Power network-oriented network security attack and defense script automatic generation method, system and equipment and medium

By constructing survey models and knowledge graph models, combined with automatic generation and adversarial exercise models, the shortcomings of static script generation have been addressed, realizing intelligent and dynamic script generation for power networks, and enhancing the power network's practical ability to respond to network threats and its defensive effectiveness.

CN121367596APending Publication Date: 2026-01-20GUIZHOU POWER GRID CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511386944.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-26
Publication Date
2026-01-20

AI Technical Summary

Technical Problem

Existing cybersecurity attack and defense script generation technologies mainly rely on static methods and cannot achieve dynamic script generation. This results in power grids having difficulty understanding and lacking accuracy when dealing with cyber threats, making it difficult to flexibly respond to new threats.

Method used

By constructing survey and demand analysis models, combined with knowledge graph and automatic generation models, intelligent and dynamic script generation is achieved. Furthermore, through adversarial drills and evaluation models and emergency response training models, the practical ability to respond to cybersecurity threats is enhanced.

Benefits of technology

It significantly improves the power grid's ability to respond to cybersecurity threats, ensures the real-time updating and adaptability of scenarios, can more accurately simulate complex attack scenarios and defense strategies, improves the detection and response speed of new threats, and optimizes the defense effect.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121367596A_ABST
    Figure CN121367596A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of power network security, in particular to a power network-oriented network security attack and defense script automatic generation method, system and device and a medium, and aims to construct a survey model to perform demand investigation and formulate a demand analysis model to ensure that the generated script meets the actual demand; meanwhile, a knowledge graph model and an automatic generation model are constructed, and automatic generation of a high-simulation attack and defense script is achieved; different from a traditional static script generation method, the method adopts reinforcement learning, knowledge graph and automatic generation technologies, realizes real-time update and adaptability of the script, and accurately simulates a complex attack and defense scene; and in addition, adversarial drilling, vulnerability assessment and emergency response training are combined, so that the response speed and defense effect of the power network to novel threats are improved, and the system risk is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of power network security, and in particular to a network security attack and defense script automatic generation method, system, device and medium for power networks. BACKGROUND

[0002] With the continuous development of the power system and the application of intelligent technology, the security of the power network has been increasingly concerned. In order to effectively improve the protection capability of the power network, in recent years, the power industry has gradually applied network attack and defense drills, vulnerability assessment and emergency response technology. These technologies simulate possible network attack scenarios and defense strategies in the power system, providing a dynamic and customizable simulation environment for security drills, greatly improving the security and emergency response capability of the power network.

[0003] However, the existing network security attack and defense script generation technology mainly relies on static script generation methods, which cannot realize dynamic script generation. Static scripts have certain understanding difficulties in the display process, and may not accurately reflect real-time attack scenarios and defense strategies in the later actual application, thereby affecting the effect of security drills and the accuracy of emergency response. In addition, static scripts cannot flexibly respond to new threats in the power network, resulting in certain technical bottlenecks in the power industry in terms of network threat response. SUMMARY

[0004] In view of the above existing problems, the present application is proposed.

[0005] Therefore, the present application provides a network security attack and defense script automatic generation method and system for power networks to solve the problem of static script generation and inability to dynamically adapt to the security needs of the power network. By constructing an investigation model and a demand analysis model, the script is highly consistent with the actual demand; by using a knowledge graph model and an automatic generation model, intelligent and dynamic script generation is realized; and by combining the confrontation drill and evaluation model and the emergency response training model, the practical ability of the power network in responding to network security threats is improved.

[0006] To solve the above technical problems, the present application provides the following technical solutions:

[0007] In a first aspect, the present application provides a network security attack and defense script automatic generation method for power networks, comprising:

[0008] An investigation model is constructed for investigation, and a demand database is developed. When the investigation is completed, a demand analysis model is developed for demand analysis, and the analyzed demand is sorted out;

[0009] Key technologies are developed and implemented, and a knowledge graph model is constructed to sort out the knowledge graph. A script automatic generation model is developed to develop and generate scripts;

[0010] When the script is generated, the scene is simulated, and the confrontation drill and evaluation model is formulated, the drill and evaluation are carried out, and the emergency response training model is formulated to train the emergency response.

[0011] As a preferred scheme of the power network-oriented network security attack and defense script automatic generation method, the constructing investigation model comprises analyzing market demand and analyzing market supply, and the analyzing market demand comprises:

[0012] The analyzing market demand comprises identifying driving factors, user portrait and demand stratification, and customizing a script library to support attack and defense scheme generation according to an environment, standardizing an evaluation script, and unifying an attack path and a scoring standard;

[0013] The analyzing market supply comprises a standardized script library, an automatic generation platform, and a SaaS drill service.

[0014] As a preferred scheme of the power network-oriented network security attack and defense script automatic generation method, the formulating demand analysis model comprises comprehensive scene coverage, dynamic adaptability, and automation and interpretability, and the comprehensive scene coverage comprises:

[0015] The comprehensive scene coverage comprises an attack surface of a power network.

[0016] The dynamic adaptability comprises adapting to changes in a power system topology.

[0017] The automation and interpretability comprise reducing the time-consuming of manually writing scripts and generating an auditable attack and defense logic chain.

[0018] As a preferred scheme of the power network-oriented network security attack and defense script automatic generation method, the constructing knowledge graph model comprises power asset modeling and attack chain modeling, and the power asset modeling comprises:

[0019] The power asset modeling comprises taking a generator, a transformer, and an RTU as a graph node.

[0020] The attack chain modeling comprises expanding tactics based on an MITRE attack framework.

[0021] As a preferred scheme of the power network-oriented network security attack and defense script automatic generation method, the formulating script automatic generation model comprises reinforcement learning path planning and defense strategy reverse derivation, and the reinforcement learning path planning comprises:

[0022] The reinforcement learning path planning comprises using an intelligent agent to explore an attack path in a knowledge graph.

[0023] The defense strategy reverse derivation comprises automatically generating a defense script according to the attack path.

[0024] As a preferred scheme of the power network-oriented network security attack and defense scenario automatic generation method, the countermeasure drill and evaluation model comprises countermeasure drill automatic generation, vulnerability priority evaluation, input of newly discovered CVE vulnerability, automatic generation of a chain of exploitation of the CVE vulnerability in the environment, and output of an influence factor.

[0025] As a preferred scheme of the power network-oriented network security attack and defense scenario automatic generation method, the countermeasure drill and evaluation model comprises countermeasure drill automatic generation, vulnerability priority evaluation, input of newly discovered CVE vulnerability, automatic generation of a chain of exploitation of the CVE vulnerability in the environment, and output of an influence factor.

[0026] In a second aspect, the present application provides a power network-oriented network security attack and defense scenario automatic generation system, comprising:

[0027] A demand investigation module constructs an investigation model to conduct investigation and formulates a demand database, and when the investigation is completed, a demand analysis model is formulated to conduct demand analysis, and the analyzed demand is combed;

[0028] A scenario generation module formulates and implements key technologies, combs a knowledge graph by constructing a knowledge graph model, formulates a scenario automatic generation model to formulate and generate a scenario;

[0029] A drill evaluation module simulates a scene when the scenario is generated, formulates a countermeasure drill and evaluation model, conducts drill and evaluation, formulates an emergency response training model, and trains emergency response.

[0030] In a third aspect, the present application provides an electronic device, comprising:

[0031] A memory and a processor;

[0032] The memory is used to store computer executable instructions, and the processor is used to execute the computer executable instructions, which realize the steps of the power network-oriented network security attack and defense scenario automatic generation method.

[0033] In a fourth aspect, the present application provides a computer readable storage medium, which stores computer executable instructions, and the computer executable instructions realize the steps of the power network-oriented network security attack and defense scenario automatic generation method when executed by a processor.

[0034] Compared with the prior art, the application has the beneficial effects that: the application can automatically generate high-simulation attack and defense scripts for specific needs of the power network through intelligent script generation and dynamic rehearsal models, significantly improving the practical combat capability of the power network in response to network security threats. Unlike traditional static script generation methods, the application uses reinforcement learning, knowledge graph and automatic generation model to ensure real-time updating and adaptability of the script, which can more accurately simulate complex attack scenarios and defense strategies. In addition, through the combination of confrontation rehearsal, vulnerability assessment and emergency response training, the detection and response speed of the power network to new threats is improved, the defense effect is effectively optimized, and the system risk is reduced. BRIEF DESCRIPTION OF DRAWINGS

[0035] In order to more clearly illustrate the technical solutions of the embodiments of the application, the following will briefly introduce the drawings needed to be used in the embodiment description. Obviously, the drawings in the following description are only some embodiments of the application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of these drawings.

[0036] Figure 1 The overall flowchart of the power network-oriented network security attack and defense script automatic generation method according to an embodiment of the application. DETAILED DESCRIPTION

[0037] In order to make the above-mentioned purposes, features and advantages of the application more apparent and easy to understand, the specific embodiments of the application will be described in detail below with reference to the drawings of the specification. Obviously, the described embodiments are only a part of the embodiments of the application, rather than all the embodiments. Based on the embodiments in the application, all other embodiments obtained by those skilled in the art without creative labor should be within the protection scope of the application.

[0038] Embodiment 1, refer to Figure 1 For an embodiment of the application, a power network-oriented network security attack and defense script automatic generation method is provided, which comprises:

[0039] S1: Construct a survey model to conduct research and develop a demand database. When the research is completed, develop a demand analysis model to conduct demand analysis, and sort out the analyzed demand.

[0040] It should be noted that constructing a survey model includes analyzing market demand and analyzing market supply.

[0041] Further, the market demand is analyzed to identify driving factors, including compliance pressure and the emergence of new threats, and user portraits and demand stratification are performed. Specifically, high-fidelity scripts cover core scenarios such as dispatch automation systems and power distribution management systems; protocol attack defense scripts focus on the specific needs of new energy stations; customized script libraries support rapid generation of attack and defense solutions according to specific environments, shortening the delivery cycle; standardized evaluation scripts are used for security checks, with unified attack paths and scoring standards.

[0042] The analysis of market supply includes standardized script library, automated generation platform and SaaS-based exercise service; the standardized script library preinstalls common attack scenarios and provides PDF / Excel format documents; the automated generation platform dynamically generates scripts based on knowledge graph and AI algorithm (by modeling power assets and attack chains, intelligently planning attack paths and automatically deriving defense strategies, executable, visual and real-time updated customized exercise solutions are achieved) to support integration with digital twin systems; the SaaS-based exercise service provides a cloud-based attack and defense environment, generates scripts and performs exercises on demand (for example, when the defense end needs to be improved, a defense script is developed and exercised), thereby reducing hardware investment.

[0043] It should be noted that the demand analysis model includes comprehensive scenario coverage, dynamic adaptability, and automation and interpretability.

[0044] Further, comprehensive scenario coverage includes power network attack surface; for example, SCADA systems, smart meters, substation communication protocols, etc., simulate physical-network fusion attacks, such as through physical device intrusion control systems, an attacker (possibly an insider or a sneaking saboteur) connects a notebook computer with engineering software directly to the programming port of a programmable logic controller (PLC) to perform intrusion.

[0045] Dynamic adaptability includes updating attack paths according to changes in power system topology; for example, adding new power generation units, adjusting loads, supporting real-time threat intelligence integration such as CVE vulnerability library and APT organization behavior patterns.

[0046] Automation and interpretability include reducing the time-consuming of manually writing scripts, generating auditable attack and defense logic chains; providing quantitative indicators of attack success probability and defense measure effectiveness, and the quantitative indicators are used to measure the success probability of the attack path and the effectiveness of the defense strategy in the exercise and evaluation process, providing auditable basis for script optimization and security decision-making.

[0047] S2: Key technologies are developed and implemented, and a knowledge graph model is built to organize knowledge graphs and develop script automatic generation models to develop and generate scripts.

[0048] It should be noted that constructing the knowledge graph model includes power asset modeling and attack chain modeling.

[0049] Further, the power asset modeling includes taking the generator, transformer and RTU as the graph node; the communication protocol such as IEC 61850, DNP3 as the edge attribute, and the device vulnerability data such as the CPE matching in the NVD vulnerability database.

[0050] Among them, the attack chain modeling includes expanding the tactics based on the MITRE attack framework; for example, “tampering with the protection relay settings”, defining the transition conditions of the attack phase (initial access→execution→persistence→lateral movement→impact).

[0051] It should also be noted that developing a script automatic generation model includes path planning of reinforcement learning and defense strategy reverse derivation.

[0052] Further, the path planning of reinforcement learning includes using the agent to explore the attack path in the knowledge graph; designing the reward function, using the PPO or DQN algorithm to train the attack strategy model, and using the score of the vulnerability+reward of avoiding detection-penalty of defense measures blocking.

[0053] The defense strategy reverse derivation includes automatically generating a defense script according to the attack path; for example, isolating the infected device, deploying a honeypot, adjusting the firewall rule, combining the power business continuity requirement, and prioritizing the power supply of critical loads such as hospitals and traffic signals.

[0054] Further, developing a simulation environment model constructs a virtual environment, including digital twin technology and multi-protocol support.

[0055] The digital twin technology includes constructing a virtual mirror of the power system, synchronizing the physical device state such as line load and switch state in real time, and supporting attack effect visualization; for example, simulating the power grid topology change caused by substation explosion.

[0056] The multi-protocol support includes integrating the Modbus / TCP, IEC 104 and other industrial protocol simulators to support real attack payload testing.

[0057] S3: When the script is generated, simulate the scene, develop a countermeasure exercise and evaluation model, conduct exercise and evaluation, and develop an emergency response training model to train the emergency response.

[0058] It should be noted that developing a countermeasure exercise and evaluation model includes automatic generation of countermeasure exercise, vulnerability priority evaluation, input of newly discovered CVE vulnerability, automatic generation of CVE vulnerability chain of utilization in the environment, and output of influence factor.

[0059] Specifically, the red-blue confrontation drill is formulated, and a red team attack script is automatically generated; for example, the terminal permission of operation and maintenance is obtained through a phishing email, and then the AGC control instruction is tampered, and a blue team defense script is synchronously generated, such as abnormal detection based on a traffic baseline, SCADA system operation log auditing.

[0060] The vulnerability priority assessment inputs a newly discovered CVE vulnerability, and automatically generates a utilization chain of the newly discovered CVE vulnerability in the power environment; for example, a power grid model is obtained by unauthorized access to a historical data server, and a risk score CVSS+power business impact factor is output.

[0061] Further, the emergency response training model includes simulating a ransomware attack, and a phased recovery plan is automatically generated; and after the emergency training is completed, the problems generated in the training process are summarized and summarized, and different levels of emergency difficulty are formulated.

[0062] Specifically, the simulation of a ransomware attack causes the dispatching system to be paralyzed, and a phased recovery plan is automatically generated; after the emergency training is completed, the problems generated in the training process are summarized and summarized, and different levels of emergency difficulty are formulated, and are divided into first level, second level and third level, wherein the first level of emergency difficulty is the largest, and the third level of emergency difficulty is the smallest, and after the summary and summary are completed, different levels of emergency plans are formulated, which are first emergency plan, second emergency plan and third emergency plan, wherein the first emergency plan is used for emergency of the first level of difficulty, and the third emergency plan is used for emergency of the third level of difficulty.

[0063] Embodiment 2 is an embodiment of the present application, which provides a network security attack and defense script automatic generation method for power network. In order to verify the beneficial effects of the present application, economic benefit calculation and simulation experiment are used for scientific demonstration.

[0064] In the power network target field, the environment includes a core dispatching system, a power distribution management system and a plurality of virtual power generation units; the specific steps are as follows:

[0065] Environment initialization: deploy a digital twin system for synchronizing physical states to ensure that the state is close to the actual system; build a power asset knowledge graph, and prepare attack payloads (such as TLS tunnels, Cobalt Strike DNS channels, etc.) and defense strategy library in combination with attack chain information.

[0066] Attack and defense drill: generate a multi-stage attack and defense logic chain according to the preset target, and execute it in the simulation environment. The simulated attack includes TLS tunnel communication, Cobalt Strike DNS communication, etc., and the response is carried out through traffic detection, log auditing and defense strategy; record the attack path and defense response during the experiment.

[0067] Evaluation and iteration: Collect indicators such as attack success rate, defense response time, and device isolation time. According to the CVSS score and the qualitative analysis of the impact on the power system, optimize the attack and defense logic chain, and conduct multiple rounds of repeated testing to verify the feasibility of the strategy.

[0068] As shown in Table 1, the results of multiple rounds of drills show:

[0069] Attack path: The average time for Cobalt Strike TLS tunnel detection is about 37 seconds, which is about half of the initial test;

[0070] Defense effectiveness: The accuracy rate of lateral movement detection is about 90%-93%, and the average execution time of key device isolation is about 45 seconds;

[0071] According to the dynamic adjustment of the attack and defense strategy in the experimental environment, but under the condition of high load burst, there is still a delay in triggering some defense strategies, which needs to be optimized later.

[0072] Table 1 Malware communication traffic and network scanning attack detection statistics

[0073]

[0074]

[0075]

[0076] In Example 3, the above is a schematic scheme of a network security attack and defense script automatic generation method for a power network. It should be noted that the technical scheme of the network security attack and defense script automatic generation system for the power network belongs to the same concept as the technical scheme of the network security attack and defense script automatic generation method for the power network described above. The technical scheme of the network security attack and defense script automatic generation system for the power network in this embodiment is not described in detail. The details can be referred to the description of the technical scheme of the network security attack and defense script automatic generation method for the power network.

[0077] The embodiment also provides a network security attack and defense script automatic generation system for a power network, which includes:

[0078] The demand investigation module constructs an investigation model for investigation and formulates a demand database. When the investigation is completed, a demand analysis model is formulated for demand analysis, and the analyzed demand is combed;

[0079] The script generation module formulates and implements key technologies, and constructs a knowledge graph model to comb the knowledge graph, formulates a script automatic generation model to formulate and generate scripts;

[0080] The rehearsal evaluation module simulates the scene after the script is generated, and formulates an anti-rehearsal and evaluation model to perform rehearsal and evaluation, formulates an emergency response training model to train the emergency response.

[0081] The embodiment also provides an electronic device suitable for the automatic generation of the network security attack and defense script facing the power network, including a memory and a processor; the memory is used to store computer executable instructions, and the processor is used to execute the computer executable instructions to realize the method for automatically generating the network security attack and defense script facing the power network.

[0082] The embodiment also provides a storage medium having a computer program stored thereon, and the program is executed by the processor to realize the method for automatically generating the network security attack and defense script facing the power network.

[0083] The storage medium proposed in the embodiment and the method for automatically generating the network security attack and defense script facing the power network proposed in the above embodiment belong to the same inventive concept, and the technical details not described in the embodiment can be referred to the above embodiment, and the embodiment and the above embodiment have the same beneficial effects.

[0084] Through the above description of the embodiments, those skilled in the art can clearly understand that the present application can be realized by means of software and necessary general hardware, and of course can also be realized by hardware. Based on such understanding, the technical solutions of the present application or the part that contributes to the prior art can be embodied in the form of a software product. The computer software product can be stored in a computer readable storage medium, such as a floppy disk, a read-only memory (ROM), a random access memory (RAM), a FLASH memory, a hard disk or an optical disk, and includes a number of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods of various embodiments of the present application.

[0085] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present application but not limit the present application. Although the present application is described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present application can be modified or replaced by equivalents without departing from the spirit and scope of the present application, and all of them should be covered in the scope of the claims of the present application.

Claims

1. A power network-oriented network security attack-defense scenario automatic generation method, characterized in that, Comprise: Build a survey model for investigation and develop a demand database, when the investigation is completed, develop a demand analysis model for demand analysis, and sort out the demand after analysis; Develop and implement key technologies, and build a knowledge graph model to sort out the knowledge graph, and develop a script automatic generation model to develop and generate scripts; When the script is generated, simulate the scene, and develop a counter-attack exercise and evaluation model for exercise and evaluation, and develop an emergency response training model for emergency response training.

2. The power network oriented network security attack-defense scenario automatic generation method of claim 1, wherein, The construction of the survey model includes analysis of market demand and analysis of market supply, including: Analysis of market demand includes identifying driving factors, user profiling and demand stratification, customized script library supporting attack and defense scheme generation according to environment, standardized evaluation script, unified attack path and scoring standard; Analysis of market supply includes standardized script library, automatic generation platform and SaaS exercise service.

3. The power network oriented network security attack-defense scenario automatic generation method of claim 2, wherein, The demand analysis model includes comprehensive scene coverage, dynamic adaptability, and automation and interpretability, including: Comprehensive scene coverage includes power network attack surface; Dynamic adaptability includes changes in power system topology; Automation and interpretability include reducing the time-consuming of manual script writing and generating auditable attack and defense logic chain.

4. The power network oriented network security attack-defense scenario automatic generation method of claim 3, wherein, The construction of the knowledge graph model includes power asset modeling and attack chain modeling, including: Power asset modeling includes generators, transformers and RTUs as graph nodes; Attack chain modeling includes expanding tactics based on MITRE attack framework.

5. The power network oriented network security attack-defense scenario automatic generation method of claim 4, wherein, The script automatic generation model includes reinforcement learning path planning and defense strategy reverse deduction, including: Reinforcement learning path planning includes using agents to explore attack paths in the knowledge graph; Defense strategy reverse deduction includes automatically generating defense scripts from attack paths.

6. The power network oriented network security attack-defense scenario automatic generation method of claim 5, wherein, The development of the counter-attack exercise and evaluation model includes counter-attack exercise automatic generation, vulnerability priority evaluation, input of newly discovered CVE vulnerabilities, automatic generation of CVE vulnerability exploitation chains in the environment, and output of impact factors.

7. The power network oriented network security attack-defense scenario automatic generation method of claim 6, wherein, The development of the emergency response training model includes simulating ransomware attacks and automatically generating phased recovery plans; and after the emergency training is completed, the problems generated during the training process are summarized, and different levels of emergency difficulty are developed.

8. A power network-oriented network security attack-defense scenario automatic generation system, applying the power network-oriented network security attack-defense scenario automatic generation method according to any one of claims 1-7, characterized in that, Comprise: Demand research module, build a survey model for investigation and develop a demand database, when the investigation is completed, develop a demand analysis model for demand analysis, and sort out the demand after analysis; Script generation module, develop and implement key technologies, and build a knowledge graph model to sort out the knowledge graph, and develop a script automatic generation model to develop and generate scripts; Exercise and evaluation module, when the script is generated, simulate the scene, and develop a counter-attack exercise and evaluation model for exercise and evaluation, and develop an emergency response training model for emergency response training. 9.A computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the computer device is configured to perform the method according to any one of claims 1-8 when the computer program is executed by the processor. The processor executes the computer program to realize the steps of the power network-oriented network security attack and defense script automatic generation method of any one of claims 1 to 7. The processor executes the computer program to realize the steps of the power network-oriented network security attack and defense script automatic generation method of any one of claims 1 to 7.

10. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program, when executed by a processor, implements the steps of the power network oriented network security attack-defense scenario automatic generation method of any one of claims 1 to 7.