Data flow tracing method for data security event and data entity mode

By integrating data security devices into the digital power grid, constructing a unified operating interface, and utilizing CNN and GNN networks for data traceability, combined with metaverse technology and blockchain evidence storage, the problem of tracing data security events and data entity patterns in the digital power grid has been solved. This has enabled rapid identification and automated processing, optimized resource scheduling, and improved the reliability and efficiency of data security.

CN121125256APending Publication Date: 2025-12-12GUANGZHOU ELECTRIC POWER COMM NETWORK LTD

Patent Information

Application Number
CN202511337097.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-18
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

Existing data flow tracing methods lack the integration of blockchain, IoT, metaverse, big data, and AI technologies in digital power grids, resulting in a lack of effective means to trace data security incidents and data entity patterns, particularly in the rational deployment and grid connection of energy storage power stations.

Method used

By integrating data security equipment and building a unified operating interface, data correlation analysis is performed using CNN convolutional neural networks and GNN graph neural networks. Combined with metaverse technology, digital twins are generated to achieve end-to-end data link traceability and threat identification. Blockchain evidence storage is used to provide automated decision-making and collaborative response, and energy storage power stations are equipped for autonomous analysis and processing.

Benefits of technology

It enables rapid identification and handling of data security incidents, improves the scientific nature and speed of decision-making, optimizes resource scheduling, reduces operating costs and carbon footprint, and ensures the reliability and traceability of data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125256A_ABST
    Figure CN121125256A_ABST
Patent Text Reader

Abstract

The invention relates to a data circulation traceability method of a data security event and a data entity mode, and aims to solve the technical problems that the similar technology in the existing digital power grid lacks the technical combination of block chains, Internet of Things and meta universe and the big data and AI artificial intelligence technology. The method is characterized in that a unified operation interface of the method is provided with a digital twinborn body generated and constructed by a meta-universe technology as a data flow traceability model, edge intelligence of a digital power grid is accessed, when data in the edge intelligence of the digital power grid is abnormally tampered, the CNN discovers data abnormity, the intruded edge intelligence is accurately positioned, and the data flow traceability of the digital power grid is realized. The range of the abnormal behavior is predicted; meanwhile, pressure testing and virtual deduction are immediately carried out in a digital twinborn body formed by the meta universe technology, a possible data security event of system crash or data leakage is predicted, an accurate disposal scheme and risk level division are given in advance, and low-level risks are autonomously handled.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to data security in digital power grids, and is a method for tracing the flow of data security events and data entity patterns. Background Technology

[0002] Currently, the core objective of data flow traceability is to record the entire lifecycle of data completely and immutably: where it came from (Origin), who processed it (Process), what changes occurred (Transform), and where it went (Destination). Existing data flow traceability technologies are being developed and applied in conjunction with cutting-edge technologies related to big data and AI, as well as blockchain, IoT, and metaverse technologies. These technologies rapidly integrate multi-source data such as network traffic, system logs, audit logs, and application logs through big data and AI, while simultaneously connecting to edge intelligent devices such as smart cars, medical equipment, and smart homes via IoT technology. This incorporates the status and operational instructions of these physical entities into the data flow traceability, achieving closed-loop traceability from virtual data to physical events. Meanwhile, metaverse technology constructs a high-fidelity digital twin for critical physical systems (such as an entire factory or the infrastructure of a city), while simultaneously improving the autonomous learning, early warning, and processing capabilities of AI, optimizing the response and handling of abnormal behavior, and ultimately applying it to the real world for precise processing. Existing methods for tracing data flow using blockchain technology include, for example, Chinese patent application number 202111313439.6, published on February 11, 2022, entitled "A Data Flow Traceability Method Based on Blockchain"; however, the aforementioned data flow traceability methods and similar technologies still lack the integration and application of IoT and metaverse technologies, as well as the support of big data and AI artificial intelligence technologies. Summary of the Invention

[0003] To overcome the aforementioned shortcomings, the purpose of this invention is to provide a data flow tracing method for data security incidents and data entity patterns, primarily addressing the lack of integration and application of blockchain, IoT, and metaverse technologies, as well as the support of big data and AI technologies, in the existing digital power grid's data flow tracing of data security incidents and data entity patterns, particularly the technical problems of the rational deployment and grid connection of energy storage power stations. This objective is achieved through the following technical solution.

[0004] A data flow tracing method for data security incidents and data entity patterns is proposed. This method integrates all data security devices and a unified operating interface through the construction of a data security defense system for a digital power grid. It uses charts to display the operational status, risk status, and protected object information of data security protection devices. The Security Operations Center (SOC) platform enables real-time monitoring and visualization of the entire network's data security status. It categorizes and manages data by device type and deployment location, allowing for one-click access to the operating interfaces of various systems, simplifying the workflow of basic maintenance personnel. The unified operating interface integrates database auditing and API monitoring of raw log data, enabling end-to-end application data link characterization and tracking and display of sensitive data links to identify potential security threats and provide a basis for subsequent risk management. The unified operating interface integrates data security log data, including network traffic, system logs, audit logs, and application logs, through API interface integration. This constructs a data association model for data flow scenarios and uses a CNN convolutional neural network to achieve rapid data extraction and processing of specific nodes through a unified data access and paradigm layer. The system assists in decision-making by combining sensitive and related data from the context of scene logs at specific nodes. It learns to perform pattern recognition and feature extraction, applying this to structural data graphs to quickly identify valuable subgraphs from complex network relationships. It aggregates and analyzes data security logs and traffic, enabling routine data security risk analysis and alerts. Through a powerful log parsing engine and correlation analysis capabilities, it promptly detects and responds to potential data security threats, providing comprehensive log management and analysis functions to ensure rapid identification and handling of data security incidents. The unified operating interface uses a digital twin generated by metaverse technology as a data flow traceability model, connected to the edge intelligence of the digital power grid. When data within the edge intelligence of the digital power grid is abnormally tampered with, a CNN convolutional neural network detects the anomaly, accurately locates the compromised edge intelligence, and predicts the scope of the abnormal behavior. Simultaneously, stress tests and virtual simulations are immediately performed on the digital twin constructed using metaverse technology to predict potential system crashes or data leaks, providing precise handling plans and risk level classifications in advance. Low-risk cases are handled autonomously. This method constructs a complete closed loop for data traceability through a data flow traceability model, encompassing perception (IoT / logs), analysis (AI), decision-making (digital twin simulation), response (SOAR), and auditing (blockchain).

[0005] The CNN convolutional neural network detects multiple low-risk anomalous behaviors linked together, or automatically marks an anomalous behavior as a high-risk event when its confidence score is extremely high. It then uses a GNN graph neural network to automatically generate an attack chain graph and sends high-level alerts to security analysts via an integrated communication platform or SOAR platform, including preliminary correlation analysis results. This allows security analysts to quickly identify who accessed or stole data, when, and how through blockchain traceability, and make decisions. Without impacting real business operations, they can assess the potential impact of various response strategies and select the optimal and most precise handling plan, greatly improving the scientific rigor and speed of decision-making.

[0006] The security analysts push reports to senior decision-makers via API, and use immersive AR video conferencing or VR conference rooms to bring experts and senior decision-makers from different locations into the same digital twin scenario to jointly view the attack situation and make collaborative decisions.

[0007] The CNN convolutional neural network includes a recurrent neural network (RNN / LSTM for processing sequence data). The recurrent neural network transforms network connections over a period of time into a pixel matrix, extracts and identifies spatial features from it, and makes an automatic response to the East Station. If it is confirmed as a false alarm, it automatically shuts down the alarm and learns to reduce the weight of similar events in the future. All automatic decisions and actions are recorded on the blockchain after being encrypted and hashed.

[0008] The digital twin is a hierarchical digital twin, employing a simulation-analysis separation architecture, including an L1 physical network layer, an L2 data flow layer, and an L3 business logic layer. The L1 physical network layer accurately simulates network topology, routing, and bandwidth; the L2 data flow layer simulates the path of core business data flow; and the L3 business logic layer simulates critical business logic. Thus, when simulation is needed, a snapshot of the current state is sent to a high-performance simulation engine cluster for parallel and accelerated simulation, and the results are then returned, balancing real-time performance and computational overhead.

[0009] The digital twin computing center of the digital twin is connected to the power grid and equipped with an energy storage power station. It also relies on the LSTM long short-term memory neural network model to achieve autonomous analysis and processing of data security incidents under low-level risks.

[0010] The model's input sequence $X_t=[x_{tT},x_{t-T+1},...,x_{t-1}]$, at time step $t$, the model's comprehensive input state vector $\mathcal{X}_t$ is:

[0011] $\mathcal{X}_t=[\mathcal{G}_t,\mathcal{S}_t,\mathcal{C}_t,\mathcal{R}_t]$;

[0012] Each component is a vector, which are concatenated and used as the input to the LSTM unit, resulting in the following input sequence for the entire model:

[0013] $X_t^{new}=[\mathcal{X}{tT},\mathcal{X}{t-T+1},...,\mathcal{X}_{t-1}]$;

[0014] The above $\mathcal{G}_t$ is the power grid state vector, representing the state information of the external power grid at time step $t$, which is the main basis for the charging decision of the energy storage power station. $p_t^g$ is the electricity price of the power grid at the current moment, $l_t^g$ is the load factor of the power grid at the current moment, which is used to predict the electricity price trend, and $r_t^{green}$ is the proportion of green energy in the current power grid, which is used to achieve the low-carbon calculation target.

[0015] The above $\mathcal{S}_t$ is the state vector of the energy storage system, representing the real-time state of the energy storage station itself at time step $t$, which is the basis for charging and discharging decisions. $soc_t$ is the current state of charge of the energy storage station, i.e. the percentage of battery remaining capacity. $p_t^{charge}$ is the current maximum rechargeable power. $p_t^{discharge}$ is the current maximum dischargeable power. $health_t$ is the health index of the energy storage station.

[0016] The above $\mathcal{C}_t$ is the computing center load vector, representing the workload and demand of the digital twin computing center at time step $t$, which is the main power consumption. $w_t$ is the length of the waiting computing task queue, $u_t$ is the current utilization rate of computing resources, $d_t$ is the urgency of the deadline of the computing task, and $priority_t$ is the average priority of the current computing task.

[0017] The above $\mathcal{R}_t$ is a security risk vector, representing the low-level data security event information monitored at step $t$, which is used to dynamically adjust the allocation of computing resources. $event_count_t$ is the frequency of recent low-level security events. $risk_score_t$ is a dynamic risk score calculated based on event type and asset importance. $type_t$ is the encoding of the main security event types.

[0018] The goal of this model is to learn a complex spatiotemporal dynamic system, and the output is typically a multivariate vector $\mathcal{Y}_t$:

[0019] $\mathcal{Y}t=LSTM(\mathcal{X}t^{new},h{t-1},c{t-1})$;

[0020] When electricity prices are low ($\mathcal{G}_t$), it is recommended to charge the battery. When the computational load is high and electricity prices are high ($\mathcal{C}_t,\mathcal{G}_t$), it is recommended to use energy storage to discharge the battery.

[0021] The $risk_score_t$ is compared with a dynamic threshold $\theta_t$ to determine whether to trigger an autonomous processing procedure. When the input $risk_score_t$ ($\mathcal{R}_t$) exceeds this threshold, the system automatically initiates a predetermined safety processing procedure. The dynamic threshold $\theta_t$ changes dynamically based on the overall system load $\mathcal{C}_t$ and the energy storage state $\mathcal{S}_t$. For example, when the system load is extremely high, the threshold $\theta_t$ can be slightly increased to prevent the safety processing procedure from consuming too many resources; when the system is idle, the threshold $\theta_t$ is decreased to improve the safety protection level.

[0022] This model is a digital twin integrating energy, computing power, and security. The input is a continuous snapshot sequence $X_t^{new}$ of the system state over a past period, and the output is the charging and discharging strategy for the energy storage system, the scheduling strategy for computing tasks, and the dynamic adjustment strategy for security thresholds. Simultaneously, it intelligently uses historical data to decide when to charge during off-peak hours, when to discharge power to the computing center, when to perform computations, and how to dynamically handle security events, thereby achieving an optimal balance between cost, efficiency, and security. Thus, the energy storage power station supplies power to the computing center during the day or other times, while the computing center charges from the grid during off-peak hours at night, enabling large-scale construction and computing tasks to be implemented at reasonable electricity prices.

[0023] The model incorporates $\mathcal{T}_t$ as the time feature vector and $\mathcal{H}_t$ as the holiday feature vector, resulting in:

[0024] $\mathcal{X}_t^{final}=[\mathcal{G}_t,\mathcal{S}_t,\mathcal{C}_t,\mathcal{R}_t,\mathcal{T}_t,\mathcal{H}_t]$;

[0025] Where $\mathcal{G}_t,\mathcal{S}_t,\mathcal{C}_t,\mathcal{R}_t$ have the same meaning as before, and $\mathcal{T}_t$ and $\mathcal{H}_t$ are newly added feature vectors. The input sequence of the model is:

[0026] $X_t^{final}=[\mathcal{X}{tT}^{final},\mathcal{X}{t-T+1}^{final},...,\mathc al{X}_{t-1}^{final}]$;

[0027] The aforementioned time feature vectors represent the capture of absolute and relative time information, helping the model learn patterns with daily, weekly, and yearly cycles. $hour_t$ represents the hour of the current time (0-23), allowing the model to learn patterns for different time periods such as morning rush hour, midday, and nighttime. $day_of_week_t$ represents the current day of the week (0-6), helping the model learn the differences between weekdays and weekends. $month_t$ represents the current month (1-12), helping the model learn seasonal patterns, such as the high electricity load of air conditioning in summer. $is_daylight_t$ is a Boolean value indicating whether it is currently daytime, calculated based on sunrise and sunset times.

[0028] The above holiday feature vector represents the quantification of the impact of holidays. Holidays typically disrupt normal weekday / weekend electricity and computing patterns. $is_holiday_t$ is a boolean value indicating whether the day is a statutory holiday.

[0029] $is_weekend_t$ is a boolean value indicating whether the day is a weekend, $holiday_type_t$ is the type code of the holiday, and different types of holidays have different degrees of impact, and $proximity_to_holiday_t$ is the holiday coefficient, where 0 represents a regular working day and 1 represents a holiday day.

[0030] As a result, the model improves the accuracy of electricity price and load forecasting, optimizes the scheduling of computational tasks for the digital twin, and refines the adjustment of security risk thresholds. The model has evolved from one that only cares about the "current system state" to one that can understand "what time it is now".

[0031] The specific implementation steps of this method are as follows:

[0032] S1. Construction and Data Access Phase: Security device integration and unified operation interface construction; collection and normalization of multi-source log data through API interface connection; and construction of a digital twin as a data flow traceability model using metaverse technology.

[0033] S2, Intelligent Analysis and Detection and Feature Extraction Stage: First, CNN convolutional neural network is used for feature extraction and anomaly detection. Then, the data flow tracing model and data graph construction are realized. GNN graph neural network is used for correlation analysis and attack chain reconstruction to generate a complete attack chain graph and reveal the attacker's lateral movement path. Finally, RNN / LSTM is used to process time series data and learn false alarms to realize model self-optimization.

[0034] S3, Threat Assessment and Virtual Simulation Phase: S301 Phase dynamically classifies risk levels, S302 Phase conducts stress testing and virtual simulation of the digital twin, and S303 Phase generates precise response plans.

[0035] S4, Response and Closed-Loop Management Phase: Through automated response and collaborative handling, blockchain evidence storage and process closure are completed.

[0036] S5. In the resource scheduling and continuous operation assurance phase, the energy storage power station equipped in the digital twin computing center relies on the LSTM long short-term memory neural network model to predict the peak and valley of the grid electricity price and the computing load. During the nighttime off-peak hours, it charges the grid at a reasonable electricity price and supplies power to the computing center to carry out large-scale secure computing tasks. This ensures that the system has sufficient and economical computing resources for autonomous analysis and processing under low-level data security incident risks.

[0037] In step S2, after the CNN convolutional neural network performs feature extraction and anomaly detection, it is fed into the UEBA engine. External threat intelligence is injected into the CNN / RNN, and machine learning is used to establish a behavioral baseline. Thus, when the CNN / RNN detects micro-anomalies, the UEBA engine is responsible for detecting macro-anomalies that deviate from historical behavioral patterns, complementing attack chain analysis and enabling earlier detection of latent threats.

[0038] The logical structure of this invention is reasonably designed, and the completeness and accuracy of the model and steps are high. In particular, the power supply process of the digital twin computing center of the digital twin is connected to the energy storage battery, which achieves the effect of low energy consumption and intelligence. It is applicable to the data flow tracing method of data security events and data entity patterns in digital power grids, as well as the technical improvements of similar methods. Attached Figure Description

[0039] Figure 1 This is a flowchart illustrating the overall process of this invention. Implementation

[0040] The specific implementation steps of the present invention will now be described in further detail with reference to the accompanying drawings. Figure 1 As shown, this method is specifically a data flow tracing approach for data security incidents and data entity patterns. The core of this method is the construction of a data security defense system for a digital power grid, integrating all data security devices and a unified operating interface. It uses charts to display the operational status, risk status, and protected object information of data security protection devices. The Security Operations Center (SOC) platform enables real-time monitoring and visualization of the entire network's data security status, allowing for categorized management by device type and deployment location, and one-click access to various system operating interfaces, simplifying the workflow of basic maintenance personnel. The unified operating interface accesses database auditing and API monitoring of raw log data, enabling end-to-end application data link characterization and tracking and display of sensitive data links to identify potential security threats and provide a basis for subsequent risk management. The unified operating interface integrates data security log data via API interface, including network traffic, system logs, audit logs, and application logs, constructing a data association model for data flow scenarios. Through a unified data access and paradigm layer, a CNN convolutional neural network enables rapid data processing for special nodes. Extraction and decision support are achieved by combining sensitive and related data from the context of scene logs at special nodes. The system learns to perform pattern recognition and feature extraction, applying this to structural data graphs to quickly identify valuable subgraphs from complex network relationships. It aggregates and analyzes data security logs and traffic, enabling routine data security risk analysis and alerts. Through a powerful log parsing engine and correlation analysis capabilities, it promptly detects and responds to potential data security threats, providing comprehensive log management and analysis functions to ensure rapid identification and handling of data security incidents. The unified operating interface uses a digital twin generated by metaverse technology as a data flow traceability model, connected to the edge intelligence of the digital power grid. When data within the edge intelligence of the digital power grid is abnormally tampered with, the CNN convolutional neural network detects the data anomaly, accurately locates the compromised edge intelligence, and predicts the scope of the abnormal behavior. Simultaneously, stress tests and virtual simulations are immediately performed on the digital twin constructed using metaverse technology to predict potential system crashes or data leaks, providing precise handling plans and risk level classifications in advance. Low-risk cases are handled autonomously.

[0041] This method addresses several issues: data flow invisibility (massive data flowing through complex power grid environments with unclear paths and undefined responsibilities); fragmented threat alerts (security devices operating independently, resulting in an overwhelming storm of alerts that drowns out genuine high-risk events); low response efficiency (relying on manual analysis, tracing, and decision-making, which is time-consuming and prone to missing optimal response opportunities); and difficulty in managing edge security (massive edge intelligent terminals are easily targeted as attack entry points, and traditional protection methods are insufficient to cover them). The overall solution architecture comprises a data access layer, an intelligent analysis layer, a digital twin layer, an application presentation layer, and a response execution layer. The intelligent analysis layer combines CNN (feature extraction), RNN / LSTM (time series analysis), and GNN (graph neural network) to achieve collaborative analysis. Specifically: CNN rapidly scans massive amounts of data to accurately identify microscopic anomalies in specific nodes; RNN / LSTM analyzes time-series behavior to identify long-term patterns, effectively reducing false alarms; and GNN constructs a data association graph, linking fragmented alerts into a complete attack chain. Meanwhile, in the intelligent response and collaborative decision-making closed loop, low-level risks are simulated and stress-tested in a twin to verify the effectiveness of the handling plan before execution, ensuring that nothing goes wrong; and relying on blockchain evidence storage, all operation records are recorded on the chain to ensure the immutability of audit traces.

[0042] Specifically, this method uses a CNN (Convolutional Neural Network) to detect multiple low-risk anomalous behaviors linked together, or to automatically mark an anomalous behavior as a high-level event when its confidence score is extremely high. It then uses a GNN (Graph Neural Network) to automatically generate an attack chain graph and sends high-level alerts to security analysts via an integrated communication platform or SOAR (Social Security Analysis Platform), including preliminary correlation analysis results. Security analysts push reports to senior decision-makers via API, and immersive AR video conferencing or VR conference rooms allow experts and senior decision-makers from different locations to enter the same digital twin scenario to jointly view the attack situation and make collaborative decisions. The CNN incorporates a recurrent neural network (RNN / LSTM for processing sequence data). The RNN transforms network connections over a period of time into a pixel matrix, extracts and identifies spatial features, and makes automatic responses. If a false alarm is confirmed, the alert is automatically disabled and the system learns to reduce the weight of similar events in the future. All automatic decisions and actions are recorded on the blockchain after being encrypted and hashed. The digital twin is a hierarchical digital twin with an analog-analysis separation architecture, including the L1 physical network layer, the L2 data flow layer, and the L3 business logic layer. The L1 physical network layer accurately simulates the network topology, routing, and bandwidth; the L2 data flow layer simulates the path of core business data flow; and the L3 business logic layer simulates key business logic.

[0043] When the aforementioned low-level risks are simulated virtually, an energy storage power station is equipped in the digital twin computing center of the digital twin. Relying on AI algorithms for intelligent scheduling, it prioritizes the use of off-peak electricity at night for large-scale computational analysis, significantly reducing operating costs and carbon footprint. Specifically, it utilizes an LSTM (Long Short-Term Memory) neural network model to achieve autonomous analysis and processing of low-level data security incidents. The model's input sequence $X_t=[x_{tT},x_{t-T+1},...,x_{t-1}]$, at time step $t$, the model's comprehensive input state vector $\mathcal{X}_t$ is:

[0044] $\mathcal{X}_t=[\mathcal{G}_t,\mathcal{S}_t,\mathcal{C}_t,\mathcal{R}_t]$;

[0045] Each component is a vector, which are concatenated and used as the input to the LSTM unit, resulting in the following input sequence for the entire model:

[0046] $X_t^{new}=[\mathcal{X}{tT},\mathcal{X}{t-T+1},...,\mathcal{X}_{t-1}]$;

[0047] The above $\mathcal{G}_t$ is the power grid state vector, representing the state information of the external power grid at time step $t$, which is the main basis for the charging decision of the energy storage power station. $p_t^g$ is the electricity price of the power grid at the current moment, $l_t^g$ is the load factor of the power grid at the current moment, which is used to predict the electricity price trend, and $r_t^{green}$ is the proportion of green energy in the current power grid, which is used to achieve the low-carbon calculation target.

[0048] The above $\mathcal{S}_t$ is the state vector of the energy storage system, representing the real-time state of the energy storage station itself at time step $t$, which is the basis for charging and discharging decisions. $soc_t$ is the current state of charge of the energy storage station, i.e., the percentage of remaining battery capacity.

[0049] $p_t^{charge}$ represents the current maximum chargeable power, and $p_t^{discharge}$ represents the current maximum dischargeable power.

[0050] $health_t$ represents the health index of the energy storage power station;

[0051] The above $\mathcal{C}_t$ is the computing center load vector, representing the workload and demand of the digital twin computing center at time step $t$, which is the main power consumption. $w_t$ is the length of the waiting computing task queue, $u_t$ is the current utilization rate of computing resources, $d_t$ is the urgency of the deadline of the computing task, and $priority_t$ is the average priority of the current computing task.

[0052] The above $\mathcal{R}_t$ is a security risk vector, representing low-level data security event information detected at step $t$, used to dynamically adjust the allocation of computing resources. $event_count_t$ is the frequency of recent low-level security events.

[0053] $risk_score_t$ is a dynamic risk score calculated based on event type and asset importance, and $type_t$ is the code for the main security event types;

[0054] The goal of this model is to learn a complex spatiotemporal dynamic system, and the output is typically a multivariate vector.

[0055] $\mathcal{Y}_t$:

[0056] $\mathcal{Y}t=LSTM(\mathcal{X}t^{new},h{t-1},c{t-1})$;

[0057] When electricity prices are low ($\mathcal{G}_t$), it is recommended to charge the battery. When the computational load is high and electricity prices are high ($\mathcal{C}_t,\mathcal{G}_t$), it is recommended to use energy storage to discharge the battery.

[0058] The $risk_score_t$ is compared with a dynamic threshold $\theta_t$ to determine whether to trigger an autonomous processing procedure. When the input $risk_score_t$ ($\mathcal{R}_t$) exceeds this threshold, the system automatically starts a predetermined safety processing procedure. The dynamic threshold $\theta_t$ changes dynamically according to the overall system load $\mathcal{C}_t$ and the energy storage state $\mathcal{S}_t$.

[0059] The model incorporates $\mathcal{T}_t$ as the time feature vector and $\mathcal{H}_t$ as the holiday feature vector, resulting in:

[0060] $\mathcal{X}_t^{final}=[\mathcal{G}_t,\mathcal{S}_t,\mathcal{C}_t,\mathcal{R}_t,\mathcal{T}_t,\mathcal{H}_t]$;

[0061] Where $\mathcal{G}_t,\mathcal{S}_t,\mathcal{C}_t,\mathcal{R}_t$ have the same meaning as before, and $\mathcal{T}_t$ and $\mathcal{H}_t$ are newly added feature vectors. The input sequence of the model is:

[0062] $X_t^{final}=[\mathcal{X}{tT}^{final},\mathcal{X}{t-T+1}^{final},...,\mathcal{X}_{t-1}^{final}]$;

[0063] The aforementioned time feature vectors represent the capture of absolute and relative time information, helping the model learn patterns with daily, weekly, and yearly cycles. $hour_t$ represents the hour of the current time (0-23), allowing the model to learn patterns for different time periods such as morning rush hour, midday, and nighttime. $day_of_week_t$ represents the current day of the week (0-6), helping the model learn the differences between weekdays and weekends. $month_t$ represents the current month (1-12), helping the model learn seasonal patterns, such as the high electricity load of air conditioning in summer. $is_daylight_t$ is a Boolean value indicating whether it is currently daytime, calculated based on sunrise and sunset times.

[0064] The above holiday feature vector represents the quantification of the impact of holidays. Holidays usually completely disrupt the normal weekday / weekend electricity and computing patterns. $is_holiday_t$ is a boolean value indicating whether the day is a statutory holiday, $is_weekend_t$ is a boolean value indicating whether the day is a weekend, $holiday_type_t$ is the type code of the holiday, and different types of holidays have different degrees of impact. $proximity_to_holiday_t$ is the holiday coefficient, where 0 represents a normal weekday and 1 represents a holiday day.

Claims

1. A method for tracing the data flow of data security incidents and data entity patterns. This method integrates all data security devices and a unified operating interface through the construction of data security defenses in a digital power grid. It uses charts to display the operating status, risk status, and information summary of protected objects of data security protection devices. The method achieves real-time monitoring and visualization of the data security status of the entire network through the Security Operations Center (SOC) platform. It also allows for categorized management by device type and deployment location, with one-click access to the operating interfaces of various systems, simplifying the workflow of basic maintenance personnel. Its features include: The unified user interface integrates database auditing and API monitoring of raw log data, enabling end-to-end application data link profiling and tracking and displaying sensitive data links. This is used to identify potential security threats and provide a basis for subsequent risk management. The unified user interface integrates data security log data via API interfaces. This log data includes network traffic, system logs, audit logs, and application logs. It constructs a data association model for data flow scenarios and uses a unified data access and paradigm layer. A CNN convolutional neural network is used to quickly extract data from special nodes and assist decision-making. Special nodes combine sensitive and related data in the context of scenario logs, learn pattern recognition and feature extraction, and apply them to structured data graphs. This allows for rapid identification of valuable subgraphs from complex network relationships, summarizing and analyzing data security logs and traffic. The system provides routine data security risk analysis and alerts, and through a powerful log parsing engine and correlation analysis capabilities, it promptly detects and responds to potential data security threats, providing comprehensive log management and analysis functions to ensure rapid identification and handling of data security incidents. The unified user interface uses a digital twin generated and constructed using metaverse technology as a data flow traceability model, and connects to the edge intelligence of the digital power grid. When data within the edge intelligence of the digital power grid is abnormally tampered with, the CNN convolutional neural network detects the data anomaly, accurately locates the compromised edge intelligence, and predicts the scope of the abnormal behavior. Simultaneously, stress tests and virtual simulations are immediately performed on the digital twin constructed using metaverse technology to predict potential system crashes or data leaks, and provide precise handling plans and risk level classifications in advance, autonomously handling low-risk cases.

2. The data flow tracing method for data security events and data entity patterns according to claim 1, characterized in that... When the CNN convolutional neural network detects multiple low-risk anomalous behaviors linked together, or when a certain anomalous behavior has an extremely high confidence score, it automatically marks it as a high-level event; and it uses the GNN graph neural network to automatically generate an attack chain graph, and sends a high-level alert to security analysts through an integrated communication platform or SOAR platform, with the information including preliminary correlation analysis results.

3. The data flow tracing method for data security incidents and data entity patterns according to claim 2, characterized in that... The security analysts push reports to senior decision-makers via API, and use immersive AR video conferencing or VR conference rooms to bring experts and senior decision-makers from different locations into the same digital twin scenario to jointly view the attack situation and make collaborative decisions.

4. The data flow tracing method for data security events and data entity patterns according to claim 2, characterized in that... The CNN convolutional neural network includes a recurrent neural network. The recurrent neural network converts network connections over a period of time into a pixel matrix, extracts and identifies spatial features from it, and makes an automatic response to the East Station. If it is confirmed to be a false alarm, it automatically shuts down the alarm and learns to reduce the weight of similar events in the future. All automatic decisions and actions are recorded on the blockchain after being encrypted and hashed.

5. The data flow tracing method for data security events and data entity patterns according to claim 1, characterized in that... The digital twin is a hierarchical digital twin with an analog-analysis separation architecture, including an L1 physical network layer, an L2 data flow layer, and an L3 business logic layer. The L1 physical network layer accurately simulates the network topology, routing, and bandwidth; the L2 data flow layer simulates the path of core business data flow; and the L3 business logic layer simulates key business logic.

6. The data flow tracing method for data security events and data entity patterns according to claim 5, characterized in that... The digital twin computing center of the digital twin is connected to the power grid and equipped with an energy storage power station. It also relies on the LSTM long short-term memory neural network model to achieve autonomous analysis and processing of data security incidents under low-level risks. The model's input sequence $X_t=[x_{tT},x_{t-T+1},...,x_{t-1}]$, at time step $t$, the model's comprehensive input state vector $\mathcal{X}_t$ is: $\mathcal{X}_t=[\mathcal{G}_t,\mathcal{S}_t,\mathcal{C}_t,\mathcal{R}_t]$; Each component is a vector, which are concatenated and used as the input to the LSTM unit, resulting in the following input sequence for the entire model: $X_t^{new}=[\mathcal{X}{tT},\mathcal{X}{t-T+1},...,\mathcal{X}_{t-1}]$; The above $\mathcal{G}_t$ is the power grid state vector, representing the state information of the external power grid at time step $t$, which is the main basis for the charging decision of the energy storage power station. $p_t^g$ is the electricity price of the power grid at the current moment, $l_t^g$ is the load factor of the power grid at the current moment, which is used to predict the electricity price trend, and $r_t^{green}$ is the proportion of green energy in the current power grid, which is used to achieve the low-carbon calculation target. The above $\mathcal{S}_t$ is the state vector of the energy storage system, representing the real-time state of the energy storage station itself at time step $t$, which is the basis for charging and discharging decisions. $soc_t$ is the current state of charge of the energy storage station, i.e., the percentage of remaining battery capacity. $p_t^{charge}$ represents the current maximum chargeable power, and $p_t^{discharge}$ represents the current maximum dischargeable power. $health_t$ represents the health index of the energy storage power station; The above $\mathcal{C}_t$ is the computing center load vector, representing the workload and demand of the digital twin computing center at time step $t$, which is the main power consumption. $w_t$ is the length of the waiting computing task queue, $u_t$ is the current utilization rate of computing resources, $d_t$ is the urgency of the deadline of the computing task, and $priority_t$ is the average priority of the current computing task. The above $\mathcal{R}_t$ is a security risk vector, representing the low-level data security event information monitored at step $t$, which is used to dynamically adjust the allocation of computing resources. $event_count_t$ is the frequency of recent low-level security events. $risk_score_t$ is a dynamic risk score calculated based on event type and asset importance. $type_t$ is the encoding of the main security event types. The goal of this model is to learn a complex spatiotemporal dynamic system, and the output is typically a multivariate vector. $\mathcal{Y}_t$: $\mathcal{Y}t=LSTM(\mathcal{X}t^{new},h{t-1},c{t-1})$; It is recommended to charge when electricity prices are low ($\mathcal{G}_t$), and when computational load is high and electricity prices are high. ($\mathcal{C}_t,\mathcal{G}_t$) suggests using energy storage discharge for power supply.

7. The data flow tracing method for data security incidents and data entity patterns according to claim 6, characterized in that... The $risk_score_t$ is compared with a dynamic threshold $\theta_t$ to determine whether to trigger an autonomous processing procedure. When the input $risk_score_t$ ($\mathcal{R}_t$) exceeds this threshold, the system automatically starts a predetermined safety processing procedure. The dynamic threshold $\theta_t$ changes dynamically according to the overall system load $\mathcal{C}_t$ and the energy storage state $\mathcal{S}_t$.

8. The data flow tracing method for data security events and data entity patterns according to claim 6, characterized in that... The model incorporates $\mathcal{T}_t$ as the time feature vector and $\mathcal{H}_t$ as the holiday feature vector, resulting in: $\mathcal{X}_t^{final}=[\mathcal{G}_t,\mathcal{S}_t,\mathcal{C}_t,\mathcal{R}_t,\mathcal{T}_t,\mathcal{H}_t]$; Where $\mathcal{G}_t,\mathcal{S}_t,\mathcal{C}_t,\mathcal{R}_t$ have the same meaning as before, and $\mathcal{T}_t$ and $\mathcal{H}_t$ are newly added feature vectors. The input sequence of the model is: $X_t^{final}=[\mathcal{X}{tT}^{final},\mathcal{X}{t-T+1}^{final},...,\mathc al{X}_{t-1}^{final}]$; The aforementioned time feature vectors represent the capture of absolute and relative time information, helping the model learn patterns with daily, weekly, and yearly cycles. $hour_t$ represents the hour of the current time (0-23), allowing the model to learn patterns for different time periods such as morning rush hour, midday, and nighttime. $day_of_week_t$ represents the current day of the week (0-6), helping the model learn the differences between weekdays and weekends. $month_t$ represents the current month (1-12), helping the model learn seasonal patterns, such as the high electricity load of air conditioning in summer. $is_daylight_t$ is a Boolean value indicating whether it is currently daytime, calculated based on sunrise and sunset times. The above holiday feature vector represents the quantification of the impact of holidays. Holidays typically disrupt normal weekday / weekend electricity and computing patterns. $is_holiday_t$ is a boolean value indicating whether the day is a statutory holiday. $is_weekend_t$ is a boolean value indicating whether the day is a weekend, $holiday_type_t$ is the type code of the holiday, and different types of holidays have different degrees of impact, and $proximity_to_holiday_t$ is the holiday coefficient, where 0 represents a regular working day and 1 represents a holiday day.

9. The data flow tracing method for data security incidents and data entity patterns according to claim 1, characterized in that... The specific implementation steps of this method are as follows: S1. Construction and Data Access Phase: Security device integration and unified operation interface construction; collection and normalization of multi-source log data through API interface connection; and construction of a digital twin as a data flow traceability model using metaverse technology. S2, Intelligent Analysis and Detection and Feature Extraction Stage: First, CNN convolutional neural network is used for feature extraction and anomaly detection. Then, the data flow tracing model and data graph construction are realized. GNN graph neural network is used for correlation analysis and attack chain reconstruction to generate a complete attack chain graph and reveal the attacker's lateral movement path. Finally, RNN / LSTM is used to process time series data and learn false alarms to realize model self-optimization. S3, Threat Assessment and Virtual Simulation Phase: S301 Phase dynamically classifies risk levels, S302 Phase conducts stress testing and virtual simulation of the digital twin, and S303 Phase generates precise response plans. S4, Response and Closed-Loop Management Phase: Through automated response and collaborative handling, blockchain evidence storage and process closure are completed. S5. In the resource scheduling and continuous operation guarantee phase, the energy storage power station equipped in the digital twin computing center relies on the LSTM long short-term memory neural network model to predict the peak and valley of the grid electricity price and the computing load; during the nighttime off-peak period, it charges the grid at a reasonable electricity price and supplies power to the computing center to implement large-scale safe computing tasks. Ensure that the system has sufficient and economical computing resources for autonomous analysis and processing even in the event of a low-level data security incident.

10. The data flow tracing method for data security events and data entity patterns according to claim 9, characterized in that... After feature extraction and anomaly detection in step S2, the CNN convolutional neural network is added to the UEBA engine. External threat intelligence is injected into the CNN / RNN, and machine learning is used to establish a behavioral baseline.

Citation Information

Patent Citations

  • Block chain-based data flow tracing method

    CN114036229A

Cited By

  • Data security risk early warning method and system based on artificial intelligence

    CN121923947A

  • Artificial intelligence-based data security risk early warning method and system

    CN121923947B