Multi-scene concurrent test method and device of power system network, computer equipment, readable storage medium and program product

By acquiring security test templates, establishing target attack instances and test instances, controlling the network topology switching matrix to form communication links, and automatically configuring the network structure, the problem of cumbersome manual configuration in existing technologies is solved, enabling flexible and efficient security testing of power system networks.

CN121125293APending Publication Date: 2025-12-12ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511405655.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-29
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

Existing power system network security testing platforms require cumbersome manual configuration and lack flexible network reconfiguration capabilities. Existing technical solutions also suffer from the technical problem of being unable to automatically configure network structures. The specific problem that existing technologies cannot effectively solve is the need for manual configuration of network structures in existing power system network security testing platforms.

Method used

This paper provides a multi-scenario concurrent testing method for power system networks. By acquiring security test templates, establishing target attack instances and test instances, controlling the network topology switching matrix to form communication links, automatically configuring the network structure, conducting security tests, and evaluating protection performance.

Benefits of technology

It enables automatic configuration of network structure, reduces manual intervention, improves the flexibility and efficiency of network testing, and can simulate network attack scenarios with high fidelity without affecting actual power grid services, providing strong support for security protection technology.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125293A_ABST
    Figure CN121125293A_ABST
Patent Text Reader

Abstract

The invention relates to a multi-scene concurrent testing method and device for a power system network, computer equipment, a computer readable storage medium and a computer program product. Comprising the following steps: in response to a starting instruction for a power system network security test, obtaining a security test template corresponding to the starting instruction; based on the security test template, determining a target attack script, establishing a target attack instance, establishing a target test instance corresponding to the security test, and selecting a target test device from the test devices; based on the security test template, controlling a network topology switching matrix to establish a communication link of the target attack instance, the target test instance and the target test equipment to form a security test scene; performing a security test based on the target attack script and the security test scene, and obtaining test data of the security test in real time; and when the security test is finished, evaluating the protection performance of the power system network based on the test data. By adopting the method, the network structure can be automatically configured to perform the security test.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of power system network technology, and in particular to a method, apparatus, computer equipment, computer-readable storage medium, and computer program product for multi-scenario concurrent testing of power system networks. Background Technology

[0002] With the large-scale integration of smart grids, new energy technologies, and various intelligent terminal devices, power systems are facing increasingly severe cybersecurity challenges. Cybersecurity threats are characterized by complex and diverse attack methods and long latency periods, placing immense pressure on power system security. To study the impact of various cyberattacks on power systems, the industry has begun constructing dedicated cybersecurity testing platforms (also known as cybersecurity ranges) for conducting simulation experiments and security drills. These cybersecurity ranges allow for highly realistic simulations of cyberattack scenarios without affecting actual power grid operations, providing strong support for the development of security protection technologies.

[0003] Current power system network security testing platforms primarily employ a hybrid simulation approach that combines virtual and physical environments. However, existing solutions require testers to repeatedly plug and unplug network cables and adjust switch configurations to switch between different testing environments. This results in cumbersome manual configuration and a lack of flexible network reconfiguration capabilities. Summary of the Invention

[0004] Therefore, it is necessary to provide a method, apparatus, computer equipment, computer-readable storage medium, and computer program product for multi-scenario concurrent testing of power system networks that can automatically configure the network structure without relying on manual configuration, in order to address the above-mentioned technical problems.

[0005] Firstly, this application provides a multi-scenario concurrent testing method for power system networks, including:

[0006] In response to a start command for power system network security testing, obtain the security test template corresponding to the start command;

[0007] Based on the security test template, determine the target attack script corresponding to the security test and establish a target attack instance; based on the security test template, establish a target test instance corresponding to the security test and select the target test device required for the security test from the test devices;

[0008] Based on the security test template, the control network topology switching matrix establishes a communication link between the target attack instance, the target test instance, and the target test device to form a security test scenario.

[0009] Security testing is conducted based on the target attack script and security test scenario, and test data is acquired in real time.

[0010] When the security test reaches the preset stop condition, the protection performance of the power system network is evaluated based on the acquired test data.

[0011] In one embodiment, the step of connecting the target attack instance, the target test instance, and the target test device through a network topology switching matrix to form a security test scenario includes:

[0012] Virtual switches are created and virtual network identifiers are assigned to the target attack instance and the target test instance. Based on the target test device, the virtual network identifier, and the virtual switch, port mapping rules are generated. The port mapping rules are used to guide the network topology switching matrix to establish a communication link between the target test device and the virtual switch corresponding to the virtual network identifier, so that the target test device can transmit data to the virtual switch through the communication link. Based on the port mapping rules, the network topology switching matrix is ​​controlled to establish a communication link between the target test device, the target attack instance, and the target test instance, forming a security test scenario.

[0013] In one embodiment, the security testing based on the target attack script and the security test scenario includes:

[0014] The system controls a target attack instance in a security testing scenario to run the target attack script and generate an attack data packet; the attack data packet is then sent to the target testing device and the target testing instance via the communication link to attack the target testing device and the target testing instance.

[0015] In one embodiment, after the security test reaches a preset stop condition, the method further includes:

[0016] Disconnect the communication links between the target test device, the target attack instance, and the target test instance; clear the port mapping rules; and delete the target attack instance and the target test instance.

[0017] In one embodiment, after acquiring the test data of the security test in real time, the method further includes:

[0018] In the presence of multiple security test scenarios, if a conflict is detected in the computing resources required by the multiple security test scenarios, the priority of the multiple security test scenarios is obtained; based on the priority of the multiple security test scenarios, computing resources are allocated to the multiple test scenarios.

[0019] In one embodiment, the method further includes:

[0020] In response to the setup operation for power system network security testing, a name for the security test is generated, the network topology required for the security test is established, and a script attack file corresponding to the security test is generated; the name, the network topology, and the script attack file constitute the security test template.

[0021] Secondly, this application also provides a multi-scenario concurrent testing device for power system networks, including:

[0022] The acquisition module is used to acquire the security test template corresponding to the start command in response to the start command for power system network security testing;

[0023] The module is used to determine the target attack script corresponding to the security test based on the security test template, and to establish a target attack instance; based on the security test template, to establish a target test instance corresponding to the security test, and to select the target test device required for the security test from the test devices;

[0024] The communication module is used to control the network topology switching matrix to establish a communication link between the target attack instance, the target test instance, and the target test device based on the security test template, thereby forming a security test scenario;

[0025] The testing module is used to perform security tests based on the target attack script and security test scenarios, and to acquire the test data of the security tests in real time.

[0026] The evaluation module is used to evaluate the protection performance of the power system network based on the acquired test data when the security test reaches the preset stop conditions.

[0027] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:

[0028] In response to a start command for power system network security testing, obtain the security test template corresponding to the start command;

[0029] Based on the security test template, determine the target attack script corresponding to the security test and establish a target attack instance; based on the security test template, establish a target test instance corresponding to the security test and select the target test device required for the security test from the test devices;

[0030] Based on the security test template, the control network topology switching matrix establishes a communication link between the target attack instance, the target test instance, and the target test device to form a security test scenario.

[0031] Security testing is conducted based on the target attack script and security test scenario, and test data is acquired in real time.

[0032] When the security test reaches the preset stop condition, the protection performance of the power system network is evaluated based on the acquired test data.

[0033] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, performs the following steps:

[0034] In response to a start command for power system network security testing, obtain the security test template corresponding to the start command;

[0035] Based on the security test template, determine the target attack script corresponding to the security test and establish a target attack instance; based on the security test template, establish a target test instance corresponding to the security test and select the target test device required for the security test from the test devices;

[0036] Based on the security test template, the control network topology switching matrix establishes a communication link between the target attack instance, the target test instance, and the target test device to form a security test scenario.

[0037] Security testing is conducted based on the target attack script and security test scenario, and test data is acquired in real time.

[0038] When the security test reaches the preset stop condition, the protection performance of the power system network is evaluated based on the acquired test data.

[0039] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, performs the following steps:

[0040] In response to a start command for power system network security testing, obtain the security test template corresponding to the start command;

[0041] Based on the security test template, determine the target attack script corresponding to the security test and establish a target attack instance; based on the security test template, establish a target test instance corresponding to the security test and select the target test device required for the security test from the test devices;

[0042] Based on the security test template, the control network topology switching matrix establishes a communication link between the target attack instance, the target test instance, and the target test device to form a security test scenario.

[0043] Security testing is conducted based on the target attack script and security test scenario, and test data is acquired in real time.

[0044] When the security test reaches the preset stop condition, the protection performance of the power system network is evaluated based on the acquired test data.

[0045] The aforementioned multi-scenario concurrent testing method, apparatus, computer equipment, computer-readable storage medium, and computer program product for power system networks first, in response to a start command for power system network security testing, acquires the security test template corresponding to the start command; based on the security test template, it determines the target attack script corresponding to the security test and establishes a target attack instance; based on the security test template, it establishes the target test instance corresponding to the security test and selects the target test equipment required for the security test from the test equipment; therefore, the target test equipment required for this test can be determined through the security test template. Then, based on the security test template, it controls the network topology switching matrix to establish communication links between the target attack instance, the target test instance, and the target test equipment, forming a security test scenario; based on the security test template, it connects the target attack instance, the target test instance, and the target test equipment through the network topology switching matrix, enabling automatic connection without relying on manual connection, making it more flexible for different network tests. Security tests are then conducted based on the target attack script and security test scenarios, and the test data is acquired in real time. When the security test reaches the preset stop condition, the protection performance of the power system network is evaluated based on the acquired test data. Using the method of this application, the network structure required for network testing can be automatically configured. Attached Figure Description

[0046] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0047] Figure 1 This is an application environment diagram of a multi-scenario concurrent testing method for power system networks in one embodiment;

[0048] Figure 2 This is a flowchart illustrating a multi-scenario concurrent testing method for a power system network in one embodiment.

[0049] Figure 3 This is a structural block diagram of a multi-scenario concurrent testing device for a power system network in one embodiment;

[0050] Figure 4 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0051] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0052] The multi-scenario concurrent testing method for power system networks provided in this application embodiment can be applied to, for example... Figure 1 In the application environment shown, server 102 communicates with network topology switching matrix 104 via the network. Network topology switching matrix 104 communicates with test equipment 106 via the network. In response to a start command for power system network security testing, server 102 obtains the security test template corresponding to the start command; based on the security test template, it determines the target attack script corresponding to the security test and establishes a target attack instance; based on the security test template, it establishes a target test instance corresponding to the security test and selects the target test equipment required for the security test from test equipment 106; based on the security test template, it controls network topology switching matrix 104 to establish a communication link between the target attack instance, the target test instance, and the target test equipment, forming a security test scenario; server 102 performs security testing based on the target attack script and the security test scenario, and obtains the test data in real time; when the security test reaches a preset stop condition, it evaluates the protection performance of the power system network based on the obtained test data. Server 102 can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.

[0053] In one exemplary embodiment, such as Figure 2 As shown, a multi-scenario concurrent testing method for power system networks is provided, which can be applied to... Figure 1 Taking server 102 as an example, the explanation includes the following steps 202 to 206. Wherein:

[0054] Step 202: In response to the start command for power system network security testing, obtain the security test template corresponding to the start command.

[0055] Optionally, multiple security tests can be performed simultaneously, in which case multiple security test templates will be obtained. Security test templates can be pre-set templates containing settings such as network attack categories and network topology, or they can be temporarily set up before the test. Security test templates can be for tests such as substation penetration or attacks on dispatch centers.

[0056] For example, create a "Substation Intranet Penetration" template and a "Dispatch Center-Substation Collaborative Attack" template. The former simulates a substation's internal network being compromised, including a firewall device, several secondary devices, and an attacker node, along with a script for the attacker to launch an ARP spoofing (Address Resolution Protocol spoofing) attack on the intranet bus. The latter simulates a collaborative attack where the dispatch master station and the substation are simultaneously compromised, including the dispatch master station server, communication gateway, several remote terminals, and an attack script simulating the injection of malicious control commands.

[0057] Step 204: Based on the security test template, determine the target attack script corresponding to the security test and establish a target attack instance; based on the security test template, establish a target test instance corresponding to the security test and select the target test device required for the security test from the test devices.

[0058] The target attack instance serves as the attack node in this security test. The target attack instance launches attacks based on the target attack script, and the target of the attack is the target test device.

[0059] Optionally, the test equipment can be relay protection devices, monitoring and control terminals, firewalls, switches, etc. The target attack instance can be a lightweight container or virtual machine. The target attack script can be an ARP spoofing (Address Resolution Protocol spoofing) script, a DNP3 malicious command (Distributed Network Protocol 3 Malicious Commands) script, etc.

[0060] Step 206: Based on the security test template, control the network topology switching matrix to establish the communication link between the target attack instance, the target test instance, and the target test device, forming a security test scenario.

[0061] The security test template includes a network topology. Based on this topology, a software architecture utilizes Software Defined Networking (SDN) and virtualization technologies to achieve flexible network control and scenario isolation. The configuration of the network topology switching matrix and virtual networks is controlled according to the test scenario requirements. The network topology switching matrix consists of a high-end programmable Ethernet switch array, capable of flexibly changing port interconnection relationships internally via electronic switches (equivalent to a dynamically rewiring crossover switch network).

[0062] Optionally, when deploying or switching scenarios, the differences between the current network topology and the security test template are compared to generate an incremental configuration list. Based on this list, the differences between the current network topology and the network topology required by the security test template are adjusted to complete network reconstruction with minimal changes. For example, when switching from scenario A to scenario B, if some nodes and connections are the same in both topologies, it is not necessary to interrupt these identical parts; only the differences need to be reconfigured.

[0063] To ensure that each scenario does not interfere with the others, an isolation control model based on container / virtual machine virtualization is adopted. Each security test scenario is allocated an independent computing and network environment upon startup: the system creates a corresponding container or lightweight virtual machine instance, starts the application process specific to that scenario, and allocates resource quotas such as processor, memory, and disk. Simultaneously, network namespace technology ensures complete isolation of the virtual networks of different scenarios; unless deliberately configured to share nodes, there are no direct data communication paths between security test scenarios. Furthermore, network bandwidth quotas are imposed on each scenario to prevent one scenario from consuming excessive bandwidth and affecting communication in other scenarios. Combined with a dynamic topology mapping algorithm, this model ensures that each scenario obtains a secure, independent, and controlled execution environment even when multiple scenarios are running concurrently, sharing underlying hardware resources while isolating the runtime environment.

[0064] Step 208: Conduct security testing based on the target attack script and security test scenario, and obtain the security test data in real time.

[0065] During parallel testing, a monitoring unit uniformly monitors all security test scenarios, focusing on critical security events and resource usage dynamics. When a security test scenario triggers a critical security event (such as firewall breach or control command tampering), the monitoring unit records event details and marks the affected devices for analysis and tracing after the test.

[0066] For example, once the network is configured, tests for all security test scenarios are started simultaneously based on the target attack script and the security test scenario, entering the parallel testing phase, where the attack script in each security test scenario is executed by the corresponding target attack instance.

[0067] Step 210: When the security test reaches the preset stop condition, evaluate the protection performance of the power system network based on the acquired test data.

[0068] Optionally, the test data can be test logs and corresponding security test templates. The default stopping condition is that the attack script has been fully executed or the set test duration has been reached.

[0069] After the test is completed, the details of the attack process in each scenario can be analyzed by using the saved test data; by comparing the results of different scenarios or different test rounds, the effectiveness of security protection measures and directions for improvement can be evaluated.

[0070] The aforementioned multi-scenario concurrent testing method for power system networks first obtains the security test template corresponding to the start command for power system network security testing in response to the start command. Based on the security test template, the target attack script corresponding to the security test is determined, and a target attack instance is established. Based on the security test template, a target test instance corresponding to the security test is established, and the target test device required for the security test is selected from the test devices. Therefore, the target test device required for this test can be determined through the security test template. Then, based on the security test template, the network topology switching matrix is ​​controlled to establish communication links between the target attack instance, the target test instance, and the target test device, forming a security test scenario. Based on the security test template, the network topology switching matrix connects the target attack instance, the target test instance, and the target test device automatically, without relying on manual connection, making it more flexible for different network tests. Subsequently, security testing is performed based on the target attack script and the security test scenario, and the test data of the security test is acquired in real time. When the security test reaches the preset stop condition, the protection performance of the power system network is evaluated based on the acquired test data. Using the method of this application, the network structure required for network testing can be automatically configured.

[0071] In an exemplary embodiment, the step of connecting the target attack instance, the target test instance, and the target test device through a network topology switching matrix to form a security test scenario includes:

[0072] Virtual switches are created and virtual network identifiers are assigned to the target attack instance and the target test instance. Based on the target test device, the virtual network identifier, and the virtual switch, port mapping rules are generated. The port mapping rules are used to guide the network topology switching matrix to establish a communication link between the target test device and the virtual switch corresponding to the virtual network identifier, so that the target test device can transmit data to the virtual switch through the communication link. Based on the port mapping rules, the network topology switching matrix is ​​controlled to establish a communication link between the target test device, the target attack instance, and the target test instance, forming a security test scenario.

[0073] Optionally, the target test equipment can be a relay protection device.

[0074] For example, an SDN (Software Defined Network Controller) controller creates a dedicated virtual switch, such as Switch A, for the target attack instance and the target test instance of the security test template, and assigns a virtual network identifier to virtual switch A; for example, the virtual network identifier of Switch A corresponding to security test template A is VLAN ID 100; then, based on the target test device, the virtual network identifier, and the virtual switch, a port mapping rule is generated, for example: binding physical port P1 (the physical port of the relay protection device) to port 1 of Switch A and adding a VLAN 100 tag, so that the relay protection device can only transmit data to Switch A under VLAN 100; based on this mapping rule, the network topology switching matrix is ​​controlled to connect physical port P1 on the relay matrix, so that the relay protection device can communicate with the target attack instance and the target test instance through Switch A.

[0075] The relay matrix consists of multiple relays, each containing multiple contacts. By controlling different combinations of relays and contacts, flexible interconnection and control between test devices can be achieved. All test devices are connected to the relay matrix, with each device isolated from the others. The test devices are connected to the network topology switching matrix through the relay matrix.

[0076] In this embodiment, based on the security testing objective, the target attack instance, target test instance, and target test device are connected through a network topology switching matrix. This allows for automatic connection of the required physical devices based on the security testing template without relying on manual connection. This enables more flexible reconstruction of the network topology during network testing.

[0077] In an exemplary embodiment, the security testing based on the target attack script and the security test scenario includes:

[0078] The system controls a target attack instance in a security testing scenario to run the target attack script and generate an attack data packet; the attack data packet is then sent to the target testing device and the target testing instance via the communication link to attack the target testing device and the target testing instance.

[0079] For example, in security test scenario A, the target attack instance in control scenario A launches vulnerability exploitation or scans and penetrates the internal network of the target test device (firewall) according to the target attack script; at the same time, in security test scenario B, the target attack instance in control scenario B sends abnormal control commands to the target test device through the target attack script (malicious instruction injection script), simulating an attacker carrying out damage through the compromised scheduling center.

[0080] In this embodiment, by controlling different security test scenarios to perform security tests simultaneously, there is no need to wait for the previous security test scenario to end before starting the next security test scenario, which effectively improves the efficiency of multi-scenario concurrent testing of power system networks.

[0081] In one exemplary embodiment, after the security test reaches a preset stop condition, the method further includes:

[0082] Disconnect the communication links between the target test device, the target attack instance, and the target test instance; clear the port mapping rules; and delete the target attack instance and the target test instance.

[0083] Optionally, after the test, the virtual environments for each security test scenario are destroyed sequentially: stop and delete the container / virtual machine instances related to the security test scenario, clear the virtual switch and switching matrix rules set for the security test scenario, and release the occupied physical ports and computing resources. Disconnect all test devices and topology switching matrices, restoring them to their initial unconnected state. Finally, the entire test platform returns to its initial idle configuration, awaiting the next set of test tasks.

[0084] For example, disconnect the communication links between the target test device, the target attack instance, and the target test instance in the completed security test scenario; release the configured computing resources; delete the target attack instance and the target test instance; and clear the corresponding port mapping rules.

[0085] In this embodiment, after a certain security test scenario is completed, the computing and bandwidth resources occupied by the corresponding security test scenario are released in a timely manner, which can provide sufficient backup resources for other security test scenarios or the next security test, so as to ensure that other security tests can be carried out smoothly.

[0086] In an exemplary embodiment, after acquiring the test data of the security test in real time, the method further includes:

[0087] In the presence of multiple security test scenarios, if a conflict is detected in the computing resources required by the multiple security test scenarios, the priority of the multiple security test scenarios is obtained; based on the priority of the multiple security test scenarios, computing resources are allocated to the multiple test scenarios.

[0088] If abnormal resource consumption is detected in a certain scenario (e.g., a scenario suddenly consuming a large amount of processors, causing the overall system load to be too high), dynamic coordination will be carried out according to the predetermined strategy: for resource contention issues, the resource quota of low-priority scenarios can be temporarily reduced to give more resources to high-priority scenarios, and if necessary, individual low-priority scenarios may even be suspended to ensure the stable operation of critical scenarios; for security conflict issues (e.g., a scenario unexpectedly attempts to establish communication with another scenario), abnormal communication will be blocked immediately and an alarm will be issued to notify the operation and maintenance personnel.

[0089] For example, in the presence of multiple security test scenarios, if the test data of each security test obtained in real time shows that there is a conflict in the computing resources required by different security test scenarios, then the priority of multiple security test scenarios is obtained, the computing resources of low-priority security test scenarios are reduced, or the testing of low-priority security test scenarios is suspended, so as to provide the necessary computing resources for high-priority security test scenarios.

[0090] In this embodiment, when there is a conflict in the resources required by different security testing scenarios, sufficient computing resources are provided for the high-priority scenarios first. This ensures that more important security testing scenarios can be carried out smoothly when computing resources are insufficient, and more important security test results can be obtained in a timely manner.

[0091] In one exemplary embodiment, the method further includes:

[0092] In response to the setup operation for power system network security testing, a name for the security test is generated, the network topology required for the security test is established, and a script attack file corresponding to the security test is generated; the name, the network topology, and the script attack file constitute the security test template.

[0093] Optionally, before starting the test, you can select some security test templates from the pre-established security test templates, or you can temporarily set up a new security test template for security testing. Each security test template includes configuration elements such as name, functional description, network topology definition, and required attack scripts or fault injection scripts. After creating a new security test template, you can choose whether to perform a security test or save it for later use.

[0094] For example, in response to the security test setup operations performed by testers or system administrators according to security test requirements, a security test name is generated, the network topology required for the security test is established, and a script attack file corresponding to the security test is generated; the name, network topology, and script attack file constitute the security test template.

[0095] In this embodiment, by pre-configuring multiple security test templates, the pre-configured security test templates can be used directly during security testing, eliminating the need for configuration for each test. The security test template is only configured when it is not available, which saves preparation time and improves the efficiency of security testing.

[0096] In one exemplary embodiment, a multi-scenario concurrent testing method for a power system network includes: in response to a start command for a power system network security test, obtaining a security test template corresponding to the start command; based on the security test template, determining a target attack script corresponding to the security test and establishing a target attack instance; based on the security test template, establishing a target test instance corresponding to the security test, and selecting the target test device required for the security test from the test devices. The SDN (Software Defined Network Controller) controller creates dedicated virtual switches, such as Switch A, for the target attack instance and the target test instance of the security test template. A virtual network identifier is assigned to Switch A; for example, the virtual network identifier of Switch A corresponding to security test template A is VLAN ID 100. Then, based on the target test device, the virtual network identifier, and the virtual switch, port mapping rules are generated. For example, physical port P1 (the physical port of the relay protection device) is bound to port 1 of Switch A, and a VLAN 100 tag is added, so that the relay protection device can only transmit data to Switch A under VLAN 100. Based on this mapping rule, the network topology switching matrix is ​​controlled to connect physical port P1 on the relay matrix, enabling the relay protection device to communicate with the target attack instance and the target test instance through Switch A. Security testing is conducted based on the target attack script and security test scenarios. For example, in security test scenario A, the target attack instance in scenario A initiates vulnerability exploitation or scans and penetrates the internal network of the target test device (firewall) according to the target attack script. Simultaneously, in security test scenario B, the target attack instance in scenario B sends abnormal control commands to the target test device through the target attack script (malicious instruction injection script), simulating an attacker carrying out sabotage through a compromised dispatch center. Test data is acquired in real time. In the presence of multiple security test scenarios, if the real-time test data shows that different security test scenarios require conflicting computing resources, the priorities of the multiple security test scenarios are determined. Computing resources for low-priority security test scenarios are reduced, or testing of low-priority security test scenarios is paused to provide the necessary computing resources for high-priority security test scenarios. When the security test reaches the preset stop condition, the communication links between the target test device, target attack instance, and target test instance in the completed security test scenario are disconnected; the configured computing resources are released; the target attack instance and target test instance are deleted; the corresponding port mapping rules are cleared; and the protection performance of the power system network is evaluated based on the acquired test data.It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages in other steps. It is understood that the steps in different embodiments can be freely combined as needed, and all kinds of non-contradictory solutions formed by the combination are within the scope of protection of this application. The process of establishing a security test template includes: responding to the security test setup operation performed by testers or system administrators according to security test requirements, generating a name for the security test, establishing the network topology required for the security test, and generating a script attack file corresponding to the security test; the name, network topology, and script attack file constitute the security test template.

[0097] In one exemplary embodiment, such as Figure 3 As shown, a multi-scenario concurrent testing device for power system networks is provided, including: an acquisition module 301, an establishment module 302, a communication module 303, a testing module 304, and an evaluation module 305, wherein:

[0098] The acquisition module is used to acquire the security test template corresponding to the start command in response to the start command for power system network security testing;

[0099] The module is used to determine the target attack script corresponding to the security test based on the security test template, and to establish a target attack instance; based on the security test template, to establish a target test instance corresponding to the security test, and to select the target test device required for the security test from the test devices;

[0100] The communication module is used to control the network topology switching matrix to establish a communication link between the target attack instance, the target test instance, and the target test device based on the security test template, thereby forming a security test scenario;

[0101] The testing module is used to perform security tests based on the target attack script and security test scenarios, and to acquire the test data of the security tests in real time.

[0102] The evaluation module is used to evaluate the protection performance of the power system network based on the acquired test data when the security test reaches the preset stop conditions.

[0103] In one exemplary embodiment, the communication module is further configured to:

[0104] Virtual switches are created and virtual network identifiers are assigned to the target attack instance and the target test instance. Based on the target test device, the virtual network identifier, and the virtual switch, port mapping rules are generated. The port mapping rules are used to guide the network topology switching matrix to establish a communication link between the target test device and the virtual switch corresponding to the virtual network identifier, so that the target test device can transmit data to the virtual switch through the communication link. Based on the port mapping rules, the network topology switching matrix is ​​controlled to establish a communication link between the target test device, the target attack instance, and the target test instance, forming a security test scenario.

[0105] In one exemplary embodiment, the test module is further configured to:

[0106] The system controls a target attack instance in a security testing scenario to run the target attack script and generate an attack data packet; the attack data packet is then sent to the target testing device and the target testing instance via the communication link to attack the target testing device and the target testing instance.

[0107] In one exemplary embodiment, the evaluation module is further configured to:

[0108] Disconnect the communication links between the target test device, the target attack instance, and the target test instance; clear the port mapping rules; and delete the target attack instance and the target test instance.

[0109] In one exemplary embodiment, the test module is further configured to:

[0110] In the presence of multiple security test scenarios, if a conflict is detected in the computing resources required by the multiple security test scenarios, the priority of the multiple security test scenarios is obtained; based on the priority of the multiple security test scenarios, computing resources are allocated to the multiple test scenarios.

[0111] In one exemplary embodiment, the acquisition module is further configured to:

[0112] In response to the setup operation for power system network security testing, a name for the security test is generated, the network topology required for the security test is established, and a script attack file corresponding to the security test is generated; the name, the network topology, and the script attack file constitute the security test template.

[0113] The modules in the aforementioned multi-scenario concurrent testing device for power system networks can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the computer device's memory as software, so that the processor can call and execute the corresponding operations of each module.

[0114] In one exemplary embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 4 As shown, the computer device includes a processor, memory, input / output interfaces, a communication interface, a display unit, and an input device. The processor, memory, and input / output interfaces are connected via a system bus, and the communication interface, display unit, and input device are also connected to the system bus via the input / output interfaces. The processor provides computational and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The input / output interfaces are used for exchanging information between the processor and external devices. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, Near Field Communication (NFC), or other technologies. When the computer program is executed by the processor, it implements a multi-scenario concurrent testing method for a power system network. The display unit of the computer device is used to form a visually visible image and can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be an LCD screen or an e-ink screen. The input device of the computer device can be a touch layer covering the display screen, or buttons, trackballs, or touchpads set on the casing of the computer device, or external keyboards, touchpads, or mice, etc.

[0115] Those skilled in the art will understand that Figure 4 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0116] In one exemplary embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:

[0117] In response to a start command for power system network security testing, obtain the security test template corresponding to the start command;

[0118] Based on the security test template, determine the target attack script corresponding to the security test and establish a target attack instance; based on the security test template, establish a target test instance corresponding to the security test and select the target test device required for the security test from the test devices;

[0119] Based on the security test template, the control network topology switching matrix establishes a communication link between the target attack instance, the target test instance, and the target test device to form a security test scenario.

[0120] Security testing is conducted based on the target attack script and security test scenario, and test data is acquired in real time.

[0121] When the security test reaches the preset stop condition, the protection performance of the power system network is evaluated based on the acquired test data.

[0122] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0123] Virtual switches are created and virtual network identifiers are assigned to the target attack instance and the target test instance. Based on the target test device, the virtual network identifier, and the virtual switch, port mapping rules are generated. The port mapping rules are used to guide the network topology switching matrix to establish a communication link between the target test device and the virtual switch corresponding to the virtual network identifier, so that the target test device can transmit data to the virtual switch through the communication link. Based on the port mapping rules, the network topology switching matrix is ​​controlled to establish a communication link between the target test device, the target attack instance, and the target test instance, forming a security test scenario.

[0124] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0125] The system controls a target attack instance in a security testing scenario to run the target attack script and generate an attack data packet; the attack data packet is then sent to the target testing device and the target testing instance via the communication link to attack the target testing device and the target testing instance.

[0126] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0127] Disconnect the communication links between the target test device, the target attack instance, and the target test instance; clear the port mapping rules; and delete the target attack instance and the target test instance.

[0128] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0129] In the presence of multiple security test scenarios, if a conflict is detected in the computing resources required by the multiple security test scenarios, the priority of the multiple security test scenarios is obtained; based on the priority of the multiple security test scenarios, computing resources are allocated to the multiple test scenarios.

[0130] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0131] In response to the setup operation for power system network security testing, a name for the security test is generated, the network topology required for the security test is established, and a script attack file corresponding to the security test is generated; the name, the network topology, and the script attack file constitute the security test template.

[0132] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor:

[0133] In response to a start command for power system network security testing, obtain the security test template corresponding to the start command;

[0134] Based on the security test template, determine the target attack script corresponding to the security test and establish a target attack instance; based on the security test template, establish a target test instance corresponding to the security test and select the target test device required for the security test from the test devices;

[0135] Based on the security test template, the control network topology switching matrix establishes a communication link between the target attack instance, the target test instance, and the target test device to form a security test scenario.

[0136] Security testing is conducted based on the target attack script and security test scenario, and test data is acquired in real time.

[0137] When the security test reaches the preset stop condition, the protection performance of the power system network is evaluated based on the acquired test data.

[0138] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0139] Virtual switches are created and virtual network identifiers are assigned to the target attack instance and the target test instance. Based on the target test device, the virtual network identifier, and the virtual switch, port mapping rules are generated. The port mapping rules are used to guide the network topology switching matrix to establish a communication link between the target test device and the virtual switch corresponding to the virtual network identifier, so that the target test device can transmit data to the virtual switch through the communication link. Based on the port mapping rules, the network topology switching matrix is ​​controlled to establish a communication link between the target test device, the target attack instance, and the target test instance, forming a security test scenario.

[0140] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0141] The system controls a target attack instance in a security testing scenario to run the target attack script and generate an attack data packet; the attack data packet is then sent to the target testing device and the target testing instance via the communication link to attack the target testing device and the target testing instance.

[0142] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0143] Disconnect the communication links between the target test device, the target attack instance, and the target test instance; clear the port mapping rules; and delete the target attack instance and the target test instance.

[0144] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0145] In the presence of multiple security test scenarios, if a conflict is detected in the computing resources required by the multiple security test scenarios, the priority of the multiple security test scenarios is obtained; based on the priority of the multiple security test scenarios, computing resources are allocated to the multiple test scenarios.

[0146] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0147] In response to the setup operation for power system network security testing, a name for the security test is generated, the network topology required for the security test is established, and a script attack file corresponding to the security test is generated; the name, the network topology, and the script attack file constitute the security test template.

[0148] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, performs the following steps:

[0149] In response to a start command for power system network security testing, obtain the security test template corresponding to the start command;

[0150] Based on the security test template, determine the target attack script corresponding to the security test and establish a target attack instance; based on the security test template, establish a target test instance corresponding to the security test and select the target test device required for the security test from the test devices;

[0151] Based on the security test template, the control network topology switching matrix establishes a communication link between the target attack instance, the target test instance, and the target test device to form a security test scenario.

[0152] Security testing is conducted based on the target attack script and security test scenario, and test data is acquired in real time.

[0153] When the security test reaches the preset stop condition, the protection performance of the power system network is evaluated based on the acquired test data.

[0154] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0155] Virtual switches are created and virtual network identifiers are assigned to the target attack instance and the target test instance. Based on the target test device, the virtual network identifier, and the virtual switch, port mapping rules are generated. The port mapping rules are used to guide the network topology switching matrix to establish a communication link between the target test device and the virtual switch corresponding to the virtual network identifier, so that the target test device can transmit data to the virtual switch through the communication link. Based on the port mapping rules, the network topology switching matrix is ​​controlled to establish a communication link between the target test device, the target attack instance, and the target test instance, forming a security test scenario.

[0156] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0157] The system controls a target attack instance in a security testing scenario to run the target attack script and generate an attack data packet; the attack data packet is then sent to the target testing device and the target testing instance via the communication link to attack the target testing device and the target testing instance.

[0158] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0159] Disconnect the communication links between the target test device, the target attack instance, and the target test instance; clear the port mapping rules; and delete the target attack instance and the target test instance.

[0160] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0161] In the presence of multiple security test scenarios, if a conflict is detected in the computing resources required by the multiple security test scenarios, the priority of the multiple security test scenarios is obtained; based on the priority of the multiple security test scenarios, computing resources are allocated to the multiple test scenarios.

[0162] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0163] In response to the setup operation for power system network security testing, a name for the security test is generated, the network topology required for the security test is established, and a script attack file corresponding to the security test is generated; the name, the network topology, and the script attack file constitute the security test template.

[0164] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.

[0165] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0166] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A multi-scenario concurrent testing method for power system networks, characterized in that, The method includes: In response to a start command for power system network security testing, obtain the security test template corresponding to the start command; Based on the security test template, determine the target attack script corresponding to the security test and establish a target attack instance; based on the security test template, establish a target test instance corresponding to the security test and select the target test device required for the security test from the test devices; Based on the security test template, the control network topology switching matrix establishes a communication link between the target attack instance, the target test instance, and the target test device to form a security test scenario. Security testing is conducted based on the target attack script and security test scenario, and test data is acquired in real time. When the security test reaches the preset stop condition, the protection performance of the power system network is evaluated based on the acquired test data.

2. The method according to claim 1, characterized in that, The security testing scenario is formed by connecting the target attack instance, the target test instance, and the target test device through a network topology switching matrix, including: Create virtual switches and assign virtual network identifiers to the target attack instance and the target test instance; Based on the target test device, the virtual network identifier, and the virtual switch, a port mapping rule is generated. The port mapping rule is used to guide the network topology switching matrix to establish a communication link between the target test device and the virtual switch corresponding to the virtual network identifier, so that the target test device can transmit data to the virtual switch through the communication link. Based on the port mapping rules, the network topology switching matrix is ​​controlled to establish communication links between the target test device, the target attack instance, and the target test instance, thus forming a security test scenario.

3. The method according to claim 2, characterized in that, The security testing based on the target attack script and security test scenario includes: The system controls a target attack instance in a security testing scenario to run the target attack script and generate attack data packets. The attack data packet is sent to the target test device and the target test instance through the communication link to attack the target test device and the target test instance.

4. The method according to claim 2, characterized in that, After the security test reaches the preset stopping conditions, it also includes: Disconnect the communication links between the target test device, the target attack instance, and the target test instance; Clear the port mapping rule; Delete the target attack instance and the target test instance.

5. The method according to claim 1, characterized in that, After acquiring the security test data in real time, the process also includes: If multiple security test scenarios exist, and a conflict is detected in the computing resources required by multiple security test scenarios, the priority of multiple security test scenarios is obtained. Based on the priority of the multiple security test scenarios, computing resources are allocated to each security test scenario.

6. The method according to claim 1, characterized in that, The method further includes: In response to the setup operation for power system network security testing, a name for the security test is generated, the network topology required for the security test is established, and a script attack file corresponding to the security test is generated; the name, the network topology, and the script attack file constitute the security test template.

7. A multi-scenario concurrent testing device for power system networks, characterized in that, The device includes: The acquisition module is used to acquire the security test template corresponding to the start command in response to the start command for power system network security testing; The module is used to determine the target attack script corresponding to the security test based on the security test template, and to establish a target attack instance; based on the security test template, to establish a target test instance corresponding to the security test, and to select the target test device required for the security test from the test devices; The communication module is used to control the network topology switching matrix to establish a communication link between the target attack instance, the target test instance, and the target test device based on the security test template, thereby forming a security test scenario; The testing module is used to perform security tests based on the target attack script and security test scenarios, and to acquire the test data of the security tests in real time. The evaluation module is used to evaluate the protection performance of the power system network based on the acquired test data when the security test reaches the preset stop conditions.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Design and implementation of programmable data plane exchange prototype based on P4

    CN108768892A

  • Network target range training environment construction method and device, electronic equipment and storage medium

    CN114301784A

  • 5G industrial control network system automatic security test method and system, and storage medium

    CN115333787A

  • Automatic network testing method and device

    CN116232906A

  • Planning and managing network probes using centralized controller

    US20200296029A1