A method for host security assessment and hardening of a power monitoring system

By constructing a security coefficient library for power monitoring systems and combining it with vulnerability and suspicious risk assessments, host security hardening is implemented. This solves the problem of incomplete network security assessment in existing power monitoring systems, enabling the identification of potential risks and the detection of threats, thereby improving system security and operational efficiency.

CN121217474BActive Publication Date: 2026-04-03GANZI POWER SUPPLY CO OF STATE GRID SICHUAN ELECTRIC POWER CO
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-11-27
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing cybersecurity assessment methods for power monitoring systems rely on a single indicator, which makes it difficult to comprehensively reflect the cybersecurity status of the system and effectively identify and prevent potential security threats.

Method used

A security coefficient database for the power monitoring system is constructed. Through comprehensive assessment of vulnerability risk coefficients and suspiciousness risk coefficients, combined with similarity analysis, host security hardening measures are implemented, including disabling default accounts, installing patches, and fixing vulnerabilities.

Benefits of technology

It enables a comprehensive reflection of the network security status of the power monitoring system, timely identification of potential risks and detection of actual threats, support for post-event forensic analysis, effective prevention of attacks, and reduction of operating costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121217474B_ABST
    Figure CN121217474B_ABST
Patent Text Reader

Abstract

This invention relates to the field of host security assessment technology for power monitoring systems, and discloses a method for host security assessment and hardening of power monitoring systems. Based on a security coefficient library, this method constructs vulnerability risk coefficients and suspicious risk coefficients for the current host security. By constructing these coefficients, the method can promptly detect anomalies and record attacker activity through log storage, supporting post-event forensic analysis. By using two different coefficients to consider risks from different directions, a dual risk assessment mechanism is achieved. The vulnerability risk coefficient focuses on inherent system security weaknesses, while the suspicious risk coefficient focuses on ongoing abnormal behavior. This achieves the effect of both identifying potential risks and detecting actual threats, comprehensively reflecting the network security status of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of host security assessment technology for power monitoring systems, specifically a method for host security assessment and hardening of power monitoring systems. Background Technology

[0002] Power monitoring systems, with computers, communication equipment, and measurement and control units as their basic components, provide a fundamental platform for real-time data acquisition, switch status detection, and remote control of power distribution systems. They can be combined with detection and control equipment to form arbitrarily complex monitoring systems, playing a core role in power distribution monitoring. This helps enterprises eliminate data silos, reduce operating costs, improve production efficiency, and accelerate response times during power distribution anomalies. To ensure the safe and stable operation of the power system, it is necessary to ensure the security of the substation power monitoring system network, prevent attacks on the monitoring system network, and effectively assess its security level.

[0003] The concept of network security situational awareness was first proposed by Tim Bass in 1999. He pointed out that "next-generation network intrusion detection systems should integrate data collected from a large number of heterogeneous distributed network sensors to achieve situational awareness in cyberspace." Network security situational awareness involves extracting security factors that may affect changes in network security situation within a specific network environment, and then analyzing and visualizing this information to predict potential trends. Network security situational awareness is a macro-level concept that emphasizes the overall state and development trend of a network environment. It uses data fusion technology to integrate various available security factor information to generate a comprehensive and holistic mapping of network security situational awareness.

[0004] With the increasing application of power monitoring systems in the power industry, cybersecurity issues have become increasingly serious. Existing cybersecurity assessment methods for power monitoring systems often rely on single assessment indicators or technologies, making it difficult to comprehensively reflect the system's cybersecurity status and thus unable to effectively identify and prevent potential security threats. Summary of the Invention

[0005] To address the shortcomings of existing technologies, this invention provides a method for host security assessment and hardening of a power monitoring system, which has the advantages of comprehensively reflecting the security status of the host and solves the aforementioned technical problems.

[0006] To achieve the above objectives, the present invention provides the following technical solution: a method for host security assessment and hardening of a power monitoring system, comprising the following steps:

[0007] S1: Collect the current security coefficient of the power monitoring system host and build a power monitoring system security coefficient library;

[0008] S2: Construct vulnerability risk coefficients and suspicious risk coefficients for the current host security based on the security coefficient library;

[0009] S3: Construct an evaluation coefficient based on the vulnerability risk coefficient and suspiciousness risk coefficient of the current host security. When the evaluation coefficient exceeds the set threshold or the current host is detected to be under attack, issue an early warning command. If the evaluation coefficient does not exceed the set threshold, no early warning is issued, and the process jumps to S1 in the next sampling period.

[0010] S4: After the warning instruction is issued, the dispatcher strengthens the current host and issues a similarity analysis instruction, then executes S5.

[0011] S5: Analyze the similarity coefficients of all hosts of the same type as the current host and simultaneously harden them based on the similarity coefficients.

[0012] As a preferred technical solution of the present invention, the vulnerability risk coefficient of the current host security is constructed in S2. The specific expression is as follows:

[0013]

[0014] in, This indicates the vulnerability risk coefficient of the current host security. This indicates the impact factor of the current host vulnerability. This indicates the current port openness factor of the host. This indicates the password strength of the current host account.

[0015] As a preferred technical solution of the present invention, the vulnerability impact coefficient The specific expression is as follows:

[0016]

[0017] in, This represents the current vulnerability assessment value of the host. The maximum value, This indicates the maximum assessed vulnerability value of the host when it was attacked in the past. This represents the average vulnerability assessment value of the host when it was attacked in the past.

[0018] As a preferred technical solution of the present invention, the evaluation value of the current host vulnerability The specific expression is as follows:

[0019]

[0020] in, This represents the average time for patching historical vulnerabilities on the current host. Indicates the current host's number Each vulnerability receives a CVSS score. Indicates the current host's number Time taken to discover a vulnerability.

[0021] As a preferred technical solution of the present invention, the port open coefficient The specific expression is as follows:

[0022]

[0023] in, This indicates the total number of ports on the current host. This represents the average number of open ports across all hosts. This indicates the total number of open ports on the current host.

[0024] The current host account password strength The specific values ​​were obtained by calculating using the Shannon entropy formula.

[0025] As a preferred technical solution of the present invention, the current host suspicion risk coefficient is constructed in S2. The specific expression is as follows:

[0026]

[0027] in, This indicates the current host's suspiciousness risk coefficient. This represents the abnormal fluctuation coefficient of the current host network traffic. This indicates the abnormal fluctuation coefficient of the current host log.

[0028] As a preferred embodiment of the present invention, the abnormal fluctuation coefficient of the current host network traffic The specific expression is as follows:

[0029]

[0030] in, Indicates the sampling duration. This indicates the duration of fluctuation, which is the difference between the time when the fluctuation exceeds the normal range and the time when it returns to the normal range. Indicates the number of abnormal connections. Indicates a fixed constant;

[0031] The current host log abnormal fluctuation coefficient The specific expression is as follows:

[0032]

[0033] in, Indicates the total number of log operations. This indicates the number of log exceptions.

[0034] As a preferred technical solution of the present invention, the vulnerability risk coefficient based on the current host security in S3 and the coefficient of doubt The specific expression for constructing the comprehensive evaluation coefficient is as follows:

[0035]

[0036] in, and These represent the weight coefficients that sum to 1. This indicates the vulnerability risk coefficient of the current host security. This indicates the current host's suspiciousness risk coefficient. This represents the evaluation coefficient.

[0037] As a preferred technical solution of the present invention, when the evaluation coefficient Exceeding the set threshold Alternatively, when an attack is detected on the current host, an early warning command is issued, which includes a distinguishing evaluation coefficient. Exceeding the set threshold And detect characters that indicate the current host is under attack. ,like , then represents the evaluation coefficient. Exceeding the set threshold ,like A value of 0 indicates that the current host is under attack. If the evaluation coefficient is... Not exceeding the set threshold Or, if an attack on the current host is not detected, no warning will be issued;

[0038] The specific expression for analyzing the similarity coefficient between the current host and all hosts of the same type as the current host in S5 is as follows:

[0039]

[0040] in, Indicates the first One similarity metric, Let represent the similarity coefficient between the j-th host and the current host. This indicates that the similarity index is summed.

[0041] As a preferred technical solution of the present invention, the specific process of the dispatcher hardening the current host in S4 is as follows: when At the same time, disable the default account and test account, install emergency security patches, prioritize fixing the top K vulnerabilities, and shorten the sampling time by 10% to 30%;

[0042] when At 0:00, save the system log and process list, back up the current state, and send a rollback request to the administrator;

[0043] The specific steps for synchronous reinforcement based on the similarity coefficient in S5 are as follows: when The operation is not performed at this time;

[0044] when 0, if the similarity coefficient between the j-th host and the current host is 0. If the threshold is exceeded, the current host's hardening method will be fully synchronized. If the similarity coefficient between the j-th host and the current host is... If the threshold is not exceeded, the vulnerability is checked, and the sampling time is reset after the check is completed to proceed to the next round of sampling.

[0045] Compared with the prior art, the present invention provides a method for host security assessment and hardening of a power monitoring system, which has the following beneficial effects:

[0046] This invention constructs vulnerability risk coefficients and suspiciousness risk coefficients for the current host security. When anomalies occur, they can be promptly detected. At the same time, the logging can record the attacker's operation traces, supporting post-event forensic analysis. By using two different coefficients to consider risk situations from different directions, a dual risk assessment mechanism is achieved. The vulnerability risk coefficient focuses on the inherent security weaknesses of the system, while the suspiciousness risk coefficient focuses on the abnormal behavior that is currently occurring. This achieves the effect of both identifying potential risks and detecting actual threats, comprehensively reflecting the network security status of the system. Attached Figure Description

[0047] Figure 1 This is a schematic diagram of the process of the present invention. Detailed Implementation

[0048] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0049] Please see Figure 1 A method for host security assessment and hardening of a power monitoring system, comprising the following steps:

[0050] S1: Collect the current security coefficient of the power monitoring system host and build a power monitoring system security coefficient library;

[0051] S2: Construct vulnerability risk coefficients and suspicious risk coefficients for the current host security based on the security coefficient library;

[0052] Retrieves the current host vulnerability assessment value from the power monitoring system security coefficient database. maximum value The maximum assessed value of the vulnerability of the host when the historical host was attacked. The average value of the vulnerability assessment of the corresponding host when the host was attacked in the past. Construct the vulnerability impact coefficient The specific expression is as follows:

[0053] ;

[0054] The number of vulnerabilities is an objective entity that is easy to count and verify. Measuring it based on the maximum value of the vulnerability assessment of the corresponding host when the host was attacked in history can ensure a clear causal relationship with security risks. Known vulnerabilities are the most frequently used entry points by attackers.

[0055] Read the average historical vulnerability remediation time of the current host from the power monitoring system security coefficient database. The current host is number CVSS score for each vulnerability The current host is number Time required to discover each vulnerability and the current host vulnerability assessment value. The specific expression is as follows:

[0056] ;

[0057] Based on the current total number of host ports Average number of open ports on all hosts Total number of open ports on the current host Port openness coefficient The specific expression is as follows:

[0058] ;

[0059] The open ports of a host directly reflect the network exposure of the system and are a core indicator for attack surface management. The results can be obtained quickly through port scanning, and corresponding data can be obtained quickly during sampling. Once a risk is discovered, clear measures such as closing ports and restricting access can be taken directly.

[0060] Current host account password strength The specific values ​​were obtained by calculating using the Shannon entropy formula. Strengthening password policies can effectively prevent common attacks such as brute-force attacks and password guessing. By upgrading or changing passwords, the cost of implementing password policies is much lower than other security measures.

[0061] Based on this, a vulnerability risk coefficient for current host security is constructed. The specific expression is as follows:

[0062]

[0063] in, This indicates the vulnerability risk coefficient of the current host security. This indicates the impact factor of the current host vulnerability. This indicates the current port openness factor of the host. Indicates the current host account password strength;

[0064] Sampling time based on the safety factor library of the power monitoring system Fluctuation duration The fluctuation duration is the difference between the time when the fluctuation exceeds the normal range and the time when it returns to the normal range, and the number of abnormal connections. Construct the abnormal fluctuation coefficient of the current host network traffic. The specific expression is as follows:

[0065]

[0066] in, Indicates the sampling duration. This indicates the duration of fluctuation, which is the difference between the time when the fluctuation exceeds the normal range and the time when it returns to the normal range. Indicates the number of abnormal connections. This represents a fixed constant, taken as 50. By observing the fluctuation state, anomalies can be detected in the early stages of an attack, enabling early warning.

[0067] Construct the abnormal fluctuation coefficient of the current host log The specific expression is as follows:

[0068]

[0069] in, Indicates the total number of log operations. It indicates the number of log anomalies, and for log fluctuations, it is relatively real-time. When an anomaly occurs, it can be issued in a timely manner. It is essentially based on actual security events, with a relatively low false alarm rate. At the same time, the storage of logs can record the attacker's operation traces and support post-event forensic analysis.

[0070] Based on this, a current host suspicion risk coefficient is constructed. The specific expression is as follows:

[0071]

[0072] in, This indicates the current host's suspiciousness risk coefficient. This represents the abnormal fluctuation coefficient of the current host network traffic. This represents the abnormal fluctuation coefficient of the current host log. The above process enables all factors to be quantified into numerical values, providing a data-driven decision-making basis for risk assessment and security hardening.

[0073] S3: Construct an evaluation coefficient based on the vulnerability risk coefficient and suspiciousness risk coefficient of the current host security. When the evaluation coefficient exceeds the set threshold or the current host is detected to be under attack, issue an early warning command. If the evaluation coefficient does not exceed the set threshold, no early warning is issued, and the process jumps to S1 in the next sampling period.

[0074] Vulnerability risk coefficient based on current host security in S3 and the coefficient of doubt The specific expression for constructing the comprehensive evaluation coefficient is as follows:

[0075]

[0076] in, and These represent the weight coefficients that sum to 1. This indicates the vulnerability risk coefficient of the current host security. This indicates the current host's suspiciousness risk coefficient. Indicates the evaluation coefficient;

[0077] When the evaluation coefficient Exceeding the set threshold Alternatively, when an attack is detected on the current host, an early warning command is issued, which includes a distinguishing evaluation coefficient. Exceeding the set threshold And detect characters that indicate the current host is under attack. ,like , then represents the evaluation coefficient. Exceeding the set threshold ,like A value of 0 indicates that the current host is under attack. The process for detecting an attack on the current host is fairly standard and will not be elaborated upon here. When the evaluation coefficient... Exceeding the set threshold When the detection of an attack on the current host occurs simultaneously, set 0, if the evaluation coefficient Not exceeding the set threshold Or, if an attack on the current host is not detected, no warning will be issued;

[0078] S4: After the warning instruction is issued, the dispatcher strengthens the current host and issues a similarity analysis instruction, then executes S5.

[0079] The specific process by which dispatchers in S4 harden the current host is as follows: When At that time, disable the default account and test account, install emergency security patches, prioritize fixing the top K=3 vulnerabilities, and shorten the sampling time by 10%~30%. When =1, it indicates that the host is in a high-risk state but has not yet been attacked. Therefore, preventive hardening measures (such as patching and fixing vulnerabilities) are taken to reduce the risk. By shortening the sampling time, the monitoring frequency of the current host is increased, thereby discovering potential problems more quickly.

[0080] when At 0:00, save the system logs and process list, back up the current state, and send a rollback request to the administrator, indicating that an attack has been detected. Therefore, emergency response measures (such as saving logs, backing up the state, and requesting a rollback) are taken to quickly restore the system and reduce losses. Operators in this field can use similar methods and are not limited to a single technical means to reduce losses. Multiple methods can be used in combination. The security state of similar hosts can be quickly restored through a fully synchronous hardening method (i.e., rollback), while vulnerability verification and reset sampling are performed on dissimilar hosts, which ensures security and avoids overreaction.

[0081] S5: Analyze the similarity coefficients of all hosts of the same type as the current host and strengthen them simultaneously based on the similarity coefficients;

[0082] The specific expression for analyzing the similarity coefficient between the current host and all hosts of the same type as the current host in S5 is as follows:

[0083]

[0084] in, Indicates the first One similarity metric, Let represent the similarity coefficient between the j-th host and the current host. This indicates that the similarity index is summed. See Table 1 below for specific indices:

[0085] Table 1

[0086] The content in Table 1 is for reference only. Those skilled in the art may add or delete it, or use indicators obtained by other means, as long as the trends among multiple indicators are the same.

[0087] The specific steps for synchronous reinforcement in S5 based on the similarity coefficient are as follows: When Instead of immediately taking action on similar hosts, we only harden the current host and do not immediately take action on similar hosts. This is because the current host is only at high risk, but has not actually been attacked. Therefore, there is no need to expand the scope immediately to avoid unnecessary resource consumption.

[0088] when 0, if the similarity coefficient between the j-th host and the current host is 0. If the threshold is exceeded, the current host's hardening method will be fully synchronized. If the similarity coefficient between the j-th host and the current host is... If the threshold is not exceeded, the vulnerability is verified, and the sampling time is reset after verification for the next round of sampling. Since an attack has already occurred, synchronization operations need to be performed on similar hosts immediately to prevent the attack from spreading. At the same time, different measures are taken according to the similarity coefficient (full synchronization or only vulnerability verification), which achieves reasonable allocation of resources. Through similarity analysis, the defense measures are extended to other hosts that may face the same attack risk, effectively controlling the spread of risk.

[0089] Example 1:

[0090] For specific parameters in this embodiment, please refer to Table 2 below:

[0091] Table 2

[0092] In this embodiment 0.7775 is greater than 0.72;

[0093] And no attack was detected on the current host, so set at this time At this point, the operator can change the default settings and choose not to perform the analysis of the similarity coefficients between the current host and all hosts of the same type as the current host in S5. The current host is only at high risk, but has not actually been attacked, so there is no need to expand the scope immediately to avoid unnecessary resource consumption.

[0094] Example 2:

[0095] The specific parameters in this embodiment are shown in Table 3 below:

[0096] Table 3

[0097] In this embodiment 0.2904 is less than 0.72;

[0098] At this time, it was detected that the current host was under attack. 0. In this embodiment, the system log and process list are saved, the current state is backed up, and a rollback request is sent to the administrator.

[0099] For the top 3 similarity rankings, please refer to Table 4 below:

[0100] Table 4

[0101] At this time, for The host will then be completely synchronized with the current host's hardening method.

[0102] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A method for host security assessment and hardening of a power monitoring system, characterized in that: Includes the following steps: S1: Collect the current security coefficient of the power monitoring system host and build a power monitoring system security coefficient library; S2: Construct the vulnerability risk coefficient and suspiciousness risk coefficient of the current host security based on the security coefficient library. The specific expressions are as follows: in, This indicates the vulnerability risk coefficient of the current host security. This indicates the impact factor of the current host vulnerability. This indicates the current port openness factor of the host. Indicates the current host account password strength; The vulnerability impact coefficient The specific expression is as follows: in, This represents the current vulnerability assessment value of the host. The maximum value, This indicates the maximum assessed vulnerability value of the host when it was attacked in the past. This represents the average vulnerability assessment value of the host when it was attacked in the past. The current host vulnerability assessment value The specific expression is as follows: in, This represents the average time for patching historical vulnerabilities on the current host. Indicates the current host's number Each vulnerability receives a CVSS score. Indicates the current host's number Time taken to discover each vulnerability; The port open coefficient The specific expression is as follows: in, This indicates the total number of ports on the current host. This represents the average number of open ports across all hosts. This indicates the total number of open ports on the current host; the password strength of the current host account. The specific values ​​were obtained by calculating using the Shannon entropy formula. S3: Construct an evaluation coefficient based on the vulnerability risk coefficient and suspiciousness risk coefficient of the current host security. When the evaluation coefficient exceeds the set threshold or the current host is detected to be under attack, issue an early warning command. If the evaluation coefficient does not exceed the set threshold, no early warning is issued, and the process jumps to S1 in the next sampling period. S4: After the warning instruction is issued, the dispatcher strengthens the current host and issues a similarity analysis instruction, then executes S5. S5: Analyze the similarity coefficients of all hosts of the same type as the current host and simultaneously harden them based on the similarity coefficients.

2. The method for host security assessment and hardening of a power monitoring system according to claim 1, characterized in that: The current host suspiciousness risk coefficient is constructed in S2. The specific expression is as follows: in, This indicates the current host's suspiciousness risk coefficient. This represents the abnormal fluctuation coefficient of the current host network traffic. This indicates the abnormal fluctuation coefficient of the current host log.

3. The method for host security assessment and hardening of a power monitoring system according to claim 2, characterized in that: The abnormal fluctuation coefficient of the current host network traffic The specific expression is as follows: in, Indicates the sampling duration. This indicates the duration of fluctuation, which is the difference between the time when the fluctuation exceeds the normal range and the time when it returns to the normal range. Indicates the number of abnormal connections. Represents a fixed constant; the abnormal fluctuation coefficient of the current host log. The specific expression is as follows: in, Indicates the total number of log operations. This indicates the number of log exceptions.

4. The method for host security assessment and hardening of a power monitoring system according to claim 3, characterized in that: The vulnerability risk coefficient based on the current host security in S3 and the coefficient of doubt The specific expression for constructing the comprehensive evaluation coefficient is as follows: in, and These represent the weight coefficients that sum to 1. This indicates the vulnerability risk coefficient of the current host security. This indicates the current host's suspiciousness risk coefficient. This represents the evaluation coefficient.

5. The method for host security assessment and hardening of a power monitoring system according to claim 4, characterized in that: When the evaluation coefficient Exceeding the set threshold Alternatively, when an attack is detected on the current host, an early warning command is issued, which includes a distinguishing evaluation coefficient. Exceeding the set threshold And detect characters that indicate the current host is under attack. ,like , then represents the evaluation coefficient. Exceeding the set threshold ,like If the evaluation coefficient is 0, it indicates that the current host is under attack. Not exceeding the set threshold Or, if an attack is not detected on the current host, no warning will be issued; The specific expression for analyzing the similarity coefficient between the current host and all hosts of the same type as the current host in S5 is as follows: in, Indicates the first One similarity metric, Indicates the first The similarity coefficient between each host and the current host. This indicates that the similarity index is summed.

6. The method for host security assessment and hardening of a power monitoring system according to claim 5, characterized in that: The specific process by which the dispatcher strengthens the current host in S4 is as follows: When At that time, disable the default account and test account, install emergency security patches, and target the top-ranked accounts. These vulnerabilities will be prioritized for remediation, and sampling time will be reduced by 10% to 30%. when At that time, save the system log and process list, back up the current state, and send a rollback request to the administrator; The specific steps for synchronous reinforcement based on the similarity coefficient in S5 are as follows: when The operation is not performed at this time; when If the first Similarity coefficient between each host and the current host If the threshold is exceeded, the current host's hardening method will be fully synchronized. Similarity coefficient between each host and the current host If the threshold is not exceeded, the vulnerability is checked, and the sampling time is reset after the check is completed to proceed to the next round of sampling.

Citation Information

Patent Citations

  • Network situation assessment method based on data mining

    CN113064932A

  • Automatic evaluation and reinforcement processing method, system and equipment for security configuration of service interface and storage medium

    CN119814406A