detects the connection status and data traffic of the corresponding physical port and feeds back the check results to the communication layer and the application layer. After receiving the permission verification instruction, the application layer checks the current permission configuration and usage records of the corresponding application and feeds back the verification results to the communication layer and the device layer. When the application layer detects abnormal use of permissions, it determines the identifier of the abnormal application, finds the corresponding communication path identifier and physical port identifier through the three-layer association mapping table, sends a link blocking command to the communication layer, and sends a status monitoring command to the device layer. After receiving the link blocking command, the communication layer cuts off the data flow of the corresponding communication path and returns the blocking result to the application layer and the device layer. After receiving the status monitoring command, the device layer monitors the operating parameters of the corresponding physical port in real time and synchronizes the monitoring data to the application layer and communication layer.

7. The security isolation method for power monitoring systems according to claim 1, characterized in that, The process of generating a tiered isolation execution plan using the cross-domain protection linkage framework includes: Extract the device-layer isolation mechanism, communication-layer blocking rules, and application-layer permission locking strategy from the cross-domain protection linkage framework. Based on the isolation scope definition information in the isolation start command, divide the protection actions into core area action set, buffer area action set, and peripheral area action set. Action sequences are generated for the core area action set, buffer area action set and peripheral area action set respectively. The core area action set includes device layer physical isolation action, communication layer direct blocking action and application layer full permission locking action. The buffer area action set includes communication layer restriction action and application layer partial permission locking action. The peripheral area action set includes application layer permission monitoring action. The startup sequence is set so that the core area action set starts earlier than the buffer area action set, the buffer area action set starts earlier than the outer area action set, and the startup interval between adjacent action sets is determined according to the spread speed of the abnormal behavior trajectory. A collaborative mechanism is established whereby, after the core area device layer action is initiated, it triggers the buffer communication layer action and the peripheral area application layer action; when the buffer communication layer action is executed, it synchronizes the status of the core area application layer action and the preparation status of the peripheral area device layer action; when the peripheral area application layer action detects an anomaly, it feeds back to the corresponding action execution components in the core area and buffer. Determine the execution conditions and termination flags for each action in each action set. The execution conditions include the completion status of the preceding action and real-time monitoring data, and the termination flags include the duration of the action execution and the achievement of the target status. The action sequences, start times, coordination methods, execution conditions, and end markers of the core area, buffer zone, and outer area are integrated to generate a hierarchical isolation execution plan.

8. The security isolation method for power monitoring systems according to claim 7, characterized in that, The aforementioned collaborative construction method involves the following steps: after the core area device layer action is initiated, it triggers the buffer communication layer action and the peripheral area application layer action; during the execution of the buffer communication layer action, the status of the core area application layer action and the preparation status of the peripheral area device layer action are synchronized; when the peripheral area application layer action detects an anomaly, it feeds back to the corresponding action execution components in the core area and buffer, including: In the hierarchical isolation execution plan, an action triggering signal mechanism is set up to assign a unique triggering signal to each startup action of the core area device layer. This triggering signal is associated with the startup conditions of the buffer communication layer and the startup conditions of the peripheral area application layer. When the core area device layer initiates an action, a corresponding trigger signal is generated and sent to the execution components of the buffer communication layer and the peripheral area application layer through the signal transmission channel of the cross-domain protection linkage framework. After receiving the trigger signal, the buffer communication layer component checks its own readiness status, and if the conditions are met, it initiates the corresponding action; after receiving the trigger signal, the peripheral area application layer component also checks its readiness status and initiates the action. Set up status synchronization nodes for buffer communication layer actions. Each synchronization node corresponds to a time point. At this time point, the buffer communication layer component sends a status query request to the core area application layer component to obtain the current execution progress and result of the core area application layer action; at the same time, it sends a preparation status query instruction to the peripheral area device layer component to collect the preparation status of the peripheral area device layer action. The buffer communication layer component collects the core area application layer status and the peripheral area device layer preparation status, compiles them into a synchronous report, stores it in the plan execution log, and feeds it back to the coordination module of the cross-domain protection linkage framework. An anomaly monitoring submodule is deployed in the application layer components of the peripheral area. This anomaly monitoring submodule analyzes the operation records and data access behavior of the application in real time. When a pattern similar to the abnormal behavior trajectory is identified, anomaly feedback information is generated. The anomaly feedback information includes the time of the anomaly, the application involved, and the operation content. The peripheral application layer components send abnormal feedback information to the corresponding device layer and communication layer components in the core area through a dedicated feedback channel, and also to the corresponding communication layer and application layer components in the buffer area. After receiving the abnormal feedback information, the core area and buffer components adjust the execution parameters of their actions.

9. The security isolation method applied to a power monitoring system according to claim 1, characterized in that, The step of pushing the hierarchical isolation execution plan to the corresponding protection execution components, collecting the isolation execution status information of each component, and updating the associated logical parameters of the cross-domain protection linkage framework based on the isolation execution status information to maintain the overall isolation status of the power monitoring system includes: The hierarchical isolation execution plan is distributed to the protection execution components at the device layer, communication layer, and application layer through the secure transmission channel of the power monitoring system. Each protection execution component only receives the action sequence and execution parameters related to itself. The protection execution component is used to parse the action instructions in the hierarchical isolation execution plan and execute them sequentially according to the startup sequence. During the execution process, the start time, current status and execution result of the action are recorded in real time to generate component execution details. Set up a status collection node to obtain the component execution details from each protection execution component at fixed time intervals, and summarize them to form isolation execution status information. The isolation execution status information includes a list of completed actions, a list of unexecuted actions, a list of abnormal actions, and the execution time of each action. Analyze the list of abnormal actions in the isolated execution status information to determine the cause of the abnormality. If it is caused by poor correlation between actions, find the corresponding correlation logic in the cross-domain protection linkage framework and adjust the triggering conditions and timing parameters in the correlation logic. If it is caused by insufficient component execution capability, optimize the action allocation method in the correlation logic and transfer some actions to the backup component. Based on the completed action list and execution time, assess the isolation effect of each protection domain. If the isolation effect in the core area does not meet expectations, strengthen the linkage between the device layer and the communication layer; if the isolation effect in the buffer zone does not meet expectations, increase the frequency of collaboration between the communication layer and the application layer. The adjusted associated logic parameters, action allocation methods, and linkage strength parameters are updated to the cross-domain protection linkage framework. The isolation status of the power monitoring system is continuously monitored. The isolation effect is judged by the changes in the real-time operation interaction link and abnormal behavior trajectory. Based on the feedback of the isolation effect, the cross-domain protection linkage framework is further optimized to maintain the stability of the overall isolation status.

10. A security isolation system applied to a power monitoring system, characterized in that, The system includes a processor and a memory, the memory and the processor being connected. The memory is used to store programs, instructions, or code, and the processor is used to execute the programs, instructions, or code in the memory to implement the security isolation method for power monitoring systems as described in any one of claims 1-9.