Power plant network security vulnerability monitoring and protection system

By constructing a dynamic protection system in the power plant network using chaotic synchronization theory and Lyapunov stability theory, the problems of unified management and real-time monitoring in power plant network security protection are solved, and efficient identification and protection against complex network threats are achieved.

CN121262003APending Publication Date: 2026-01-02SHENHUA SHENDONG POWER XINJIANG ZHUNDONG WUCAIWAN POWER GENERA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511754270.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-26
Publication Date
2026-01-02

AI Technical Summary

Technical Problem

Existing power plant network security protection technologies are insufficient to achieve unified management and monitoring of various devices and systems in industrial control networks, cannot promptly detect and address potential security risks, and traditional protection technologies cannot cope with increasingly complex network attacks.

Method used

A dynamic behavior feature library is constructed using chaotic synchronization theory. By collecting network communication data under normal operating conditions, a network behavior benchmark reference system is established. Network traffic anomalies are monitored and analyzed in real time. The system security status is evaluated by combining Lyapunov stability theory, protection strategy adjustment instructions are generated, and the protection rules of boundary protection devices and host protection systems are dynamically updated.

Benefits of technology

It enables real-time monitoring and dynamic protection of power plant networks, improves the accuracy of identifying new types of network attacks, reduces false alarms and false negatives, enhances the overall protection capability of the system, and ensures that security protection measures at different levels work together.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121262003A_ABST
    Figure CN121262003A_ABST
Patent Text Reader

Abstract

The invention relates to the field of monitoring and protection, and discloses a power plant network security vulnerability monitoring and protection system which is used for providing a solution for power plant network security protection. Comprising the steps of establishing an industrial control network flow dynamic reference model, constructing a dynamic behavior feature library, performing chaos synchronous contrastive analysis, generating a network behavior deviation index, performing multi-scale decomposition and abnormal mode recognition, obtaining a network security threat level evaluation result, calculating a system security stability index according to the result, and generating a protection strategy adjustment instruction. The method comprises the following steps: synchronously updating protection rules, forming a closed loop, collecting protection effect feedback data, generating an evaluation report through multi-dimensional analysis, reconstructing parameters in combination with a threat situation, generating a self-adaptive parameter adjustment strategy, feeding back and updating, and forming a dynamic protection system. The real-time performance and adaptability of power plant network security protection are effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of monitoring and protection, and in particular to a network security vulnerability monitoring and protection system for power plants. Background Technology

[0002] With the acceleration of industrial informatization, power plants, as critical infrastructure, face increasingly severe cybersecurity challenges. Power plant industrial control systems undertake core tasks such as power production, transmission, and distribution, heavily relying on network communication for collaborative control and data exchange between devices. However, the increasing openness and complexity of industrial control network environments have led to frequent cybersecurity vulnerabilities in power plants. Malicious attacks or data breaches could not only disrupt power supply and cause widespread blackouts, but also severely impact national energy security, social stability, and people's lives.

[0003] Currently, power plant network security protection mainly relies on traditional security protection technologies. These technologies can resist some network attacks to a certain extent, but as attack methods continue to evolve and become more complex, their limitations are becoming increasingly apparent.

[0004] Furthermore, the power plant's industrial control network contains a wide variety of equipment and complex communication protocols, resulting in poor compatibility and interoperability between different devices and systems. This poses a significant challenge to network security. Existing security technologies struggle to achieve unified management and monitoring of various devices and systems within the industrial control network, and are unable to promptly detect and address potential security vulnerabilities.

[0005] Therefore, we propose a power plant network security vulnerability monitoring and protection system to solve the above problems. Summary of the Invention

[0006] This invention provides a power plant network security vulnerability monitoring and protection system, which provides a solution for power plant network security protection.

[0007] The first aspect of this invention provides a power plant network security vulnerability monitoring and protection system, comprising: a data acquisition module for establishing a dynamic benchmark model of industrial control network traffic, constructing a dynamic behavior feature library by collecting network communication data under normal operating conditions, and forming a network behavior benchmark reference system product; a comparison module for performing chaotic synchronous comparison analysis between current network traffic data and the network behavior benchmark reference system product, generating a network behavior deviation index product; an identification module for analyzing abnormal network traffic characteristics, performing multi-scale decomposition and abnormal pattern identification on the network behavior deviation index product, and generating a network security threat level assessment result product; an evaluation module for calculating a system security stability index and generating a protection strategy adjustment instruction product based on the network behavior deviation index product and the network security threat level assessment result product; and an update module for synchronously updating the protection rules of boundary protection devices, host protection systems, and centralized monitoring platforms according to the protection strategy adjustment instruction product, forming a closed-loop protection system.

[0008] Optionally, in a first implementation of the first aspect of the present invention, the method includes: collecting network communication data under normal operating conditions, including protocol instruction sequences, communication timing characteristics, and traffic amplitude variation data, to form a benchmark dataset product; constructing a chaotic attractor state space based on the benchmark dataset product, mapping the network communication data to trajectory points in the state space, to form a chaotic attractor state space product; determining the coupling strength and feedback gain parameters of the synchronization system based on the chaotic attractor state space product, to form a synchronization mechanism configuration parameter product; and calculating the synchronization error threshold and dynamic behavior boundary of network traffic under normal operating conditions based on the synchronization mechanism configuration parameter product, to generate a network behavior benchmark reference system product.

[0009] Optionally, in a second implementation of the first aspect of the present invention, the method includes: real-time acquisition of current network traffic data, extraction of protocol instruction sequences, communication timing characteristics, and traffic amplitude change data to form a real-time network feature sequence product; mapping the real-time network feature sequence product to a real-time state trajectory based on the network behavior benchmark reference system product to generate a real-time state trajectory product; constructing a real-time drive response synchronization system based on the network behavior benchmark reference system product, synchronizing and comparing the real-time state trajectory product with the benchmark state trajectory to generate a synchronization error sequence product; performing multi-dimensional statistical analysis on the synchronization error sequence product, calculating error statistical characteristic values, and generating a network behavior deviation index product.

[0010] Optionally, in the third implementation of the first aspect of the present invention, based on the synchronization error sequence product, the mean, variance, and extreme value features of the error are extracted to form a basic error statistical feature product; the basic error statistical feature product is subjected to time-domain analysis to calculate the error trend change rate and fluctuation frequency features, generating an error dynamic feature product; based on the error dynamic feature product, combined with the synchronization error threshold in the network behavior benchmark reference system product, the relative deviation and abnormal cumulative effect are calculated to generate a composite deviation index product; the composite deviation index product is processed and combined with preset weight coefficients to generate a network behavior deviation index product.

[0011] Optionally, in the fourth implementation of the first aspect of the present invention, the method includes: constructing time series data based on the network behavior deviation index product; performing multi-scale decomposition on the time series to generate multi-scale feature component products; extracting abnormal patterns from the multi-scale feature component products, identifying abnormal fluctuation characteristics at each scale, and generating multi-scale abnormal pattern feature vector products; performing pattern matching analysis based on the multi-scale abnormal pattern feature vector products and a predefined threat feature library to calculate threat similarity scores and generate threat pattern matching result products; and determining the threat level based on the threat pattern matching result products and real-time network environment parameters through a dynamic threshold determination mechanism to generate network security threat level assessment result products.

[0012] Optionally, in the fifth implementation of the first aspect of the present invention, based on the multi-scale feature component products, the statistical moment features and spectral distribution features of each scale component are calculated respectively to generate multi-scale statistical feature vector products; correlation analysis is performed on the multi-scale statistical feature vector products to identify the coupling relationship and cooperative change pattern between different scales, and scale coupling feature products are generated; based on the scale coupling feature products and combined with the network behavior deviation index products, an abnormal pattern recognition matrix is ​​constructed to generate multi-scale abnormal pattern feature vector products.

[0013] Optionally, in the sixth implementation of the first aspect of the present invention, the method includes: constructing a system security state vector based on the network behavior deviation index product and the network security threat level assessment result product to form a security state space description product; calculating the stability boundary conditions of the system security state based on the security state space description product to generate a stability boundary constraint product; analyzing the changing trend of the system security state vector based on the stability boundary constraint product, calculating the Lyapunov exponent, and generating a system security stability index product; and determining the direction and intensity of the protection strategy adjustment based on the system security stability index product and the current network operating state parameters to generate a protection strategy adjustment instruction product.

[0014] Optionally, in the seventh implementation of the first aspect of the present invention, a multi-dimensional risk assessment matrix product is generated based on the system security stability index product, combined with network device load rate, business criticality level, and real-time threat intelligence data; the multi-dimensional risk assessment matrix product is prioritized to determine the priority of protection strategy adjustments for boundary protection, host protection, and centralized monitoring, generating a protection strategy priority sequence product; based on the protection strategy priority sequence product, combined with preset protection strength levels and response time requirements, a protection strategy adjustment instruction set product is generated; conflict detection and consistency verification are performed on the protection strategy adjustment instruction set product to ensure the synergy between various protection strategies, generating a protection strategy adjustment instruction product.

[0015] Optionally, in the eighth implementation of the first aspect of the present invention, the method includes: parsing the protection policy adjustment instruction product, extracting boundary protection rule parameters, host protection strength parameters, and monitoring policy parameters to generate a multi-level protection configuration parameter product; dynamically reconstructing the access control list and protocol filtering rules of the industrial firewall based on the boundary protection rule parameters in the multi-level protection configuration parameter product to generate an updated boundary protection rule set product; adjusting the process behavior monitoring strength and file access control policy of the host protection system based on the host protection strength parameters in the multi-level protection configuration parameter product to generate an adaptive host protection policy set product; and reconstructing the correlation analysis rules and alarm thresholds of the centralized monitoring platform based on the monitoring policy parameters in the multi-level protection configuration parameter product, combined with the boundary protection rule set product and the adaptive host protection policy set product, to form a closed-loop protection system.

[0016] Optionally, in the ninth implementation of the first aspect of the present invention, a dynamic module is further included: based on the closed-loop protection system, collecting protection effect feedback data, including attack blocking records, false alarm statistics, and system performance indicators, and generating a protection effect evaluation dataset product; performing multi-dimensional analysis on the protection effect evaluation dataset product, calculating protection efficiency indicators and system adaptability indicators, and generating a protection effectiveness evaluation report product; based on the protection effectiveness evaluation report product, combined with the real-time network threat situation, reconstructing the dynamic benchmark model parameters in the chaos synchronization theory and the anomaly identification threshold of fractional calculus, and generating an adaptive parameter adjustment strategy product; feeding back the adaptive parameter adjustment strategy product to dynamically update the network behavior benchmark reference system and the anomaly identification mechanism, forming a dynamic protection system.

[0017] Beneficial effects: By collecting normal operating data to build a dynamic behavior feature library and dynamically updating the network behavior benchmark reference system based on chaotic synchronization theory, it can reflect the behavior pattern of the industrial control network under normal conditions in real time. The system can automatically adjust the monitoring benchmark as the network environment changes, effectively respond to new network attacks and unknown vulnerabilities, and avoid the limitations of traditional static rule bases that cannot adapt to dynamic changes. Based on the feedback data of protection effectiveness and the real-time network threat situation, the dynamic module reconstructs the parameters of the dynamic benchmark model in the chaos synchronization theory and the anomaly identification threshold of fractional calculus, generates an adaptive parameter adjustment strategy, and feeds back and updates the network behavior benchmark reference system and anomaly identification mechanism. It can automatically optimize monitoring parameters according to the actual situation, improve the identification accuracy and protection effect of different types of network attacks. The update module parses the protection strategy adjustment instructions, extracts multi-level protection configuration parameters, and dynamically reconstructs and adjusts the boundary protection equipment, host protection system and centralized monitoring platform respectively, ensuring that the security protection measures at different levels can cooperate with each other to form multiple lines of defense and improve the overall protection capability of the system. When collecting network communication data, the system focuses on data specific to industrial control networks, such as protocol command sequences, communication timing characteristics, and traffic amplitude changes. Through in-depth analysis of this data, the system can more accurately understand the operating rules and device behavior of the industrial control network, thereby more effectively identifying anomalies and threats and reducing false alarms and missed alarms. Attached Figure Description

[0018] Figure 1 This is a schematic diagram of an embodiment of the power plant network security vulnerability monitoring and protection system according to the present invention; Figure 2 This is a schematic diagram of one embodiment of the power plant network security vulnerability monitoring and protection equipment in this invention. Detailed Implementation

[0019] This invention provides a power plant network security vulnerability monitoring and protection system, offering a solution for power plant network security protection. The terms "first," "second," "third," "fourth," etc. (if present) in the specification, claims, and accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" or "having" and any variations thereof are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or device that includes a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or devices.

[0020] For ease of understanding, the specific process of the embodiments of the present invention is described below. Please refer to [link / reference]. Figure 1 One embodiment of the power plant network security vulnerability monitoring and protection system in this invention includes: 101. Acquisition module, used to establish a dynamic benchmark model of industrial control network traffic based on chaotic synchronization theory, and to build a dynamic behavior feature library by collecting network communication data under normal operating conditions, forming a network behavior benchmark reference system product; It is understood that the executing entity of this invention can be a power plant network security vulnerability monitoring and protection device, or it can be a terminal or a server; the specific implementation is not limited here. This embodiment of the invention will be described using a server as an example.

[0021] Specifically, network communication data under normal operating conditions is collected, including protocol command sequences, communication timing characteristics, and traffic amplitude variation data, to form a benchmark dataset product; Based on the benchmark dataset product, a chaotic attractor state space is constructed, and network communication data is mapped to trajectory points in the state space to form a chaotic attractor state space product. Based on the state-space product of the chaotic attractor, a driving response synchronization system is established, the coupling strength and feedback gain parameters of the synchronization system are determined, and the configuration parameter product of the synchronization mechanism is formed. Based on the parameter output of the synchronization mechanism, calculate the synchronization error threshold and dynamic behavior boundary of network traffic under normal operating conditions, and generate the network behavior benchmark reference system output. 102. The comparison module is used to monitor network traffic in real time and calculate synchronization error. It performs chaotic synchronization comparison analysis between the current network traffic data and the network behavior benchmark reference system product to generate network behavior deviation index product. Specifically, real-time network traffic data is collected, and protocol command sequences, communication timing characteristics, and traffic amplitude change data are extracted to form real-time network characteristic sequence products; Based on the chaotic attractor state space in the network behavior benchmark reference system product, the real-time network feature sequence product is mapped to the real-time state trajectory to generate the real-time state trajectory product. Based on the synchronization mechanism configuration parameters in the network behavior benchmark reference system product, a real-time drive response synchronization system is constructed to synchronize and compare the real-time state trajectory product with the benchmark state trajectory to generate a synchronization error sequence product. Multi-dimensional statistical analysis is performed on the synchronization error sequence products to calculate the error statistical characteristic values ​​and generate network behavior deviation index products.

[0022] It should be noted that, based on the synchronization error sequence product, the mean, variance, and extreme value features of the error are extracted to form the basic error statistical feature product; time-domain analysis is performed on the basic error statistical feature product to calculate the error trend change rate and fluctuation frequency features, generating the error dynamic feature product; based on the error dynamic feature product, combined with the synchronization error threshold in the network behavior benchmark reference system product, the relative deviation and abnormal cumulative effect are calculated to generate the composite deviation index product; the composite deviation index product is normalized and combined with preset weight coefficients to generate the final network behavior deviation index product.

[0023] 103. Identification module, used to analyze network traffic anomaly characteristics using fractional calculus, perform multi-scale decomposition and anomaly pattern identification on network behavior deviation index products, and generate network security threat level assessment results. Specifically, based on the network behavior deviation index product, time series data is constructed, and fractional derivative operations are used to decompose the time series at multiple scales to generate multi-scale feature component products. Anomaly pattern extraction is performed on the multi-scale feature component products to identify anomalous fluctuation characteristics at each scale and generate multi-scale anomalous pattern feature vector products. Based on the multi-scale anomaly pattern feature vector product, combined with a predefined threat feature library, pattern matching analysis is performed to calculate the threat similarity score and generate threat pattern matching result products. Based on the threat pattern matching results and combined with real-time network environment parameters, the threat level is determined through a dynamic threshold determination mechanism, generating a network security threat level assessment result.

[0024] It should be noted that, based on the multi-scale feature component products, the statistical moment characteristics and spectral distribution characteristics of each scale component are calculated to generate multi-scale statistical feature vector products; correlation analysis is performed on the multi-scale statistical feature vector products to identify the coupling relationship and cooperative change pattern between different scales, generating scale coupling feature products; based on the scale coupling feature products, combined with the network behavior deviation index products, an anomaly pattern recognition matrix is ​​constructed to generate multi-scale anomaly pattern feature vector products.

[0025] 104. Evaluation module, used to evaluate the system security status by combining Lyapunov stability theory, calculate the system security stability index and generate protection strategy adjustment instruction products based on network behavior deviation index product and network security threat level evaluation result product; Specifically, based on the network behavior deviation index product and the network security threat level assessment product, a system security state vector is constructed to form a security state space description product; Based on the product of the safety state space description, a Lyapunov function is constructed to calculate the stability boundary conditions of the system's safety state and generate the product of the stability boundary constraints. Based on the stability boundary constraint products, analyze the changing trend of the system's safety state vector, calculate the Lyapunov exponent, and generate the system's safety stability index products. Based on the system security stability index product and combined with the current network operating status parameters, the direction and intensity of the protection strategy adjustment are determined, and the protection strategy adjustment instruction product is generated.

[0026] It should be noted that, based on the system security stability index product, combined with network device load rate, business criticality level, and real-time threat intelligence data, a multi-dimensional risk assessment matrix product is generated; the multi-dimensional risk assessment matrix product is prioritized to determine the adjustment priority of protection strategies for boundary protection, host protection, and centralized monitoring, generating a protection strategy priority sequence product; based on the protection strategy priority sequence product, combined with preset protection strength levels and response time requirements, a protection strategy adjustment instruction set product is generated; conflict detection and consistency verification are performed on the protection strategy adjustment instruction set product to ensure the synergy between various protection strategies, generating the final protection strategy adjustment instruction product.

[0027] 105. Update module, used to implement dynamic adaptive protection strategy adjustment, synchronously update the protection rules of boundary protection equipment, host protection system and centralized monitoring platform according to the protection strategy adjustment instruction output, forming a closed-loop protection system; Specifically, the protection strategy adjustment instruction product is parsed, and boundary protection rule parameters, host protection strength parameters and monitoring strategy parameters are extracted to generate multi-level protection configuration parameter products. Based on the boundary protection rule parameters in the multi-level protection configuration parameter product, the access control list and protocol filtering rules of the industrial firewall are dynamically reconstructed to generate an updated boundary protection rule set product. Based on the host protection strength parameters in the multi-level protection configuration parameter product, the process behavior monitoring strength and file access control policy of the host protection system are adjusted to generate an adaptive host protection policy set product. Based on the monitoring strategy parameters in the multi-level protection configuration parameter product, combined with the boundary protection rule set product and the adaptive host protection strategy set product, the correlation analysis rules and alarm thresholds of the centralized monitoring platform are reconstructed to form a closed-loop protection system product.

[0028] 106. Dynamic module, used to collect protection effect feedback data based on the closed-loop protection system product, including attack blocking records, false alarm statistics and system performance indicators, and generate protection effect evaluation dataset product; Multi-dimensional analysis is performed on the protective effect assessment dataset to calculate the protective efficiency index and system adaptability index, and a protective effectiveness assessment report is generated. Based on the protection effectiveness assessment report, combined with the real-time network threat situation, the dynamic benchmark model parameters and the anomaly identification threshold of fractional calculus in the chaos synchronization theory are reconstructed to generate an adaptive parameter adjustment strategy product. The adaptive parameter adjustment strategy output is fed back to dynamically update the network behavior benchmark and anomaly identification mechanism, forming a dynamic protection system.

[0029] In this embodiment of the invention, the acquisition module constructs a network behavior benchmark reference system based on chaotic synchronization theory; the comparison module monitors and calculates synchronization errors in real time to generate a network behavior deviation index; the identification module uses fractional calculus to analyze anomalies and assess the threat level; the evaluation module calculates the system security stability index and generates protection strategy adjustment instructions based on Lyapunov stability theory; the update module updates the protection rules according to the instructions to form a closed loop; and the dynamic module collects feedback data, generates adaptive parameter adjustment strategies, and provides feedback updates to form a dynamic protection system.

[0030] Based on chaotic synchronization theory and fractional calculus, benchmarks can be established more accurately and anomalies can be identified, effectively improving the monitoring capabilities for power plant network security vulnerabilities. By combining Lyapunov stability theory to assess the system's security status, threat level assessment and security stability calculations become more scientific and reasonable. Through dynamic modules, a dynamic protection system is formed, which can adaptively adjust according to real-time network conditions, improving the timeliness and effectiveness of protection and enhancing the system's ability to respond to complex network threats.

[0031] Figure 2 This is a schematic diagram of the structure of a power plant network security vulnerability monitoring and protection device 200 provided in an embodiment of the present invention. The power plant network security vulnerability monitoring and protection device 200 can vary significantly due to different configurations or performance. It may include one or more central processing units (CPUs) 210 (e.g., one or more processors) and a memory 220, and one or more storage media 230 (e.g., one or more mass storage devices) for storing application programs 233 or data 232. The memory 220 and storage media 230 can be temporary or persistent storage. The program stored in the storage media 230 may include one or more modules (not shown in the diagram), each module may include a series of instruction operations on the power plant network security vulnerability monitoring and protection device 200. Furthermore, the processor 210 may be configured to communicate with the storage media 230 and execute the series of instruction operations in the storage media 230 on the power plant network security vulnerability monitoring and protection device 200.

[0032] The power plant network security vulnerability monitoring and protection equipment 200 may also include one or more power supplies 240, one or more wired or wireless network interfaces 250, one or more input / output interfaces 260, and / or one or more operating systems 231, such as Windows Server, Mac OS X, Unix, Linux, FreeBSD, etc. Those skilled in the art will understand that... Figure 2 The illustrated structure of the power plant network security vulnerability monitoring and protection equipment does not constitute a limitation on the power plant network security vulnerability monitoring and protection equipment. It may include more or fewer components than illustrated, or combine certain components, or have different component arrangements.

[0033] The present invention also provides a power plant network security vulnerability monitoring and protection device, which includes a memory and a processor. The memory stores computer-readable instructions. When the computer-readable instructions are executed by the processor, the processor performs the steps of the power plant network security vulnerability monitoring and protection system in the above embodiments.

[0034] The present invention also provides a computer-readable storage medium, which can be a non-volatile computer-readable storage medium or a volatile computer-readable storage medium, wherein the computer-readable storage medium stores instructions that, when the instructions are executed on a computer, cause the computer to perform the steps of the power plant network security vulnerability monitoring and protection system.

[0035] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0036] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0037] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A power plant network security vulnerability monitoring and protection system, characterized in that, The power plant network security vulnerability monitoring and protection system includes: The data acquisition module is used to establish a dynamic benchmark model of industrial control network traffic. It constructs a dynamic behavior feature library by collecting network communication data under normal operating conditions, and forms a network behavior benchmark reference system product. The comparison module is used to perform chaotic synchronous comparison analysis between the current network traffic data and the product of the network behavior benchmark reference system, and generate a network behavior deviation index product. The identification module is used to analyze abnormal network traffic characteristics, perform multi-scale decomposition and abnormal pattern identification on the network behavior deviation index product, and generate network security threat level assessment results. The evaluation module is used to calculate the system security stability index and generate protection strategy adjustment instruction products based on the network behavior deviation index product and the network security threat level evaluation result product; The update module is used to synchronously update the protection rules of the boundary protection equipment, host protection system and centralized monitoring platform according to the protection strategy adjustment instruction product, so as to form a closed-loop protection system.

2. The power plant network security vulnerability monitoring and protection system according to claim 1, characterized in that, include: Collect network communication data under normal operating conditions, including protocol command sequences, communication timing characteristics, and traffic amplitude variation data, to form a benchmark dataset product; Based on the benchmark dataset product, a chaotic attractor state space is constructed, and network communication data is mapped to trajectory points in the state space to form a chaotic attractor state space product. Based on the state-space product of the chaotic attractor, the coupling strength and feedback gain parameters of the synchronization system are determined, and the configuration parameter product of the synchronization mechanism is formed. Based on the parameter output of the synchronization mechanism, the synchronization error threshold and dynamic behavior boundary of network traffic under normal operating conditions are calculated, and a network behavior benchmark reference system is generated.

3. The power plant network security vulnerability monitoring and protection system according to claim 1, characterized in that, include: Real-time collection of current network traffic data, extraction of protocol instruction sequences, communication timing characteristics and traffic amplitude change data, forming real-time network characteristic sequence products; Based on the network behavior benchmark reference system product, the real-time network feature sequence product is mapped to the real-time state trajectory to generate the real-time state trajectory product. Based on the network behavior benchmark reference system product, a real-time drive response synchronization system is constructed, and the real-time state trajectory product is synchronously compared with the benchmark state trajectory to generate a synchronization error sequence product. Multi-dimensional statistical analysis is performed on the synchronization error sequence products to calculate the error statistical characteristic values ​​and generate network behavior deviation index products.

4. The power plant network security vulnerability monitoring and protection system according to claim 3, characterized in that, Based on the synchronization error sequence products, the error mean, variance and extreme value features are extracted to form the basic error statistical feature products; Time-domain analysis is performed on the basic error statistical characteristic products to calculate the error trend change rate and fluctuation frequency characteristics, and to generate dynamic error characteristic products. Based on the error dynamic feature product, combined with the synchronization error threshold in the network behavior benchmark reference system product, the relative deviation and abnormal cumulative effect are calculated to generate a composite deviation index product. The composite deviation index product is processed and combined with preset weight coefficients to generate the network behavior deviation index product.

5. The power plant network security vulnerability monitoring and protection system according to claim 1, characterized in that, include: Based on the network behavior deviation index product, time series data is constructed, and the time series is decomposed into multi-scale products to generate multi-scale feature components. Anomaly pattern extraction is performed on the multi-scale feature component products to identify anomalous fluctuation characteristics at each scale and generate multi-scale anomalous pattern feature vector products. Based on the multi-scale anomaly pattern feature vector product, combined with a predefined threat feature library, pattern matching analysis is performed to calculate the threat similarity score and generate threat pattern matching result products. Based on the threat pattern matching results and combined with real-time network environment parameters, the threat level is determined through a dynamic threshold determination mechanism, generating a network security threat level assessment result.

6. The power plant network security vulnerability monitoring and protection system according to claim 5, characterized in that, Based on the multi-scale feature component products, the statistical moment characteristics and spectral distribution characteristics of each scale component are calculated respectively to generate multi-scale statistical feature vector products. Correlation analysis is performed on the multi-scale statistical feature vector products to identify coupling relationships and collaborative change patterns between different scales, and scale-coupled feature products are generated. Based on the scale-coupled feature product and combined with the network behavior deviation index product, an anomaly pattern recognition matrix is ​​constructed to generate multi-scale anomaly pattern feature vector products.

7. The power plant network security vulnerability monitoring and protection system according to claim 1, characterized in that, include: Based on the network behavior deviation index product and the network security threat level assessment product, a system security state vector is constructed to form a security state space description product. Based on the safety state space description product, calculate the stability boundary conditions of the system's safety state and generate stability boundary constraint products; Based on the stability boundary constraint products, analyze the changing trend of the system's safety state vector, calculate the Lyapunov exponent, and generate the system's safety stability index products. Based on the system security stability index product and combined with the current network operating status parameters, the direction and intensity of the protection strategy adjustment are determined, and the protection strategy adjustment instruction product is generated.

8. The power plant network security vulnerability monitoring and protection system according to claim 7, characterized in that, Based on the system security stability index product, combined with network device load rate, business criticality level and real-time threat intelligence data, a multi-dimensional risk assessment matrix product is generated. Prioritize the products of the multi-dimensional risk assessment matrix to determine the priority of adjusting protection strategies for boundary protection, host protection, and centralized monitoring, and generate protection strategy priority sequence products. Based on the protection strategy priority sequence product, combined with the preset protection strength level and response time requirements, a protection strategy adjustment instruction set product is generated. Conflict detection and consistency verification are performed on the protection strategy adjustment instruction set product to ensure the synergy between various protection strategies and generate protection strategy adjustment instruction product.

9. The power plant network security vulnerability monitoring and protection system according to claim 1, characterized in that, include: Analyze the protection strategy adjustment instruction output, extract boundary protection rule parameters, host protection strength parameters and monitoring strategy parameters, and generate multi-level protection configuration parameter output; Based on the boundary protection rule parameters in the multi-level protection configuration parameter product, the access control list and protocol filtering rules of the industrial firewall are dynamically reconstructed to generate an updated boundary protection rule set product. Based on the host protection strength parameters in the multi-level protection configuration parameter product, the process behavior monitoring strength and file access control policy of the host protection system are adjusted to generate an adaptive host protection policy set product. Based on the monitoring strategy parameters in the multi-level protection configuration parameter products, and combined with the boundary protection rule set products and the adaptive host protection strategy set products, the correlation analysis rules and alarm thresholds of the centralized monitoring platform are reconstructed to form a closed-loop protection system.

10. The power plant network security vulnerability monitoring and protection system according to claim 1, characterized in that, It also includes dynamic modules: Based on the closed-loop protection system, protection effectiveness feedback data is collected, including attack blocking records, false alarm statistics and system performance indicators, to generate protection effectiveness evaluation dataset products; Multi-dimensional analysis is performed on the protective effect assessment dataset to calculate the protective efficiency index and system adaptability index, and a protective effectiveness assessment report is generated. Based on the protection effectiveness assessment report, combined with the real-time network threat situation, the dynamic benchmark model parameters and the anomaly identification threshold of fractional calculus in the chaos synchronization theory are reconstructed to generate an adaptive parameter adjustment strategy product. The adaptive parameter adjustment strategy output is fed back to dynamically update the network behavior benchmark and anomaly identification mechanism, forming a dynamic protection system.