Method and device for determining safety protection strategy of charging pile operating system
By acquiring the interaction data and topology of the charging pile operating system, high-risk processes and external devices were identified, and precise security protection strategies were formulated. This solved the problem of inaccurate security protection strategies in the charging pile operating system and improved the system's security and protection efficiency.
Patent Information
- Application Number
- CN202511723409.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-21
- Publication Date
- 2026-01-16
AI Technical Summary
In existing technologies, the security protection strategies of charging pile operating systems are not accurately determined, which affects the stability and reliability of the charging process.
By acquiring the current interaction data and interaction topology of the charging pile operating system, the target risk chain is identified, including high-risk processes and external devices, and then a precise security protection strategy is formulated.
It enables dynamic risk assessment of the charging pile operating system, avoiding resource waste and omission of key risks caused by indiscriminate protection, and improving the overall security and protection efficiency of the system.
Smart Images

Figure CN121340979A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of data processing, in particular to a method and device for determining a security protection strategy of a charging pile operation system. BACKGROUND
[0002] In the related art, as a key infrastructure of electric vehicles, the security protection of the charging pile operation system directly relates to the stability and reliability of the charging process. However, in the related art, when determining the security protection strategy of the charging pile operation system, there is the technical problem of inaccurate determination of the security protection strategy.
[0003] To solve the above problems, no effective solution has been proposed so far. SUMMARY
[0004] Embodiments of the present application provide a method and device for determining a security protection strategy of a charging pile operation system, to at least solve the technical problem of inaccurate determination of the security protection strategy of the charging pile operation system in the related art.
[0005] According to an aspect of an embodiment of the present application, a method for determining a security protection strategy of a charging pile operation system is provided, comprising: obtaining current interaction data of the charging pile operation system; calling an interaction topology relationship of the charging pile operation system, wherein the charging pile operation system comprises a plurality of processes, the interaction topology relationship comprises a first node formed by the plurality of processes, a second node formed by a plurality of external connected devices, and an edge formed by a node association relationship, the node association relationship comprises an external interaction relationship, the external interaction relationship represents an interaction relationship between a process and an external connected device, and the plurality of external connected devices are devices having an interaction relationship with the charging pile operation system; determining a target risk chain corresponding to the charging pile operation system according to the current interaction data and the interaction topology relationship, wherein the target risk chain comprises at least one target process and at least one target external connected device, the target process is a process in the plurality of processes whose process risk index is greater than a process risk threshold, and the target external connected device is an external connected device in the plurality of external connected devices whose device risk index is greater than a device risk threshold; and determining a security protection strategy corresponding to the charging pile operation system according to the target risk chain.
[0006] Optionally, the determining, according to the current interaction data and the interaction topological relation, a target risk chain corresponding to the charging pile operation system, comprises: determining, according to the current interaction data, first risk indexes respectively corresponding to a plurality of external connection interaction relations in the interaction topological relation; determining, from the plurality of external connection interaction relations, a first interaction relation according to the first risk indexes respectively corresponding to the plurality of external connection interaction relations, wherein the first interaction relation is an external connection interaction relation with a first risk index greater than a first risk threshold; and determining, according to the first interaction relation and the interaction topological relation, a target risk chain corresponding to the charging pile operation system.
[0007] Optionally, the determining, according to the first interaction relation and the interaction topological relation, a target risk chain corresponding to the charging pile operation system, comprises: in a case where the node association relation comprises process interaction relations and device interaction relations, determining second risk indexes respectively corresponding to a plurality of process interaction relations in the interaction topological relation and third risk indexes respectively corresponding to a plurality of device interaction relations; determining, from the plurality of process interaction relations, a second interaction relation according to the second risk indexes respectively corresponding to the plurality of process interaction relations, wherein the second interaction relation is a process interaction relation with a second risk index greater than a second risk threshold in the plurality of process interaction relations; determining, from the plurality of device interaction relations, a third interaction relation according to the third risk indexes respectively corresponding to the plurality of device interaction relations, wherein the third interaction relation is a device interaction relation with a third risk index greater than a third risk threshold in the plurality of device interaction relations; and determining, according to the first interaction relation, the second interaction relation, the third interaction relation, and the interaction topological relation, a target risk chain corresponding to the charging pile operation system.
[0008] Optionally, the determining, according to the first interaction relation, the second interaction relation, the third interaction relation, and the interaction topological relation, a target risk chain corresponding to the charging pile operation system, comprises: determining, according to the first interaction relation and the interaction topological relation, a first risk propagation feature corresponding to the charging pile operation system; determining, according to the second interaction relation, the first risk propagation feature, and the interaction topological relation, a second risk propagation feature corresponding to the charging pile operation system; determining, according to the third interaction relation, the first risk propagation feature, the second risk propagation feature, and the interaction topological relation, a third risk propagation feature corresponding to the charging pile operation system; and determining, according to the third risk propagation feature, a target risk chain corresponding to the charging pile operation system.
[0009] Optionally, before the calling the interaction topology relationship of the charging pile operation system, the method further includes: obtaining process interaction data, device interaction data and external connection interaction data corresponding to the charging pile operation system; determining a first topology relationship corresponding to the charging pile operation system according to the process interaction data, wherein the first topology relationship represents a topology structure between a plurality of processes in the charging pile operation system; determining a second topology relationship corresponding to the charging pile operation system according to the device interaction data, wherein the second topology relationship represents a topology structure between a plurality of external connection devices in the charging pile operation system; and determining the interaction topology relationship corresponding to the charging pile operation system according to the external connection interaction data, the first topology relationship and the second topology relationship.
[0010] Optionally, the determining the interaction topology relationship corresponding to the charging pile operation system according to the external connection interaction data, the first topology relationship and the second topology relationship includes: determining an initial topology relationship corresponding to the charging pile operation system according to the external connection interaction data, the first topology relationship and the second topology relationship, wherein there is a connection edge between any two first nodes and second nodes in a plurality of target nodes of the initial topology relationship, the plurality of target nodes include a first node composed of a plurality of processes and a second node composed of a plurality of external connection devices; adjusting a running state of the plurality of first nodes except for any one first node in the plurality of first nodes according to an execution order of the plurality of first nodes, and adjusting a running state of the any one first node to obtain an adjusted running state; determining a state change index corresponding to each of the plurality of second nodes according to the adjusted running state; determining a change node corresponding to the any one first node from the plurality of second nodes according to the state change index corresponding to each of the plurality of second nodes, wherein the corresponding change node is a second node with a state change index greater than a state change threshold value, until the plurality of first nodes are processed to obtain a change node corresponding to each of the plurality of first nodes; and adjusting the initial topology relationship according to the change node corresponding to each of the plurality of first nodes to obtain the interaction topology relationship corresponding to the charging pile operation system.
[0011] Optionally, the determining the security protection strategy corresponding to the charging pile operation system according to the target risk chain includes: determining a process risk time sequence feature corresponding to a target process in the target risk chain; determining a device risk time sequence feature corresponding to a target external connection device in the target risk chain; and determining the security protection strategy corresponding to the charging pile operation system according to the process risk time sequence feature and the device risk time sequence feature.
[0012] According to an aspect of an embodiment of the present application, there is provided a device for determining a security protection policy of a charging pile operating system, comprising: an obtaining module configured to obtain current interaction data of the charging pile operating system; a calling module configured to call an interaction topology relationship of the charging pile operating system, wherein the charging pile operating system comprises a plurality of processes, the interaction topology relationship comprises a first node formed by the plurality of processes, a second node formed by a plurality of external connected devices, and an edge formed by a node association relationship, the node association relationship comprises an external interaction relationship, the external interaction relationship represents an interaction relationship between a process and an external connected device, and the plurality of external connected devices are devices having an interaction relationship with the charging pile operating system; a first determining module configured to determine a target risk chain corresponding to the charging pile operating system according to the current interaction data and the interaction topology relationship, wherein the target risk chain comprises at least one target process and at least one target external connected device, the target process is a process in the plurality of processes having a process risk index greater than a process risk threshold, and the target external connected device is an external connected device in the plurality of external connected devices having a device risk index greater than a device risk threshold; and a second determining module configured to determine a security protection policy corresponding to the charging pile operating system according to the target risk chain.
[0013] According to an aspect of an embodiment of the present application, there is provided an electronic device, comprising: a processor; a memory for storing instructions executable by the processor; wherein the processor is configured to execute the instructions to implement the security protection policy determination method of the charging pile operating system of any one of the aspects.
[0014] According to an aspect of an embodiment of the present application, there is provided a computer readable storage medium, comprising: when instructions in the computer readable storage medium are executed by a processor of an electronic device, the electronic device is enabled to perform the security protection policy determination method of the charging pile operating system of any one of the aspects.
[0015] In the embodiment of the present application, current interaction data of the charging pile operation system is acquired; an interaction topology relationship of the charging pile operation system is called, wherein the charging pile operation system includes a plurality of processes, the interaction topology relationship includes a first node formed by the plurality of processes, a second node formed by a plurality of external connected devices, and an edge formed by a node association relationship, and the node association relationship includes an external interaction relationship, the external interaction relationship represents an interaction relationship between the processes and the external connected devices, and the plurality of external connected devices are devices having an interaction relationship with the charging pile operation system; according to the current interaction data and the interaction topology relationship, a target risk chain corresponding to the charging pile operation system is determined, wherein the target risk chain includes at least one target process and at least one target external connected device, the target process is a process in the plurality of processes whose process risk index is greater than a process risk threshold, and the target external connected device is an external connected device in the plurality of external connected devices whose device risk index is greater than a device risk threshold; and according to the target risk chain, a security protection strategy corresponding to the charging pile operation system is determined. By acquiring the current interaction data of the charging pile operation system, the actual interaction state of the processes and the external connected devices can be mastered in real time, and a dynamic basis is provided for risk determination. The interaction topology relationship includes the first node (process), the second node (external connected device), and the node association relationship, so that the interaction architecture of the processes and the devices can be clearly determined. Therefore, by combining the current interaction data and the interaction topology relationship, the target risk chain including the high-risk processes and the external connected devices can be determined, the systematic risk caused by the linkage of the single high-risk node can be avoided by not looking at it in isolation, and the security protection strategy of the charging pile operation system can be accurately determined based on the target risk chain, so as to avoid resource waste or key risk omission caused by indiscriminate protection, and thus the technical problem that the security protection strategy of the charging pile operation system is not accurately determined in the related art is solved. BRIEF DESCRIPTION OF DRAWINGS
[0016] The accompanying drawings, which are included to provide a further understanding of the application and are incorporated in and constitute a part of this application, illustrate embodiments of the application and serve to explain the principles of the application. In the drawings:
[0017] Figure 1 FIG. 1 is a flowchart of a security protection strategy determination method of a charging pile operation system according to an embodiment of the present application;
[0018] Figure 2 FIG. 2 is a structural block diagram of a security protection strategy determination device of a charging pile operation system according to an embodiment of the present application. DETAILED DESCRIPTION
[0019] In the following, the technical solutions in the embodiments of the present application will be described clearly and completely with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all the other embodiments obtained by a person of ordinary skill in the art without creative work should fall within the protection scope of the present application.
[0020] It should be noted that the terms "first", "second" and the like in the description and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "comprise" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0021] Embodiment 1
[0022] According to the embodiments of the present application, an embodiment of a security protection strategy determination method of a charging pile operation system is provided. It should be noted that the steps shown in the flowchart of the drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described herein can be executed in an order different from that herein.
[0023] Figure 1 is a flowchart of a security protection strategy determination method of a charging pile operation system according to the embodiments of the present application, as Figure 1 shown, the method comprises the following steps:
[0024] S102, acquiring current interaction data of the charging pile operation system.
[0025] In the step S102 provided in the present application, the current interaction data of the charging pile operation system is acquired.
[0026] Among them, the charging pile operation system is a system for managing and controlling the operation of the charging pile.
[0027] The current interaction data involves current interaction data of the charging pile operation system, which reflects the running state and interaction of the charging pile at the current time, and includes real-time interaction data between processes in the charging pile operation system and external devices.
[0028] By obtaining the current interaction data of the charging pile operation system, the actual interaction state and running state of the charging pile operation system can be grasped in real time, and a dynamic and reliable data basis is provided for subsequent risk determination and generation of targeted security protection strategies.
[0029] In step S104, the interaction topology relationship of the charging pile operation system is called, wherein the charging pile operation system includes a plurality of processes, the interaction topology relationship includes a first node formed by the plurality of processes, a second node formed by a plurality of external devices, and an edge formed by a node association relationship, and the node association relationship includes an external interaction relationship, the external interaction relationship represents an interaction relationship between the processes and the external devices, and the plurality of external devices are devices having an interaction relationship with the charging pile operation system.
[0030] In step S104 provided in the present application, the interaction topology relationship of the charging pile operation system is called.
[0031] The interaction topology relationship involves the interaction topology structure corresponding to the charging pile operation system, including process nodes, external device nodes, and their association relationships.
[0032] The plurality of processes are programs running and executing different tasks or functions in the charging pile operation system.
[0033] The first node is a node formed by the plurality of processes in the interaction topology relationship.
[0034] The second node is a node formed by the plurality of external devices in the interaction topology relationship.
[0035] The edge is used to represent the interaction relationship between the nodes, and is a visualized form of the node association relationship.
[0036] The node association relationship is the association relationship (such as the interaction relationship) between the nodes in the interaction topology relationship, including the external interaction relationship.
[0037] The external interaction relationship is used to represent the interaction relationship between the processes and the external devices, and reflects how the processes of the charging pile operation system interact with the external devices.
[0038] Among them, it involves multiple external devices, which are external devices interacting with the charging pile operating system, such as payment terminals, human-machine interaction (HMI) interfaces, and charging controllers.
[0039] By calling the interaction topology relationship of the charging pile operating system, the interaction architecture and association between multiple processes and multiple external devices in the charging pile operating system can be determined, and further analysis basis for the comprehensive analysis of the process and external device interaction process is provided.
[0040] S106, according to the current interaction data and the interaction topology relationship, determine the target risk chain corresponding to the charging pile operating system, wherein the target risk chain includes at least one target process and at least one target external device, the target process is the process risk index of the process in the multiple processes greater than the process risk threshold, and the target external device is the device risk index of the external device in the multiple external devices greater than the device risk threshold.
[0041] In step S106 provided in the present application, the target risk chain corresponding to the charging pile operating system is determined according to the current interaction data and the interaction topology relationship.
[0042] Among them, it involves the target risk chain, which is a link containing high-risk processes and high-risk external devices determined by analyzing the interaction topology relationship and the current interaction data in the charging pile operating system, reflecting the potential risk propagation path in the charging pile operating system.
[0043] Among them, it involves the target process, which is the process in the multiple processes of the charging pile operating system whose process risk index exceeds the set process risk threshold. These processes are considered to be high-risk and may pose a threat to the security of the system.
[0044] Among them, it involves the target external device, which is the device in the multiple external devices of the charging pile operating system whose device risk index exceeds the set device risk threshold. These devices are also considered to be high-risk and may introduce security risks through interaction with processes.
[0045] Among them, it involves the process risk index, which is used to measure the risk degree of each process in the charging pile operating system.
[0046] Among them, it involves the process risk threshold, which is a preset value used to determine whether the process is a high-risk process. When the risk index of the process exceeds this threshold, the process is identified as a high-risk process and needs to be focused on and protected.
[0047] Among them, the device risk index is involved, which is used to measure the risk degree of each external device in the charging pile operation system.
[0048] Among them, the device risk threshold is involved, which is used to judge whether the external device belongs to a high-risk device. When the risk index of the device exceeds this threshold, the device is identified as a high-risk device that needs to be focused on and protected.
[0049] According to the current interaction data, the real-time interaction state of the process and the external device in the charging pile operation system can be obtained, and combined with the interaction topology relationship, the interaction logic between the process and the external device can be accurately determined. Therefore, the target process whose risk index exceeds the threshold in the process and the target external device whose risk index exceeds the threshold in the external device can be accurately identified, and then the target risk chain containing these high-risk elements can be constructed.
[0050] S108, according to the target risk chain, determine the security protection strategy corresponding to the charging pile operation system.
[0051] In step S108 provided in the present application, according to the target risk chain, the security protection strategy corresponding to the charging pile operation system is determined.
[0052] Among them, the security protection strategy is involved, which is a protection strategy for coping with security threats in the charging pile operation system, including access control, data encryption, anomaly detection, resource limitation, etc., to ensure the safe operation of the charging pile operation system.
[0053] According to the current interaction data and the interaction topology relationship, the target risk chain is determined, which can ensure that the security protection strategy of the charging pile operation system accurately focuses on the high-risk link, avoids ignoring the potential systemic risk propagation path due to isolated analysis of a single node, realizes the safe dynamic detection and active defense of the high-risk process and external device, and improves the overall security and protection efficiency of the system.
[0054] By the above steps S102-S108, the current interaction data of the charging pile operation system is obtained; the interaction topology relationship of the charging pile operation system is called, wherein the charging pile operation system includes a plurality of processes, the interaction topology relationship includes a first node formed by the plurality of processes, a second node formed by a plurality of external connected devices, and an edge formed by a node association relationship, and the node association relationship includes an external interaction relationship, the external interaction relationship represents an interaction relationship between the processes and the external connected devices, and the plurality of external connected devices are devices having an interaction relationship with the charging pile operation system; according to the current interaction data and the interaction topology relationship, a target risk chain corresponding to the charging pile operation system is determined, wherein the target risk chain includes at least one target process and at least one target external connected device, the target process is a process in the plurality of processes whose process risk index is greater than a process risk threshold, and the target external connected device is an external connected device in the plurality of external connected devices whose device risk index is greater than a device risk threshold; and a security protection strategy corresponding to the charging pile operation system is determined according to the target risk chain. By obtaining the current interaction data of the charging pile operation system, the actual interaction state of the processes and the external connected devices can be mastered in real time, and a dynamic basis is provided for risk determination. The interaction topology relationship includes the first node (process), the second node (external connected device), and the node association relationship, so that the interaction architecture of the processes and the devices can be clearly determined. Therefore, by combining the current interaction data and the interaction topology relationship, the target risk chain including the high-risk processes and the external connected devices can be determined, the systematic risk caused by the linkage of the single high-risk node can be avoided by looking at the single high-risk node in isolation, and the security protection strategy of the charging pile operation system can be accurately determined based on the target risk chain, so as to avoid resource waste or key risk omission caused by indiscriminate protection, and thus the technical problem that the security protection strategy of the charging pile operation system is not accurately determined in the related art is solved.
[0055] As an optional embodiment, according to the current interaction data and the interaction topology relationship, the target risk chain corresponding to the charging pile operation system is determined, including: according to the current interaction data, determining a first risk index corresponding to each external interaction relationship in the interaction topology relationship; according to the first risk index corresponding to each external interaction relationship in the interaction topology relationship, determining a first interaction relationship from the plurality of external interaction relationships, wherein the first interaction relationship is an external interaction relationship whose first risk index is greater than a first risk threshold; and according to the first interaction relationship and the interaction topology relationship, determining the target risk chain corresponding to the charging pile operation system.
[0056] In this embodiment, the specific steps of determining the target risk chain corresponding to the charging pile operation system according to the current interaction data and the interaction topology relationship are described.
[0057] The first risk index is involved, which is used to measure the risk degree of each external interaction relationship.
[0058] Among them, the first interaction relationship is related to the first interaction relationship in the plurality of external interaction relationships, and the first risk index is greater than the preset first risk threshold. These interaction relationships are considered to be high-risk and need to be further analyzed and monitored to determine whether they will pose a threat to the safety of the charging pile operation system.
[0059] Among them, the first risk threshold is related to the first risk threshold for determining whether the external interaction relationship belongs to high-risk. When the first risk index of a certain external interaction relationship exceeds this threshold, the interaction relationship is identified as a high-risk interaction relationship that needs to be focused on and analyzed.
[0060] According to the current interaction data, the first risk index of the external interaction relationship is determined, which can quantify the risk degree of each interaction relationship; by screening out the external interaction relationship whose first risk index exceeds the threshold to determine the first interaction relationship, the high-risk interaction path can be accurately identified; and then the target risk chain is determined in combination with the interaction topological relationship, the potential risks of the charging pile operation system are comprehensively sorted and accurately positioned, and reliable basis is provided for subsequent development of targeted security protection strategies.
[0061] As an optional embodiment, according to the first interaction relationship and the interaction topological relationship, the target risk chain corresponding to the charging pile operation system is determined, including: in the case that the node association relationship includes process interaction relationship and device interaction relationship, determining the second risk index corresponding to each process interaction relationship in the interaction topological relationship and the third risk index corresponding to each device interaction relationship; according to the second risk index corresponding to each process interaction relationship, determining the second interaction relationship from the plurality of process interaction relationships, wherein the second interaction relationship is the process interaction relationship in the plurality of process interaction relationships whose second risk index is greater than the second risk threshold; according to the third risk index corresponding to each device interaction relationship, determining the third interaction relationship from the plurality of device interaction relationships, wherein the third interaction relationship is the device interaction relationship in the plurality of device interaction relationships whose third risk index is greater than the third risk threshold; according to the first interaction relationship, the second interaction relationship, the third interaction relationship, and the interaction topological relationship, the target risk chain corresponding to the charging pile operation system is determined.
[0062] In this embodiment, the specific steps of determining the target risk chain corresponding to the charging pile operation system according to the first interaction relationship and the interaction topological relationship are described.
[0063] Among them, the second risk index is related to the risk degree of the corresponding process interaction relationship in the interaction topological relationship.
[0064] Among them, the third risk index is involved, which is used to measure the risk degree of the corresponding device interaction relationship in the interaction topology relationship.
[0065] Among them, the second interaction relationship is involved, which is the interaction relationship in the multiple process interaction relationships whose second risk index is greater than the preset second risk threshold. These interaction relationships are considered high-risk process interaction relationships and need to be further analyzed and monitored to determine whether they will pose a threat to the security of the charging pile operating system.
[0066] Among them, the second risk threshold is involved, which is used to determine whether the process interaction relationship belongs to high-risk. When the second risk index of a certain process interaction relationship exceeds this threshold, the interaction relationship is identified as a high-risk interaction relationship that needs to be focused on and analyzed.
[0067] Among them, the third interaction relationship is involved, which is the interaction relationship in the multiple device interaction relationships whose third risk index is greater than the preset third risk threshold. These interaction relationships are considered high-risk device interaction relationships and need to be further analyzed and monitored to determine whether they will pose a threat to the security of the charging pile operating system.
[0068] Among them, the third risk threshold is involved, which is used to determine whether the device interaction relationship belongs to high-risk. When the third risk index of a certain device interaction relationship exceeds this threshold, the interaction relationship is identified as a high-risk interaction relationship that needs to be focused on and analyzed.
[0069] By determining the second risk index of the multiple process interaction relationships and the third risk index of the multiple device interaction relationships in the interaction topology relationship, the risk degree of logical layer process cooperation and physical layer device linkage can be accurately quantified. Then, according to the corresponding risk threshold, high-risk second interaction relationships and third interaction relationships can be screened out, focusing on key risk points such as abnormal calls between processes and abnormal linkages between devices. Combined with the determined high-risk external connection interaction relationship (first interaction relationship) and the inherent architecture of the interaction topology relationship, the high-risk association relationships scattered in the logical layer, physical layer and cross-layer can be linked into a complete target risk chain, avoiding the omission of risks in the transmission path between processes, devices and processes and devices. Ensure that the target risk chain covers all-dimensional risk associations and provide comprehensive and focused core basis for the accurate formulation of subsequent security protection strategies.
[0070] As an optional embodiment, the target risk chain corresponding to the charging pile operation system is determined according to the first interaction relationship, the second interaction relationship, the third interaction relationship, and the interaction topology relationship, including: determining the first risk propagation feature corresponding to the charging pile operation system according to the first interaction relationship and the interaction topology relationship; determining the second risk propagation feature corresponding to the charging pile operation system according to the second interaction relationship, the first risk propagation feature, and the interaction topology relationship; determining the third risk propagation feature corresponding to the charging pile operation system according to the third interaction relationship, the first risk propagation feature, the second risk propagation feature, and the interaction topology relationship; and determining the target risk chain corresponding to the charging pile operation system according to the third risk propagation feature.
[0071] In this embodiment, the specific steps of determining the target risk chain corresponding to the charging pile operation system according to the first interaction relationship, the second interaction relationship, the third interaction relationship, and the interaction topology relationship are illustrated.
[0072] Among them, the first risk propagation feature is analyzed based on the first interaction relationship (i.e. high-risk external connection interaction relationship) and the interaction topology relationship, and the characteristics of the security risk propagation between processes and external connected devices, such as propagation path and propagation mode.
[0073] Among them, the second risk propagation feature is analyzed based on the first risk propagation feature, combined with the second interaction relationship (high-risk process interaction relationship) and the interaction topology relationship, and the characteristics of the security risk propagation between processes and external connected devices, and between processes, such as propagation path and propagation mode.
[0074] Among them, the third risk propagation feature is analyzed based on the third interaction relationship (i.e. high-risk device interaction relationship), the first and second risk propagation features, and the interaction topology relationship, and the characteristics of the security risk propagation between processes and external connected devices, between processes, and between external connected devices, such as propagation path and propagation mode.
[0075] First, according to the high-risk external connection interaction relationship (first interaction relationship) and the interaction topological relationship, the first risk propagation characteristic of the security risk propagation between the process and the external connection device is determined, which can build a basic analysis framework of risk propagation, and clearly define the core path and mode of the initial risk propagation; on this basis, combined with the high-risk process interaction relationship (second interaction relationship) and the interaction topological relationship, the second risk propagation characteristic of the propagation between the process and the external connection device and the process and the process is further determined, which can expand the analysis dimension of risk propagation and complete the key law of risk diffusion between processes; then, the third risk propagation characteristic of the full-scene propagation between the process and the external connection device, the process and the process, and the external connection device is determined by integrating the high-risk device interaction relationship (third interaction relationship), the first and second risk propagation characteristics, and the interaction topological relationship, which can realize the comprehensive control of the risk propagation law and avoid missing the multi-dimensional risk transmission path; finally, the target risk chain is determined according to the third risk propagation characteristic, which can accurately determine the complete link of risk propagation in the system, provide accurate basis for subsequent targeted risk blocking and protection enhancement, and ensure that the security protection of the charging pile operating system is more comprehensive and targeted.
[0076] As an optional embodiment, before the interaction topological relationship of the charging pile operating system is called, the process interaction data corresponding to the charging pile operating system, the device interaction data, and the external connection interaction data are obtained; the first topological relationship corresponding to the charging pile operating system is determined according to the process interaction data, wherein the first topological relationship represents the topological structure between the multiple processes in the charging pile operating system; the second topological relationship corresponding to the charging pile operating system is determined according to the device interaction data, wherein the second topological relationship represents the topological structure between the multiple external connection devices in the charging pile operating system; and the interaction topological relationship corresponding to the charging pile operating system is determined according to the external connection interaction data, the first topological relationship, and the second topological relationship.
[0077] In this embodiment, the specific steps before the interaction topological relationship of the charging pile operating system is called are explained.
[0078] Among them, the process interaction data is involved, which is the interaction data between multiple processes in the charging pile operating system, reflecting the interaction between processes.
[0079] Among them, the device interaction data is involved, which is the interaction data between multiple external connection devices in the charging pile operating system, reflecting the interaction between external connection devices.
[0080] Among them, the external connection interaction data is involved, which is the interaction data between the process and the external connection device in the charging pile operating system, reflecting the interaction between the process and the external connection device.
[0081] The first topological relationship is a topological structure among a plurality of processes in the charging pile operating system, and describes an interaction logic architecture among the processes.
[0082] The second topological relationship is a topological structure among a plurality of external connected devices in the charging pile operating system, and describes an interaction logic architecture among the external connected devices.
[0083] The process interaction data, the device interaction data and the external connection interaction data of the charging pile operating system are acquired, so that the interaction inside and outside the system can be comprehensively mastered; the first topological relationship and the second topological relationship are respectively determined according to the data, so that the interaction logic architecture among the processes and among the external connected devices can be clearly described; finally, the interaction topological relationship is determined in combination with the external connection interaction data and the two topological relationships, so that the integrity and accuracy of the interaction topological relationship can be ensured, and the charging pile operating system interaction architecture can be accurately described, thereby providing a reliable basis for subsequent risk analysis and security protection strategy formulation.
[0084] As an optional embodiment, determining the interaction topological relationship corresponding to the charging pile operating system according to the external connection interaction data, the first topological relationship and the second topological relationship comprises: determining an initial topological relationship corresponding to the charging pile operating system according to the external connection interaction data, the first topological relationship and the second topological relationship, wherein there is a connected edge between any two first nodes and second nodes in a plurality of target nodes of the initial topological relationship, the plurality of target nodes include a first node composed of a plurality of processes and a second node composed of a plurality of external connected devices; according to the execution order of the plurality of first nodes, for any one of the plurality of first nodes, the running state of other first nodes in the plurality of first nodes except the any one first node is unchanged, and the running state of the any one first node is adjusted to obtain an adjusted running state; determining a state change index corresponding to each of the plurality of second nodes according to the adjusted running state; determining a change node corresponding to the any one first node from the plurality of second nodes according to the state change index corresponding to each of the plurality of second nodes, wherein the corresponding change node is a second node with a state change index greater than a state change threshold, until the plurality of first nodes are processed, to obtain a change node corresponding to each of the plurality of first nodes; and adjusting the initial topological relationship according to the change node corresponding to each of the plurality of first nodes to obtain the interaction topological relationship corresponding to the charging pile operating system.
[0085] In this embodiment, the specific steps of determining the interaction topological relationship corresponding to the charging pile operating system according to the external connection interaction data, the first topological relationship and the second topological relationship are described.
[0086] The initial topological relationship is constructed based on the external interaction data, the first topological relationship, and the second topological relationship.
[0087] The plurality of target nodes includes a first node composed of a plurality of processes and a second node composed of a plurality of external devices.
[0088] The running state is the execution state of each process (first node) at a certain time. The running state can include the activity state, resource occupation, data transmission, and the like of the process. By adjusting the running state, the influence on other nodes (such as the second node) can be observed.
[0089] The state change index is used to measure the degree of change in the state of the second node after the running state of the first node is adjusted. The higher the state change index, the more significant the state change of the node.
[0090] The state change threshold is used to determine whether the state change of a node is significant. When the state change index of a certain node exceeds this threshold, the node is considered to be a state change significant node (i.e., a change node).
[0091] The change node is a node whose state change index is greater than a preset state change threshold among the plurality of second nodes.
[0092] The initial topological relationship is determined based on the external interaction data, the first topological relationship, and the second topological relationship, which can construct a preliminary architecture of the interaction between the processes and the external devices in the charging pile operation system. By adjusting the running state of each first node one by one and observing its influence on the second node, the change node with a significant state change is determined, which can accurately identify the key influencing point in the process and device interaction. Based on these change nodes, the initial topological relationship is adjusted, which can ensure that the interaction topological relationship dynamically reflects the real interaction of the system, to accurately depict the interaction architecture of the charging pile operation system, and provide a reliable basis for subsequent risk assessment and security protection strategy formulation.
[0093] As an optional embodiment, according to the target risk chain, a security protection strategy corresponding to the charging pile operation system is determined, including: for a target process in the target risk chain, determining a process risk time sequence feature corresponding to the target process; for a target external device in the target risk chain, determining a device risk time sequence feature corresponding to the target external device; and determining a security protection strategy corresponding to the charging pile operation system based on the process risk time sequence feature and the device risk time sequence feature.
[0094] This embodiment describes the specific steps for determining the security protection strategy corresponding to the charging pile operating system based on the target risk chain.
[0095] This involves the temporal characteristics of process risk, which are the patterns of change in the risk characteristics of the target process in the target risk chain over time.
[0096] This involves the temporal characteristics of equipment risk, which are the patterns of change in the risk characteristics of externally connected equipment in the target risk chain over time.
[0097] Determining the process risk timing characteristics of the target process and the device risk timing characteristics of the target external equipment in the target risk chain can accurately capture the dynamic change patterns of risks. Based on these timing characteristics, the formulation of security protection strategies can ensure the real-time nature and pertinence of protection measures, avoid protection failures caused by dynamic changes in risks, achieve dynamic security protection of the charging pile operating system, and improve the overall security of the system.
[0098] Based on the above embodiments and optional embodiments, an optional implementation method is provided, which is described in detail below.
[0099] In related technologies, charging piles, as a critical infrastructure for electric vehicles, directly affect the stability and reliability of the charging process through the security protection of their operating systems. However, in these technologies, there is a technical problem of inaccurate determination of security protection strategies for the charging pile operating system.
[0100] There is currently no effective solution to the above problems.
[0101] In view of this, an optional embodiment of the present invention provides a method for determining the security protection strategy of a charging pile operating system, which can effectively solve the above-mentioned technical problems.
[0102] S1, obtain the current interaction data of the charging pile operating system;
[0103] Specifically, it collects real-time data on the interactions between the charging pile's operating system and external devices or internal processes during operation. This data reflects the charging pile's current operating status and interaction status.
[0104] S2, retrieve the interaction topology of the charging pile operating system. The charging pile operating system includes multiple processes. The interaction topology includes a first node composed of multiple processes, a second node composed of multiple external devices, and edges composed of node association relationships. The node association relationships include external interaction relationships, which represent the interaction relationships between processes and external devices. The multiple external devices are devices that have interaction relationships with the charging pile operating system.
[0105] Furthermore, before retrieving the interaction topology of the charging pile operating system, it may also include:
[0106] Acquire process interaction data, device interaction data, and external connection interaction data corresponding to the charging pile operating system; based on the process interaction data, determine a first topological relationship corresponding to the charging pile operating system, wherein the first topological relationship represents the topological structure between multiple processes in the charging pile operating system; based on the device interaction data, determine a second topological relationship corresponding to the charging pile operating system, wherein the second topological relationship represents the topological structure between multiple external devices in the charging pile operating system; based on the external connection interaction data, the first topological relationship, and the second topological relationship, determine an initial topological relationship corresponding to the charging pile operating system, wherein any two first nodes and second nodes among the multiple target nodes in the initial topological relationship are connected by an edge, and the multiple target nodes include a first node composed of multiple processes and a second node composed of multiple external devices; according to multiple first... The execution order of the nodes is as follows: For any one of the multiple first nodes, the running state of the other first nodes remains unchanged, and the running state of the first node is adjusted to obtain the adjusted running state; based on the adjusted running state, the state change index corresponding to each of the multiple second nodes is determined; based on the state change index corresponding to each of the multiple second nodes, the change node corresponding to any one of the first nodes is determined from the multiple second nodes, where the corresponding change node is the second node whose state change index is greater than the state change threshold, until the multiple first nodes have been processed, and the change nodes corresponding to each of the multiple first nodes are obtained; based on the change nodes corresponding to each of the multiple first nodes, the initial topology is adjusted to obtain the interaction topology corresponding to the charging pile operating system.
[0107] Specifically, in the charging pile operating system, process interaction data, device interaction data, and external connection interaction data are first acquired to construct a first topological relationship between processes (inter-process interaction architecture) and a second topological relationship between external devices (inter-device interaction architecture). Then, combined with the external connection interaction data, an initial topological relationship is formed, which includes process nodes (first nodes) and external device nodes (second nodes), with edges representing their interaction relationships. Next, by adjusting the running state of each process node one by one, the state change index of the external device nodes is observed, and nodes with significant state changes (changing nodes) are selected. Based on these changing nodes, the initial topological relationship is dynamically adjusted (for example, for the second node, only the edges between changing nodes and the first node are retained, and the edges between non-changing nodes and the first node are deleted). Finally, a complete interaction topological relationship is generated, clarifying the interaction architecture and risk propagation path between processes and external devices in the charging pile operating system.
[0108] S3. Based on the current interaction data and interaction topology, determine the target risk chain corresponding to the charging pile operating system. The target risk chain includes at least one target process and at least one target external device. The target process is the process with a process risk index greater than the process risk threshold among multiple processes, and the target external device is the external device with a device risk index greater than the device risk threshold among multiple external devices.
[0109] Furthermore, S3 may also include:
[0110] Based on the current interaction data, determine the first risk index corresponding to each of the multiple external interaction relationships in the interaction topology; based on the first risk index corresponding to each of the multiple external interaction relationships in the interaction topology, determine the first interaction relationship from the multiple external interaction relationships, wherein the first interaction relationship is an external interaction relationship whose first risk index is greater than a first risk threshold; when the node association relationship includes process interaction relationships and device interaction relationships, determine the second risk index corresponding to each of the multiple process interaction relationships in the interaction topology, and the third risk index corresponding to each of the multiple device interaction relationships; based on the second risk index corresponding to each of the multiple process interaction relationships, determine the second interaction relationship from the multiple process interaction relationships, wherein the second interaction relationship is a multiple process interaction relationship whose second risk index is greater than a second risk threshold. The process interaction relationship of the threshold; based on the third risk index corresponding to each of the multiple device interaction relationships, the third interaction relationship is determined from the multiple device interaction relationships, wherein the third interaction relationship is the device interaction relationship in which the third risk index is greater than the third risk threshold; based on the first interaction relationship and the interaction topology relationship, the first risk propagation feature corresponding to the charging pile operating system is determined; based on the second interaction relationship, the first risk propagation feature, and the interaction topology relationship, the second risk propagation feature corresponding to the charging pile operating system is determined; based on the third interaction relationship, the first risk propagation feature, the second risk propagation feature, and the interaction topology relationship, the third risk propagation feature corresponding to the charging pile operating system is determined; based on the third risk propagation feature, the target risk chain corresponding to the charging pile operating system is determined.
[0111] Specifically, in the charging pile operating system, by analyzing current interaction data and interaction topology, a first risk index is first calculated for each external interaction relationship, and high-risk external interaction relationships (first interaction relationships) with risk indices exceeding the first risk threshold are selected. Next, process interaction relationships and device interaction relationships are further analyzed, and their second and third risk indices are calculated respectively. High-risk process interaction relationships (second interaction relationships) and high-risk device interaction relationships (third interaction relationships) with risk indices exceeding the corresponding thresholds are selected. Based on these high-risk interaction relationships, the propagation characteristics of risk between processes and external devices, between processes, and between devices are gradually determined (first, second, and third risk propagation characteristics). Finally, by combining these risk propagation characteristics, a target risk chain containing high-risk processes and high-risk external devices is constructed, thereby accurately identifying potential risk propagation paths in the charging pile operating system.
[0112] S4. Based on the target risk chain, determine the security protection strategy corresponding to the charging pile operating system.
[0113] Furthermore, S4 may also include:
[0114] For the target process in the target risk chain, determine the process risk timing characteristics corresponding to the target process; for the target external device in the target risk chain, determine the device risk timing characteristics corresponding to the target external device; based on the process risk timing characteristics and the device risk timing characteristics, determine the security protection strategy corresponding to the charging pile operating system.
[0115] Specifically, in the charging pile operating system, the risk temporal characteristics (i.e., the pattern of risk change over time) of high-risk processes and external devices in the target risk chain are analyzed. For the target process, its risk performance at different points in time is determined (e.g., risk increase or decrease trend); for the target external devices, their risk change characteristics are similarly analyzed. Based on these temporal characteristics, targeted security protection strategies are formulated, such as implementing stricter security protection for processes with an increasing risk trend, or encrypting communication and restricting access for high-risk external devices, thereby dynamically adjusting protection measures to ensure the safe operation of the charging pile operating system.
[0116] Furthermore, addressing the process-peripheral (i.e., externally connected devices) association mapping relationship, a protection and detection index system that satisfies the deep coupling of "process, port, and peripheral" is constructed. This forms an integrated security solution for forward checking and reverse hardening under the corresponding test command library, thereby further resolving a series of difficulties such as the difficulty in customizing active protection strategies for charging piles, low detection efficiency, and poor configuration flexibility. Specifically, a process monitoring tool scans all running processes in the system to obtain key information for each process and identify peripheral devices (i.e., externally connected devices), including: charging controllers, metering chips / modules, payment terminals, communication modules, HMI interfaces, security modules, etc. Each peripheral typically corresponds to: a device file, a specific input / output (I / O) memory address range (peripheral register mapping), and a kernel driver module in the operating system. Subsequently, peripheral detection can be achieved by intercepting system calls and low-level operations initiated by processes that are related to hardware operations. Furthermore, based on the aforementioned process-peripheral detection, by deeply detecting the specific operations of the interaction between the process and the underlying hardware peripherals, a precise mapping relationship and access control policy are established. This enables the construction of a proactive security protection system for the charging pile operating system, which is a closed-loop linkage of policy application, detection execution, and optimization. Compared with the existing direct process detection, this system improves the accuracy of protection against core physical risks and enhances the detection accuracy. It strengthens deeper defense and finer-grained access control and resource management, surpassing traditional detection methods that only focus on the attributes of the process itself. It is an indispensable key link in the proactive protection system for charging pile information security.
[0117] The above optional implementation methods can achieve at least the following beneficial effects:
[0118] (1) Compared with related technologies, the present invention can obtain the current interaction data of the charging pile operating system, so as to grasp the actual interaction status of the process and the external device in real time, and provide dynamic basis for risk assessment. The interaction topology relationship includes the first node (process), the second node (external device) and the node association relationship, which can clarify the interaction architecture of the process and the device. By combining the current interaction data and the interaction topology relationship, the target risk chain containing high-risk processes and external devices can be determined. This can avoid looking at a single high-risk node in isolation and ignoring the systemic risks caused by its linkage. Based on the target risk chain, the security protection strategy of the charging pile operating system can be accurately determined, avoiding the waste of resources or the omission of key risks caused by indiscriminate protection. This solves the technical problem in related technologies where the security protection strategy of the charging pile operating system is not accurately determined.
[0119] (2) Compared with related technologies, this invention can accurately quantify the risk level of logical layer process collaboration and physical layer device linkage by determining the second risk index of multiple process interaction relationships and the third risk index of multiple device interaction relationships in the interaction topology. Then, based on the corresponding risk threshold, high-risk second and third interaction relationships can be screened out, which can focus on key risk points such as abnormal calls between processes and abnormal linkage between devices. Combined with the already determined high-risk external connection interaction relationship (first interaction relationship) and the inherent architecture of the interaction topology, it can connect the high-risk association relationships scattered in the logical layer, physical layer and cross layer into a complete target risk chain, avoid missing the transmission path of risks between processes, between devices and between processes and devices, and ensure that the target risk chain covers all-dimensional risk associations, providing a comprehensive and focused core basis for the accurate formulation of subsequent security protection strategies.
[0120] (3) Compared with related technologies, this invention first determines the first risk propagation characteristics of security risks between processes and external devices based on high-risk external interaction relationships (first interaction relationship) and interaction topology relationships. This can build a basic analysis framework for risk propagation and clarify the core path and mode of initial risk propagation. On this basis, combined with high-risk process interaction relationships (second interaction relationship) and interaction topology relationships, the second risk propagation characteristics, including propagation between processes and external devices and between processes, are further determined. This can expand the analysis dimensions of risk propagation and complete the key laws of risk diffusion between processes. Then, by integrating high-risk device interaction relationships (third interaction relationship), the first two risk propagation characteristics and interaction topology relationships, the third risk propagation characteristics covering the propagation of risks between processes and external devices, between processes, and between external devices are determined. This can achieve a comprehensive grasp of the laws of risk propagation and avoid missing multi-dimensional risk transmission paths. Finally, the target risk chain is determined based on the third risk propagation characteristics. This can accurately determine the complete link of risk propagation within the system and provide accurate basis for subsequent targeted risk blocking and enhanced protection, ensuring that the security protection of the charging pile operating system is more comprehensive and targeted.
[0121] (4) Compared with related technologies, the present invention can construct a preliminary architecture for the interaction between processes and external devices in the charging pile operating system by determining the initial topology relationship based on external interaction data, the first topology relationship and the second topology relationship; by adjusting the running state of each first node one by one and observing its impact on the second node, the change nodes with significant state changes can be identified, and the key impact points in the interaction between processes and devices can be accurately identified; by adjusting the initial topology relationship based on these change nodes, the interaction topology relationship can be ensured to dynamically reflect the real interaction of the system, so as to achieve an accurate characterization of the interaction architecture of the charging pile operating system and provide a reliable basis for subsequent risk assessment and security protection strategy formulation.
[0122] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that the present invention is not limited to the described order of actions, because according to the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to the present invention.
[0123] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of the present invention.
[0124] Example 2
[0125] According to an embodiment of the present invention, an apparatus for implementing the above-described method for determining the security protection strategy of a charging pile operating system is also provided. Figure 2 This is a structural block diagram of a security protection strategy determination device for a charging pile operating system according to an embodiment of the present invention, such as... Figure 2 As shown, the device includes: an acquisition module 202, a retrieval module 204, a first determination module 206, and a second determination module 208. The device will be described in detail below.
[0126] The module 202 is used to acquire the current interaction data of the charging pile operating system; the module 204 is connected to the acquisition module 202 and is used to retrieve the interaction topology of the charging pile operating system, wherein the charging pile operating system includes multiple processes, the interaction topology includes a first node composed of multiple processes, a second node composed of multiple external devices, and edges composed of node association relationships, the node association relationships include external interaction relationships, the external interaction relationships represent the interaction relationships between processes and external devices, and the multiple external devices are devices that have interaction relationships with the charging pile operating system; the first determination module 206 is connected to the retrieval module 204 and is used to determine the target risk chain corresponding to the charging pile operating system based on the current interaction data and the interaction topology, wherein the target risk chain includes at least one target process and at least one target external device, the target process is the process whose process risk index is greater than the process risk threshold among the multiple processes, and the target external device is the external device whose device risk index is greater than the device risk threshold among the multiple external devices; the second determination module 208 is connected to the first determination module 206 and is used to determine the security protection strategy corresponding to the charging pile operating system based on the target risk chain.
[0127] It should be noted that the above-mentioned acquisition module 202, retrieval module 204, first determination module 206 and second determination module 208 correspond to steps S102 to S108 in the method for determining the security protection strategy of the charging pile operating system. The multiple modules and the corresponding steps implement the same instances and application scenarios, but are not limited to the content disclosed in the above embodiment 1.
[0128] Example 3
[0129] According to another aspect of the present invention, an electronic device is also provided, comprising: a processor; and a memory for storing processor-executable instructions, wherein the processor is configured to execute instructions to implement the security protection strategy determination method of the charging pile operating system described above.
[0130] Example 4
[0131] According to another aspect of the present invention, a computer-readable storage medium is also provided, which, when the instructions in the computer-readable storage medium are executed by the processor of an electronic device, enables the electronic device to execute the security protection strategy determination method of the charging pile operating system described above.
[0132] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0133] In the above embodiments of the present invention, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0134] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.
[0135] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0136] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0137] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.
[0138] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A method for determining a security protection policy of a charging pile operation system, characterized in that, The method comprises: obtaining current interaction data of a charging pile operating system; calling an interaction topology relationship of the charging pile operating system, wherein the charging pile operating system comprises a plurality of processes, the interaction topology relationship comprises a first node formed by the plurality of processes, a second node formed by a plurality of external connection devices, and an edge formed by a node association relationship, the node association relationship comprises an external connection interaction relationship, the external connection interaction relationship represents an interaction relationship between a process and an external connection device, and the plurality of external connection devices are devices having an interaction relationship with the charging pile operating system; determining a target risk chain corresponding to the charging pile operating system according to the current interaction data and the interaction topology relationship, wherein the target risk chain comprises at least one target process and at least one target external connection device, the target process is a process in the plurality of processes whose process risk index is greater than a process risk threshold, and the target external connection device is an external connection device in the plurality of external connection devices whose device risk index is greater than a device risk threshold; determining a security protection strategy corresponding to the charging pile operating system according to the target risk chain.
2. The method of claim 1, wherein, The method of determining the target risk chain corresponding to the charging pile operating system according to the current interaction data and the interaction topology relationship comprises: determining a first risk index corresponding to each of a plurality of external connection interaction relationships in the interaction topology relationship according to the current interaction data; determining a first interaction relationship from the plurality of external connection interaction relationships according to the first risk index corresponding to each of the plurality of external connection interaction relationships in the interaction topology relationship, wherein the first interaction relationship is an external connection interaction relationship whose first risk index is greater than a first risk threshold; determining the target risk chain corresponding to the charging pile operating system according to the first interaction relationship and the interaction topology relationship.
3. The method of claim 2, wherein, The method of determining the target risk chain corresponding to the charging pile operating system according to the first interaction relationship and the interaction topology relationship comprises: in the case where the node association relationship comprises a process interaction relationship and a device interaction relationship, determining a second risk index corresponding to each of a plurality of process interaction relationships in the interaction topology relationship and a third risk index corresponding to each of a plurality of device interaction relationships; determining a second interaction relationship from the plurality of process interaction relationships according to the second risk index corresponding to each of the plurality of process interaction relationships, wherein the second interaction relationship is a process interaction relationship whose second risk index is greater than a second risk threshold in the plurality of process interaction relationships; determining a third interaction relationship from the plurality of device interaction relationships according to the third risk index corresponding to each of the plurality of device interaction relationships, wherein the third interaction relationship is a device interaction relationship whose third risk index is greater than a third risk threshold in the plurality of device interaction relationships; determining the target risk chain corresponding to the charging pile operating system according to the first interaction relationship, the second interaction relationship, the third interaction relationship, and the interaction topology relationship.
4. The method of claim 3, wherein, The first interaction relationship, the second interaction relationship, the third interaction relationship, and the interaction topological relationship are used to determine a target risk chain corresponding to the charging pile operation system, including: The first interaction relationship and the interaction topological relationship are used to determine a first risk propagation feature corresponding to the charging pile operation system; The second interaction relationship, the first risk propagation feature, and the interaction topological relationship are used to determine a second risk propagation feature corresponding to the charging pile operation system; The third interaction relationship, the first risk propagation feature, the second risk propagation feature, and the interaction topological relationship are used to determine a third risk propagation feature corresponding to the charging pile operation system; The third risk propagation feature is used to determine a target risk chain corresponding to the charging pile operation system.
5. The method of claim 1, wherein, Before the interaction topological relationship of the charging pile operation system is called, the following steps are further included: Process interaction data, device interaction data, and external connection interaction data corresponding to the charging pile operation system are obtained; The process interaction data is used to determine a first topological relationship corresponding to the charging pile operation system, wherein the first topological relationship represents a topological structure among multiple processes in the charging pile operation system; The device interaction data is used to determine a second topological relationship corresponding to the charging pile operation system, wherein the second topological relationship represents a topological structure among multiple external connection devices in the charging pile operation system; The external connection interaction data, the first topological relationship, and the second topological relationship are used to determine an interaction topological relationship corresponding to the charging pile operation system.
6. The method of claim 5, wherein, The external connection interaction data, the first topological relationship, and the second topological relationship are used to determine an interaction topological relationship corresponding to the charging pile operation system, including: The external connection interaction data, the first topological relationship, and the second topological relationship are used to determine an initial topological relationship corresponding to the charging pile operation system, wherein there is a connection edge between any two first nodes and second nodes in a plurality of target nodes of the initial topological relationship, the plurality of target nodes include a first node composed of multiple processes and a second node composed of multiple external connection devices; According to the execution order of the multiple first nodes, for any one first node in the multiple first nodes, the running state of other first nodes in the multiple first nodes except the any one first node is unchanged, and the running state of the any one first node is adjusted to obtain an adjusted running state; The adjusted running state is used to determine a state change index corresponding to each of the multiple second nodes; The state change index corresponding to each of the multiple second nodes is used to determine a change node corresponding to the any one first node from the multiple second nodes, wherein the corresponding change node is a second node with a state change index greater than a state change threshold, and until the multiple first nodes are processed, a change node corresponding to each of the multiple first nodes is obtained. According to the change nodes corresponding to the first nodes, the initial topology relationship is adjusted to obtain an interaction topology relationship corresponding to the charging pile operation system.
7. The method according to any one of claims 1 to 6, characterized in that, The security protection strategy corresponding to the charging pile operation system is determined according to the target risk chain, including: For a target process in the target risk chain, process risk time sequence characteristics corresponding to the target process are determined; For a target external connection device in the target risk chain, device risk time sequence characteristics corresponding to the target external connection device are determined; According to the process risk time sequence characteristics and the device risk time sequence characteristics, a security protection strategy corresponding to the charging pile operation system is determined. 8.A device for determining a security protection policy of a charging pile operation system, characterized in that, Including: An acquisition module is configured to acquire current interaction data of a charging pile operation system; A calling module is configured to call an interaction topology relationship of the charging pile operation system, wherein the charging pile operation system includes a plurality of processes, the interaction topology relationship includes first nodes formed by the plurality of processes, second nodes formed by a plurality of external connection devices, and edges formed by node association relationships, the node association relationships include external connection interaction relationships, the external connection interaction relationships represent interaction relationships between processes and external connection devices, and the plurality of external connection devices are devices having interaction relationships with the charging pile operation system; A first determination module is configured to determine a target risk chain corresponding to the charging pile operation system according to the current interaction data and the interaction topology relationship, wherein the target risk chain includes at least one target process and at least one target external connection device, the target process is a process in the plurality of processes having a process risk index greater than a process risk threshold value, and the target external connection device is an external connection device in the plurality of external connection devices having a device risk index greater than a device risk threshold value; A second determination module is configured to determine a security protection strategy corresponding to the charging pile operation system according to the target risk chain.
9. An electronic device, comprising: Including: A processor; A memory for storing instructions executable by the processor; The processor is configured to execute the instructions to implement the security protection strategy determination method of the charging pile operation system according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, When the instructions in the computer readable storage medium are executed by the processor of the electronic device, the electronic device can execute the security protection strategy determination method of the charging pile operation system according to any one of claims 1 to 7.