A digital power grid network security protection effectiveness quantitative evaluation method, system, device and medium
By constructing a threat situation projection map of digital power grid networks and a multi-level quantitative assessment system, the accuracy problem of threat situation modeling and assessment of digital power grid networks has been solved. This enables accurate prediction of threat propagation paths and scientific quantitative assessment of protection effectiveness, supporting rapid response to network attacks.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-19
- Publication Date
- 2026-03-27
AI Technical Summary
Existing technologies lack threat situation modeling methods for digital power grids, making it impossible to accurately predict network threat propagation paths and scientifically assess protection effectiveness. Traditional assessment methods rely on qualitative analysis and cannot accurately quantify the impact of various threat factors on power grid security.
A threat situation projection map of the digital power grid network is constructed. Intrusion paths are searched through reverse and forward construction algorithms. A real-time threat event analysis algorithm is established by combining depth-first and breadth-first search strategies. Threat state transition and network-wide threat situation assessment index are calculated through a multi-level quantitative evaluation system.
It achieves comprehensive coverage and accurate prediction of threats to digital power grid networks, dynamically tracks the evolution of threats, provides scientific quantitative assessment of protection effectiveness, and supports decision-makers in responding quickly to cyberattacks.
Smart Images

Figure CN121173594B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of digital power grid network security, and particularly relates to a digital power grid network security protection effectiveness quantitative evaluation method, system, device and medium. BACKGROUND
[0002] As an important carrier of the power system, digital power grid realizes intelligent operation and management of the power grid through digital technology. With the deepening of the construction of digital power grid, the power grid system is facing increasingly complex network security threats. Traditional power systems mainly focus on physical security, while digital power grid introduces a large number of information communication technologies, making network attacks an important factor threatening the safe operation of the power grid.
[0003] In the field of digital power grid, large-scale smart grid systems not only involve extensive geographical distribution, but also require high real-time performance to ensure the stability and safety of power supply. In the face of increasingly severe network attack threats, the security protection technology of digital power grid is particularly important. From the perspective of system theory and control theory, the network security defense system of digital power grid is a large-scale complex system with monitoring and regulation as the core. The system integrates distributed data from sensors and databases through multi-level information fusion, and identifies and actively responds to potential network attacks in real time.
[0004] Currently, the network security protection of digital power grid mainly adopts traditional security protection means, such as firewalls, intrusion detection systems, and other passive defense measures. These methods have problems such as response lag, false positive rate, etc. when facing complex network attacks. At the same time, the existing security evaluation methods mostly use qualitative analysis, lack of quantitative evaluation indicators and scientific evaluation system, and are difficult to accurately reflect the real security state and protection effectiveness of digital power grid.
[0005] In the prior art, network security situation awareness mainly focuses on single-point threat detection and static risk assessment, lacking dynamic modeling of threat propagation paths and real-time analysis of network-wide threat situation. Traditional evaluation methods are often based on experience judgment or simple statistical analysis, which cannot accurately quantify the influence of various threat factors on power grid security, nor can they provide scientific data support for decision makers. SUMMARY
[0006] In view of the above problems, the present application is proposed.
[0007] Therefore, the technical problem solved by the present application is: how to solve the problem that the prior art lacks threat situation modeling methods for the characteristics of digital power grid, and cannot accurately predict the network threat propagation path and scientifically evaluate the protection effectiveness.
[0008] To solve the above technical problems, the application provides the following technical scheme: a digital power grid network security protection efficiency quantitative evaluation method, which comprises the following steps: constructing a digital power grid network threat situation deduction graph, starting from a threat target state through a reverse construction algorithm for key equipment, reversely searching an intrusion path by using a depth-first search strategy, starting from an initial state through a forward construction algorithm for a whole network topology, and forwardly searching all potential intrusion paths of the whole network power system by an attacker by using a breadth-first search strategy;
[0009] Based on the threat situation deduction graph, a network real-time threat event stack is established through a threat event real-time analysis algorithm, each network real-time threat event is sequentially traversed, threat events in the threat situation deduction graph are matched with real-time threat events, a space-time correlation relationship of network threats is analyzed, and timestamps of threat states and threat events are updated;
[0010] A multi-level quantitative evaluation system from threat events to a whole network threat situation is established, threat events are quantitatively evaluated through calculation of four dimensions of asset value degree, threat event influence degree, threat event success support rate and threat event concealment degree, and threat state transition atomic sequence evaluation indexes, threat path evaluation indexes, threat target evaluation indexes and whole network threat situation evaluation indexes are gradually recursively calculated based on threat event evaluation indexes.
[0011] As a preferred scheme of the digital power grid network security protection efficiency quantitative evaluation method, the method comprises the following steps: the construction of the digital power grid network threat situation deduction graph comprises the following steps: taking a threat target state as a starting point through a reverse construction algorithm, judging a threat event threat situation of the target, querying network vulnerability information, adding threat state nodes meeting a premise state to the threat situation deduction graph until an initial state node is reached or the number of state transitions exceeds a maximum value;
[0012] An initial state set is established through a forward construction algorithm, a threat event threat situation of an initial state node is judged, threat state node information reached after an intrusion is queried, whether the threat state node is in a threat finite set is judged, and the process is continued until no network vulnerability threat event is generated or the number of state transitions exceeds a maximum value.
[0013] As a preferred scheme of the digital power grid network security protection efficiency quantitative evaluation method, the threat event real-time analysis algorithm comprises the following steps: defining a variable to satisfy a situation judgment function to judge a threat state and a threat event satisfying situation, defining a timestamp function to record a threat event and a threat state occurrence time, and defining a time window to filter invalid and expired threat events;
[0014] The time and space correlation of the threat events is analyzed, the threat state and the timestamp of the threat event are updated, and a real-time threat situation deduction diagram is output by traversing each threat event in a network real-time threat event stack.
[0015] As a preferred scheme of the digital power grid network security protection efficiency quantitative evaluation method, the establishment of the multi-level quantitative evaluation system from the threat event to the whole network threat situation includes calculating the asset value degree by combining the asset value vector and the asset value weight, defining the threat event influence degree based on the attack classification and the corresponding level, calculating the threat event success support rate by matching the network vulnerability information and the vulnerability information used by the threat event, and calculating the threat event concealment degree by synthesizing the device influence function, the user influence function and the intrusion degree function.
[0016] Based on the threat event evaluation index, the threat state transition atomic sequence evaluation index is calculated by combining the threat event success support rate and the weight, the threat path evaluation index is calculated by considering all threat state transition atomic sequence evaluation indexes on the path, the threat target evaluation index is calculated by combining the intrusion path selection probability, and the whole network threat situation evaluation index is obtained by summing the threat situation evaluation indexes of all threat targets in the whole network.
[0017] As a preferred scheme of the digital power grid network security protection efficiency quantitative evaluation method, the calculation of the threat event success support rate includes searching for whether the necessary vulnerability used by the threat event exists in the network state node, and if all necessary vulnerabilities are not contained, the threat event success support rate is zero.
[0018] If all necessary vulnerabilities are contained, further search is performed to determine whether other vulnerabilities exist, if the other vulnerabilities exist, the threat event success support rate is the accumulation of the weight of the other vulnerabilities, and if the other vulnerabilities do not exist, the threat event success support rate is 1.
[0019] As a preferred scheme of the digital power grid network security protection efficiency quantitative evaluation method, the calculation of the threat event concealment degree includes defining the device influence function according to the degree of detection device alarm caused by the network security state change, defining the user influence function according to the degree of user awareness caused by the network security state change, and defining the intrusion degree function according to the intrusion degree caused by the threat event.
[0020] When the device is not alarmed or the user is not aware, the threat event concealment degree is 1, and when the device is alarmed or the user is aware, the threat event concealment degree is the product of the intrusion degree and the average value of the device influence and the user influence.
[0021] As a preferred scheme of the digital power grid network security protection efficiency quantitative evaluation method, wherein: further comprising calculating the early warning success rate, defense success rate, average disposal time and tactical decision accuracy timeliness of the digital power grid network security protection based on the quantitative evaluation result, forming a comprehensive protection efficiency evaluation index system.
[0022] The application provides a digital power grid network security protection efficiency quantitative evaluation system.
[0023] To solve the above technical problems, the application provides the following technical scheme: a digital power grid network security protection efficiency quantitative evaluation system, comprising: a threat situation construction module, configured to construct a digital power grid network threat situation deduction graph, starting from a threat target state through a reverse construction algorithm facing key equipment, searching an intrusion path in reverse through a depth-first search strategy, and starting from an initial state through a forward construction algorithm facing a whole network topology, searching all potential intrusion paths of the attacker to the whole network power system in forward through a breadth-first search strategy;
[0024] A real-time analysis module is configured to establish a network real-time threat event stack through a threat event real-time analysis algorithm based on the threat situation deduction graph, sequentially traverse each network real-time threat event, match the threat events in the threat situation deduction graph with the real-time threat events, analyze the space-time correlation relationship of the network threat and update the time stamp of the threat state and the threat event;
[0025] A quantitative evaluation module is configured to establish a multi-level quantitative evaluation system from the threat event to the whole network threat situation, quantitatively evaluate the threat event through calculation of four dimensions of asset value degree, threat event influence degree, threat event success support rate and threat event concealment degree, and gradually recursively calculate a threat state transition atomic sequence evaluation index, a threat path evaluation index, a threat target evaluation index and a whole network threat situation evaluation index based on a threat event evaluation index.
[0026] The application provides a computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the digital power grid network security protection efficiency quantitative evaluation method when executing the computer program.
[0027] The application provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the steps of the digital power grid network security protection efficiency quantitative evaluation method.
[0028] The application has the beneficial effects that: the application is constructed by bidirectional threat situation deduction graph, solves the problem of incomplete coverage of traditional one-way threat analysis, and the reverse construction algorithm ensures the accurate identification of the threat path of the key equipment, and the forward construction algorithm realizes the complete coverage of the whole network threat situation. The threat event real-time analysis algorithm converts the static threat graph into a dynamic threat situation through space-time correlation analysis, realizes the real-time tracking and prediction of the threat evolution process, and solves the problem of poor timeliness of the traditional method. The multi-level quantitative evaluation system starts from four core dimensions of threat events, realizes the quantitative evaluation from local to whole through recursive calculation, and converts the qualitative threat analysis into quantitative efficiency evaluation. BRIEF DESCRIPTION OF DRAWINGS
[0029] In order to more clearly illustrate the technical solutions of the embodiments of the application, the drawings needed to be used in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative labor.
[0030] Figure 1 A general flowchart of a digital power grid network security protection efficiency quantitative evaluation method provided by an embodiment of the application.
[0031] Figure 2 A network threat real-time analysis algorithm diagram of a digital power grid network security protection efficiency quantitative evaluation method provided by an embodiment of the application.
[0032] Figure 3 A diagram of gradually recursive quantitative evaluation from local to whole of a digital power grid network security protection efficiency quantitative evaluation method provided by an embodiment of the application.
[0033] Figure 4 A threat event success support rate measurement algorithm diagram of a digital power grid network security protection efficiency quantitative evaluation system provided by an embodiment of the application. DETAILED DESCRIPTION
[0034] In order to make the above-mentioned purposes, features and advantages of the application more obvious and easy to understand, the specific embodiments of the application will be described in detail below with reference to the drawings of the specification. Obviously, the described embodiments are part of the embodiments of the application, rather than all the embodiments. Based on the embodiments in the application, all other embodiments obtained by those skilled in the art without creative labor should be within the protection scope of the application.
[0035] Embodiment 1, refer to Figures 1-4 For an embodiment of the application, the embodiment provides a digital power grid network security protection efficiency quantitative evaluation method, which comprises:
[0036] S100: Constructing a digital power grid network threat situation deduction graph, starting from a threat target state through a reverse construction algorithm for key equipment, using a depth-first search strategy to search for intrusion paths in reverse, and starting from an initial state through a forward construction algorithm for the entire network topology, using a breadth-first search strategy to search for all potential intrusion paths of the attacker to the entire network power system;
[0037] S200: Based on the threat situation deduction graph, a network real-time threat event stack is established through a threat event real-time analysis algorithm, each network real-time threat event is iterated in turn, the threat events in the threat situation deduction graph are matched with the real-time threat events, the spatio-temporal correlation of network threats is analyzed and the timestamps of threat states and threat events are updated;
[0038] S300: A multi-level quantitative evaluation system from threat events to the entire network threat situation is established, threat events are quantitatively evaluated through calculation of asset value, threat event impact, threat event success support rate, and threat event concealment, and based on threat event evaluation indexes, threat state transition atomic sequence evaluation indexes, threat path evaluation indexes, threat target evaluation indexes, and entire network threat situation evaluation indexes are recursively calculated.
[0039] It should be noted that as the core carrier of new power systems, digital power grids have network security threats with complex attack paths, fast threat propagation speed, and wide influence range. Traditional security evaluation methods mainly rely on single-point detection and static analysis, and cannot cope with distributed attacks and dynamic threat evolution. Key equipment in digital power grids, such as SCADA systems (Supervisory Control And Data Acquisition), intelligent terminals, communication gateways, and other nodes are numerous and interconnected. Once a node is compromised, the threat can quickly spread to other key equipment through network topology, causing a chain reaction. At the same time, digital power grids have very high real-time requirements, and threat detection and response must be completed within milliseconds, which puts higher requirements on the quantitative evaluation of security protection effectiveness.
[0040] Therefore, in view of the above-mentioned key problems of digital power grid network security protection, such as difficulty in threat situation modeling, insufficient real-time analysis capability, and lack of quantitative evaluation system, through steps S100-S300, a bidirectional search threat situation deduction model is constructed, comprehensive coverage and accurate prediction of attack paths are achieved; a real-time threat analysis mechanism is established to dynamically track the threat evolution process and update the threat state in a timely manner; a multi-level quantitative evaluation system is constructed to progressively evaluate from threat events to the entire network situation, and scientific quantification and accurate evaluation of the effectiveness of digital power grid network security protection are achieved.
[0041] Embodiment 2, which is an embodiment of the present application, provides a digital power grid network security protection effectiveness quantitative evaluation method based on the previous embodiment, comprising: step S100 of constructing a digital power grid network threat situation deduction graph, step S100 comprising steps A1-A2:
[0042] A1: starting from a threat target state, judging whether a threat event threatens the target, querying network vulnerability information, and adding a threat state node meeting the premise state to the threat situation deduction graph until the initial state node is reached or the maximum number of state transitions is exceeded;
[0043] Specifically, the reverse construction algorithm for threat targets can effectively reduce the size of the network threat situation deduction graph and improve the search efficiency of the algorithm by defining the maximum number of state transitions MAXSTEP, as the number of threat states in the actual network environment is limited, while ensuring that no threat states are missed.
[0044] Target state , a single threat target state node representing a specific attack end state that an attacker hopes to achieve; threat target set , a set containing multiple target states , which is the sum of all potential threat target states; linked list ; a data structure for storing the threat target set, which adopts a linked list form to facilitate dynamic addition and deletion of threat target states; threat target ; a specific attack object or attack intention of an attacker, which may correspond to one or more target states; threat target state set ST, a set of threat target states dynamically maintained during algorithm execution, used for intersection judgment with the state transition function set;
[0045] Put the threat target set containing the target state into the linked list , take a target state from the head of the linked list, judge whether the threat target state has been met, if it has been met, it means that the state has been traversed, and it is put back into the linked list ; if it is not met, proceed to the next step.
[0046] The premise state of the threat target composes the state transition function set { }. Search the finite set of threat events ET to find all threat event sets { } that lead to , and iterate with the threat event set { }. Judge the state transition function set { and threat target state set whether intersect, if intersect, add this threat event to the DG dynamic graph (Dynamic Graph, refers to the data structure of threat situation deduction graph), and update the corresponding state node; if not intersect, forward recursion of target state, state transition times plus 1, algorithm iteration; in the iteration process, judge state transition function set } is empty, if not empty, return to continue iteration; if empty, proceed to the next step. Judge whether the threat event set } is empty, if not empty, return to continue iteration; if empty, add the current threat state to The initial state set of the threat is represented by the initial state node set D0, which represents the starting state node set of the threat analysis.
[0047] It should be noted that the reverse construction algorithm needs to establish a data structure management of threat state nodes during execution, each threat state node contains state identifier, threat type classification, premise condition set, influence range parameter and state transition probability matrix.
[0048] In the search process, the algorithm maintains a dynamically updated threat state priority queue, and sorts the search path according to the importance of the threat target and the attack complexity. At the same time, a state node access marking mechanism is established to avoid circular search and repeated calculation, and the search efficiency is improved by marking the accessed state nodes.
[0049] In the construction of state transition function set, the algorithm needs to consider the trigger condition and execution probability of threat event, the trigger condition of threat event is described by logical expression, and the logical expression description includes system state condition, time constraint condition and resource availability condition. The execution probability is estimated based on historical attack data, and the dynamic adjustment probability value is adjusted. When the threat event set is empty, the algorithm automatically backtracks to the upper state node and continues to search other possible threat paths.
[0050] A2: Establish the initial state set by the forward construction algorithm, judge the threat of threat events to the initial state node, query the threat state node information reached after intrusion, judge whether the threat state node is in the threat finite set, until there is no threat event of network vulnerability or the state transition times exceed the maximum value.
[0051] Specifically, the forward construction algorithm starts by adding the initial state node to the initial state node set D0. Within the range of the maximum state transition times MAXSTEP, judge whether the reachable threat state has been satisfied. If it is satisfied, it means that the state has been traversed and it is put back into the reachable state node set Dr; if it is not satisfied, get the threat events that can be triggered to the reachable state node A set of threat events is generated. It is determined whether the reachable state node is in the threat finite set ST, if not, the reachable node is added to the threat finite set ST and the temporary set Stemp, and the algorithm iteration is performed; if yes, the corresponding threat event and state node are added to the DG, and after the algorithm iteration is completed, the threat situation deduction graph of the global network is output.
[0052] The results of the forward construction algorithm and the reverse construction algorithm are fused to form a complete threat situation deduction graph. The fusion process first converts the graphs constructed in the two directions into a standardized directed graph format. Node fusion uses an attribute matching algorithm to calculate the similarity through the threat type, impact range, and state characteristics of the nodes, identify duplicate nodes, and merge them. In the edge fusion process, for threat event edges with the same start and end nodes, a probability weighted average method is used to calculate the transition probability after fusion.
[0053] The fused threat situation deduction graph is verified for completeness. The verification process includes path connectivity checking to ensure that there is a reachable path from the initial state to each threat target; loop detection to identify and process loop structures in the graph; consistency checking to verify the logical consistency of the forward and reverse construction results. After verification is complete, a standardized threat situation deduction graph data structure is generated.
[0054] In this embodiment, the threat event real-time analysis algorithm in step S200 includes the following steps B1-B2:
[0055] B1: Define a variable satisfaction condition function to determine the satisfaction condition of the threat state and the threat event, define a timestamp function to record the occurrence time of the threat event and the threat state, and define a time window to filter invalid and expired threat events;
[0056] Specifically, a variable satisfaction condition function D(x) is defined. The state node set includes an initial state node set D0 and an undetermined state node set UDr, D0 is the initial state node set, representing the initial security state of the network, and UDr is the undetermined state node set, representing the node whose state is uncertain and the elements of the threat event set De of the utilization node exist in three states (TRUE, FALSE, HYP). The variable satisfaction condition function D(x) is used to determine the satisfaction condition of the threat state or the threat event, where TRUE indicates that the variable has been satisfied, FALSE indicates that the variable has not been satisfied, and HYP indicates that the variable is assumed to be satisfied. The determination results of the threat state and the threat event are as follows:
[0057] ;
[0058] ;
[0059] wherein, is a set of threat events; is a threat state decision function for determining the satisfaction of the threat state s.
[0060] Based on the structured data of the threat situation deduction diagram, a time-space correlation analysis database of threat events is established. The time-space correlation analysis database describes the relationship between threat events through multi-dimensional feature vectors, including the time dimension of the order, duration and frequency, and the space dimension of the network topology distance, influence range overlap and propagation path similarity.
[0061] B2: Traverse each threat event in the network real-time threat event stack, analyze the time-space correlation relationship of the threat event, update the threat state and the time stamp of the threat event, and output the real-time threat situation deduction diagram.
[0062] Specifically, define the time stamp function T(x). In a complete intrusion process, for a step of intrusion, network threat events may occur multiple times, causing multiple alarms of security monitoring devices. In order to determine and record the occurrence time of the latest threat event and threat state, a time stamp function T(x) needs to be set.
[0063] For the time stamp function of network threat events and the time stamp function of network threat states , meet , then the time stamp of the network threat event can be expressed as , ; the time stamp of the network threat state can be expressed as:
[0064] ;
[0065] ;
[0066] ;
[0067] wherein, is a network threat event; is a set of network threat states; is a time stamp function of network threat states; is a time stamp function of network threat events; is the current time; is a threat event stack; is a threat state stack; is a network threat event prerequisite state; is a set of exploitable network threat states; is not limited by time; is a network threat event; for a network threat event; for a precondition set of the threat state s'; for a timestamp function of the threat state s'; for a threat state; for representing a threat event instance, which is a specific implementation of the network threat event e; for representing a specific occurrence time of the threat event instance , that is, a timestamp at which the threat event is detected or occurs in the actual system.
[0068] define a time window . The time window is the maximum time interval in which the intrusion behavior takes effect. For some invalid and expired threat events, the size of the time window is set as Δ , if is satisfied, it indicates that some invalid and expired threat events with too large time span are generated, which have lost value and should be filtered out. If is satisfied, it indicates that the two continuous threat events are valid. is the absolute value of the time difference between the occurrence times of the two continuous threat events; and the network threat real-time analysis algorithm is described as Figure 2 .
[0069] First, a network real-time threat event stack is established, each network real-time threat event is traversed in turn, the threat events in the DG are matched with the real-time threat events, various space-time correlation relationships of the network threats are analyzed and processed accordingly, finally, the threat state and the timestamp of the threat event are updated, and are input into the DG to construct a network real-time threat situation deduction graph (RTDG), and when the network real-time threat event stack is empty, the algorithm stops.
[0070] The evaluation method of the present application is based on the established network threat situation deduction graph, and is quantitatively evaluated in a logical order from local to whole, as shown in Figure 3 .
[0071] The real-time threat situation deduction graph is constructed while being dynamically updated, and the dynamic update includes two modes of incremental update and full update. The incremental update is suitable for the case that the number of threat events is small, and only the state information of the affected nodes and edges is updated. The full update is suitable for the case that the threat situation changes greatly, and the state distribution of the entire threat situation deduction graph is recalculated.
[0072] A threat event priority ranking is established, and the threat events are ranked according to the urgency, influence range and processing complexity. High-priority threat events are preferentially entered into the processing queue to ensure that critical threats can be responded to in time. At the same time, a threat event aggregation mechanism is established to merge similar threat events for processing, reducing repeated calculation and analysis overhead.
[0073] In this embodiment, the multi-level quantitative evaluation system from threat events to the whole network threat situation is established in step S300, including the following steps C1-C4:
[0074] C1: Calculate the asset value degree by combining the asset value vector with the asset value weight, define the threat event impact degree based on attack classification and corresponding level, calculate the threat event success support rate by matching network vulnerability information with vulnerability information used by the threat event, and calculate the threat event concealment degree by synthesizing the device impact function, the user impact function and the intrusion degree function;
[0075] Specifically, the four indexes related to the threat event evaluation index and the quantitative calculation method thereof.
[0076] (1) Asset value degree : Reflects the value of the network entity invaded and used.
[0077] (2) Threat event impact degree : Embodies the effectiveness and destructiveness of the threat event.
[0078] (3) Threat event success support rate : Reflects the probability of success of the threat event using vulnerability information.
[0079] (4) Threat event concealment degree : Embodies the concealment degree of the threat event in the intrusion process.
[0080] Asset value degree:
[0081] Assets are the objects on which threat events act, and the evaluation of threat events cannot be separated from the measurement of asset value degree. Assets with high value degree bring greater benefits to intruders, and therefore often become the focus of various threats. Select part of the basic evaluation index set related to asset value degree for level measurement, as shown in the following table. The evaluation index set includes three indexes: confidentiality impact (ConI), integrity impact (IntI) and availability impact (AvaI).
[0082] Asset value reflects the value of the network entity invaded, and according to the CVSS basic evaluation index set, the following definitions are made. CVSS is the Common Vulnerability Scoring System, a standardized method for evaluating the severity of network security vulnerabilities; refer to Table 1,
[0083] Table 1: CVSS part of basic evaluation index measurement set
[0084]
[0085] Define asset value vector V. Asset value vector V = [ConI, IntI, AvaI], which represents that asset value is composed of three components of confidentiality value, integrity value and availability value, and the total amount of asset value is obtained by calculating the sum of the three components.
[0086] Define asset value weight μ. Asset value weight is the proportion of the three components of asset value vector in the total amount of asset value, which can be expressed as μ = [ConI, IntI, AvaI] / (ConI + IntI + AvaI). ] The calculation method of each weight value is:
[0087] ;
[0088] Wherein, ConI represents the confidentiality asset value weight, IntI represents the integrity asset value weight, AvaI represents the availability asset value weight, and satisfies: ; ConI is the confidentiality impact; IntI is the integrity impact; AvaI is the availability impact.
[0089] The greater the ConI, IntI and AvaI index impacts of the basic evaluation index measurement set, the greater the corresponding index level measurement value, and the greater the threat to the asset. Therefore, the asset value degree V is obtained by combining the asset value vector V and the asset value weight μ, and the calculation formula of the asset value degree V is:
[0090] ;
[0091] Wherein, i = 1, 2, 3 respectively represent the three components of asset value vector: confidentiality value, integrity value and availability value, μ represents asset value weight, and I represents the level measurement of the three components of asset value.
[0092] Based on the threat event evaluation index, the index is obtained by multiplying the four dimensions (asset value degree V(e), threat event impact degree I(e), success support rate P(e), and concealment degree H(e)) calculated in the foregoing steps, that is:
[0093] ;
[0094] Wherein, is the evaluation index of the i th threat event; is the sum of asset value degrees of the i th threat event affecting the device, is the impact degree of the i th threat event, is the success support rate of the i th threat event, is the concealment degree of the i th threat event.
[0095] The threat path evaluation index is calculated by combining all threat state transition atomic sequence evaluation indexes on the path, and the threat target evaluation index is calculated by combining the intrusion path selection probability. The threat situation evaluation index of all threat targets in the network is summed to obtain the network threat situation evaluation index.
[0096] Specifically, the network threat event influence degree The threat event influence degree is divided into high, medium, low, and very low levels according to the definition method of attack classification and corresponding level in the Snort user manual, and the level measurement values are 4, 3, 2, and 1 respectively. All threat events correspond to 34 attack types, of which 10 attack types have high threat event influence degrees, 16 attack types have medium threat event influence degrees, 7 attack types have low threat event influence degrees, and 1 attack type has a very low threat event influence degree, as shown in the following table. Referring to Table 2,
[0097] Table 2: Attack classification and threat event influence degree level
[0098]
[0099] The calculation of the four quantitative dimensions establishes a unified numerical normalization and weight distribution mode. Asset value degree, threat event influence degree, success support rate, and concealment degree adopt different quantitative methods and numerical ranges, and need to be normalized to the same numerical interval. The normalization process adopts the minimum-maximum standardization method, and the numerical values of each dimension are mapped to the [0, 1] interval.
[0100] The coupling relationship between the dimensions is established, and the mutual influence degree between the dimensions is quantified. Asset value degree and threat event influence degree have a positive correlation, and the impact caused by attacks on high-value assets is more serious. Success support rate and concealment degree have a negative correlation, and attacks that are easy to succeed usually have poor concealment and are easy to be detected. The coupling coefficients between the dimensions are determined through correlation analysis, and a correction matrix is established to adjust the dimension values calculated separately.
[0101] The determination of the dimension weight is driven by historical data. The importance of each dimension is obtained through a questionnaire survey, and the weight distribution is determined by statistical analysis of historical attack cases. In the weight distribution process, special needs of different application scenarios are considered, such as key infrastructure protection scenarios that pay more attention to asset value degree, and real-time monitoring scenarios that pay more attention to success support rate.
[0102] C2: The success support rate of a threat event is calculated by checking whether the necessary vulnerabilities for the threat event are present in the network state node. If not, the success support rate of the threat event is zero.
[0103] If the necessary vulnerabilities are present, further checking is performed to determine whether other vulnerabilities are present. If so, the success support rate of the threat event is the sum of the weights of the other vulnerabilities. If not, the success support rate of the threat event is 1.
[0104] Specifically, the vulnerability information present in the network is matched with the vulnerability information utilized by the threat event to calculate the success support rate P(e) of the threat event. The vulnerability information vul utilized by the threat event is obtained from the ontology-based threat situation knowledge base established, and according to the threat degree caused by the vulnerability, vul can be divided into necessary vulnerabilities and other vulnerabilities. The necessary vulnerabilities refer to the vulnerability information that must be relied on for the successful occurrence of the threat event. The other vulnerabilities refer to the vulnerability information that may be needed in addition to the necessary vulnerabilities, and each of the other vulnerabilities has a certain weight ω, indicating the degree of influence on the successful implementation of the threat event, and the sum of all weights is 1. The threat event success support rate measurement algorithm is as shown in the following table. Figure 4 The threat event success support rate measurement algorithm is shown in the following table.
[0105] The calculation of the success support rate of the threat event relies on an accurate vulnerability information database. A vulnerability information management system is established, which includes functions such as vulnerability discovery, evaluation, classification, and updating. The vulnerability discovery obtains the latest vulnerability information through automated vulnerability scanning, security notification subscription, and analysis, and adjusts the scoring results in combination with the specific system environment and configuration.
[0106] The classification management of the vulnerability information adopts a multi-dimensional label system, including labels such as vulnerability type, affected component, exploitation difficulty, and repair status. Version control of the vulnerability information is established to record the change history and update track of the vulnerability information. When the vulnerability information changes, the system automatically recalculates the success support rate of the affected threat event to ensure the accuracy of the evaluation results.
[0107] The distinction between necessary vulnerabilities and other vulnerabilities is based on the attack mechanism analysis of the threat event. The necessary vulnerabilities are the sufficient and necessary conditions for the successful implementation of the threat event, and the lack of any one of the necessary vulnerabilities will result in the failure of the attack. The other vulnerabilities are auxiliary conditions for improving the success rate of the attack, and the weight value is determined according to the degree of contribution to the success of the attack. The weight allocation process adopts the analytic hierarchy process, and the relative importance of each vulnerability is determined through a judgment matrix.
[0108] C3: calculating the concealment degree of threat event includes defining a device impact function according to the degree of network security state change causing the detection device to alarm, defining a user impact function according to the degree of network security state change causing the user to be aware, and defining an intrusion degree function according to the degree of intrusion caused by the threat event;
[0109] The concealment degree of threat event is 1 when the device does not alarm or the user is not aware, and is the product of the intrusion degree and the average of the device impact and the user impact when the device alarms or the user is aware.
[0110] Specifically, the concealment degree of threat event in the intrusion process is related to three aspects of factors: (1) whether the change of network security state can cause the detection device to alarm; (2) whether the change of network security state can cause the user to be aware; and (3) the degree of intrusion caused by the threat event when the change of network security state causes the detection device to alarm or causes the user to be aware.
[0111] According to whether the change of network security state can cause the detection device to alarm, the following device impact function is defined:
[0112] ;
[0113] Wherein, is the device impact function, quantifying the influence of the threat event on the degree of alarm of the detection device; is a device impact coefficient, indicating the case that does not cause alarm or the degree is very small ( 2 ) ; is a device impact coefficient, indicating the case that causes alarm to a large extent ( ) ;
[0114] In addition to causing the detection device to alarm each time, the threat event may cause the user to be aware if the network security state changes greatly, so that the user can take corresponding means to prevent it. Therefore, according to whether the change of network security state can cause the user to be aware, the following user impact function is defined:
[0115] ;
[0116] Wherein, is the user impact function, quantifying the influence of the threat event on the degree of user awareness; is a user impact coefficient, indicating the degree of possible user attention ( 1 ) ;
[0117] The degree of intrusion caused by the threat event when the change of network security state of the digital power grid causes the detection device to alarm or causes the user to be aware is of great significance to the intrusion process when targeting the threat target, so the following intrusion degree function is defined:
[0118] ;
[0119] Among them, Degree indicates the degree of intrusion when the network security status changes, step indicates the number of intrusion steps that trigger device alarms or cause users to become aware of the intrusion, and range indicates the total number of steps in the intrusion path.
[0120] Taking into account the above three factors, the degree of concealment of threat events It can be represented as:
[0121] ;
[0122] in, Indicates the first The degree of intrusion of each threat event, Indicates the first The device impact coefficient of a threat event. Indicates the first The user impact coefficient of a threat event. When When this occurs, it indicates that the device did not trigger an alarm or the user was unaware, and the corresponding threat event is relatively well concealed; when At this point, the concealment level is the average impact coefficient of the detection equipment and the user, indicating that the equipment alarms or the user notices the occurrence of a threat event, corresponding to a relatively poor concealment of the threat event.
[0123] Secondly, the threat status of the network will be analyzed and evaluated in depth step by step according to the stages of threat events, threat state transition atomic sequences, threat paths, threat targets, and overall network threat situation, and specific quantitative calculation methods for various evaluation indices will be given.
[0124] Threat Event Assessment Index The (evaluate index of threat event) depends on four factors: asset value, threat event impact, threat event success rate, and threat event concealment. The calculation methods for these four factors have been analyzed in detail above. The calculation formula is:
[0125] ;
[0126] in, Let be the assessment index for the i-th threat event; This represents the sum of the asset value of the device affected by the i-th threat event. This represents the impact of the i-th threat event. This represents the success rate of the i-th threat event. This represents the concealment level of the i-th threat event.
[0127] A threat state transition atomic sequence is the smallest unit of state transition that occurs after a threat state is affected by a threat event. Threat state transition atomic sequence evaluation index. The (evaluate index of transactionsequence) represents the impact of a successful threat state transition atomic sequence. The calculation formula is:
[0128] ;
[0129] in, Indicating a threat event This causes the network state node to change state. to state The probability, Represents all states The premise of the threat event, Indicating a threat event The success rate of support, Indicating a threat event Successful support rates across all arriving states The percentage of successful support for threat events.
[0130] Threat Path Assessment Index The (evaluate index of threat path) represents the impact of a threat action after it intrudes along a certain path. This index needs to consider all threat state transition atomic sequences along that path for evaluation. The calculation formula is:
[0131] ;
[0132] in, This indicates the impact of the successful occurrence of the i-th threat state transition atomic sequence on the threat path. Threat Target Assessment Index: Before attempting to intrude into a threat target, an intruder must first plan a suitable path. It is assumed that the intruder can intelligently make choices, selecting a path with relatively low complexity based on the attack complexity of each vulnerability. The proposed vulnerability attack complexity grading quantification standard is used to calculate the threat target assessment index, as shown in Table 3.
[0133] Table 3. Quantification Standards for Vulnerability Attack Complexity:
[0134]
[0135] Definition 1: Probability of selecting an atomic target during state transition For any chosen threat state transition atom sequence v in the threat path ( , , ) the state of intruder arriving , and the corresponding vulnerability attack complexity is , then the state transition atomic target selection probability is:
[0136]
[0137] wherein, represents the state of intruder arriving , and the set of next step invasion targets that can be selected, is the state of intruder arriving , and the corresponding vulnerability attack complexity is , and the state transition atomic target selection probability is is the source state node in the threat state transition atomic sequence; is the threat event in the threat state transition atomic sequence; is the state in the threat state transition atomic sequence.
[0138] Definition 2: Intrusion path selection probability CP. Let the intrusion paths of intruder arriving at a certain threat target be n, which can be represented as Path={Path1,Path2,Path3,…,Pathn}, and the possibility of intruder selecting any one of the intrusion paths Pathi={s0,e1,s1,e2,s2,…,sn−1,en,sn} in Path is :
[0139] ;
[0140] wherein, represents the state transition atomic target selection probability of two continuous threat states; j is the jth intrusion path; and n is the total number of intrusion paths.
[0141] Threat target evaluation index (the evaluate index of threat goal) represents the sum of the impact caused by intruder selecting each threat path to invade the intended threat target, which comprehensively considers the possibility of intruder selecting a threat path and the success rate of reaching the threat target by using the threat path, and the calculation formula is:
[0142] ;
[0143] wherein, represents the probability of intruder selecting the ith threat path, represents the impact situation after invading the threat target by using the ith threat path. The success rate of reaching the threat target.
[0144] The whole network threat situation evaluation index The whole network threat situation evaluation index (evaluate index of network): considering the existence of n threat targets in the whole network, which can be expressed as Goal={Goal1, Goal2, Goal3,…, Goaln}, the index represents the sum of the threat situation evaluation indexes of all threat targets in the whole network,
[0145] The calculation formula is:
[0146] ;
[0147] Among them, represents the evaluation index of the i th threat target.
[0148] The multi-level quantitative evaluation system is constructed, and the data flow and result transmission mode between levels are established. The threat event evaluation index as the basic layer provides data input for the upper layer evaluation. The threat state transition atomic sequence evaluation index is calculated based on the threat event evaluation index, considering the probability and influence range of state transition.
[0149] The calculation of the whole network threat situation evaluation index considers the mutual dependence relationship between threat targets. The target dependence relationship graph is established to describe the influence transmission path between threat targets. When a threat target is attacked, its influence may be transmitted to other targets through the dependence relationship. The quantification of the dependence relationship adopts the influence transmission coefficient, which is determined based on the business association degree and technical coupling degree between targets. The final whole network threat situation evaluation index is calculated by modifying the dependence relationship graph, reflecting the cascading influence effect of the threat.
[0150] C4: further includes calculating the early warning success rate, defense success rate, average disposal time and tactical decision accuracy timeliness of the digital power grid network security protection based on the quantitative evaluation results, forming a comprehensive protection efficiency evaluation index system.
[0151] The specific implementation of the digital power grid network security protection efficiency index based on the quantitative evaluation results is the whole network threat situation evaluation index as the basic input data, combined with the system real-time monitoring parameters for comprehensive calculation. The calculation of the early warning success rate is based on the coupling relationship between the threat event concealment function and the system detection ability, which is quantified by the formula:
[0152] ;
[0153] Among them, PW represents the early warning success rate, is the concealment degree of the i th threat event (defined in the foregoing C3), TR represents the standard response time requirement of threat events. The formula evaluates the probability of early warning failure by the product of concealment and detection delay time, and the success rate of early warning is obtained by subtracting the probability from 1.
[0154] The defense success rate calculation combines the reverse indicators of threat event success support rate and system protection coverage, and uses the formula to quantify:
[0155] ;
[0156] Where PD represents the defense success rate, is the success support rate of the i-th threat event (calculated in the foregoing C2), represents the protection measure coverage coefficient for the i-th threat event, and N represents the total number of threat events. The relative ease of defense is reflected by the reciprocal of the success support rate, and the overall defense effect is evaluated in combination with the protection coverage coefficient.
[0157] The average handling time is calculated based on the threat path evaluation index and the response process complexity, and the formula is:
[0158] ;
[0159] Where MTTR represents the average handling time, is the evaluation index of the i-th threat path (calculated recursively in the foregoing C1), represents the response process complexity factor corresponding to the i-th threat path, represents the standard time required to handle the i-th threat path. The formula calculates the overall handling time by weighted average of the threat path evaluation index.
[0160] The accuracy and timeliness of tactical decision-making are achieved by comprehensive evaluation of threat target evaluation index and decision support system performance parameters, and the calculation formula is:
[0161] ;
[0162] Where DA represents the decision accuracy and timeliness index, is the evaluation index of the j-th threat target (calculated in the foregoing C1), represents the historical decision accuracy rate for the j-th threat target, represents the average decision time for the j-th threat target. The decision quality is comprehensively evaluated by weighting the threat target importance, combining the ratio of historical accuracy rate and decision time.
[0163] In summary, the reverse construction algorithm realizes the depth-first search of the threat path through the dynamic management of the state transition function set and the threat target set, ensuring that the threat analysis of the key threat target is not missed; the forward construction algorithm ensures the complete coverage of the whole network threat situation through the breadth-first traversal of the initial state set. The real-time threat event analysis establishes the space-time correlation analysis framework of the threat event through the definition of the variable satisfaction condition judgment function, the timestamp function and the time window, realizes the dynamic update of the real-time threat situation and the automatic filtering of the historical threat. The multi-level quantitative evaluation system realizes the conversion of the abstract threat concept into the calculable quantitative index through the specific implementation of the asset value vector, the attack classification level, the vulnerability matching algorithm and the concealment calculation model. The threat event success support rate algorithm accurately reflects the actual feasibility of the threat event through the distinction calculation of the necessary vulnerability and other vulnerabilities, providing accurate data support for the defense strategy formulation.
[0164] Embodiment 3, refer to Figure 2 and Figure 4 , the embodiment provides a kind of digital power grid network security protection efficiency quantitative evaluation system, comprising, threat situation construction module, for constructing digital power grid network threat situation deduction chart, by the reverse construction algorithm of key equipment, from threat target state, using depth-first search strategy, reverse search intrusion path, while through the forward construction algorithm of whole network topology, from initial state, using breadth-first search strategy, forward search all potential intrusion paths of attacker to whole network power system;
[0165] Real-time analysis module, for based on threat situation deduction chart, through threat event real-time analysis algorithm, establishes network real-time threat event stack, iterates each network real-time threat event in turn, matches threat event in threat situation deduction chart with real-time threat event, analyzes the space-time correlation of network threat and updates the timestamp of threat state and threat event;
[0166] Quantitative evaluation module, for establishing multi-level quantitative evaluation system from threat event to whole network threat situation, threat event is quantitatively evaluated by calculating asset value degree, threat event influence degree, threat event success support rate and threat event concealment degree, threat state transition atomic sequence evaluation index, threat path evaluation index, threat target evaluation index and whole network threat situation evaluation index are gradually recursively calculated based on threat event evaluation index.
[0167] The embodiment also provides an electronic device suitable for a digital power grid network security protection efficiency quantitative evaluation method, comprising: a memory and a processor; the memory is used to store computer executable instructions, and the processor is used to execute the computer executable instructions to realize the digital power grid network security protection efficiency quantitative evaluation method provided in the above embodiment.
[0168] The embodiment also provides a storage medium, which stores a computer program, and the computer program is executed by a processor to implement the digital power grid network security protection efficiency quantitative evaluation method provided in the above embodiment.
[0169] The storage medium provided in the embodiment and the digital power grid network security protection efficiency quantitative evaluation method provided in the above embodiment belong to the same inventive concept, and the technical details not described in the embodiment can be referred to the above embodiment, and the embodiment has the same beneficial effects as the above embodiment.
[0170] From the above description about the embodiments, those skilled in the art can clearly understand that the present application can be realized by means of software and necessary universal hardware, and of course can also be realized by hardware, but in many cases the former is a better embodiment. Based on such understanding, the technical solutions of the present application or the part that contributes to the prior art can be embodied in the form of a software product, which can be stored in a computer readable storage medium, such as a floppy disk, a read-only memory (ROM), a random access memory (RAM), a FLASH memory, a hard disk, or an optical disc, and includes a number of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods of various embodiments of the present application.
[0171] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present application but not limit the present application, and although the present application has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present application can be modified or replaced by equivalents without departing from the spirit and scope of the present application, and all of them should be covered in the scope of the claims of the present application.
Claims
1. A method for quantitatively evaluating the network security protection effectiveness of digital power grids, characterized in that: The method comprises the following steps: constructing a digital power grid network threat situation deduction graph, starting from a threat target state by using a reverse construction algorithm for key equipment, and using a depth-first search strategy to reversely search an intrusion path; meanwhile, starting from an initial state by using a forward construction algorithm for a whole network topology, and using a breadth-first search strategy to forwardly search all potential intrusion paths of the attacker to the whole network power system; Based on the threat situation deduction graph, a network real-time threat event stack is established by using a threat event real-time analysis algorithm, each network real-time threat event is sequentially traversed, a threat event in the threat situation deduction graph is matched with a real-time threat event, a space-time correlation of the network threat is analyzed, and a timestamp of the threat state and the threat event is updated; The method for constructing the digital power grid network threat situation deduction graph comprises the following steps: starting from a threat target state by using a reverse construction algorithm, judging a threat event threat situation of the target, querying network vulnerability information, adding a threat state node meeting a premise state to the threat situation deduction graph, and stopping until an initial state node is reached or a state transition number exceeds a maximum value; An initial state set is established by using a forward construction algorithm, a threat event threat situation of an initial state node is judged, information of a threat state node reached after intrusion is queried, whether the threat state node is in a threat finite set is judged, and stopping until no network vulnerability threat event is generated or a state transition number exceeds a maximum value; A multi-level quantitative evaluation system from a threat event to a whole network threat situation is established, a threat event is quantitatively evaluated by calculating four dimensions of asset value degree, threat event influence degree, threat event success support rate and threat event concealment degree, a threat state transition atomic sequence evaluation index, a threat path evaluation index, a threat target evaluation index and a whole network threat situation evaluation index are gradually recursively calculated based on a threat event evaluation index; The multi-level quantitative evaluation system from the threat event to the whole network threat situation comprises the following steps: asset value degree is calculated by combining an asset value vector and an asset value weight, a threat event influence degree is defined based on attack classification and corresponding grade, a threat event success support rate is calculated by matching network vulnerability information and vulnerability information used by the threat event, and a threat event concealment degree is calculated by comprehensively considering a device influence function, a user influence function and an intrusion degree function; Based on the threat event evaluation index, the threat state transition atomic sequence evaluation index is calculated by combining the threat event success support rate and the weight, the threat path evaluation index is calculated by considering all threat state transition atomic sequence evaluation indexes on the path, the threat target evaluation index is calculated by combining an intrusion path selection probability, and a whole network threat situation evaluation index is obtained by summing threat situation evaluation indexes of all threat targets in the whole network.
2. The method of claim 1, wherein the method further comprises: determining a security level of the digital grid based on the security performance of the digital grid. The threat event real-time analysis algorithm comprises the following steps: a variable satisfying condition judgment function is defined to judge a threat state and a threat event satisfying condition, a timestamp function is defined to record a threat event and a threat state occurrence time, and a time window is used to filter invalid and expired threat events. The time and space correlation of the threat events is analyzed, the threat state and the timestamp of the threat event are updated, and a real-time threat situation deduction diagram is output.
3. The method of claim 2, wherein: The calculation of the threat event success support rate includes searching for whether the network state node has necessary vulnerabilities exploited by the threat event, and if not, the threat event success support rate is zero; If all necessary vulnerabilities are included, further search is conducted to determine whether other vulnerabilities exist, and if so, the threat event success support rate is the sum of the weights of the other vulnerabilities, and if not, the threat event success support rate is 1.
4. The method of claim 3, wherein: The calculation of the threat event concealment degree includes defining a device impact function according to the degree of detection device alarm caused by network security state change, defining a user impact function according to the degree of user awareness caused by network security state change, and defining an intrusion degree function according to the degree of intrusion caused by the threat event; When the device does not alarm or the user does not perceive, the threat event concealment degree is 1, and when the device alarms or the user perceives, the threat event concealment degree is the product of the intrusion degree and the average of the device impact and the user impact.
5. The method of claim 4, wherein: It also includes calculating the early warning success rate, defense success rate, average disposal time, and tactical decision accuracy timeliness of digital power grid network security protection based on the quantitative evaluation results, and forming a comprehensive protection performance evaluation index system.
6. A system for quantitatively evaluating the effectiveness of a digital power grid cybersecurity protection, applying the method for quantitatively evaluating the effectiveness of a digital power grid cybersecurity protection according to any one of claims 1-5. It includes: A threat situation construction module for constructing a digital power grid network threat situation deduction diagram, starting from a threat target state through a reverse construction algorithm for key devices, using a depth-first search strategy to search for intrusion paths in reverse, and starting from an initial state through a forward construction algorithm for the whole network topology, using a breadth-first search strategy to search for all potential intrusion paths of the attacker to the whole power system; A real-time analysis module for establishing a network real-time threat event stack based on the threat situation deduction diagram through a threat event real-time analysis algorithm, sequentially traversing each network real-time threat event, matching the threat events in the threat situation deduction diagram with the real-time threat events, analyzing the time and space correlation of network threats, and updating the threat state and the timestamp of the threat event; A quantitative evaluation module for establishing a multi-level quantitative evaluation system from threat events to the whole network threat situation, quantitatively evaluating threat events through four dimensions of asset value degree, threat event impact degree, threat event success support rate, and threat event concealment degree, and gradually recursively calculating threat state transition atomic sequence evaluation index, threat path evaluation index, threat target evaluation index, and whole network threat situation evaluation index based on threat event evaluation index. 7.A computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the computer device is configured to perform the method according to any one of claims 1-6 when the computer program is executed by the processor. The processor executes the computer program to realize the steps of the digital power grid network security protection performance quantitative evaluation method of any one of claims 1 to 5.
8. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to realize the steps of the digital power grid network security protection performance quantitative evaluation method of any one of claims 1 to 5.
Citation Information
Patent Citations
Network safety situation awareness method based on power CPS
CN113162930A
Network security situation prediction method based on historical alarm event times
CN117319074A