Power system network security test method and device, computer equipment, medium and product

By establishing hardware and software connections, loading simulation model components, and conducting network attack and defense tests in power system network security testing, the problem of low efficiency in traditional testing methods is solved, enabling rapid setup and reconstruction, and improving testing efficiency and result reliability.

CN121125296APending Publication Date: 2025-12-12ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511411572.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-29
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

Traditional power system network security testing methods are inefficient, difficult to adapt to frequently changing testing needs, and require rewiring and reconfiguration each time a test scenario is set up.

Method used

By establishing a hardware connection with the test function module, loading the simulation model component, establishing a software connection, and connecting with the device under test through a standardized interface, network attack and defense tests are conducted. After the test is completed, the system is restored to its initial state, enabling rapid setup and reconstruction.

Benefits of technology

It improves the efficiency of network security testing, enables rapid setup and reconstruction of the testing environment, and ensures the reliability and repeatability of test results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125296A_ABST
    Figure CN121125296A_ABST
Patent Text Reader

Abstract

The invention relates to a power system network security test method and device, computer equipment, a medium and a product. The method comprises the following steps: in response to a current trigger signal of a test function module, connecting with a power interface of the test function module through a communication interface, establishing hardware connection with the test function module, loading a corresponding simulation model component according to identification information and configuration parameters of the test function module, and testing the test function module according to the corresponding simulation model component. And establishing software connection between the test function module and the simulation model component, establishing test connection with the to-be-tested equipment through the standardized interface, loading a power system operation scene for the to-be-tested equipment under the condition that the test connection verification is passed, performing network attack and defense test on the to-be-tested equipment through a preset test case, and performing network attack and defense test on the to-be-tested equipment. And after the test is completed, recovering the test function module and the simulation model component to an initial state, responding to a next trigger signal of the test function module, and re-establishing the hardware connection with the test function module. By adopting the method, the safety test efficiency can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of power system network security technology, and in particular to a power system network security testing method, apparatus, computer equipment, medium and product. Background Technology

[0002] Key aspects of power systems, such as dispatch control, substation monitoring, and distribution automation, rely heavily on industrial control systems for remote monitoring and control. If these systems are attacked by cyberattacks, they may cause power equipment to malfunction or become paralyzed, posing serious threats to power grid security.

[0003] In traditional technologies, the environment for power system cybersecurity testing primarily employs test platforms built with real equipment. This involves assembling actual controllers, relay protection devices, terminals, and other equipment in a laboratory to create a scaled-down power control network for attack simulation and protection testing. However, this approach requires rewiring and reconfiguration for each specific test scenario, making it difficult to adapt to frequently changing testing needs and resulting in low security testing efficiency. Summary of the Invention

[0004] Therefore, it is necessary to provide a power system network security testing method, device, computer equipment, medium, and product that can improve the efficiency of security testing in response to the above-mentioned technical problems.

[0005] Firstly, this application provides a power system network security testing method, including:

[0006] In response to the current trigger signal of the test function module, it connects to the power interface of the test function module through the communication interface to establish a hardware connection with the test function module;

[0007] Based on the identification information and configuration parameters of the test function module, load the corresponding simulation model component and establish a software connection between the test function module and the simulation model component;

[0008] A test connection is established with the device under test through a standardized interface, and the test connection is verified based on the electrical quantity feedback signal from the device under test.

[0009] If the connection test is successful, load the power system operation scenario for the device under test. In the power system operation scenario, network attack and defense tests are performed on the device under test using preset test cases.

[0010] Once the network attack and defense test is completed, the test function module and simulation model components are restored to their initial state, and in response to the next trigger signal from the test function module, the hardware connection with the test function module is re-established.

[0011] In one embodiment, after loading the corresponding simulation model component based on the identification information and configuration parameters of the test function module, the process includes:

[0012] Generate a global clock signal and send it synchronously to all test function modules so that the test function modules run according to the simulation step size indicated by the global clock signal.

[0013] In one embodiment, the test connection includes an electrical connection and a network link connection; the step of establishing a test connection with the device under test through a standardized interface includes:

[0014] Based on the device information of the device under test, provide the corresponding power signals and analog signals to the device under test through a standardized interface to establish an electrical connection with the device under test;

[0015] Establish a network link connection with the device under test through a standardized interface.

[0016] In one embodiment, the step of performing network attack and defense testing on the device under test using preset test cases includes:

[0017] The system scans and probes the open ports and known vulnerabilities of the device under test, and performs network attack and defense tests on the network links of the device under test through network attack cases.

[0018] In one embodiment, the step of restoring the test function module and simulation model components to their initial state includes:

[0019] Disconnect the software connections between the test function modules and the simulation model components in a preset order;

[0020] Restore the test function module to an idle state and delete the loaded simulation model components.

[0021] In one embodiment, the method further includes:

[0022] During the network attack and defense testing of the device under test using preset test cases, test data is acquired.

[0023] Once the network attack and defense test is completed, a test report is generated based on the test data. The test report includes a list of security vulnerabilities of the device under test, the response data of the device under test under each type of attack, the performance index change curve of the device under test, abnormal events, and the network security protection level of the device under test.

[0024] Secondly, this application also provides a power system network security testing device, comprising:

[0025] The hardware connection module is used to respond to the current trigger signal of the test function module, and connect to the power interface of the test function module through the communication interface to establish a hardware connection with the test function module.

[0026] The software connection module is used to load the corresponding simulation model components and establish a software connection between the test function module and the simulation model components based on the identification information and configuration parameters of the test function module.

[0027] The connection verification module is used to establish a test connection with the device under test through a standardized interface, and to verify the test connection based on the electrical quantity feedback signal of the device under test.

[0028] The security testing module is used to load a power system operation scenario for the device under test after the test connection verification is passed. In the power system operation scenario, network attack and defense tests are performed on the device under test through preset test cases.

[0029] The module recovery module is used to restore the test function module and simulation model components to their initial state after the network attack and defense test is completed, and to re-establish the hardware connection with the test function module in response to the next trigger signal of the test function module.

[0030] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the method steps of any one of the first aspects.

[0031] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the method steps of any one of the first aspects.

[0032] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, implements the method steps of any one of the first aspects.

[0033] The aforementioned power system network security testing methods, devices, computer equipment, media, and products, in response to the current trigger signal of the test function module, establish a hardware connection with the test function module by connecting to the power interface of the test function module through a communication interface. Based on the identification information and configuration parameters of the test function module, they load the corresponding simulation model components, establishing a software connection between the test function module and the simulation model components. A test connection is established with the device under test (DUT) through a standardized interface, and the test connection is verified based on the electrical quantity feedback signals from the DUT. If the test connection verification is successful, a power system operation scenario for the DUT is loaded. In the power system operation scenario, network attack and defense tests are performed on the DUT using preset test cases. After the network attack and defense tests are completed, the test function module and simulation model components are restored to their initial state. In response to the next trigger signal of the test function module, a new hardware connection with the test function module is established. This enables rapid setup and reconstruction of the test environment, improving the efficiency of network security testing. Attached Figure Description

[0034] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0035] Figure 1 This is a diagram illustrating the application environment of a power system network security testing method in one embodiment.

[0036] Figure 2 This is a flowchart illustrating a power system network security testing method in one embodiment;

[0037] Figure 3 This is a flowchart illustrating a power system network security testing method in another embodiment;

[0038] Figure 4 This is a structural block diagram of a power system network security testing device in one embodiment;

[0039] Figure 5 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0040] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0041] The power system network security testing method provided in this application embodiment can be applied to, for example... Figure 1 In the application environment shown, terminal 102 communicates with server 104 via a network. A data storage system can store the data that server 104 needs to process. The data storage system can be integrated onto server 104 or placed on a cloud or other network server. Terminal 102, in response to the current trigger signal of the test function module, connects to the power interface of the test function module via a communication interface to establish a hardware connection. Based on the identification information and configuration parameters of the test function module, it loads the corresponding simulation model component, establishes a software connection between the test function module and the simulation model component, establishes a test connection with the device under test (DUT) through a standardized interface, and verifies the test connection based on the electrical quantity feedback signal from the DUT. If the test connection verification is successful, it loads a power system operation scenario for the DUT. In the power system operation scenario, it performs network attack and defense testing on the DUT using preset test cases. After the network attack and defense test is completed, it restores the test function module and simulation model component to their initial state and, in response to the next trigger signal of the test function module, re-establishes the hardware connection with the test function module. Terminal 102 can be, but is not limited to, various personal computers, laptops, smartphones, tablets, drones, low-altitude aircraft, IoT devices, and portable wearable devices. IoT devices can include smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, and projection equipment. Portable wearable devices can include smartwatches, smart bracelets, and head-mounted displays. Head-mounted displays can be virtual reality (VR) devices, augmented reality (AR) devices, and smart glasses. Server 104 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.

[0042] In one exemplary embodiment, such as Figure 2 As shown, a power system network security testing method is provided, which is applied to... Figure 1 Taking terminal 102 as an example, the explanation includes the following steps 202 to 210. Wherein:

[0043] S202: In response to the current trigger signal of the test function module, connect to the power interface of the test function module through the communication interface to establish a hardware connection with the test function module.

[0044] Optionally, when a test function module (such as a power simulation module, substation simulation module, etc.) issues a trigger signal, the system interfaces with its power interface through a unified communication interface (such as a high-speed backplane bus) to complete the physical hardware connection. No manual wiring is required; after the module is inserted, it is automatically secured by the standardized slots and quick-locking mechanism on the platform, and the power and communication interfaces are automatically connected via the backplane bus.

[0045] S204: Based on the identification information and configuration parameters of the test function module, load the corresponding simulation model component and establish a software connection between the test function module and the simulation model component.

[0046] Optionally, by reading the identification information (such as ID chip data) and configuration parameters of the test function module, the corresponding simulation model (such as wind turbine model, IEC61850 protocol model, etc.) can be automatically matched and loaded from the model library, and the logical association between the module and the model can be established in the virtual environment to achieve software-level collaboration.

[0047] S206: Establish a test connection with the device under test through a standardized interface, and verify the test connection based on the electrical quantity feedback signal from the device under test.

[0048] Optionally, the device under test (such as a relay protection device, firewall, etc.) is connected to the platform through the standardized interface (such as current and voltage terminals, Ethernet port) of the device under test interface module. The system verifies the connection is valid by detecting the electrical quantity feedback of the device (such as whether the current / voltage signal is received normally) and the communication handshake status.

[0049] S208: If the connection test is successful, load the power system operation scenario for the device under test. In the power system operation scenario, perform network attack and defense tests on the device under test using preset test cases.

[0050] Optionally, after verifying the connection is valid, a preset power system operation scenario (such as normal load fluctuation, short circuit fault, dispatch command interaction, etc.) is loaded, and integrated security testing tools (such as vulnerability scanner, attack traffic generator) are started to launch network attacks according to test cases, while recording the response data of the device under test.

[0051] S210: After the network attack and defense test is completed, restore the test function module and simulation model components to their initial state, and re-establish the hardware connection with the test function module in response to the next trigger signal of the test function module.

[0052] Optionally, after the test is completed, the system can be reset with one click, uninstalling the scene model, disconnecting the software connections between modules, and restoring all modules to their initial state so as to receive the next trigger signal and quickly reassemble a new test environment.

[0053] In the aforementioned power system network security testing method, in response to the current trigger signal of the test function module, a hardware connection is established with the test function module by connecting to its power interface through a communication interface. Based on the identification information and configuration parameters of the test function module, the corresponding simulation model component is loaded, establishing a software connection between the test function module and the simulation model component. A test connection is established with the device under test (DUT) through a standardized interface, and the test connection is verified based on the electrical quantity feedback signal from the DUT. If the test connection verification is successful, a power system operation scenario for the DUT is loaded. In the power system operation scenario, network attack and defense tests are performed on the DUT using preset test cases. After the network attack and defense tests are completed, the test function module and simulation model component are restored to their initial state. In response to the next trigger signal of the test function module, a new hardware connection with the test function module is established. This method enables rapid setup and reconstruction of the test environment, improving the efficiency of network security testing.

[0054] In an exemplary embodiment, after loading the corresponding simulation model components according to the identification information and configuration parameters of the test function modules, the process includes: generating a global clock signal and synchronously sending the global clock signal to all test function modules so that the test function modules run according to the simulation step size indicated by the global clock signal.

[0055] Optionally, the central control system of the test bench (such as an industrial computer or embedded main control unit) generates a high-precision global clock signal (e.g., a unified pulse signal or timestamp) as the time reference for the entire test environment. The accuracy of this clock signal must meet the requirements of dynamic simulation of the power system, ensuring millisecond-level or even microsecond-level time synchronization. The global clock signal is simultaneously sent to all connected test function modules (such as power simulation modules, substation simulation modules, communication protocol simulation modules, etc.) via the high-speed backplane bus or dedicated synchronization link of the test bench. Regardless of module type or functional differences, all modules receive the same clock signal as the operating reference. After receiving the global clock signal, each test function module will strictly follow the simulation step size indicated by the signal (e.g., updating the state every 10 milliseconds) to run its loaded simulation model components. In this embodiment, by generating a global clock signal and synchronously sending it to all test function modules, the test function modules can run according to the simulation step size indicated by the global clock signal, ensuring the time consistency of the simulation scenario and improving the reliability of the test results.

[0056] In an exemplary embodiment, the test connection includes an electrical connection and a network link connection; the step of establishing a test connection with the device under test (DUT) through a standardized interface includes: providing the DUT with corresponding power signals and analog signals through a standardized interface based on the DUT's device information, thereby establishing an electrical connection with the DUT; and establishing a network link connection with the DUT through a standardized interface.

[0057] Optionally, when the device under test (DUT) (such as a relay protection device, a measurement and control terminal, etc.) is connected to the test bench, the system first provides matching electrical signals through the standardized interface of the DUT interface module according to its device information (such as device type and required signal specifications). For devices that need to simulate the secondary circuit of the power grid (such as relay protection devices), the interface module outputs current and voltage simulation signals consistent with the real power grid, simulating the electrical quantities received by the device in the real system. For devices that require power supply, the interface module provides power signals that conform to its specifications to ensure normal startup and operation of the device. This is achieved through standardized physical interfaces, eliminating the need for manual adjustment of signal parameters; the interface module automatically adapts to the device requirements. For DUTs that rely on network communication (such as firewalls, intrusion detection systems, and intelligent devices supporting the IEC61850 protocol), a link connection is established through standardized network interfaces (such as Ethernet ports and fiber optic interfaces). The interface module connects the DUT to the simulated communication network of the test bench, enabling it to receive or send messages conforming to the power system protocol. For network security devices (such as firewalls), the interface module will connect them in series or parallel to the simulated network link, placing them in a network topology consistent with the real power grid, ensuring that they can normally intercept, forward, or analyze network traffic.

[0058] In this embodiment, by providing corresponding power signals and analog signals to the device under test (DUT) through a standardized interface based on the DUT's device information, an electrical connection is established between the DUT and the DUT. A network link connection is also established between the DUT and the DUT through the standardized interface. This improves the device compatibility and versatility of the test bench, ensures that the test environment is consistent with the real-world scenario, and thus improves the reliability of the test results.

[0059] In an exemplary embodiment, the steps of performing network attack and defense testing on the device under test using preset test cases include: scanning and probing open ports and known vulnerabilities of the device under test, and performing network attack and defense testing on the network links of the device under test using network attack cases.

[0060] Optionally, the test bench invokes the integrated vulnerability scanning tool to perform a comprehensive scan of the network interfaces of the device under test. Port scanning identifies open network ports on the device (such as TCP / UDP ports), the corresponding service types, and access control policies (such as whether external connections are allowed), identifying unauthorized high-risk ports (such as default management ports not being closed). Vulnerability scanning, based on a built-in vulnerability database (containing known vulnerabilities in common power industry equipment, such as protocol implementation defects and configuration vulnerabilities), sends specific probe packets to the device to detect the presence of known security vulnerabilities and records the vulnerability type, risk level, and triggering conditions. Building upon the scan, the test bench utilizes tools such as attack traffic generators to launch targeted attacks on the network links connecting to the device under test, based on preset network attack cases.

[0061] In this embodiment, by scanning and probing the open ports and known vulnerabilities of the device under test, and by conducting network attack and defense tests on the network links of the device under test through network attack cases, the inherent security risks of the device can be accurately located, and real attack scenarios can be simulated, thereby improving the standardization and repeatability of network security testing.

[0062] In an exemplary embodiment, the step of restoring the test function module and the simulation model component to their initial state includes: disconnecting the software connection between the test function module and the simulation model component in a preset order; restoring the test function module to an idle state; and deleting the loaded simulation model component.

[0063] Optionally, the central control system of the test bench gradually disconnects the software connections between each test function module and its corresponding simulation model component according to a pre-set logical sequence. For example, it first disconnects the signal interaction link between the interface module of the device under test and the communication protocol model, and then disconnects the virtual communication connection between the substation simulation module and the dispatch center simulation module, ensuring that the data flow and control commands between the modules are completely terminated, avoiding residual states caused by disordered disconnections. After the software connection is disconnected, the control system sends a reset command to each test function module, restoring its hardware state to the initial idle mode. At the same time, the central control system unloads the loaded simulation model components from memory, releasing system resources and preparing for the next round of testing.

[0064] In this embodiment, by disconnecting the software connection between the test function module and the simulation model component in a preset order, restoring the test function module to an idle state, and deleting the loaded simulation model component, residual interference from the test scene can be avoided, ensuring the independence and accuracy of the test results.

[0065] In an exemplary embodiment, the method further includes: acquiring test data during network attack and defense testing of the device under test using preset test cases; generating a test report based on the test data after the network attack and defense test is completed; the test report includes a list of security vulnerabilities of the device under test, response data of the device under test under each type of attack, performance index change curves of the device under test, abnormal events, and network security protection level of the device under test.

[0066] Optionally, during the network attack and defense test, the test bench's monitoring system continuously collects multi-dimensional test data. This includes security vulnerability data, which records open ports detected by vulnerability scanning tools, known vulnerability types (such as buffer overflows and weak passwords), vulnerability triggering conditions, and risk levels of the device under test. Attack response data records the specific responses of the device under test for each network attack case. Performance metrics data tracks the CPU utilization, memory usage, network throughput, and other performance parameters of the device under test in real time, generating curves showing their changes over time. Abnormal event data refers to unexpected events that occur during the test, recording the time of occurrence, triggering scenario, and associated attack type. Based on this data, a pre-set evaluation model quantifies the network security protection level of the device under test. After the network attack and defense test is completed, the test bench's central control system summarizes, analyzes, and formats the collected raw data, automatically generating a structured test report.

[0067] In this embodiment, by acquiring test data during the network attack and defense test of the device under test through preset test cases, and generating a test report based on the test data after the network attack and defense test is completed, the test results can be fully quantified and visualized, ensuring the comprehensiveness and reliability of the test.

[0068] In one exemplary embodiment, such as Figure 3 As shown, a power system network security testing method is provided, which includes the following steps:

[0069] (1) Module selection and assembly: Based on the test object and the preset test objectives, select the required functional modules (such as wind turbine generator simulation modules, intelligent substation secondary system communication modules, fault injection modules, etc.) from the module unit library of the test platform, insert the selected modules into the standard slot positions of the test platform, and fix them in place using the quick-locking mechanism. After each module is inserted, its power interface and communication interface will automatically connect through the backplane bus of the test platform, without the need for additional wiring. At this time, the basic hardware connection of the module is completed, and the physical architecture is ready.

[0070] (2) Interface Configuration and Scenario Topology Construction: After all necessary functional modules are inserted, the central control system of the platform identifies and initializes the newly added modules. The control system reads the identification information and initial configuration parameters of each module through the internal bus, and then loads the corresponding simulation model components in the background. Subsequently, according to the pre-set test scenario requirements, the control system automatically configures the logical connection relationship between each module and constructs a complete simulation network topology. For example, if the test scenario is a network security test of a substation connected to a wind farm, the control system will map the output electrical quantities of the "wind turbine simulation module" to the corresponding input interface of the "substation simulation module", and establish a data link between the "dispatch center simulation module" and the substation module through the communication protocol simulation module, thereby creating a virtual network topology of wind farm-substation-dispatch center. The entire connection configuration process is completed automatically by the system, without the need for manual connection of each module; testers only need to select a scenario template or customize connection rules. After configuration, the virtual topology relationship in the simulation environment is consistent with the requirements of the real power grid scenario, and the interaction channels between each module have been established.

[0071] (3) Connection of the device under test (DUT): After the simulation scenario is set up, the DUT is connected to the interface module of the test bench. The DUT can be a secondary power device (such as a relay protection device, a measurement and control terminal, a power distribution automation terminal, etc.) or a network security device (such as an industrial firewall, an intrusion detection system, etc.). During connection, the connection is made through the standardized interface provided by this invention: for example, the voltage and current interfaces of the actual relay protection device are connected to the secondary circuit simulation output terminal of the test bench, and the uplink communication port is connected to the communication network port of the test bench; or, the firewall under test is connected in series on the link between the simulation communication network and the simulation module of the dispatch master station, so that it can play the role of network packet forwarding and filtering. The test bench provides the DUT with a matching power supply, a simulation signal source and a communication link to ensure that the DUT is correctly connected to the simulation environment in both electrical and communication aspects. The control system confirms that the device has been connected to the test network and started to interact by detecting the electrical quantity feedback and communication handshake of the interface of the DUT. For example, for a relay protection device, it will detect whether it receives the simulated current / voltage signal normally, and for a firewall, it will verify the connectivity of the network link. Once everything is confirmed to be correct, the test bench enters the ready state.

[0072] (4) Scene Loading and Operation Simulation: After the hardware connection and scene configuration are completed, the scene simulation engine of the test bench is started, and the pre-set power system operation scene parameters are loaded. Testers can select or compile specific scene scripts, such as load curves under normal operating conditions, fault occurrence time and type, attack occurrence time, etc. After the simulation engine is started, it will drive the various functional modules to operate in coordination according to these scene parameters: for example, the generator simulation module will change with time according to the set output power curve; the load simulation module will periodically adjust the load size to reflect the day and night load fluctuations; the fault injection module will be triggered at the predetermined simulation time point to introduce anomalies such as short circuit faults and communication interruptions; the communication protocol module will continuously generate various real-time data messages (such as GOOSE messages from protection devices, telemetry and tele-signaling uploads, etc.). Through the linkage of various modules, the test bench at this time reproduces a dynamic power system scene covering normal operation and abnormal operating conditions, making the device under test connected to it seem as if it is in a real environment. It is worth mentioning that, due to the global synchronization mechanism, the simulation timelines of each module are strictly aligned. For example, the moment of fault occurrence corresponds synchronously with the protection action, dispatch alarm, etc. of the entire system, thus providing a reliable and consistent scene for network security testing.

[0073] (5) Network Security Testing Execution: Once the simulation scenario is running stably and the device under test is confirmed to be connected normally, the formal security testing phase begins. Testers can use the security testing tools integrated into the platform of this invention to initiate various network attack and defense test operations on the device under test according to predetermined test cases. For example, a vulnerability scanner can be invoked to scan and probe the open ports and known vulnerabilities of the device under test; a protocol fuzzer can be used to continuously send malformed or abnormally formatted messages to the relay protection device to test its robustness to abnormal inputs; a network attack traffic generator can be used to simulate typical network attack traffic (such as DDoS flooding, man-in-the-middle attack data tampering, etc.) and apply it to the simulated network link where the device under test is located to evaluate the device's response capability under attack. If the device under test is a protection device (such as a firewall), various malicious traffic can be injected into the simulated network and the firewall's interception and alarm effects can be observed. During the test, the platform's monitoring system tracks and records the operating status and feedback information of the device under test in real time, including the device's CPU / memory resource usage, network interface message transmission and reception statistics, device logs and alarm information, and relay protection action signal output, etc. By collecting data from multiple angles, we ensure a comprehensive understanding of the device's performance under attack disturbances. During testing, if any anomalies are detected (such as device restarts, communication interruptions, malfunctions, etc.), the monitoring system will record the time of occurrence and relevant data for easy post-event analysis.

[0074] (6) Result Analysis and Environment Reset: After all the pre-defined test cases have been executed, the attack traffic is stopped and the simulation scenario operation ends. The platform control system automatically collects test data and generates a test report. This report summarizes various information recorded during the test, including a list of discovered security vulnerabilities, the response status of the device under test under each attack (such as whether alarms are generated, whether abnormal restarts occur, etc.), the device performance index change curves, and abnormal events captured in the communication log. The report also provides an evaluation conclusion on the network security protection capabilities of the device for testers and R&D units to refer to and improve. Finally, taking advantage of the modular architecture of this invention, a one-click reset operation is performed on the test platform: the control system disconnects the software connections between each simulation module in the set order, restoring the running state of all modules to the initial idle state; the simulation engine unloads the scenario model, and the time synchronization mechanism is reset. If necessary, testers can remove some modules or add other modules to prepare for the next test task. The entire environment reset and new scenario reorganization process is very fast, without the need for long downtime, thus ensuring that the test environment can be quickly switched and enter the next round of testing under continuous testing requirements.

[0075] In this embodiment, functional units such as power supply simulation, substation simulation, and dispatch center simulation are modularized by adopting standardized hardware interfaces and backplane bus design. Each module can be freely plugged in and combined, and the control system can automatically identify modules and complete plug-and-play configuration, enabling rapid setup and reconstruction of the test environment. Through integrated network security testing tools such as vulnerability scanning, protocol fuzzing, and attack traffic simulation, along with real-time monitoring and data recording units, the system can automatically launch diverse attack tests on the device under test in the simulation scenario and collect responses, significantly reducing manual intervention and ensuring the comprehensiveness and efficiency of the testing.

[0076] It should be understood that although the steps in the flowcharts of the above embodiments are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages in other steps. It is understood that the steps in different embodiments can be freely combined as needed, and all non-contradictory solutions formed by such combinations are within the scope of protection of this application.

[0077] Based on the same inventive concept, this application also provides a power system network security testing device for implementing the power system network security testing method described above. The solution provided by this device is similar to the implementation scheme described in the above method; therefore, the specific limitations in one or more power system network security testing device embodiments provided below can be found in the limitations of the power system network security testing method described above, and will not be repeated here.

[0078] In one exemplary embodiment, such as Figure 4 As shown, a power system network security testing device is provided, comprising: a hardware connection module 10, a software connection module 20, a connection verification module 30, a security testing module 40, and a module recovery module 50, wherein:

[0079] The hardware connection module 10 is used to respond to the current trigger signal of the test function module, and connect to the power interface of the test function module through the communication interface to establish a hardware connection with the test function module.

[0080] The software connection module 20 is used to load the corresponding simulation model components according to the identification information and configuration parameters of the test function module, and establish a software connection between the test function module and the simulation model components.

[0081] The connection verification module 30 is used to establish a test connection with the device under test through a standardized interface, and to verify the test connection based on the electrical quantity feedback signal of the device under test.

[0082] The security testing module 40 is used to load a power system operation scenario for the device under test after the test connection verification is passed. In the power system operation scenario, network attack and defense tests are performed on the device under test through preset test cases.

[0083] The module recovery module 50 is used to restore the test function module and simulation model components to their initial state after the network attack and defense test is completed, and to re-establish the hardware connection with the test function module in response to the next trigger signal of the test function module.

[0084] In an exemplary embodiment, the software connection module 20 is further configured to generate a global clock signal and synchronously send the global clock signal to all test function modules so that the test function modules run according to the simulation step size indicated by the global clock signal.

[0085] In an exemplary embodiment, the test connection includes an electrical connection and a network link connection; the security test module 40 is also used to provide corresponding power signals and analog signals to the device under test through a standardized interface based on the device information of the device under test, and to establish an electrical connection with the device under test; and to establish a network link connection with the device under test through a standardized interface.

[0086] In one exemplary embodiment, the security testing module 40 is also used to scan and probe open ports and known vulnerabilities of the device under test, and to perform network attack and defense tests on the network links of the device under test through network attack cases.

[0087] In an exemplary embodiment, the module recovery module 50 is further configured to disconnect the software connection between the test function module and the simulation model component in a preset order; restore the test function module to an idle state; and delete the loaded simulation model component.

[0088] In an exemplary embodiment, the module recovery module 50 is further configured to acquire test data during the network attack and defense test of the device under test using preset test cases; and generate a test report based on the test data after the network attack and defense test is completed; the test report includes a list of security vulnerabilities of the device under test, response data of the device under test under each type of attack, performance index change curves of the device under test, abnormal events, and network security protection level of the device under test.

[0089] Each module in the aforementioned power system network security testing device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the corresponding operations of each module.

[0090] In one exemplary embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 5As shown, the computer device includes a processor, memory, input / output interface, communication interface, display unit, and input device. The processor, memory, and input / output interface are connected via a system bus, and the communication interface, display unit, and input device are also connected to the system bus via the input / output interface. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The input / output interface is used for exchanging information between the processor and external devices. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, Near Field Communication (NFC), or other technologies. When the computer program is executed by the processor, it implements a power system network security testing method. The display unit is used to form a visually visible image and can be a display screen, projection device, or virtual reality imaging device. The display screen can be an LCD screen or an e-ink screen. The input device of the computer device can be a touch layer covering the display screen, or buttons, trackballs, or touchpads set on the casing of the computer device, or external keyboards, touchpads, or mice, etc.

[0091] Those skilled in the art will understand that Figure 5 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0092] In an exemplary embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, and the processor executes the computer program to perform the following steps: In response to a current trigger signal of a test function module, a hardware connection is established with the test function module by connecting to its power interface via a communication interface; according to the identification information and configuration parameters of the test function module, a corresponding simulation model component is loaded, establishing a software connection between the test function module and the simulation model component; a test connection is established with the device under test (DUT) via a standardized interface, and the test connection is verified based on the electrical quantity feedback signal of the DUT; if the test connection verification is successful, a power system operation scenario for the DUT is loaded, and network attack and defense testing is performed on the DUT using preset test cases within the power system operation scenario; if the network attack and defense test is completed, the test function module and the simulation model component are restored to their initial state, and the hardware connection with the test function module is re-established in response to the next trigger signal of the test function module.

[0093] In one embodiment, when the processor executes the computer program, after loading the corresponding simulation model components according to the identification information and configuration parameters of the test function modules, the process includes: generating a global clock signal and synchronously sending the global clock signal to all test function modules so that the test function modules run according to the simulation step size indicated by the global clock signal.

[0094] In one embodiment, the test connection includes an electrical connection and a network link connection; the establishment of a test connection with the device under test (DUT) through a standardized interface when the processor executes a computer program includes: providing the DUT with corresponding power signals and analog signals through a standardized interface based on the DUT's device information, thereby establishing an electrical connection with the DUT; and establishing a network link connection with the DUT through a standardized interface.

[0095] In one embodiment, the network attack and defense testing of the device under test by means of preset test cases when the processor executes the computer program includes: scanning and probing open ports and known vulnerabilities of the device under test, and performing network attack and defense testing on the network links of the device under test by means of network attack cases.

[0096] In one embodiment, restoring the test function module and simulation model component to their initial state when the processor executes the computer program includes: sequentially disconnecting the software connection between the test function module and the simulation model component in a preset order; restoring the test function module to an idle state; and deleting the loaded simulation model component.

[0097] In one embodiment, when the processor executes the computer program, it also performs the following steps: acquiring test data during network attack and defense testing of the device under test using preset test cases; generating a test report based on the test data after the network attack and defense test is completed; the test report includes a list of security vulnerabilities of the device under test, response data of the device under test under each type of attack, performance index change curves of the device under test, abnormal events, and network security protection level of the device under test.

[0098] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, it performs the following steps: in response to a current trigger signal of a test function module, it connects to the power interface of the test function module through a communication interface to establish a hardware connection with the test function module; according to the identification information and configuration parameters of the test function module, it loads the corresponding simulation model component to establish a software connection between the test function module and the simulation model component; it establishes a test connection with the device under test (DUT) through a standardized interface and verifies the test connection based on the electrical quantity feedback signal of the DUT; if the test connection verification is successful, it loads a power system operation scenario for the DUT, and performs network attack and defense testing on the DUT using preset test cases in the power system operation scenario; if the network attack and defense test is completed, it restores the test function module and the simulation model component to their initial state, and re-establishes the hardware connection with the test function module in response to the next trigger signal of the test function module.

[0099] In one embodiment, when the computer program is executed by the processor, after loading the corresponding simulation model components according to the identification information and configuration parameters of the test function modules, the process includes: generating a global clock signal and synchronously sending the global clock signal to all test function modules so that the test function modules run according to the simulation step size indicated by the global clock signal.

[0100] In one embodiment, the test connection includes an electrical connection and a network link connection; the establishment of a test connection with the device under test (DUT) through a standardized interface when the computer program is executed by the processor includes: providing the DUT with corresponding power signals and analog signals through the standardized interface based on the DUT's device information, and establishing an electrical connection with the DUT; and establishing a network link connection with the DUT through the standardized interface.

[0101] In one embodiment, when a computer program is executed by a processor, network attack and defense testing of the device under test is performed using preset test cases, including: scanning and probing open ports and known vulnerabilities of the device under test, and performing network attack and defense testing of the network links of the device under test using network attack cases.

[0102] In one embodiment, restoring the test function module and simulation model component to their initial state when the computer program is executed by the processor includes: sequentially disconnecting the software connection between the test function module and the simulation model component in a preset order; restoring the test function module to an idle state; and deleting the loaded simulation model component.

[0103] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: acquiring test data during network attack and defense testing of the device under test using preset test cases; generating a test report based on the test data after the network attack and defense test is completed; the test report includes a list of security vulnerabilities of the device under test, response data of the device under test under each type of attack, performance index change curves of the device under test, abnormal events, and network security protection level of the device under test.

[0104] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, performs the following steps: responding to a current trigger signal of a test function module, connecting to the power interface of the test function module via a communication interface to establish a hardware connection with the test function module; loading a corresponding simulation model component based on the identification information and configuration parameters of the test function module to establish a software connection between the test function module and the simulation model component; establishing a test connection with the device under test (DUT) via a standardized interface and verifying the test connection based on the electrical quantity feedback signal of the DUT; if the test connection verification is successful, loading a power system operation scenario for the DUT, and performing network attack and defense testing on the DUT using preset test cases within the power system operation scenario; and, upon completion of the network attack and defense test, restoring the test function module and the simulation model component to their initial state, and re-establishing the hardware connection with the test function module in response to the next trigger signal of the test function module.

[0105] In one embodiment, when the computer program is executed by the processor, after loading the corresponding simulation model components according to the identification information and configuration parameters of the test function modules, the process includes: generating a global clock signal and synchronously sending the global clock signal to all test function modules so that the test function modules run according to the simulation step size indicated by the global clock signal.

[0106] In one embodiment, the test connection includes an electrical connection and a network link connection; the establishment of a test connection with the device under test (DUT) through a standardized interface when the computer program is executed by the processor includes: providing the DUT with corresponding power signals and analog signals through the standardized interface based on the DUT's device information, and establishing an electrical connection with the DUT; and establishing a network link connection with the DUT through the standardized interface.

[0107] In one embodiment, when a computer program is executed by a processor, network attack and defense testing of the device under test is performed using preset test cases, including: scanning and probing open ports and known vulnerabilities of the device under test, and performing network attack and defense testing of the network links of the device under test using network attack cases.

[0108] In one embodiment, restoring the test function module and simulation model component to their initial state when the computer program is executed by the processor includes: sequentially disconnecting the software connection between the test function module and the simulation model component in a preset order; restoring the test function module to an idle state; and deleting the loaded simulation model component.

[0109] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: acquiring test data during network attack and defense testing of the device under test using preset test cases; generating a test report based on the test data after the network attack and defense test is completed; the test report includes a list of security vulnerabilities of the device under test, response data of the device under test under each type of attack, performance index change curves of the device under test, abnormal events, and network security protection level of the device under test.

[0110] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.

[0111] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0112] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A power system network security testing method, characterized in that, Dispatch center module used in power system network security test bench; The power system network security test bench also includes a test function module, a communication interface, and a standardized interface; the method includes: In response to the current trigger signal of the test function module, the device connects to the power interface of the test function module through the communication interface to establish a hardware connection with the test function module. Based on the identification information and configuration parameters of the test function module, load the corresponding simulation model component and establish a software connection between the test function module and the simulation model component; A test connection is established with the device under test through the standardized interface, and the test connection is verified based on the electrical quantity feedback signal of the device under test. If the connection test is successful, a power system operation scenario for the device under test is loaded. In the power system operation scenario, network attack and defense tests are performed on the device under test using preset test cases. Upon completion of the network attack and defense test, the test function module and the simulation model component are restored to their initial state, and in response to the next trigger signal of the test function module, the hardware connection with the test function module is re-established.

2. The method according to claim 1, characterized in that, After loading the corresponding simulation model components according to the identification information and configuration parameters of the test function module, the process includes: A global clock signal is generated and synchronously sent to all test function modules so that the test function modules run according to the simulation step size indicated by the global clock signal.

3. The method according to claim 1, characterized in that, The test connection includes electrical connection and network link connection; the establishment of the test connection with the device under test through a standardized interface includes: Based on the device information of the device under test, corresponding power signals and analog signals are provided to the device under test through a standardized interface to establish an electrical connection with the device under test; A network link connection is established between the device under test and the device through the standardized interface.

4. The method according to claim 1, characterized in that, The network attack and defense test of the device under test using preset test cases includes: The open ports and known vulnerabilities of the device under test are scanned and detected, and network attack and defense tests are conducted on the network links of the device under test through network attack cases.

5. The method according to claim 1, characterized in that, Restoring the test function module and the simulation model component to their initial state includes: Disconnect the software connections between the test function module and the simulation model component in a preset order; The test function module is restored to an idle state, and the loaded simulation model component is deleted.

6. The method according to claim 1, characterized in that, The method further includes: During the network attack and defense testing of the device under test using preset test cases, test data is acquired. Upon completion of the network attack and defense test, a test report is generated based on the test data. The test report includes a list of security vulnerabilities of the device under test, the response data of the device under test under each type of attack, the performance index change curve of the device under test, abnormal events, and the network security protection level of the device under test.

7. A power system network security testing device, characterized in that, The device includes: A hardware connection module is used to respond to the current trigger signal of the test function module, and connect to the power interface of the test function module through the communication interface to establish a hardware connection with the test function module. The software connection module is used to load the corresponding simulation model component according to the identification information and configuration parameters of the test function module, and establish a software connection between the test function module and the simulation model component. The connection verification module is used to establish a test connection with the device under test through a standardized interface, and to verify the test connection based on the electrical quantity feedback signal of the device under test. The security testing module is used to load a power system operation scenario for the device under test after the test connection verification is passed. In the power system operation scenario, network attack and defense tests are performed on the device under test through preset test cases. The module recovery module is used to restore the test function module and the simulation model component to their initial state after the network attack and defense test is completed, and to re-establish the hardware connection with the test function module in response to the next trigger signal of the test function module.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.