Power network security threat intelligence sharing method, system and device based on federated learning, and medium

By constructing a power network security threat intelligence sharing model based on federated learning, the problem of existing technologies being unable to conduct demonstration simulations of different intensities and evaluate the stress resistance of solutions was solved. This enabled cross-enterprise data sharing and collaboration, improving the security protection capabilities and data accuracy of power networks.

CN121367597APending Publication Date: 2026-01-20GUIZHOU POWER GRID CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511387087.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-26
Publication Date
2026-01-20

AI Technical Summary

Technical Problem

Existing power network security threat intelligence sharing mechanisms cannot conduct demonstrations and simulations of varying intensities to assess the resilience of solutions, and it is difficult to effectively collect issues encountered during drills, resulting in insufficient protection capabilities.

Method used

By employing a federated learning-based approach, we construct network probing, data filtering, encryption, and demonstration protection models, conduct multi-level demonstration simulations, and optimize the scheme through anomaly data models and joint protection sharing models to achieve cross-enterprise data sharing and collaboration.

Benefits of technology

It has improved the security protection capabilities of the power grid, enhanced the accuracy and reliability of data sharing, optimized the practical application effect of the solution, and improved the ability to respond to complex threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121367597A_ABST
    Figure CN121367597A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of power network security, in particular to a federated learning-based power network security threat intelligence sharing method, system and device and a medium, and the method comprises the steps: obtaining threat messages through constructing a network detection model, and forming a problem database; establishing a data screening model, performing data cleaning and verification, removing abnormal data and extracting features, and constructing an abnormal data model; key data are encrypted, an encryption model is constructed, demonstration protection simulation is performed after encryption is completed, a joint protection sharing model is formulated after simulation, and data sharing is realized; through federal learning, a power network security threat intelligence sharing model is constructed, and cross-mechanism data sharing is realized while data privacy is guaranteed; compared with the prior art, through simulation drilling and testing of different strengths, the compressive strength of the scheme is evaluated, problems are collected, the scheme is optimized, and the network security protection capability is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of power network security, and in particular to a power network security threat intelligence sharing method, system, device and medium based on federated learning. BACKGROUND

[0002] Currently, power network security threat intelligence sharing has become one of the key measures to improve the overall protection capability of the power system. Through standardized data exchange, cross-agency collaboration and regulatory policy support, power companies can effectively respond to complex network threats. Such intelligence sharing not only helps improve grid security, but also enhances the defense capabilities of each power company when facing new attack threats.

[0003] Although power network security threat intelligence sharing plays an important role in improving protection capabilities, it still faces a series of challenges in implementation. The main problems include insufficient data quality, poor technical compatibility, privacy protection issues, etc. Especially when sharing threat intelligence, it is not possible to demonstrate the scheme in advance, and even if a demonstration simulation is performed, it is not possible to perform demonstration simulations of different intensities. This makes it difficult to evaluate the pressure resistance of the developed scheme, and the problems that arise during the exercise cannot be effectively collected and fed back. To address these issues, the present application provides a feasible solution based on federated learning, which can perform demonstration simulations of different levels during scheme development and effectively collect problems that arise during the exercise, thereby optimizing the scheme and enhancing its practical application effect. SUMMARY

[0004] In view of the above existing problems, the present application is proposed.

[0005] Therefore, the present application provides a power network security threat intelligence sharing method and system based on federated learning to solve the problem of being unable to perform demonstration simulations of different intensities and evaluate the pressure resistance of the scheme in the prior art. Through multi-level demonstration simulation and problem collection optimization, the present application improves the security protection capability of the power network and promotes cross-enterprise data sharing and collaboration.

[0006] To solve the above technical problems, the present application provides the following technical solutions:

[0007] In a first aspect, the present application provides a power network security threat intelligence sharing method based on federated learning, comprising:

[0008] Constructing a network exploration model to obtain threat messages generated on the network, forming a problem database after obtaining, and constructing a communication sharing model;

[0009] A data screening model is established to clean the obtained data, the data sources are verified after cleaning, the abnormal data are removed when the verification is completed, and the characteristics of the abnormal data are extracted to construct an abnormal data model;

[0010] The key data is encrypted, and a key encryption model is constructed, a demonstration protection model is constructed after encryption, demonstration simulation is carried out, a joint protection sharing model is formulated after demonstration simulation, and data sharing is carried out.

[0011] As a preferred scheme of the power network security threat intelligence sharing method based on federated learning, wherein: the network exploration model comprises C2, IP address tracking, URL and domain name analysis, threat intelligence analysis of attack tactics and techniques generated on the network, and malware sample collection and analysis, including:

[0012] The C2 and IP address tracking identifies the relevant infrastructure and tools of the threat actor by collecting and analyzing the IP addresses of malware and command and control server communication;

[0013] The URL and domain name analysis includes checking the URL and domain name and subdomain name hosted by the malware;

[0014] The threat intelligence analysis of attack tactics and techniques generated on the network identifies new threats and actively builds knowledge about current threats by using the MITRE attack framework, applying TTPs for investigation;

[0015] The malware sample collection and analysis automatically detects known malware and identifies new variants by creating and applying YARA rules, and uses the built-in YARA search function of the threat intelligence service to find related samples.

[0016] As a preferred scheme of the power network security threat intelligence sharing method based on federated learning, wherein: the establishment of the data screening model includes demand analysis and strategy formulation, including:

[0017] The demand analysis includes clearly defining the screening target and specific requirements, collecting and integrating data, integrating multi-source data, and constructing a unified database;

[0018] The strategy formulation includes selecting a screening method according to the demand and data characteristics, defining screening conditions and parameters, setting tool configuration and deployment, selecting technical tools, configuring screening, and deploying to a production environment, then performing and verifying, running the screening process, and generating threat alerts.

[0019] As a preferred scheme of the power network security threat intelligence sharing method based on federated learning provided in the application, wherein: the construction of the abnormal data model comprises analysis of data source diversity and analysis of data format heterogeneity.

[0020] As a preferred scheme of the power network security threat intelligence sharing method based on federated learning provided in the application, wherein: the construction of the key encryption model comprises encryption of data, restriction of access, and establishment of a security audit mechanism, which comprises:

[0021] The encryption of data comprises encryption processing of the shared threat intelligence, and a plurality of encryption processing layers are set in the encryption process, and when the second encryption layer is reached, an alarm is triggered;

[0022] The restriction of access comprises implementation of an access control mechanism, and when access is required, authorized access information is held;

[0023] The establishment of the security audit mechanism comprises monitoring and recording of the information sharing process.

[0024] As a preferred scheme of the power network security threat intelligence sharing method based on federated learning provided in the application, wherein: the construction of the demonstration protection model comprises setting up a threat feature database after the extraction of the features of the network threat is completed, and constructing a data crawling and updating module to update the data in the threat database by crawling and feedback of the threat data obtained, and formulating different levels of demonstration protection schemes according to the extracted threat feature data, constructing a scheme problem collection library to collect problems in the demonstration process, and adjusting and updating the demonstration protection scheme after the collection is completed.

[0025] As a preferred scheme of the power network security threat intelligence sharing method based on federated learning provided in the application, wherein: the formulation of the joint protection sharing model comprises construction of a modular system, building of a platformized data middle office, and cross-domain collaborative updating, which comprises:

[0026] The construction of the modular system comprises decomposition of the data sharing process, decoupling of functions, and flexible configuration;

[0027] The building of the platformized data middle office comprises construction of a unified data middle office based on cloud computing, integration of business system data, and provision of standardized data services;

[0028] The cross-domain collaborative updating comprises power coordination and power transportation optimization.

[0029] In a second aspect, the application provides a power network security threat intelligence sharing system based on federated learning, comprising:

[0030] The network exploration module constructs a network exploration model, acquires threat messages generated on the network, forms a problem database after acquisition, and constructs a communication sharing model;

[0031] The data screening module establishes a data screening model, cleans the acquired data, verifies the data source after cleaning, eliminates abnormal data after verification, extracts the characteristics of abnormal data, and constructs an abnormal data model.

[0032] The protection sharing module encrypts the key data, constructs a key encryption model, constructs a demonstration protection model after encryption, performs demonstration simulation, formulates a joint protection sharing model after demonstration simulation, and performs data sharing.

[0033] In a third aspect, the present application provides an electronic device, comprising:

[0034] a memory and a processor;

[0035] The memory is used to store computer executable instructions, and the processor is used to execute the computer executable instructions, which realize the steps of the power network security threat intelligence sharing method based on federated learning.

[0036] In a fourth aspect, the present application provides a computer readable storage medium storing computer executable instructions, which realize the steps of the power network security threat intelligence sharing method based on federated learning when executed by a processor.

[0037] Compared with the prior art, the present application has the following advantages: the present application constructs a power network security threat intelligence sharing model based on a federated learning method, which can realize efficient data sharing across agencies while ensuring data privacy and security. Compared with existing centralized data sharing solutions, the present application can evaluate the pressure resistance of the sharing solution in advance through simulation and testing of different intensities, and collect problems that occur during the simulation process, thereby optimizing the solution and improving the network security protection capability. In addition, the present application can integrate multi-source data, improve the accuracy and reliability of the data by using data screening and anomaly detection models, and enhance the ability of the power network to respond to complex threats. BRIEF DESCRIPTION OF DRAWINGS

[0038] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed in the embodiment description. Obviously, the drawings in the following description are only some embodiments of the present application, and those skilled in the art can obtain other drawings according to these drawings without creative labor.

[0039] Fig. 1The overall flowchart of the power network security threat intelligence sharing method based on federated learning is shown in an embodiment of the present application.

[0040] Fig. 2 The design diagram of the power network security threat intelligence sharing method based on federated learning is shown in an embodiment of the present application.

[0041] Fig. 3 The schematic diagram of the power network security threat intelligence sharing method based on federated learning is shown in an embodiment of the present application. DETAILED DESCRIPTION

[0042] In order to make the above objectives, characteristics and advantages of the present application more obvious and easy to understand, the specific embodiments of the present application will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor should fall within the scope of protection of the present application.

[0043] Embodiment 1, refer to Figs. 1-3 In an embodiment of the present application, a power network security threat intelligence sharing method based on federated learning is provided, comprising:

[0044] S1: Construct a network exploration model to acquire threat messages generated on the network, form a problem database after acquisition, and construct a communication and sharing model.

[0045] It should be noted that constructing a network exploration model includes C2, IP address tracking, URL and domain name analysis, intelligence analysis of attack tactics and techniques generated on the network, and malicious software sample collection and analysis, as shown in Fig. 2

[0046] Further, C2, IP address tracking: the IP address used by malware to communicate with its command and control (C2) server is an important intelligence indicator. By collecting and analyzing IP addresses, relevant infrastructure and tools of threat actors are identified, and defense measures are updated.

[0047] URL and domain name analysis: checking domain names and subdomain names provides information about URLs used to host malware, which helps to identify phishing attack websites and more extensive infrastructure used by attackers.

[0048] ​Intelligence analysis of attack tactics and techniques generated on the network: using the MITRE attack framework, applying specific TTPs as part of the investigation, identifying emerging threats, and proactively building knowledge about current threats to prepare for potential future attacks, focusing on real-time rankings of the most popular TTPs detected in malware and phishing samples, selecting any TTP and submitting it to the threat intelligence lookup for searching for sandbox sessions where instances of it were found, thus gaining insight into the attacker's behavior patterns.

[0049] Malware sample collection and analysis: application of YARA rules, creation and application of YARA rules to automatically detect known malware and quickly identify new variants with similar characteristics, use of built-in YARA search functionality provided by threat intelligence services to upload, edit, store, and use custom rules to find related samples, thus gaining insight into the spread of malware and attack methods.

[0050] It should also be noted that the construction of a communication and sharing model includes digital platform sharing, regular meetings and training, and project cooperation and joint research.

[0051] Furthermore, digital platform sharing includes intranet platforms, mobile applications, and cloud platforms; among them, the intranet platform includes the construction of a unified data sharing platform, integrating device monitoring, operation analysis, fault handling, and other functional modules, realizing centralized storage and real-time access of data; mobile applications support querying device information, reporting faults, and receiving warnings; cloud platforms use cloud computing technology to realize cross-regional and cross-departmental data sharing and collaborative analysis, improving resource utilization efficiency.

[0052] Regular meetings and training include technical problem exchange, fault case analysis, and technical capability improvement; among them, technical problem exchange is carried out regularly to share the latest research results, technical difficulties, and their solutions; fault case analysis analyzes typical faults or accidents, summarizes lessons learned, and improves emergency response capabilities; technical capability improvement is carried out online or offline to improve the mastery and application of new technologies and new equipment.

[0053] Cooperation and joint research include cross-disciplinary technical research, cutting-edge technology cooperation, and standard development; among them, cross-disciplinary technical research focuses on common problems and concentrates resources for joint research; cutting-edge technology cooperation conducts technical research to promote technology application; standard development includes participation or leadership in standard development to enhance technology influence.

[0054] S2: Establish a data screening model to clean the obtained data, verify the data source after cleaning, remove abnormal data after verification, and extract the characteristics of abnormal data to build an abnormal data model.

[0055] It should be noted that establishing a data screening model includes demand analysis and strategy formulation, as shown in Fig. 2 , Fig. 3

[0056] Further, the demand analysis includes clarifying the screening target (such as defending network attacks, monitoring physical security) and specific requirements (such as data range, time granularity, detection frequency), collecting and integrating data, integrating multi-source data (such as network traffic, logs, sensor data, threat intelligence), and building a unified database.

[0057] Strategy formulation includes selecting appropriate screening methods (such as rules + machine learning; selecting by manual selection, making selection judgment according to demand and data characteristics), defining screening conditions and parameters, and setting tool configuration and deployment, selecting technical tools (such as SIEM, NTA), configuring screening rules or models, and deploying to production environment, then performing and verifying, running screening process, generating threat alerts, and evaluating screening accuracy through manual review and cross-validation (such as comparison with historical attack records).

[0058] Among them, manual review includes arranging security analysts to check the threat alerts screened out one by one or by sampling; comparing original logs, network traffic or other data sources to confirm whether the alerts are real; labeling false positives or abnormal alerts; forming a review report to provide basis for subsequent strategy adjustment.

[0059] Cross-validation includes dividing historical threat data into training set and validation set (such as k-fold cross-validation); training rules or machine learning models on the training set and testing screening results on the validation set; comparing model prediction with known real attack records to calculate accuracy, recall rate and other indicators; optimizing screening conditions, model parameters or rule strategies according to the validation results to improve automated screening effect.

[0060] It should also be noted that building an abnormal data model includes analyzing the diversity of data sources and analyzing the heterogeneity of data formats, as shown in Fig. 2

[0061] ​​Furthermore, the analysis of the diversity of data sources includes the network layer, physical layer, supply chain layer, internal layer, and external layer. The network layer includes firewall logs, intrusion detection system alerts, network traffic data, and malware samples. The physical layer includes data from substation video surveillance, access control system logs, environmental sensor data, and equipment status monitoring data. The supply chain layer involves equipment procurement records, software version information, supplier security assessment reports, and vulnerability disclosure data. The internal layer includes employee login logs, operation records, permission change records, and data access logs. The external layer includes IP blacklists, malicious domains, and attack organization activity information provided by integrated threat intelligence platforms.

[0062] The analysis of data format heterogeneity includes structured data, semi-structured data, and unstructured data. Structured data, such as equipment ledgers in databases and timestamps and event types in logs, is stored and analyzed directly in tabular form. Semi-structured data, such as SCADA protocol messages in XML format and API call records in JSON format, needs to be parsed to extract key fields. Unstructured data, including SCADA protocol messages in XML format and API call records in JSON format, also needs to be parsed to extract key fields.

[0063] S3: Encrypt critical data and build a critical encryption model. After encryption, build a demonstration protection model and conduct a demonstration simulation. After the demonstration simulation, formulate a joint protection sharing model and share the data.

[0064] It should be noted that building a key encryption model includes encrypting data, restricting access, and establishing a security audit mechanism.

[0065] Encrypting data includes encrypting shared threat intelligence and implementing multiple layers of encryption during the encryption process. An alarm is triggered when the second encryption layer is reached. Fig. 3 As shown.

[0066] Encryption can be achieved by setting a key, including setting a key question.

[0067] Restricting access includes implementing strict access control mechanisms, ensuring that only authorized users can access sensitive information when necessary.

[0068] Establishing a security audit mechanism includes monitoring and recording the information sharing process to facilitate future tracking and accountability.

[0069] Further, the demonstration protection model is constructed, including setting up a threat feature database after the feature of the network threat is extracted, and constructing a data crawling and updating module, updating the data in the threat database through the threat data obtained by crawling and feedback, and formulating different levels of demonstration protection schemes according to the extracted threat feature data, constructing a scheme problem collection library, collecting problems in the demonstration process, and adjusting and updating the demonstration protection scheme after the collection is completed.

[0070] Specifically, after the feature of the network threat is extracted, a threat feature database is set up, and a data crawling and updating module is constructed, the data in the threat database is updated through the threat data obtained by crawling and feedback, the timeliness of the data in the threat database is ensured, different levels of demonstration protection schemes are formulated according to the extracted threat feature data, and the first scheme, the second scheme and the third scheme are respectively provided, wherein the first scheme has the highest difficulty of demonstration protection, and the third scheme has the lowest difficulty of demonstration protection, and a scheme problem collection library is constructed to collect problems in the demonstration process, and the demonstration protection scheme is adjusted and updated after the collection is completed.

[0071] The different levels of demonstration protection schemes are formulated according to the feature data by manual and software.

[0072] The adjustment and update include adjusting the demonstration protection scheme, collecting some problems in the demonstration process when there is an abnormality in the original scheme, and adjusting and updating the abnormality and the problems in the later period.

[0073] Further, the joint protection sharing model is formulated, including constructing a modular system, building a platform data center, and processing cross-field collaboration, such as Fig. 2 as shown.

[0074] The modular system is constructed by decomposing the data sharing process into independent modules to realize function decoupling and flexible configuration; the data sharing application module includes recording the applicant, the unit, the application reason, the data demand form and the access IP address to ensure traceability; the data sharing application module includes recording the applicant, the unit, the application reason, the data demand form and the access IP address to ensure traceability; the visual configuration platform includes providing a drag-and-drop interface to allow users to customize data display methods.

[0075] The platform data center is built, including building a unified data center based on cloud computing, integrating data of various business systems, and providing standardized data services; realizing data governance, quality inspection and real-time calculation through professional tools to support data sharing needs of various business scenarios; building a privacy computing platform to support data fusion across departments and institutions, and improving the accuracy of data joint modeling applications.

[0076] The cross-domain collaborative update processing includes power coordination and power traffic optimization; data interworking, pre-service links, and reduction of unnecessary operation links; through the use of privacy computing technology, ensuring that data does not leave the domain, only sharing model parameters or prediction results; establishing a data service interface to support real-time query of relevant indicators such as usage rate and power.

[0077] Embodiment 2 provides a power network security threat intelligence sharing method based on federated learning, which is an embodiment of the present application. In order to verify the beneficial effects of the present application, economic benefit calculation and simulation experiments are used for scientific demonstration.

[0078] The experimental process includes data collection, data screening and modeling, and encryption and protection verification; testing in the power network simulation range, capturing ICMP tunnel, penetration testing tool (such as Metasploit), remote control tool (such as Cobalt Strike) and proxy tool (such as Shadowsock) traffic through security device flow probe; using rule and machine learning dual-engine to clean traffic data, building a five-dimensional data source analysis system to realize unstructured data conversion and improve packet parsing efficiency by 20%; key data uses SM4 basic layer encryption (key length 128 bits) + AES-256 dynamic layer encryption (SM4 basic layer encryption is used to meet the standard, and AES-256 is used for cross-domain compatibility), the second layer encryption alarm delay is ≤50ms; test complex attack chain reconstruction, penetration testing traffic interception, proxy tool scene respectively, update efficiency is improved by 1.2 times, interception rate is about 97%, false positive rate is about 2%.

[0079] As shown in Table 1, the experimental results show that compared with the traditional centralized threat intelligence sharing scheme, the federated learning method shortens the threat intelligence sharing delay by about 40% (from an average of 200ms to 120ms).

[0080] Table 1 Network attack traffic and detection and interception effect experiment table

[0081]

[0082]

[0083] Embodiment 3, the above is a schematic solution of a power network security threat intelligence sharing method based on federated learning. It should be noted that the technical solution of the power network security threat intelligence sharing system based on federated learning belongs to the same concept as the technical solution of the power network security threat intelligence sharing method based on federated learning described above. The technical details of the power network security threat intelligence sharing system based on federated learning in this embodiment are not described in detail, and can be referred to the description of the technical solution of the power network security threat intelligence sharing method based on federated learning described above.

[0084] The embodiment also provides a power network security threat intelligence sharing system based on federated learning, comprising:

[0085] The network exploration module constructs a network exploration model, acquires threat messages generated on the network, forms a problem database after acquisition, and constructs a communication sharing model.

[0086] The data screening module establishes a data screening model, cleans the acquired data, verifies the data source after cleaning, eliminates abnormal data after verification, extracts the features of abnormal data, and constructs an abnormal data model.

[0087] The protection sharing module encrypts the key data and constructs a key encryption model, as shown in Fig. 3 After encryption, a demonstration protection model is constructed for demonstration simulation. After demonstration simulation, a joint protection sharing model is formulated for data sharing.

[0088] The embodiment also provides an electronic device suitable for power network security threat intelligence sharing based on federated learning, comprising a memory and a processor. The memory is used to store computer executable instructions, and the processor is used to execute the computer executable instructions to realize the power network security threat intelligence sharing method based on federated learning proposed in the above embodiment.

[0089] The embodiment also provides a storage medium having a computer program stored thereon. The program is executed by a processor to realize the power network security threat intelligence sharing method based on federated learning proposed in the above embodiment.

[0090] The storage medium proposed in the embodiment and the power network security threat intelligence sharing method based on federated learning proposed in the above embodiment belong to the same inventive concept. The technical details not described in detail in the embodiment can be referred to the above embodiment, and the embodiment has the same beneficial effects as the above embodiment.

[0091] Those skilled in the art can clearly understand the present application by the above description of the embodiments, and the present application can be realized by software and necessary general hardware, and of course, can also be realized by hardware. Based on such understanding, the technical solutions of the present application or the part that contributes to the prior art can be embodied in the form of a software product, which can be stored in a computer readable storage medium, such as a floppy disk, a read-only memory (ROM), a random access memory (RAM), a FLASH, a hard disk, or an optical disc, and includes a number of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods of various embodiments of the present application.

[0092] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present application but not limit the present application, and although the present application is described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present application can be modified or replaced equivalently without departing from the spirit and scope of the present application, and all should be covered in the scope of the claims of the present application.

Claims

1. A power network security threat intelligence sharing method based on federated learning, characterized in that, The method comprises the following steps: Building a network exploration model to obtain threat messages generated on the network, forming a problem database after obtaining, and building a communication and sharing model; Establishing a data screening model to clean the obtained data, verifying the data source after cleaning, removing abnormal data when the verification is completed, extracting the characteristics of abnormal data, and building an abnormal data model; Encrypting the key data and building a key encryption model, building a demonstration protection model after encryption, performing demonstration simulation, formulating a joint protection sharing model after demonstration simulation, and sharing data.

2. The federated learning based power network security threat intelligence sharing method of claim 1, wherein, The network exploration model comprises C2, IP address tracking, URL and domain name analysis, intelligence analysis of attack tactics and techniques generated on the network, and malicious software sample collection and analysis, including: C2, IP address tracking collects and analyzes the IP addresses of malicious software and command and control server communication, identifies the relevant infrastructure and tools of threat actors; URL and domain name analysis includes checking the URLs and domain names and subdomains hosted by malicious software; Intelligence analysis of attack tactics and techniques generated on the network uses the MITRE attack framework to investigate using TTPs, identifies emerging threats, and actively builds knowledge about current threats; Malicious software sample collection and analysis automatically detects known malicious software and identifies new variants by creating and applying YARA rules, and uses the built-in YARA search function of the threat intelligence service to search for related samples.

3. The federated learning based power network security threat intelligence sharing method of claim 2, wherein, The data screening model comprises demand analysis and strategy formulation, including: Demand analysis includes clearly defining screening targets and specific requirements, collecting and integrating data, integrating multi-source data, and building a unified database; Strategy formulation includes selecting a screening method based on requirements and data characteristics, defining screening conditions and parameters, setting tool configuration and deployment, selecting technical tools, configuring screening, and deploying to a production environment, then performing and verifying, running the screening process, and generating threat alerts.

4. The federated learning based power network security threat intelligence sharing method of claim 3, wherein, The abnormal data model comprises analysis of the diversity of data sources and analysis of data format heterogeneity.

5. The federated learning based power network security threat intelligence sharing method of claim 4, wherein, The key encryption model comprises data encryption, access restriction, and security audit mechanism establishment, including: Data encryption includes encrypting shared threat intelligence and setting multiple encryption layers during encryption, which triggers an alarm when the second encryption layer is reached; Access restriction includes implementing an access control mechanism, which requires authorized access information when access is required; Establishing a security audit mechanism includes monitoring and recording the information sharing process.

6. The federated learning based power network security threat intelligence sharing method of claim 5, wherein, The demonstration protection model comprises the following steps: After extracting the characteristics of network threats, a threat feature database is established, a data crawling and updating module is built, the threat data obtained by crawling and feedback is used to update the data in the threat database, different levels of demonstration protection schemes are formulated according to the extracted threat feature data, a scheme problem collection library is built to collect problems during the demonstration process, and the demonstration protection scheme is adjusted and updated after the collection is completed.

7. The federated learning based power network security threat intelligence sharing method of claim 6, wherein, The joint protection sharing model includes constructing a modular system, building a platform data middle platform, and performing cross-domain collaborative update processing, which includes: Constructing a modular system includes decomposing data sharing processes, decoupling functions, and flexible configuration; Building a platform data middle platform includes building a unified data middle platform based on cloud computing, integrating business system data, and providing standardized data services; Performing cross-domain collaborative update processing includes power coordination and power transportation optimization.

8. A power network security threat intelligence sharing system based on federated learning, applying a power network security threat intelligence sharing method based on federated learning according to any one of claims 1-7, characterized in that, It includes: Network exploration module, build network exploration model, get threat message generated on the network, form problem database after getting, and build exchange sharing model; Data filtering module, establish data filtering model, clean the obtained data, verify the data source after cleaning, remove abnormal data after verification, and extract the characteristics of abnormal data to build an abnormal data model; Protection sharing module, encrypt key data, build key encryption model, build demonstration protection model after encryption, demonstrate simulation, develop joint protection sharing model after simulation, and share data. 9.A computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the computer device is configured to perform the method according to any one of claims 1-8 when the computer program is executed by the processor. The processor executes the computer program to realize the steps of the power network security threat intelligence sharing method based on federated learning in any one of claims 1 to 7.

10. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to realize the steps of the power network security threat intelligence sharing method based on federated learning in any one of claims 1 to 7.