Power system network security protection method and system based on generative artificial intelligence
By employing a generative artificial intelligence-based approach to power system cybersecurity, and utilizing large-scale models and security detection tools for comprehensive analysis, this approach addresses the challenge of existing technologies in dealing with novel attack methods, achieving efficient and accurate cybersecurity protection while reducing false alarm rates.
Patent Information
- Application Number
- CN202511458310.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-13
- Publication Date
- 2026-01-06
AI Technical Summary
Existing network security equipment struggles to detect and respond to new attack methods in a timely manner, has a high false alarm rate, and suffers from high rule base maintenance costs. It is also unable to effectively address new threats such as ransomware and APTs, and lacks sufficient internal malicious behavior detection capabilities.
A power system cybersecurity protection method using generative artificial intelligence involves receiving tasks through an intelligent agent, generating detection results using large models and security detection tools, performing comprehensive analysis, and sending instructions to security protection tools to carry out cybersecurity protection.
It enables timely and accurate identification of network attacks, reduces false alarm rates, improves the digitalization level of network security protection, and reduces the maintenance cost of the rule base.
Smart Images

Figure CN121283733A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a power system network security protection method and system based on generative artificial intelligence. Background Technology
[0002] With the accelerated construction of new power systems, digital technologies such as cloud computing, big data, the Internet of Things, and artificial intelligence are deeply integrated with power grid operations, driving the power grid from digital transformation to high-quality development. Since 2023, generative artificial intelligence technology has achieved significant breakthroughs, with large-scale models represented by ChatGPT developing rapidly and being widely applied. As a widely recognized new technology with the potential to change the world, it is gradually being implemented in various industries and scenarios, empowering the power grid's digital intelligence capabilities while also greatly promoting the construction and upgrading of cybersecurity protection systems.
[0003] In recent years, the cybersecurity situation has continued to deteriorate, with emerging threats such as ransomware, APTs, and state-sponsored attacks further exacerbating power grid security risks. Under the construction of new power systems, the power grid network architecture continues to expand, security boundaries are becoming increasingly blurred, power grid operations are becoming more open, multi-party data interactions are becoming more frequent, and the risks of new technology integration are becoming more prominent. The power grid's exposure surface and attack risks are continuously expanding, and issues such as massive alerts, phishing emails, encrypted traffic, and vulnerability attacks are further complicating power grid security efforts.
[0004] Current mainstream cybersecurity equipment still relies on signature matching as its technical approach, depending on attack signatures for detection and protection. While rule-based and signature-matching-based security technologies can handle known attacks, they struggle to detect and respond promptly to emerging attack methods such as ransomware, APTs, and zero-day vulnerabilities, resulting in a high false positive rate and requiring significant maintenance costs for rule bases. Furthermore, manual analysis inevitably misses crucial details and lacks sufficient ability to detect internal malicious behavior. A security system relying solely on accumulating security equipment and manpower is insufficient to effectively address new security threats and changes in cyberspace.
[0005] Therefore, it is urgent to carry out research on the application of generative artificial intelligence technology in the field of power system cybersecurity, build a new generation of digital and intelligent cybersecurity system, promote the transformation of protection technology from technology stacking to intelligent linkage technology integration, and promote the transformation of security system from passive defense to active defense, thereby improving the digital and intelligent level of cybersecurity work.
[0006] Therefore, a power system network security protection method based on generative artificial intelligence is needed to solve the problems existing in the above-mentioned technical solutions. Summary of the Invention
[0007] Therefore, the present invention provides a power system network security protection method and a power system network security protection system based on generative artificial intelligence, so as to solve or at least alleviate the above-mentioned problems.
[0008] According to one aspect of the present invention, a power system cybersecurity protection method based on generative artificial intelligence is provided, executed in an intelligent agent. The method includes: receiving a cybersecurity protection task for the power system sent by a service layer; acquiring cybersecurity data related to the cybersecurity protection task; arranging and generating one or more detection tasks according to the cybersecurity protection task and the cybersecurity data; for each detection task, executing the detection task using a corresponding large model or security detection tool to generate a detection result; performing comprehensive analysis on one or more detection results corresponding to one or more detection tasks to obtain a comprehensive judgment result corresponding to the cybersecurity protection task, the comprehensive judgment result indicating whether the power system is under cyberattack; and sending a security protection instruction to a corresponding security protection tool according to the comprehensive judgment result, so that the security protection tool executes the security protection instruction to perform cybersecurity protection on the power system.
[0009] Optionally, in the power system network security protection method based on generative artificial intelligence according to the present invention, the intelligent agent is communicatively connected to the model layer and the tool layer, respectively. The model layer includes multiple large models, including a network security vertical domain large model, a full-size base large model, and a small-size base large model. The tool layer includes multiple security tools, wherein one or more of the security tools are security detection tools and / or security protection tools. For each detection task, the detection task is executed using the corresponding large model or security detection tool to generate a detection result, including: for each detection task, calling the corresponding large model of the model layer or the security detection tool of the tool layer to execute the detection task, and receiving the detection result returned by the large model or the security detection tool after executing the detection task.
[0010] Optionally, in the power system network security protection method based on generative artificial intelligence according to the present invention, for each detection task, the detection task is executed using a corresponding large model or security detection tool to generate a detection result, including: for each detection task, dynamically selecting a corresponding large model or security detection tool according to the complexity, real-time performance, and computing power cost of the detection task, and executing the detection task using the large model or security detection tool to generate a detection result.
[0011] Optionally, in the power system network security protection method based on generative artificial intelligence according to the present invention, the one or more detection tasks include at least one detection task corresponding to a large model, and the detection task corresponding to the large model includes network security data and prompt words; for each detection task, the detection task is executed using the corresponding large model or security detection tool to generate detection results, including: for the detection task corresponding to the large model, inputting the network security data and prompt words into the large model, and using the large model to analyze the network security data based on the prompt words to generate detection results.
[0012] Optionally, in the power system network security protection method based on generative artificial intelligence according to the present invention, sending a security protection instruction to the corresponding security protection tool according to the comprehensive judgment result, so that the security protection tool executes the security protection instruction to perform network security protection for the power system, includes: sending a security protection rule and a security protection instruction to the corresponding security protection tool according to the comprehensive judgment result, so that the security protection tool executes the security protection instruction according to the security protection rule to perform network security protection for the power system.
[0013] Optionally, in the power system network security protection method based on generative artificial intelligence according to the present invention, one or more detection tasks are arranged and generated according to the network security protection task and the network security data, and the method further includes: cleaning and aggregating the network security data to obtain business security aggregated data; and arranging and generating one or more detection tasks according to the network security protection task and the business security aggregated data.
[0014] Optionally, in the power system network security protection method based on generative artificial intelligence according to the present invention, the security protection tools include one or more of firewalls, terminal detection and response tools, network detection and response tools, and identity and access management tools; the security protection instructions include one or more of blocking instructions, terminal isolation instructions, and account banning instructions.
[0015] Optionally, in the power system network security protection method based on generative artificial intelligence according to the present invention, the network security protection task includes analyzing abnormal traffic of power equipment in the power system, the network security data includes traffic data packets, and the comprehensive judgment result is used to indicate whether the traffic is attack traffic; according to the comprehensive judgment result, sending a security protection instruction to the corresponding security protection tool so that the security protection tool executes the security protection instruction to perform network security protection on the power system, including: if the comprehensive judgment result indicates that the traffic is attack traffic, sending a blocking instruction to the firewall so that the firewall executes the blocking instruction to block network access of the source IP address corresponding to the abnormal traffic.
[0016] Optionally, in the power system network security protection method based on generative artificial intelligence according to the present invention, the comprehensive judgment result is suitable for indicating whether a process is a suspicious process; according to the comprehensive judgment result, a security protection instruction is sent to the corresponding security protection tool so that the security protection tool executes the security protection instruction to perform network security protection for the power system, including: if the comprehensive judgment result indicates that the process is a suspicious process, then an isolation terminal instruction is sent to the terminal detection and response tool so that the terminal detection and response tool executes the isolation terminal instruction to isolate the corresponding terminal.
[0017] Optionally, in the power system network security protection method based on generative artificial intelligence according to the present invention, the comprehensive judgment result is further used to indicate whether it is necessary to further analyze the detection results corresponding to each detection task; the method further includes: if the comprehensive judgment result indicates that it is necessary to further analyze the detection results corresponding to each detection task, then using forensic tools to collect the corresponding memory image and log file, and further analyzing the detection results corresponding to each detection task based on the memory image and log file.
[0018] Optionally, in the power system network security protection method based on generative artificial intelligence according to the present invention, the execution status returned by the security protection tool after executing the security protection instruction is received, and the execution status is used to indicate whether the security protection instruction was executed successfully.
[0019] Optionally, in the power system network security protection method based on generative artificial intelligence according to the present invention, the network security vertical domain large model includes one or more of the following: security operation large model, data security large model, threat detection large model, and email security large model; the full-size base large model includes one or more of the following: Guangming large model, DeepSeek, and Qwen3-235B-A22B; and the small-size base large model includes one or more of the following: Qwen3, GLM6B, and Llama-3.1.
[0020] Optionally, in the power system network security protection method based on generative artificial intelligence according to the present invention, the security detection tool includes one or more of threat intelligence tools, threat detection models, malicious code models, and encrypted traffic analysis models.
[0021] According to one aspect of the present invention, a power system network security protection system is provided, comprising: a model layer including multiple large models, such as a network security vertical domain large model, a full-size base large model, and a small-size base large model; a tool layer including multiple security tools, such as security detection tools and / or security protection tools; an intelligent agent, communicatively connected to the model layer and the tool layer respectively, adapted to execute the method described above to perform network security protection on the power system; and a service layer, communicatively connected to the intelligent agent, adapted to send network security protection tasks for the power system to the intelligent agent.
[0022] Optionally, in the power system network security protection system according to the present invention, the business layer includes multiple business modules, including an asset management business module, a boundary security control business module, a terminal security protection business module, a cloud security business module, a vulnerability mining business module, a penetration testing business module, a data security management business module, a supply chain security control business module, an emergency response business module, a safe operation business module, and a command and dispatch business module.
[0023] According to one aspect of the present invention, a computing device is provided, comprising: at least one processor; and a memory storing program instructions, wherein the program instructions are configured to be executed by the at least one processor, the program instructions including instructions for performing the power system network security protection method based on generative artificial intelligence as described above.
[0024] According to one aspect of the present invention, a computer program product is provided, comprising computer program instructions, wherein the computer program instructions, when executed by a processor, implement the method as described above.
[0025] According to one aspect of the present invention, a readable storage medium storing program instructions is provided, which, when read and executed by a computing device, causes the computing device to perform the power system network security protection method based on generative artificial intelligence as described above.
[0026] According to the technical solution of this invention, a power system network security protection method based on generative artificial intelligence is provided. The method involves an intelligent agent receiving network security protection tasks for the power system from the business layer, acquiring network security data related to these tasks, and then generating one or more detection tasks based on the network security protection tasks and network security data. These tasks are then executed using corresponding large-scale models or security detection tools to generate detection results. A comprehensive judgment result is obtained by comprehensively analyzing the detection results of each task. Finally, a security protection instruction is sent to the corresponding security protection tool based on the comprehensive judgment result, thereby enabling network security protection of the power system. Based on this, the invention comprehensively utilizes various large-scale models and security detection tools for network security detection, enabling more timely and accurate identification of various network attacks and efficient response and handling of these attacks using various security protection tools. This effectively reduces the false alarm rate and improves the digitalization level of power system network security protection. Furthermore, it eliminates the need to maintain a rule base, thus reducing maintenance costs.
[0027] The above description is merely an overview of the technical solution of the present invention. In order to better understand the technical means of the present invention and to implement it in accordance with the contents of the specification, and in order to make the above and other objects, features and advantages of the present invention more apparent and understandable, specific embodiments of the present invention are described below. Attached Figure Description
[0028] To achieve the foregoing and related objectives, certain illustrative aspects are described herein in conjunction with the following description and accompanying drawings. These aspects indicate various ways in which the principles disclosed herein may be practiced, and all aspects and their equivalents are intended to fall within the scope of the claimed subject matter. The foregoing and other objectives, features, and advantages of this disclosure will become more apparent from the following detailed description, taken in conjunction with the accompanying drawings. Throughout this disclosure, the same reference numerals generally refer to the same parts or elements.
[0029] Figure 1 A schematic diagram of a power system network security protection system 100 provided according to an embodiment of the present invention is shown; Figure 2 A schematic diagram of a computing device 200 provided according to an embodiment of the present invention is shown; Figure 3 A flowchart illustrating a power system network security protection method 300 based on generative artificial intelligence according to an embodiment of the present invention is shown. Detailed Implementation
[0030] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art.
[0031] For ease of understanding, the terminology involved in this invention will be explained below.
[0032] Generative AI is an important branch of artificial intelligence that can generate text, images, audio, video, code, and other content based on algorithms and models. Unlike traditional AI, generative AI not only analyzes data but also learns and generates new content with logical coherence. This technology relies on multimodal models to generate heterogeneous data according to user needs. Large language models are currently the mainstream generative AI approach, capable of generating text, images, and data based on rules.
[0033] Large Language Models (LLMs) are deep learning models trained on large amounts of text data, enabling them to generate natural language text or understand the meaning of language text. Examples of large language models include DeepSeek, ChatGPT, and Tongyiqianwen. The core functions of a large language model essentially include: 1) understanding user-given rules or requirements and making logical inferences; 2) making inferences or creating based on externally given rules / knowledge (i.e., input from the user or other programs) combined with its own rules / knowledge (i.e., rules already present in the model) acquired during training.
[0034] To address the problems of existing network security devices being unable to detect and respond to new attack methods in a timely manner, having a high false alarm rate, and requiring high rule base maintenance costs, this invention provides a power system network security protection method based on generative artificial intelligence. This method can identify and respond to various network attacks in a timely and accurate manner, effectively reduce the false alarm rate, and improve the digitalization level of power system network security protection.
[0035] The power system network security protection method based on generative artificial intelligence provided by the embodiments of the present invention can be implemented in a power system network security protection system. The power system network security protection system of the present invention is described below.
[0036] Figure 1 A schematic diagram of a power system network security protection system 100 provided according to an embodiment of the present invention is shown.
[0037] like Figure 1As shown, the power system network security protection system 100 includes a business layer 110, an intelligent agent 120, a model layer 130, and a tool layer 140. The intelligent agent 120 is communicatively connected to the business layer 110, the model layer 130, and the tool layer 140, respectively. The business layer 110 and the tool layer 140 are also wiredly connected, for example, via a wired or wireless network connection.
[0038] In this embodiment of the invention, model layer 130 may include various large models, including a network security vertical domain large model, a full-size base large model (large language model), and a small-size base large model. For example, the network security vertical domain large model may include one or more of the following: a security operation large model, a data security large model, a threat detection large model, and an email security large model. The full-size base large model may include one or more of the following: the Guangming large model, DeepSeek, and Qwen3-235B-A22B. The small-size base large model may include one or more of the following: Qwen3, GLM6B, and Llama-3.1.
[0039] Tool layer 140 may include multiple security tools, which may come from different vendors. These multiple security tools may include one or more security detection tools and one or more security protection tools. The one or more security tools may be security detection tools and / or security protection tools. In this embodiment of the invention, the security detection tool can be used to perform detection tasks, and the security protection tool can be used to execute security protection instructions. It should be noted that the one or more security tools in tool layer 140 may be both security detection tools and security protection tools. In some embodiments, the multiple security tools in tool layer 140 may include, for example, threat intelligence tools, AI-enhanced security models (including threat detection models, malware models, and encrypted traffic analysis models based on machine learning or deep learning), large-model-generated temporary network security tools (one-time-use network security tools that run in a sandbox and are destroyed after execution), and traditional network security tools. Traditional network security tools include, but are not limited to, Identity and Access Management (IAM) tools, Security Orchestration Automation and Response (SOAR) platforms, Privileged Account Management (PAM) tools, Endpoint Detection and Response (EDR) tools, Network Detection and Response (NDR) tools, Traffic Analysis (NTA) tools, Key Management and Hardware Security Modules (KMS / HSM), Firewalls (WAF, Web Application Firewall), Spoofing and Deception Tools, Reporting and Ticketing Systems, Sandboxes and Dynamic Analysis Tools, etc.
[0040] In some embodiments, agent 120 can call various security tools in the security layer through standard interfaces such as RESTful API, gRPC, and GraphQL. Agent 120 can also communicate asynchronously with various security tools in the security layer through a message bus based on message mechanisms such as Kafka, MQ, and Syslog. In some embodiments, agent 120 can trigger a predetermined playbook through SOAR (Security Orchestration Automation and Response Platform) to uniformly schedule multiple security tools from different vendors.
[0041] In some embodiments, the security detection tool includes one or more of threat intelligence tools, threat detection models, malicious code models, and encrypted traffic analysis models, but the present invention is not limited thereto.
[0042] Security protection tools may include one or more of firewalls (WAF), endpoint detection and response tools (EDR), network detection and response tools (NDR), and identity and access management tools (IAM), but the present invention is not limited thereto.
[0043] In embodiments of the present invention, data layer 150 is used to store network security data. Data layer 150 can realize the collection, processing, scheduling, governance, and evaluation of network security data. Furthermore, data layer 150 can provide data for the large model in model layer 130 and the security model in tool layer 140. In some embodiments, data layer 150 includes a data storage and computing framework, covering storage and computing software for traditional structured and unstructured data, such as Ceph, PostgreSQL, OceanBase, Hadoop, Spark, Hive, MySQL, ElasticSearch, MongoDB, Redis, Milvus, etc., and uses Kafka+Flink+(ClickHouse+Trino) / Starrocks+Iceberg to build a unified data lake warehouse.
[0044] In an embodiment of the present invention, the business layer 110 can send a network security protection task for the power system to the intelligent agent 120. This network security protection task may include, for example, analyzing abnormal traffic flow of power equipment in the power system. After receiving the network security protection task from the business layer 110, the intelligent agent 120 can request network security data (including business data and security data) related to the network security protection task from the data layer 150. Based on the network security protection task and the network security data, it can then orchestrate and generate one or more detection tasks. For each detection task, the intelligent agent 120 can utilize (call) the corresponding large model or security detection tool to execute the detection task and generate detection results. Subsequently, the intelligent agent 120 can perform a comprehensive analysis of one or more detection results corresponding to one or more detection tasks to obtain a comprehensive judgment result corresponding to the network security protection task. This comprehensive judgment result can be used to indicate whether the power system is under network attack (and also to indicate the type of network attack). Finally, based on the comprehensive judgment result, the intelligent agent 120 can send a security protection command (e.g., a blocking command to a firewall) to the security protection tool corresponding to the tool layer 140, so that the security protection tool can execute the security protection command to achieve network security protection for the power system.
[0045] The detection task corresponding to the large model can include cybersecurity data and prompts. For the detection task corresponding to the large model, agent 120 can input the cybersecurity data and prompts into the large model, and use the large model to analyze the cybersecurity data based on the prompts to generate detection results.
[0046] In some embodiments, security protection instructions may include one or more of the following: blocking instructions (corresponding to firewalls), terminal isolation instructions (corresponding to the terminal detection and response tool EDR), and account banning instructions, but the present invention is not limited thereto.
[0047] In some embodiments, the intelligent agent 120 may request network security data related to the network security protection task from the data layer 150 via the data layer 150 API, message bus, or data virtualization layer.
[0048] In some embodiments, the intelligent agent 120 can pre-clean and aggregate network security data to obtain business security aggregated data. Specifically, the intelligent agent 120 can invoke data processing services (such as ETL, feature engineering, and real-time stream processing) to clean and aggregate network security data to obtain business security aggregated data. Furthermore, the intelligent agent 120 can orchestrate and generate one or more detection tasks based on network security protection tasks and business security aggregated data.
[0049] In embodiments of the present invention, the intelligent agent 120 can be configured to execute a power system network security protection method 300 based on generative artificial intelligence to achieve network security protection of the power system. The power system network security protection method 300 based on generative artificial intelligence of the present invention will be described in detail below.
[0050] In embodiments of the present invention, such as Figure 1 As shown, the business layer 110 may include multiple business modules. Specifically, the multiple business modules may include an asset management business module, a boundary security control business module, an endpoint security protection business module, a cloud security business module, a vulnerability discovery business module, a penetration testing business module, a data security management business module, a supply chain security control business module, an emergency response business module, a secure operation business module, and a command and dispatch business module, but the present invention is not limited to the above-mentioned multiple business modules.
[0051] The intelligent agent 120 may include multiple network security intelligent agents 120 (including but not limited to asset management intelligent agents, alarm analysis intelligent agents, penetration testing intelligent agents, vulnerability discovery intelligent agents, data security intelligent agents, and secure operation intelligent agents), so that the intelligent agents can process network security protection tasks from multiple business modules by executing the power system network security protection method 300 based on generative artificial intelligence described below, thereby supporting a variety of network security services of the power system.
[0052] The power system network security protection system 100 provided in this embodiment of the invention receives network security protection tasks for the power system from the business layer through an intelligent agent, acquires network security data related to the network security protection tasks, and then generates one or more detection tasks based on the network security protection tasks and network security data. The detection tasks are then executed using corresponding large-scale models or security detection tools to generate detection results. A comprehensive judgment result is obtained by comprehensively analyzing the detection results corresponding to each detection task. Finally, a security protection instruction is sent to the corresponding security protection tool based on the comprehensive judgment result, so that the security protection tool can perform network security protection for the power system. Based on this, the present invention comprehensively utilizes various large-scale models and security detection tools for network security detection, enabling more timely and accurate identification of various network attacks, and efficient response and handling of various network attacks using various security protection tools. This effectively reduces the false alarm rate and improves the digitalization level of power system network security protection. Furthermore, no rule base maintenance is required, which helps reduce maintenance costs.
[0053] In one embodiment, the intelligent agent 120 of the present invention can be implemented as a computing device, so that the power system network security protection method 300 based on generative artificial intelligence of the present invention can be executed in the computing device.
[0054] Figure 2 A schematic diagram of a computing device 200 according to an embodiment of the present invention is shown. Figure 2 As shown, in a basic configuration, computing device 200 includes at least one processing unit 202 and system memory 204. According to one aspect, depending on the configuration and type of the computing device, the processing unit 202 may be implemented as a processor. System memory 204 includes, but is not limited to, volatile memory (e.g., random access memory), non-volatile memory (e.g., read-only memory), flash memory, or any combination of such memories. According to one aspect, system memory 204 includes an operating system 205.
[0055] According to one aspect, operating system 205 is, for example, suitable for controlling the operation of computing device 200. Furthermore, examples are practiced in conjunction with graphics libraries, other operating systems, or any other applications, and are not limited to any particular application or system. Figure 2 The basic configuration is illustrated by the components within the dashed lines. According to one aspect, the computing device 200 has additional features or functions. For example, according to one aspect, the computing device 200 includes additional data storage devices (removable and / or non-removable), such as disks, optical discs, or magnetic tapes. This additional storage... Figure 2 The middle part is shown by removable storage device 209 and non-removable storage device 210.
[0056] As stated above, according to one aspect, program module 203 is stored in system memory 204. According to one aspect, program module 203 may include one or more applications. The present invention does not limit the type of application; for example, applications may include: email and contact applications, word processing applications, spreadsheet applications, database applications, slideshow applications, drawing or computer-aided applications, web browser applications, etc.
[0057] In an embodiment of the present invention, program module 203 includes multiple program instructions that execute the power system network security protection method 300 based on generative artificial intelligence of the present invention.
[0058] According to one aspect, examples can be practiced on circuits including discrete electronic components, packaged or integrated electronic chips containing logic gates, circuits utilizing microprocessors, or on a single chip containing electronic components or a microprocessor. For example, it can be practiced via wherein... Figure 2Each or many of the components shown can be implemented as an example by integrating a System-on-a-Chip (SOC) on a single integrated circuit. According to one aspect, such an SOC device may include one or more processing units, graphics units, communication units, system virtualization units, and various application functions, all integrated (or “burned in”) as a single integrated circuit onto a chip substrate. When operating via the SOC, the functions described herein can be operated via dedicated logic integrated on a single integrated circuit (chip) with other components of the computing device 200. Embodiments of the invention can also be implemented using other techniques capable of performing logical operations (e.g., AND, OR, and NOT), including but not limited to mechanical, optical, fluid, and quantum technologies. Additionally, embodiments of the invention can be implemented within a general-purpose computer or in any other circuit or system.
[0059] According to one aspect, computing device 200 may also have one or more input devices 212, such as a keyboard, mouse, pen, voice input device, touch input device, etc. It may also include output devices 214, such as a display, speaker, printer, etc. The foregoing devices are examples and other devices may also be used. Computing device 200 may include one or more communication connections 216 that allow communication with other computing devices 218. Examples of suitable communication connections 216 include, but are not limited to: RF transmitter, receiver and / or transceiver circuitry; Universal Serial Bus (USB), parallel and / or serial ports.
[0060] As used herein, the term computer-readable medium includes computer storage medium. Computer storage medium can include volatile and non-volatile, removable and non-removable media implemented using any method or technology for storing information (e.g., computer-readable instructions, data structures, or program modules). System memory 204, removable storage device 209, and non-removable storage device 210 are examples of computer storage media (i.e., memory storage). Computer storage media can include random access memory (RAM), read-only memory (ROM), electrically erasable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital universal disc (DVD) or other optical storage, magnetic tape, magnetic tape, disk storage or other magnetic storage devices, or any other article of manufacture that can be used to store information and is accessible by computing device 200. According to one aspect, any such computer storage medium can be part of computing device 200. Computer storage media does not include carrier waves or other transmitted data signals.
[0061] According to one aspect, a communication medium is implemented by computer-readable instructions, data structures, program modules, or other data in a modulated data signal (e.g., a carrier wave or other transmission mechanism), and includes any information transmission medium. According to one aspect, the term "modulated data signal" describes a signal having one or more sets of characteristics or altered in a manner that encodes information in the signal. By way of example and not limitation, a communication medium includes wired media such as wired networks or direct wired connections, and wireless media such as acoustic, radio frequency (RF), infrared, and other wireless media.
[0062] In an embodiment of the present invention, a computing device 200 is configured to execute a power system network security protection method 300 based on generative artificial intelligence. The computing device 200 includes one or more processors and one or more readable storage media storing program instructions. When the program instructions are configured to be executed by the one or more processors, the computing device executes the power system network security protection method 300 based on generative artificial intelligence according to this embodiment of the invention, so that the computing device 200 performs network security protection on the power system by executing the power system network security protection method 300 based on generative artificial intelligence of the present invention.
[0063] In some embodiments, the computing device that executes the power system network security protection method 300 based on generative artificial intelligence in the present invention can be an intelligent agent 120, that is, the power system network security protection method 300 based on generative artificial intelligence can be executed in the intelligent agent 120.
[0064] The following is a detailed description of the power system network security protection method 300 based on generative artificial intelligence in the embodiments of the present invention.
[0065] Figure 3 A flowchart illustrating a power system network security protection method 300 based on generative artificial intelligence according to an embodiment of the present invention is shown. Figure 3 As shown, the power system network security protection method 300 based on generative artificial intelligence includes the following steps 310-360.
[0066] Step 310: The intelligent agent 120 can receive network security protection tasks for the power system sent by the service layer 110.
[0067] Step 320: Agent 120 can acquire network security data related to network security protection tasks.
[0068] In this embodiment of the invention, the intelligent agent 120 may request network security data related to the network security protection task from the data layer 150. For example, in some embodiments, the intelligent agent 120 may request network security data related to the network security protection task from the data layer 150 via the data layer 150 API, message bus, or data virtualization layer.
[0069] Step 330: The intelligent agent 120 can arrange and generate one or more detection tasks based on network security protection tasks and network security data.
[0070] In some embodiments, the intelligent agent 120 can pre-clean and aggregate network security data to obtain business security aggregated data. Specifically, the intelligent agent 120 can invoke data processing services (such as ETL, feature engineering, and real-time stream processing) to clean and aggregate network security data to obtain business security aggregated data. Furthermore, the intelligent agent 120 can orchestrate and generate one or more detection tasks based on network security protection tasks and business security aggregated data.
[0071] Step 340: For each detection task, agent 120 can use (call) the corresponding large model or security detection tool to perform the detection task and generate detection results.
[0072] In some embodiments, the intelligent agent 120 is communicatively connected to the model layer 130 and the tool layer 140, respectively. The model layer 130 may include various large models, such as a network security vertical domain large model, a full-size base large model (large language model), and a small-size base large model. For example, the network security vertical domain large model may include one or more of the following: a security operations large model, a data security large model, a threat detection large model, and an email security large model. The full-size base large model may include one or more of the following: the Guangming large model, DeepSeek, and Qwen3-235B-A22B. The small-size base large model may include one or more of the following: Qwen3, GLM6B, and Llama-3.1.
[0073] The tool layer 140 may include multiple security tools, which may include one or more security detection tools and one or more security protection tools. These one or more security tools can be security detection tools and / or security protection tools. It should be noted that the one or more security tools in the tool layer 140 can be both security detection tools and security protection tools. In some embodiments, the agent 120 can call various security tools in the security layer through standard interfaces such as RESTful API, gRPC, and GraphQL. The agent 120 can also communicate asynchronously with various security tools in the security layer through a message bus based on message mechanisms such as Kafka, MQ, and Syslog. In some embodiments, the agent 120 can trigger a predetermined playbook through SOAR (Security Orchestration Automation and Response Platform) to uniformly schedule multiple security tools from different vendors.
[0074] In some embodiments, security detection tools include one or more of threat intelligence tools, threat detection models, malicious code models, and encrypted traffic analysis models.
[0075] In some embodiments, in step 340, for each detection task, the agent 120 can call the large model of the corresponding model layer 130 or the security detection tool of the tool layer 140 to perform the detection task and generate the corresponding detection result, and then receive the detection result returned by the large model or the security detection tool after performing the detection task.
[0076] In some embodiments, for each detection task, the agent 120 can dynamically select the corresponding large model or security detection tool based on the complexity, real-time requirements, and computing cost of the detection task, and use the large model or security detection tool to execute the detection task to generate detection results.
[0077] In some embodiments, one or more detection tasks in step 340 include at least one detection task corresponding to a large model (e.g., a threat detection large model). This detection task corresponding to the large model includes network security data (specifically, cleaned and aggregated business security aggregated data) and prompts. In one specific embodiment, the network security data (business security aggregated data) may include, for example, traffic data packets; the prompts may be, for example, "This is a Pcap data packet of traffic; please analyze whether it is attack traffic." In step 340, for the detection task corresponding to the large model, the agent 120 can input the network security data (business security aggregated data) and prompts into the large model, and use the large model to analyze the network security data based on the prompts to generate detection results.
[0078] Step 350: The intelligent agent 120 can perform comprehensive analysis on one or more detection results corresponding to one or more detection tasks to obtain a comprehensive judgment result corresponding to the network security protection task. In this embodiment of the invention, the comprehensive judgment result can be used to indicate whether the power system is under network attack (and can also indicate what kind of network attack it is under).
[0079] In step 360, the intelligent agent 120 can send a security protection command to the security protection tool corresponding to the tool layer 140 based on the comprehensive judgment result, so that the security protection tool can execute the security protection command to realize network security protection of the power system.
[0080] Specifically, when the intelligent agent 120 determines that the power system is under cyberattack based on the comprehensive judgment result, it can send a security protection command to the security protection tool corresponding to the tool layer 140 so that the security protection tool can execute the security protection command to realize network security protection of the power system.
[0081] In some embodiments, security protection tools may include one or more of a firewall (WAF), an endpoint detection and response tool (EDR), a network detection and response tool (NDR), and an identity and access management tool (IAM), but the present invention is not limited thereto.
[0082] Security protection commands may include one or more of the following: blocking commands (corresponding to firewalls), terminal isolation commands (corresponding to terminal detection and response tools EDR), and account banning commands, but this invention is not limited thereto.
[0083] In some embodiments, in step 360, the intelligent agent 120 can further send security protection rules and security protection instructions to the corresponding security protection tool based on the comprehensive judgment result, so that the security protection tool can execute the security protection instructions according to the security protection rules to achieve network security protection for the power system. The security protection rules may be, for example, updated firewall rules, temporary blocking rules, or optimized access control policies. The intelligent agent 120 may send updated firewall rules or temporary blocking rules to the firewall (WAF), or it may send optimized access control policies to the Identity and Access Management (IAM) tool. Here, the optimized access control policy may be automatically generated by the intelligent agent 120 based on historical attack patterns.
[0084] In some embodiments, after the intelligent agent 120 sends a security protection instruction to the security protection tool corresponding to the tool layer 140 based on the comprehensive judgment result, it can also receive the execution status returned by the security protection tool after executing the security protection instruction. The execution status is used to indicate whether the security protection instruction (e.g., blocking instruction, terminal isolation instruction, account banning instruction) has been successfully executed.
[0085] In one specific embodiment, the network security protection task in step 310 includes analyzing abnormal traffic of power equipment (e.g., distributed photovoltaic inverters) in the power system. The network security data related to this network security protection task obtained in step 320 may include traffic data packets, which may include, for example, the source IP address, destination IP address, port number, and protocol type corresponding to the traffic.
[0086] In step 330, the intelligent agent 120 can generate multiple detection tasks based on the aforementioned network security protection tasks and related network security data (including traffic data packets). These detection tasks are as follows: 1) Check if IP address 123.123.234.234 is an attacking IP (this detection task corresponds to a threat intelligence tool); 2) Determine if there is an attack based on the captured traffic data packets (this detection task corresponds to a threat detection model); 3) Analyze whether the traffic contains malicious code (this detection task corresponds to a malicious code model); 4) This is a Pcap data packet of the traffic; please analyze whether it is attack traffic. The phrase "This is a Pcap data packet of the traffic; please analyze whether it is attack traffic" can be used as a prompt to input into the threat detection model.
[0087] In step 350, agent 120 can comprehensively analyze the multiple detection results corresponding to the above-mentioned multiple detection tasks to obtain a comprehensive judgment result. The comprehensive judgment result can be used to indicate whether the traffic is attack traffic. If the comprehensive judgment result indicates that the traffic is attack traffic, in step 360, agent 120 can send a blocking command to the firewall (WAF). For example, it can call the WAF API to send a blocking command to the firewall (WAF), so that the firewall can block the network access of the source IP address corresponding to the abnormal traffic by executing the blocking command, thereby realizing network security protection for the power system. Furthermore, agent 120 can send temporary blocking rules and blocking commands to the firewall according to the comprehensive judgment result, so that the firewall can execute the blocking command according to the temporary blocking rules to block the network access of the source IP address corresponding to the abnormal traffic.
[0088] In one specific embodiment, in step 340, one or more detection results may include an alarm event sent to agent 120 by the security detection tool (EDR) after detecting suspicious process behavior. The comprehensive judgment result in step 350 may also indicate whether the process is a suspicious process. If the comprehensive judgment result indicates that the process is a suspicious process, then in step 360, agent 120 may send an isolation terminal instruction to the terminal detection and response tool (EDR), so that the terminal detection and response tool (EDR) can isolate the corresponding terminal by executing the isolation terminal instruction, thereby achieving network security protection for the power system.
[0089] In some embodiments, the comprehensive judgment result in step 350 may also indicate whether further analysis of the individual detection results corresponding to each detection task is required. Tool layer 140 also includes an forensic tool. If the comprehensive judgment result indicates that further analysis of the individual detection results corresponding to each detection task is required, agent 120 may utilize the forensic tool of tool layer 140 to collect the corresponding memory image and log files. Specifically, agent 120 may utilize the forensic tool of tool layer 140 to collect the corresponding memory image and log files and receive the memory image and log files returned by the forensic tool. Subsequently, agent 120 may further analyze the individual detection results corresponding to each detection task based on the memory image and log files.
[0090] The power system network security protection method 300 based on generative artificial intelligence according to the present invention receives network security protection tasks for the power system from the business layer through an intelligent agent, acquires network security data related to the network security protection tasks, and then generates one or more detection tasks based on the network security protection tasks and network security data. The detection tasks are then executed using corresponding large-scale models or security detection tools to generate detection results. A comprehensive judgment result is obtained by comprehensively analyzing the detection results corresponding to each detection task. Finally, a security protection instruction is sent to the corresponding security protection tool based on the comprehensive judgment result, so as to perform network security protection for the power system through the security protection tool. Based on this, the present invention comprehensively utilizes various large-scale models and security detection tools for network security detection, which can more timely and accurately identify various network attacks, and efficiently respond to and handle various network attacks using various security protection tools. This effectively reduces the false alarm rate and improves the digitalization level of power system network security protection. Furthermore, no rule base maintenance is required, which helps reduce maintenance costs.
[0091] Furthermore, embodiments of the present invention also disclose: A7, the method as described in any one of A1-A6, wherein the security protection tool includes one or more of a firewall, a terminal detection and response tool, a network detection and response tool, and an identity and access management tool; the security protection instruction includes one or more of a blocking instruction, a terminal isolation instruction, and an account banning instruction. A8, the method as described in A7, wherein the network security protection task includes analyzing abnormal traffic of power equipment in a power system, the network security data includes traffic data packets, and the comprehensive judgment result is used to indicate whether the traffic is attack traffic; based on the comprehensive judgment result, a security protection instruction is sent to the corresponding security protection tool so that the security protection tool executes the security protection instruction to perform network security protection for the power system, including: if the comprehensive judgment result indicates that the traffic is attack traffic, a blocking instruction is sent to the firewall so that the firewall executes the blocking instruction to block network access of the source IP address corresponding to the abnormal traffic. A9. The method as described in A7, wherein the comprehensive judgment result is suitable for indicating whether a process is a suspicious process; according to the comprehensive judgment result, a security protection instruction is sent to the corresponding security protection tool so that the security protection tool executes the security protection instruction to perform network security protection for the power system, including: if the comprehensive judgment result indicates that the process is a suspicious process, then an isolation terminal instruction is sent to the terminal detection and response tool so that the terminal detection and response tool executes the isolation terminal instruction to isolate the corresponding terminal. A10. The method as described in any one of A1-A9, wherein the comprehensive judgment result is further used to indicate whether further analysis of each detection result corresponding to each detection task is required; the method further includes: if the comprehensive judgment result indicates that further analysis of each detection result corresponding to each detection task is required, then a forensic tool is used to collect the corresponding memory image and log file, and further analysis of each detection result corresponding to each detection task is performed based on the memory image and log file. A11. The method as described in any one of A1-A10, further including: receiving an execution status returned by the security protection tool after executing the security protection instruction, the execution status indicating whether the security protection instruction was successfully executed. A12. The method described in A2, wherein the network security vertical domain large model includes one or more of the following: security operation large model, data security large model, threat detection large model, and email security large model; the full-size base large model includes one or more of the following: Guangming large model, DeepSeek, and Qwen3-235B-A22B; and the small-size base large model includes one or more of the following: Qwen3, GLM6B, and Llama-3.1.A13. The method as described in any one of A1-A12, wherein the security detection tool includes one or more of threat intelligence tools, threat detection models, malware models, and encrypted traffic analysis models. B15. The system as described in B14, wherein the business layer includes multiple business modules, including an asset management business module, a boundary security control business module, an endpoint security protection business module, a cloud security business module, a vulnerability discovery business module, a penetration testing business module, a data security management business module, a supply chain security control business module, an emergency response business module, a secure operation business module, and a command and dispatch business module.
[0092] The various techniques described herein can be implemented in combination with hardware or software, or a combination thereof. Thus, the methods and apparatus of the present invention, or certain aspects or portions thereof, can take the form of program code (i.e., instructions) embedded in a tangible medium, such as a removable hard disk, USB flash drive, floppy disk, CD-ROM, or any other machine-readable storage medium, wherein when the program is loaded into and executed by a machine such as a computer, the machine becomes an apparatus for practicing the present invention.
[0093] When the program code is executed on a programmable computer, the mobile terminal generally includes a processor, a processor-readable storage medium (including volatile and non-volatile memory and / or storage elements), at least one input device, and at least one output device. The memory is configured to store program code; the processor is configured to execute the generative artificial intelligence-based power system network security protection method of the present invention according to instructions in the program code stored in the memory.
[0094] By way of example, and not limitation, readable media include readable storage media and communication media. Readable storage media stores information such as computer-readable instructions, data structures, program modules, or other data. Communication media generally embodies computer-readable instructions, data structures, program modules, or other data in the form of modulated data signals such as carrier waves or other transmission mechanisms, and includes any information delivery medium. Any combination of the above is also included within the scope of readable media.
[0095] In the specification provided herein, the algorithms and displays are not inherently related to any particular computer, virtual system, or other device. Various general-purpose systems can also be used with the examples of this invention. The required structure for constructing such systems is apparent from the above description. Furthermore, this invention is not directed to any particular programming language. It should be understood that the contents of the invention described herein can be implemented using various programming languages, and the above description of specific languages is for the purpose of disclosing the best mode of implementation of the invention.
[0096] Numerous specific details are set forth in the specification provided herein. However, it will be understood that embodiments of the invention may be practiced without these specific details. In some instances, well-known methods, structures, and techniques have not been shown in detail so as not to obscure the understanding of this specification.
[0097] Similarly, it should be understood that, in order to streamline this disclosure and aid in understanding one or more of the various aspects of the invention, in the above description of exemplary embodiments of the invention, various features of the invention are sometimes grouped together in a single embodiment, figure, or description thereof.
[0098] Those skilled in the art will understand that modules, units, or components of the devices disclosed in the examples herein can be arranged in the devices described in this embodiment, or alternatively, can be located in one or more devices different from the devices in this example. The modules in the foregoing examples can be combined into a single module or, in addition, can be divided into multiple sub-modules.
[0099] Unless otherwise specified, the use of ordinal numbers such as “first,” “second,” “third,” etc., to describe ordinary objects merely indicates different instances of similar objects and is not intended to imply that the objects being described must have a given order in time, space, ordering, or any other manner.
Claims
1. A method for power system network security protection based on generative artificial intelligence, executed in an agent, the method comprising: receiving a network security protection task for a power system sent by a business layer; obtaining network security data related to the network security protection task; orchestrating one or more detection tasks according to the network security protection task and the network security data; for each detection task, executing the detection task using a corresponding large model or security detection tool to generate a detection result; comprehensively analyzing one or more detection results corresponding to one or more detection tasks to obtain a comprehensive determination result corresponding to the network security protection task, the comprehensive determination result being used to indicate whether the power system is under a network attack; sending a security protection instruction to a corresponding security protection tool according to the comprehensive determination result, so that the security protection tool executes the security protection instruction to perform network security protection on the power system.
2. The method of claim 1, wherein, The agent is communicatively connected with a model layer and a tool layer, the model layer includes a plurality of large models, the plurality of large models include network security vertical domain large models, full-size base large models, and small-size base large models, and the tool layer includes a plurality of security tools, one or more of which are security detection tools and / or security protection tools; for each detection task, executing the detection task using a corresponding large model or security detection tool to generate a detection result, comprising: for each detection task, calling a large model of the model layer or a security detection tool of the tool layer to execute the detection task, and receiving a detection result returned by the large model or the security detection tool after executing the detection task.
3. The method of claim 1 or 2, wherein, for each detection task, executing the detection task using a corresponding large model or security detection tool to generate a detection result, comprising: for each detection task, dynamically selecting a corresponding large model or security detection tool according to the complexity, real-time performance, and computing power cost of the detection task, and executing the detection task using the large model or the security detection tool to generate a detection result.
4. The method of any one of claims 1-3, wherein, The one or more detection tasks include at least one detection task of a corresponding large model, and the detection task of the corresponding large model includes network security data and a prompt word; for each detection task, executing the detection task using a corresponding large model or security detection tool to generate a detection result, comprising: for the detection task of the corresponding large model, inputting the network security data and the prompt word into the large model, and using the large model to analyze the network security data based on the prompt word to generate a detection result.
5. The method of any one of claims 1-4, wherein, According to the comprehensive determination result, sending a security protection instruction to a corresponding security protection tool, so that the security protection tool executes the security protection instruction to perform network security protection on the power system, comprising: According to the comprehensive determination result, sending a security protection rule and a security protection instruction to a corresponding security protection tool, so that the security protection tool executes the security protection instruction according to the security protection rule to perform network security protection on the power system.
6. The method of any one of claims 1-5, wherein, According to the network security protection task and the network security data, one or more detection tasks are generated by orchestration, and the method further includes: cleaning and aggregating the network security data to obtain service security aggregated data; generating one or more detection tasks by orchestration according to the network security protection task and the service security aggregated data.
7. A power system network security protection system, comprising: a model layer including a plurality of large models, the plurality of large models including network security vertical large models, full-size base large models, and small-size base large models; a tool layer including a plurality of security tools, the security tools being security detection tools and / or security protection tools; an intelligent agent in communication connection with the model layer and the tool layer, and adapted to execute the method of any one of claims 1-13 to perform network security protection on the power system; a service layer in communication connection with the intelligent agent, and adapted to send network security protection tasks of the power system to the intelligent agent.
8. A computing device, comprising: at least one processor; and a memory storing program instructions, wherein the program instructions are configured to be processed by the at least one processor, and the program instructions include instructions for processing the method of any one of claims 1-6.
9. A computer program product comprising computer program instructions, wherein, The computer program instructions, when executed by the processor, implement the method of any one of claims 1-6.
10. A readable storage medium storing program instructions, which, when read and processed by a computing device, cause the computing device to process the method of any one of claims 1-6.