A power monitoring system network security checking method and system
By constructing a network topology map of the power monitoring system through passive traffic analysis and active detection, and combining it with a multi-dimensional security verification mechanism, the problems of low efficiency and inconsistent results in the network security verification of the power monitoring system are solved, and efficient and reliable security verification is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- STATE GRID ZHEJIANG ELECTRIC POWER CO LTD NINGBO POWER SUPPLY CO
- Filing Date
- 2025-12-18
- Publication Date
- 2026-04-17
AI Technical Summary
Existing methods for verifying network security in power monitoring systems are inefficient, can easily affect the normal operation of the system, and produce inconsistent verification results, making it difficult to comprehensively detect network security risks.
Passive traffic analysis and active detection mechanisms are used to map the assets of the power monitoring system, construct a network topology map, and provide real-time visualization through a multi-dimensional security verification mechanism to ensure that the verification process does not affect the system stability.
It has enabled comprehensive network information collection and security verification, improved verification efficiency, reduced reliance on professional personnel, and ensured the reliability and consistency of verification results.
Smart Images

Figure CN121396803B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power monitoring technology, specifically to a method and system for network security verification of power monitoring systems. Background Technology
[0002] With the continuous development of information technology and power automation technology, power monitoring systems have gradually become a core component of power industry operations, involving a wide variety of equipment and increasing cybersecurity risks. Power monitoring systems typically consist of numerous devices and complex network structures, encompassing various equipment such as time synchronization servers, remote control units, monitoring hosts, databases, and protection and control devices. The normal operation of these devices directly affects the stability and security of the power system. However, due to the special nature of the power industry and the complexity of monitoring systems, traditional manual verification methods often face the following problems: low efficiency of manual inspection, requiring item-by-item inspection of each device, which is cumbersome and time-consuming; inconsistent verification results, due to differences in the skill levels of technical personnel, leading to inconsistent results for the same verification task; high verification difficulty, due to the large number of equipment types and rapid technological updates, manual verification requires highly skilled personnel and lacks standardized and regulated operating procedures; and difficulty in comprehensively detecting security risks, as traditional manual inspection methods struggle to achieve a comprehensive and in-depth investigation of potential threats such as network security vulnerabilities, cross-regional asset use, and unauthorized external connections.
[0003] Chinese Patent, Publication No. CN118368147A, Publication Date: July 19, 2024, discloses a power monitoring network security detection system and method. This system analyzes and processes three influencing factor sets—external security index, quality index, and external interference index—to generate a total defined index, which is used to determine the security of the power monitoring network system. This invention is the first to combine the analysis of these three influencing factor sets and further subdivide them, comprehensively evaluating nine aspects: attack blocking rate, Trojan horse implantation risk, virus infection risk, data transmission speed, data latency, data throughput, data tampering risk, unauthorized device access, and unauthorized access permission acquisition risk. It generates a comprehensive external security index, a comprehensive quality index, and a comprehensive external interference index, which are then further analyzed to generate a total defined index to determine the security of the power monitoring network system. While this provides a relatively comprehensive security check of the power monitoring network, the proactive check process may affect the normal operation of the power monitoring system, making it difficult to balance stable operation and efficient check efficiency. Summary of the Invention
[0004] This invention addresses the problem of low efficiency in existing power monitoring system networks due to the difficulty in automating verification processes and the potential disruption to normal system operation during verification. It provides a method and system for network security verification in power monitoring systems. By using passive traffic analysis to cover all communication devices, no networked assets are overlooked. Combined with active detection to supplement blind spots in passive data collection, this method maximizes the collection of comprehensive network information without affecting the normal operation of the power monitoring system network. Furthermore, it constructs a network topology map, providing real-time visualization of the multi-dimensional security verification process and lowering the verification threshold, thereby improving verification efficiency while ensuring comprehensiveness.
[0005] In a first aspect, one technical solution provided in this embodiment of the invention is: a network security verification method for a power monitoring system, comprising the following steps:
[0006] S1. Based on passive flow analysis and active detection mechanisms, asset mapping is performed on each device in the power monitoring system to obtain a list of equipment assets.
[0007] S2. Based on the equipment asset list, the logical connection relationships of each node in the power monitoring system are integrated to obtain the field network topology diagram;
[0008] S3. Based on the on-site network topology diagram and using a multi-dimensional security verification mechanism, perform security verification on the power monitoring network, and update the on-site network topology diagram based on the verification results.
[0009] In this solution, passive traffic analysis is based on bypass access, which can prevent the injection of any interfering data packets into the network. Active detection employs a lightweight design, strictly controlling CPU / bandwidth usage, thus ensuring that core power system operations are unaffected during security checks and guaranteeing system stability. By constructing a field network topology map, the partition affiliation and compliant communication links of each device are clearly defined, providing a unified benchmark framework for subsequent security checks. The use of power industry-specific icons and standardized terminology allows even non-expert technical personnel to quickly grasp the network architecture, avoiding omissions due to insufficient architectural understanding. Furthermore, different regulatory agencies and inspectors can work based on the same topology map, and results can be directly compared and shared, resolving collaborative pain points such as fragmented inspections and inconsistent results, thereby improving inspection efficiency. Through multi-dimensional security checks, various risks such as cross-regional operations, unauthorized external connections, configuration defects, malicious code, and vulnerabilities are considered, adapting to the characteristics of the power industry and ensuring that industry-specific risks are not overlooked, thus improving the reliability of security check results.
[0010] Preferably, in S1, the specific process of passive traffic parsing includes:
[0011] Collect flow data from the power monitoring system, including communication messages and protocol data exchanged between devices;
[0012] Deep packet inspection of communication packets yields the IP address, MAC address, port number, communication protocol type, and device-specific identifier in the packet header as device characteristic information;
[0013] The service communication relationships of the device are obtained by determining the interaction timing and data flow of communication messages based on protocol data;
[0014] Device characteristic information and business communication relationships are used as core device information.
[0015] In this solution, communication messages and protocol data from natural interactions between devices are collected via bypass, eliminating the need for probe packets or configuration modifications, thus avoiding impact on core system operations such as remote control transmission and protection linkage. Deep message inspection acquires fine-grained information such as IP addresses, MAC addresses, power-specific protocol types, and device-specific identifiers, preventing omissions and misclassifications of networked devices. Protocol data clarifies the timing and flow of device interactions, providing a reliable logical connection basis for subsequent topology mapping and establishing compliant communication standards for security verification. Furthermore, the entire process requires no manual intervention, significantly improving collection efficiency, reducing reliance on specialized personnel, and adapting to complex power network environments.
[0016] As a preferred embodiment, the specific process of the active detection mechanism in S1 includes:
[0017] Send targeted detection requests to unknown devices in the power monitoring system network that are not listed in the core device information;
[0018] Based on the targeted detection request, the open port list, operating system version, database type / version, and network device configuration summary of the unknown device are collected, and the above information is used as the unknown device information.
[0019] This solution uses targeted detection to accurately collect key information such as open ports, operating system / database versions, and network configuration summaries. This avoids overlooking hidden assets such as offline backup devices and low-interaction embedded devices. Furthermore, the detection focuses on unknown devices, avoiding blind scanning and adapting to the stability requirements of the power system with low interference. The information obtained can improve the equipment asset list, fill the information gaps of passive collection, and provide a complete asset baseline for subsequent topology mapping and multi-dimensional security verification, ensuring that the verification is thorough and without blind spots.
[0020] Preferably, the core equipment information and the unknown equipment information are complemented to obtain an equipment information dataset;
[0021] Based on a preset equipment type classification mechanism, the equipment in the equipment information dataset is classified to obtain an equipment asset list. The equipment asset list includes at least the equipment ID, equipment type, model / version, manufacturer identifier, affiliated plant, network partition, open port, supported protocols, communication object list, and data collection timestamp.
[0022] This solution complements core equipment information with unknown equipment information, integrates passive analysis and active detection results to fill gaps in hidden asset information and avoid equipment omissions or incomplete information. At the same time, it categorizes and generates a list containing key fields such as equipment ID, type, protocol, and communication object according to a preset mechanism, presenting asset details in a standardized manner. This ensures information integrity and unifies data format, providing a precise and unified asset baseline for subsequent topology mapping and multi-dimensional security verification. It ensures that the verification process is standardized and efficient, meeting the compliance and traceability requirements of the power monitoring system.
[0023] Preferably, in S2, the logical connection relationships of each node in the power monitoring system are integrated based on the equipment asset list to obtain the field network topology diagram, including the following steps:
[0024] Based on the device type, the device function is determined, and based on the device function, each device is divided into the core layer, aggregation layer and access layer according to its importance.
[0025] Construct device communication links based on device IDs and communication object lists, and associate them with corresponding open ports and supported protocols;
[0026] The power monitoring system is divided into communication partitions based on the manufacturer's identifier, the plant or substation to which it belongs, and the network partition, with the boundary devices as the dividing points.
[0027] The network topology is obtained by arranging the core layer devices in the center, the aggregation layer around the core layer, and the access layer grouped according to physical location, and classifying each device into a communication partition.
[0028] This solution employs a layered approach based on device function and importance, with a central core layer, surrounding aggregation layers, and access layers arranged in physical groups. This approach highlights the critical role of core devices such as remote control units (RTUs) while aligning with the actual site layout, making the network architecture intuitive and easy to understand, facilitating rapid focus on key assets. By constructing device links based on device IDs and communication object lists, and associating ports with protocols, the solution objectively reconstructs the true communication relationships, avoiding verification biases caused by ambiguous links. Furthermore, the solution partitions the network using boundary devices as dividing points, conforming to power monitoring system partitioning standards. This provides a clear partitioning benchmark for cross-regional verification and detection of unauthorized external connections, offering a unified and visualized architectural basis for subsequent multi-dimensional security verification, thereby improving verification accuracy and efficiency.
[0029] Preferably, the multi-dimensional security verification includes verification of unauthorized external connections, verification of cross-regional assets, verification of configuration compliance, detection of malicious code, and detection of vulnerabilities;
[0030] The specific process for verifying violations of external connections includes:
[0031] Collect system logs, remote operation records, and network connection status of the target device during operation in the on-site network topology diagram;
[0032] If any of the following situations occur in the system log: unauthorized external device access, improper operation in remote operation traces, or unauthorized internal / external IP address or network card configuration error in network connection status, the target device will be marked as an unauthorized external connection device and displayed on the on-site network topology diagram.
[0033] This solution comprehensively covers unauthorized peripheral access, improper remote operation, and unauthorized IP connections by collecting multi-dimensional data such as system logs, remote operation traces, and network connection status. This avoids misjudgments caused by single data points and ensures the accuracy of verification. At the same time, it directly marks the non-compliant devices on the on-site network topology map, realizing risk visualization and facilitating the quick location of potential hazards by verification personnel without having to sift through massive amounts of data. This adapts to the high security requirements of the power system, can promptly block external attack paths and data leakage risks, provides clear targets for subsequent handling, and ensures that the core business of the power monitoring system is not affected by unauthorized external connections.
[0034] Preferably, the specific process of the cross-regional asset verification includes:
[0035] Collect communication packets of the target device in the on-site network topology diagram, and determine the communication path of the target device based on the gateway jump record of the communication packet and the corresponding device communication link;
[0036] If the target device's communication path crosses the boundary devices of at least two communication zones, the target device is marked as a cross-zone asset device and displayed on the field network topology map;
[0037] The specific process for verifying the configuration compliance includes:
[0038] Based on the device type of the target device in the on-site network topology diagram, the target configuration index is selected from the preset configuration index library;
[0039] The actual configuration parameters of the target device are compared with the preset compliance parameter range of the target configuration indicators. If the parameters exceed the compliance parameter range, the target device is marked as non-compliant and displayed on the on-site network topology diagram.
[0040] This solution collects communication packets and combines gateway jump records with device communication links to lock the actual communication path, objectively determining whether partition boundaries have been crossed, thus avoiding omissions or misjudgments caused by network complexity during manual verification. By comparing the actual configuration with the compliance parameter range, the compliance status is quantitatively determined, reducing subjective differences. By directly marking non-compliant and non-compliant devices on the topology map, risk visualization is achieved, facilitating quick location and rectification by maintenance personnel, thereby improving verification efficiency and building a solid configuration security defense for the stable operation of the power monitoring system.
[0041] Preferably, the specific process of malicious code detection includes:
[0042] Behavioral features of system files, installed clients, and running processes of target devices in the on-site network topology diagram are extracted, including file encryption algorithms, process privilege escalation behaviors, and communication methods.
[0043] Based on a preset risk assessment index system, the behavioral characteristics are evaluated to obtain a security score. Target devices with security scores less than the security threshold are marked as risk devices and displayed on the on-site network topology diagram.
[0044] This solution comprehensively covers typical malicious code behaviors by extracting key behavioral characteristics of system files, installed clients, and running processes, thus avoiding false negatives caused by single-feature detection. It also reduces subjective human error by quantitatively scoring based on a preset indicator system and using objective thresholds to determine risks. Furthermore, by directly marking risky devices on the on-site network topology, it achieves risk visualization, facilitating rapid location of potential hazards. This adapts to the high security requirements of power systems, enabling timely identification of potential malicious code threats, blocking their damage and propagation, and ensuring the stable operation of core businesses.
[0045] Preferably, the specific process of vulnerability detection includes:
[0046] A vulnerability feature verification packet is sent to the target device in the on-site network topology diagram. The vulnerability features include at least system vulnerabilities, protocol vulnerabilities, configuration vulnerabilities, firmware vulnerabilities, and account vulnerabilities.
[0047] If the target device matches the corresponding vulnerability characteristics, it will be marked as a vulnerable device and displayed on the on-site network topology diagram.
[0048] In this solution, vulnerability signature verification packets can be sent to target and match potential vulnerabilities, detecting and covering multiple types of vulnerabilities such as system, protocol, configuration, firmware, and account vulnerabilities, thus providing comprehensive protection against both power-specific and general vulnerabilities. By directly marking vulnerable devices on the topology map, risk visualization is achieved, facilitating rapid location and handling. This allows for the timely discovery of hidden dangers and the blocking of exploitation paths, preventing vulnerabilities from causing equipment failures or security incidents, and ensuring the stable operation of the core business of the power monitoring system.
[0049] Secondly, one technical solution provided in this embodiment of the invention is: a network security verification system for a power monitoring system, including an asset mapping module, a topology generation module, and a multi-dimensional security verification module;
[0050] The asset mapping module performs asset mapping on each device in the power monitoring system based on passive flow analysis and active detection mechanisms to obtain a list of equipment assets.
[0051] The topology generation module integrates the logical connection relationships of each node in the power monitoring system based on the equipment asset list to obtain the field network topology map.
[0052] The multi-dimensional security verification module performs security verification on the power monitoring network based on the on-site network topology diagram and adopts a multi-dimensional security verification mechanism, and sends the verification results to the topology generation module to update the on-site network topology diagram.
[0053] In this solution, a corresponding system is built to integrate the security verification methods, thereby enabling human-computer interaction and improving the user experience.
[0054] The beneficial effects of this invention are as follows: This invention covers all communication devices through passive traffic analysis, ensuring that no network assets are missed. Combined with active detection to supplement the blind spots of passive collection, it can collect comprehensive network information to the greatest extent without affecting the normal operation of the power monitoring system network. Furthermore, it constructs a network topology map and provides real-time visualization of the multi-dimensional security verification process, thereby lowering the verification threshold and improving verification efficiency while ensuring the comprehensiveness of the verification.
[0055] The above description of the invention is merely an overview of the technical solution of the present invention. In order to better understand the technical means of the present invention and to implement it in accordance with the contents of the specification, and in order to make the above and other objects, features and advantages of the present invention more apparent and understandable, specific embodiments of the present invention are described below. Attached Figure Description
[0056] Other features, objects, and advantages of the invention will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings. The drawings are for illustrative purposes only and are not intended to limit the invention. Furthermore, the same reference numerals denote the same parts throughout the drawings.
[0057] Figure 1 This is a flowchart of a network security verification method for a power monitoring system according to the present invention;
[0058] Figure 2 This is a schematic diagram of a network security verification system for a power monitoring system according to the present invention. Detailed Implementation
[0059] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only one preferred embodiment of this invention and are only used to explain this invention. They do not limit the scope of protection of this invention. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this invention.
[0060] Before discussing the exemplary embodiments in more detail, it should be mentioned that some exemplary embodiments are described as processes or methods depicted as flowcharts. Although the flowcharts describe the operations (or steps) as sequential processes, many of the operations (or steps) can be performed in parallel, concurrently, or simultaneously. Furthermore, the order of the operations can be rearranged. The process can be terminated when its operation is completed, but it may also have additional steps not included in the figures; the process may correspond to a method, function, procedure, subroutine, subroutine, etc.
[0061] Example 1: As Figure 1 As shown, to address the problem that existing power monitoring system networks struggle to automate verification processes and suffer from low verification efficiency due to potential disruptions to normal system operation, this embodiment provides a power monitoring system network security verification method, comprising the following steps:
[0062] S1: Based on passive flow analysis and active detection mechanisms, asset mapping is performed on each device in the power monitoring system to obtain a list of equipment assets.
[0063] In this embodiment, the specific process of passive traffic parsing includes:
[0064] Collect flow data from the power monitoring system, including communication messages and protocol data exchanged between devices;
[0065] Deep packet inspection of communication packets yields the IP address, MAC address, port number, communication protocol type, and device-specific identifier in the packet header as device characteristic information;
[0066] The service communication relationships of the device are obtained by determining the interaction timing and data flow of communication messages based on protocol data;
[0067] Device characteristic information and business communication relationships are used as core device information.
[0068] Specifically, the verification device is connected to the power plant, substation, or main station network via bypass access; the verification device is physically isolated from the production control network through a security isolation module to avoid interference with on-site operations; the verification device is started, completes software and hardware self-checks and loads the pre-set verification strategies and rule base, and obtains traffic data of all devices in the network through the mirror port. During the collection process, no data packets that affect business operations are injected into the network to ensure the normal operation and maintenance of the power monitoring system.
[0069] This embodiment bypasses the natural interaction of communication messages and protocol data between devices, avoiding the need for probe packet injection or configuration modification, thus preventing impact on core system services such as remote control transmission and protection linkage. Deep message inspection obtains fine-grained information such as IP, MAC, power-specific protocol types, and device-specific identifiers, eliminating omissions and misclassifications of networked devices. Protocol data clarifies the timing and flow of device interactions, providing a reliable logical connection basis for subsequent topology mapping and establishing compliant communication standards for security verification. Furthermore, the entire process requires no manual intervention, significantly improving data collection efficiency, reducing reliance on specialized personnel, and adapting to complex power network environments.
[0070] In this embodiment, the specific process of the active detection mechanism includes:
[0071] Send targeted detection requests to unknown devices in the power monitoring system network that are not listed in the core device information;
[0072] Based on the targeted detection request, the open port list, operating system version, database type / version, and network device configuration summary of the unknown device are collected as unknown device information.
[0073] Specifically, for devices not explicitly identified in passive detection, targeted probe requests are sent to collect data such as the device's open port list, operating system version, database type / version, and network device configuration summary, thereby complementing the passive detection data.
[0074] This embodiment uses targeted detection to accurately collect key information such as open ports, operating system / database versions, and network configuration summaries. This avoids overlooking hidden assets such as offline backup devices and low-interaction embedded devices. Furthermore, the detection focuses on unknown devices, avoiding blind scanning and adapting to the stability requirements of the power system with low interference. The information obtained can improve the equipment asset list, fill the information gaps of passive collection, and provide a complete asset baseline for subsequent topology mapping and multi-dimensional security verification, ensuring that the verification is thorough.
[0075] In this embodiment, the core device information and the unknown device information are complemented to obtain a device information dataset;
[0076] Based on a preset equipment type classification mechanism, the equipment in the equipment information dataset is classified to obtain an equipment asset list. The equipment asset list includes at least the equipment ID, equipment type, model / version, manufacturer identifier, affiliated plant, network partition, open port, supported protocols, communication object list, and data collection timestamp.
[0077] This embodiment complements core equipment information with unknown equipment information, integrates passive analysis and active detection results, fills gaps in hidden asset information, and avoids equipment omissions or incomplete information. At the same time, it categorizes and generates a list containing key fields such as equipment ID, type, protocol, and communication object according to a preset mechanism, presenting asset details in a standardized manner. This ensures information integrity and unifies data format, providing a precise and unified asset baseline for subsequent topology mapping and multi-dimensional security verification. It ensures that the verification process is standardized and efficient, and meets the compliance and traceability requirements of the power monitoring system.
[0078] S2: Based on the equipment asset list, the logical connection relationships of each node in the power monitoring system are integrated to obtain the field network topology diagram.
[0079] In this embodiment, the logical connection relationships of each node in the power monitoring system are integrated based on the equipment asset list to obtain the field network topology map, including the following steps:
[0080] Based on the device type, the device function is determined, and based on the device function, each device is divided into the core layer, aggregation layer and access layer according to its importance.
[0081] Construct device communication links based on device IDs and communication object lists, and associate them with corresponding open ports and supported protocols;
[0082] The power monitoring system is divided into communication partitions based on the manufacturer's identifier, the plant or substation to which it belongs, and the network partition, with the boundary devices as the dividing points.
[0083] The network topology is obtained by arranging the core layer devices in the center, the aggregation layer around the core layer, and the access layer grouped according to physical location, and classifying each device into a communication partition.
[0084] In this embodiment, the core layer devices can be master station switches and routers, the aggregation layer devices can be plant aggregation switches, and the access layer devices can be protection and control devices, monitoring hosts, etc. Boundary devices include firewalls, security isolation devices, gateways, etc.
[0085] This embodiment employs a layered approach based on device function and importance, with a central core layer, surrounding aggregation layers, and access layers arranged in physical groups. This approach highlights the critical role of core devices such as remote control units (RTUs) while also aligning with the actual site layout, making the network architecture intuitive and easy to understand, facilitating rapid focus on key assets. By constructing device links based on device IDs and communication object lists, and associating ports with protocols, the actual communication relationships are objectively reconstructed, avoiding verification biases caused by ambiguous links. Furthermore, partitioning the network using boundary devices as dividing points conforms to the zoning specifications of power monitoring systems, providing a clear zoning benchmark for cross-regional verification and detection of unauthorized external connections. This provides a unified and visualized architectural basis for subsequent multi-dimensional security verification, improving the accuracy and efficiency of verification.
[0086] S3: Based on the on-site network topology diagram and using a multi-dimensional security verification mechanism, perform security verification on the power monitoring network, and update the on-site network topology diagram based on the verification results.
[0087] In this embodiment, the multi-dimensional security verification includes verification of unauthorized external connections, verification of cross-regional assets, verification of configuration compliance, detection of malicious code, and detection of vulnerabilities;
[0088] The specific process for verifying violations of external connections includes:
[0089] Collect system logs, remote operation records, and network connection status of the target device during operation in the on-site network topology diagram;
[0090] If any of the following situations occur in the system log: unauthorized external device access, improper operation in remote operation traces, or unauthorized internal / external IP address or network card configuration error in network connection status, the target device will be marked as an unauthorized external connection device and displayed on the on-site network topology diagram.
[0091] Specifically, by extracting trace information at the host level, the system detects USB device access records, network card configuration information (including wireless network cards, Bluetooth, and multi-network card binding), remote login logs, remote application usage traces, and external network connections of assets during operation. By comparing these records with the compliant communication whitelist of the power intranet, if any asset is found to be connecting to unauthorized intranet IPs or external public IPs, it is automatically marked as an unauthorized external connection event. Through the log merging engine of the verification device, the system can perform time-series analysis of the unauthorized traces, trace the formation process and potential risk impact of the unauthorized external connections, thereby achieving automatic identification and evidence retention of unauthorized external connection behavior.
[0092] This embodiment comprehensively covers unauthorized peripheral access, improper remote operation, and unauthorized IP connection scenarios by collecting multi-dimensional data such as system logs, remote operation traces, and network connection status. This avoids misjudgments caused by single data points and ensures the accuracy of verification. At the same time, it directly marks the non-compliant devices on the on-site network topology map, realizing risk visualization and facilitating the quick location of potential hazards by verification personnel without having to sift through massive amounts of data. This adapts to the high security requirements of the power system, can promptly block external attack paths and data leakage risks, provides clear targets for subsequent handling, and ensures that the core business of the power monitoring system is not affected by unauthorized external connections.
[0093] In this embodiment, the specific process of cross-regional asset verification includes:
[0094] Collect communication packets of the target device in the on-site network topology diagram, and determine the communication path of the target device based on the gateway jump record of the communication packet and the corresponding device communication link;
[0095] If the target device's communication path crosses the boundary devices of at least two communication zones, the target device is marked as a cross-zone asset device and displayed on the field network topology map;
[0096] The specific process for verifying the configuration compliance includes:
[0097] Based on the device type of the target device in the on-site network topology diagram, the target configuration index is selected from the preset configuration index library;
[0098] The actual configuration parameters of the target device are compared with the preset compliance parameter range of the target configuration indicators. If the parameters exceed the compliance parameter range, the target device is marked as non-compliant and displayed on the on-site network topology diagram.
[0099] Specifically, cross-regional asset verification is based on the automatic identification capability of network partitions. It determines the ownership scope of assets within different partitions and, in conjunction with asset mapping information, judges whether there are cases of assets being used across partitions. When it is found that the equipment configuration parameters show that its region is inconsistent with the actual network communication region, the system automatically records the cross-regional asset event and generates the corresponding entry in the verification report for verification by regulatory authorities. This method can solve the problem that cross-regional violations are difficult to detect due to the complexity of network division and differences in personnel cognition in traditional manual investigations, thereby achieving rapid location and compliance verification of cross-regional non-compliant assets.
[0100] Furthermore, the compliance verification process, based on the power industry's network security standards and operational procedures, automates the checks on the configuration items of operating systems, databases, and network devices. Operating system verification supports 63 indicators (including account security, password policies, log auditing, port management, and permission configuration), database verification supports 19 indicators (including account permissions, weak passwords, audit logs, data encryption, and open ports), and network device verification supports 28 indicators (including access control lists, routing configuration, firewall rules, VLAN segmentation, and log enabling). The verification device compares the actual configuration parameters of the field devices with a built-in compliance rule base. If discrepancies are found, they are automatically identified and categorized into the corresponding risk category, and specific remediation suggestions are generated in the verification results. For example, when comparing numerical indicators such as password length ≥ 8 characters or log retention days ≥ 90 days, the actual values of the target device are compared with the indicator values; if they are met, the device is compliant; otherwise, it is non-compliant.
[0101] This embodiment collects communication packets, combines gateway jump records with device communication links to lock the actual communication path, and objectively determines whether partition boundaries are crossed, avoiding omissions or misjudgments caused by network complexity during manual verification. By comparing the actual configuration with the compliance parameter range, the compliance status is quantitatively determined, reducing subjective differences. By directly marking non-compliant and non-compliant devices on the topology map, risk visualization is achieved, making it convenient for maintenance personnel to quickly locate and rectify the issues, thereby improving verification efficiency and building a solid configuration security defense for the stable operation of the power monitoring system.
[0102] In this embodiment, the specific process of malicious code detection includes:
[0103] Behavioral features of system files, installed clients, and running processes of target devices in the on-site network topology diagram are extracted, including file encryption algorithms, process privilege escalation behaviors, and communication methods.
[0104] Based on a preset risk assessment index system, the behavioral characteristics are evaluated to obtain a security score. Target devices with security scores less than the security threshold are marked as risk devices and displayed on the on-site network topology diagram.
[0105] Specifically, the built-in malware detection engine performs a comprehensive scan of the target asset's system files, installed clients, and running processes, supporting three modes: signature comparison, heuristic analysis, and behavioral detection. It also includes verification of malware scanning time and the update time of the detection engine's signature database. For known malware, signature comparison is used, comparing the collected system file hash values and process signatures with known features in the malware signature database one by one. If the file hash value matches a ransomware signature and the process name matches a known Trojan process name, the presence of malware is directly confirmed. For unknown malware, heuristic analysis is used to extract key behavioral features such as file encryption algorithms, process privilege escalation behavior, covert communication methods, and code obfuscation features from files and processes that do not match known features. Based on the built-in risk assessment model, abnormal features are scored; for example, batch modification of system configuration files adds 30 points. Attempting to access the protection device firmware adds 50 points; transmitting data to overseas IPs using encrypted communication adds 40 points; a security score of ≥60 points is marked as containing malicious code. Behavioral detection involves tracking the dynamic behavior of the running process throughout its entire lifecycle, with a focus on monitoring the following malicious behaviors: destructive behaviors, including modifying system kernel files, deleting power-specific configuration files, and tampering with log records; theft behaviors, such as reading remote control data, dispatch instructions, and sensitive information such as device firmware parameters; propagation behaviors, such as spreading to other devices through network sharing, USB devices, and unauthorized external links; and control behaviors, such as creating backdoor accounts, obtaining device administrator privileges, and remotely controlling device operation.
[0106] This embodiment comprehensively covers typical malicious code behaviors by extracting key behavioral features from system files, installed clients, and running processes, thereby avoiding false negatives caused by single-feature detection. By quantifying and scoring based on a preset indicator system and determining risks with objective thresholds, it reduces subjective human error. By directly marking risky devices on the field network topology map, it achieves risk visualization, facilitates rapid location of hidden dangers, and thus adapts to the high security requirements of power systems. It can promptly identify potential malicious code threats, block their damage and spread, and ensure the stable operation of core businesses.
[0107] In this embodiment, the specific process of vulnerability detection includes:
[0108] A vulnerability feature verification packet is sent to the target device in the on-site network topology diagram. The vulnerability features include at least system vulnerabilities, protocol vulnerabilities, configuration vulnerabilities, firmware vulnerabilities, and account vulnerabilities.
[0109] If the target device matches the corresponding vulnerability characteristics, it is marked as a vulnerable device. For example, if Windows Server 2016 does not have the KB5023705 patch installed, it is determined that there is a CVE-2023-24586 vulnerability and it is displayed on the on-site network topology diagram.
[0110] Specifically, the vulnerability detection method combines asset mapping results with a power grid security vulnerability database using a verification device. Through proactive detection, it automatically analyzes the internal structure and potential security flaws of the target asset to generate a vulnerability distribution list. This method can perform specialized detection on common high-risk vulnerabilities in the power grid and supports targeted extended detection of newly added high-risk vulnerabilities. The vulnerability detection results are linked to the asset category.
[0111] Furthermore, to improve verification efficiency, this embodiment also provides a one-click verification function. By reading the grid connection application documents of newly built power plants or substations and combining them with asset information mapping functions, the system automatically performs tasks such as network asset mapping, detection of illegal external connections, configuration compliance checks, cross-regional asset identification, and vulnerability detection. After all tasks are completed, the system automatically generates a network security verification checklist and a unified format verification report based on the comparative analysis of real-time verification results and historical verification results, and provides a visual display interface and electronic download interface.
[0112] Furthermore, this embodiment achieves this through an integrated hardware and software design of the verification device. The hardware part adopts a bypass access module and a security isolation module to ensure passive traffic collection and security analysis without affecting the normal operation of the power monitoring system. The software part adopts a modular architecture design, corresponding to functional modules such as asset mapping, topology generation, illegal external connection detection, configuration verification, malicious code detection, and vulnerability detection. This integrated hardware and software design enables the verification device to be plug-and-play in complex power field environments.
[0113] Furthermore, the final cybersecurity verification report generated in this embodiment not only includes the security issues discovered during the verification, but also remediation suggestions based on a knowledge base, severity classification of issues, comparison of historical issue recurrence, and retention of operation logs during the verification process. The report is output using a unified template and has a visual statistical chart display function, which facilitates the comparison and sharing of results among different regulatory agencies and verification personnel. In this way, the unification of verification content, the standardization of verification actions, and the traceability of verification results are achieved.
[0114] This embodiment can target and match potential vulnerabilities by sending vulnerability signature verification packets, and detect vulnerabilities covering multiple types such as systems, protocols, configurations, firmware, and accounts, thereby providing comprehensive protection against both power-specific and general vulnerabilities. By directly marking vulnerable devices on the topology map, risk visualization is achieved, facilitating rapid location and handling. This allows for the timely discovery of hidden dangers and the blocking of exploitation paths, preventing vulnerabilities from causing equipment failures or security incidents, and ensuring the stable operation of the core business of the power monitoring system.
[0115] Example 2: Figure 2As shown, this embodiment also provides a network security verification system for a power monitoring system, including an asset mapping module, a topology generation module, and a multi-dimensional security verification module;
[0116] The asset mapping module performs asset mapping on each device in the power monitoring system based on passive flow analysis and active detection mechanisms to obtain a list of equipment assets.
[0117] The topology generation module integrates the logical connection relationships of each node in the power monitoring system based on the equipment asset list to obtain the field network topology map.
[0118] The multi-dimensional security verification module performs security verification on the power monitoring network based on the on-site network topology diagram and adopts a multi-dimensional security verification mechanism, and sends the verification results to the topology generation module to update the on-site network topology diagram.
[0119] By building a corresponding system to integrate the security verification methods in this solution, human-computer interaction is achieved, improving the user experience.
[0120] As a further supplement to this embodiment, the following scenario will be used as an example to further illustrate this solution:
[0121] Taking the annual network security verification of a 500 kV substation as an example, the verification device is first deployed to access the mirror port of the main station monitoring switch via a bypass method, and the isolation module verifies that there is no risk of writeback.
[0122] Asset mapping: Automatically identified a total of 54 key assets, including 6 monitoring hosts, 28 protection and control devices, and 2 database servers;
[0123] Topology mapping: Generates a 3-layer topology map and discovers a spare fiber optic link that is not registered in the topology;
[0124] Unauthorized external connection: A monitoring host was found to have a remote desktop login record at 3:00 AM, with the source IP being an external office network;
[0125] Cross-zone inspection: Two protection devices were found to be communicating across the monitoring zone and the protection zone, which does not comply with the zoning requirements;
[0126] Configuration check: The database weak password "admin123" was listed as high risk, and log auditing was not enabled on the three switches;
[0127] Malicious code: No malicious process detected;
[0128] Vulnerability detection: Two time synchronization servers were found to have the publicly disclosed high-risk vulnerability CVE-2024-XXXXX;
[0129] One-click verification: Automatically performs all checks sequentially and completes the difference comparison;
[0130] Results Report: Generates an electronic signature report and outputs the rectification priority: First, rectify high-risk issues: block remote access from the external network; update the time-synchronization server patch; then, rectify medium-risk issues: change the database password and enable log auditing.
[0131] As can be seen from the above embodiments, it has at least the following substantial effects:
[0132] (1) The passive traffic analysis of this invention is based on bypass access, which can prevent the injection of any interfering data packets into the network. The active detection adopts a lightweight design, which can strictly control the CPU / bandwidth usage, thereby ensuring that the core business of the power system is not affected when conducting security checks, and ensuring the stability of the system operation.
[0133] (2) By constructing a field network topology diagram, this invention clarifies the partition affiliation and compliant communication links of each device, providing a unified benchmark framework for subsequent security verification. At the same time, it adopts power industry-specific icons and standardized terminology, enabling non-senior technical personnel to quickly grasp the network architecture and avoid verification omissions due to insufficient understanding of the architecture. Furthermore, different regulatory agencies and verification personnel can work based on the same topology diagram, and the results can be directly compared and shared, solving the pain points of collaboration such as each department checking its own data and the inability to unify the results, thereby improving verification efficiency.
[0134] (3) This invention takes into account various risks such as cross-regional, unauthorized external connections, configuration defects, malicious code, and vulnerabilities through multi-dimensional security checks. It is adapted to the characteristics of the power industry and ensures that no industry-specific risks are overlooked, thereby improving the reliability of the security check results.
[0135] The specific embodiments described above are preferred embodiments of the network security verification method and system for power monitoring systems of the present invention, and are not intended to limit the specific scope of the present invention. The scope of the present invention includes but is not limited to the specific embodiments described above. All equivalent changes made in accordance with the shape and structure of the present invention are within the protection scope of the present invention.
Claims
1. A method for network security verification of a power monitoring system, characterized in that: Includes the following steps: S1. Based on passive flow analysis and active detection mechanisms, asset mapping is performed on each device in the power monitoring system to obtain a list of equipment assets. The specific process of passive traffic parsing includes: Without injecting probe packets or modifying the configuration, collect flow data from the power monitoring system, including communication messages and protocol data exchanged between devices; Deep packet inspection of communication packets yields the IP address, MAC address, port number, communication protocol type, and device-specific identifier in the packet header as device characteristic information; The service communication relationships of the device are obtained by determining the interaction timing and data flow of communication messages based on protocol data; Use device characteristic information and business communication relationships as core device information; The specific process of an active detection mechanism includes: Send targeted detection requests to unknown devices in the power monitoring system network that are not listed in the core device information; Based on the targeted detection request, the open port list, operating system version, database type / version, and network device configuration summary of the unknown device are collected, and the above information is used as the unknown device information. S2. Based on the equipment asset list, the logical connection relationships of each node in the power monitoring system are integrated to obtain the field network topology diagram; the field network topology diagram consists of a core layer, a aggregation layer, and an access layer, with the devices in the core layer arranged in the center, the aggregation layer surrounding the core layer, and the access layer grouped according to physical location; S3. Based on the on-site network topology map and using a multi-dimensional security verification mechanism, perform security verification on the power monitoring network, and update the on-site network topology map based on the verification results; the multi-dimensional security verification includes verification of unauthorized external connections, verification of cross-regional assets, verification of configuration compliance, detection of malicious code, and detection of vulnerabilities.
2. The network security verification method for a power monitoring system according to claim 1, characterized in that: The core equipment information and the unknown equipment information are complemented to obtain the equipment information dataset; Based on a preset equipment type classification mechanism, the equipment in the equipment information dataset is classified to obtain an equipment asset list. The equipment asset list includes at least the equipment ID, equipment type, model / version, manufacturer identifier, affiliated plant, network partition, open port, supported protocols, communication object list, and data collection timestamp.
3. The network security verification method for a power monitoring system according to claim 2, characterized in that: In S2, the logical connection relationships of each node in the power monitoring system are integrated based on the equipment asset list to obtain the field network topology diagram, including the following steps: Based on the device type, the device function is determined, and based on the device function, each device is divided into the core layer, aggregation layer and access layer according to its importance. Construct device communication links based on device IDs and communication object lists, and associate them with corresponding open ports and supported protocols; The power monitoring system is divided into communication partitions based on the manufacturer's identifier, the plant or substation to which it belongs, and the network partition, with the boundary devices as the dividing points. The network topology is obtained by arranging the core layer devices in the center, the aggregation layer around the core layer, and the access layer grouped according to physical location, and classifying each device into a communication partition.
4. The network security verification method for a power monitoring system according to claim 1, characterized in that: The specific process for verifying violations of external connections includes: Collect system logs, remote operation records, and network connection status of the target device during operation in the on-site network topology diagram; If any of the following situations occur in the system log: unauthorized external device access, improper operation in remote operation traces, or unauthorized internal / external IP address or network card configuration error in network connection status, the target device will be marked as an unauthorized external connection device and displayed on the on-site network topology diagram.
5. The network security verification method for a power monitoring system according to claim 1, characterized in that: The specific process of the cross-regional asset verification includes: Collect communication packets of the target device in the on-site network topology diagram, and determine the communication path of the target device based on the gateway jump record of the communication packet and the corresponding device communication link; If the target device's communication path crosses the boundary devices of at least two communication zones, the target device is marked as a cross-zone asset device and displayed on the field network topology map; The specific process for verifying the configuration compliance includes: Based on the device type of the target device in the on-site network topology diagram, the target configuration index is selected from the preset configuration index library; The actual configuration parameters of the target device are compared with the preset compliance parameter range of the target configuration indicators. If the parameters exceed the compliance parameter range, the target device is marked as non-compliant and displayed on the on-site network topology diagram.
6. The network security verification method for a power monitoring system according to claim 1, characterized in that: The specific process of malicious code detection includes: Behavioral features of system files, installed clients, and running processes of target devices in the on-site network topology diagram are extracted, including file encryption algorithms, process privilege escalation behaviors, and communication methods. Based on a preset risk assessment index system, the behavioral characteristics are evaluated to obtain a security score. Target devices with security scores less than the security threshold are marked as risk devices and displayed on the on-site network topology map.
7. The network security verification method for a power monitoring system according to claim 1, characterized in that: The specific process of vulnerability detection includes: A vulnerability feature verification packet is sent to the target device in the on-site network topology diagram. The vulnerability features include at least system vulnerabilities, protocol vulnerabilities, configuration vulnerabilities, firmware vulnerabilities, and account vulnerabilities. If the target device matches the corresponding vulnerability characteristics, it will be marked as a vulnerable device and displayed on the on-site network topology diagram.
8. A network security verification system for a power monitoring system, applicable to the network security verification method for a power monitoring system as described in any one of claims 1-7, characterized in that: It includes an asset mapping module, a topology generation module, and a multi-dimensional security verification module; The asset mapping module performs asset mapping on each device in the power monitoring system based on passive flow analysis and active detection mechanisms to obtain a list of equipment assets. The topology generation module integrates the logical connection relationships of each node in the power monitoring system based on the equipment asset list to obtain the field network topology map. The multi-dimensional security verification module performs security verification on the power monitoring network based on the on-site network topology diagram and adopts a multi-dimensional security verification mechanism, and sends the verification results to the topology generation module to update the on-site network topology diagram.
Citation Information
Patent Citations
Power monitoring network security detection system and method
CN118368147A
Electric power industry ubiquitous Internet of Things security protection gateway system, method and deployment architecture
CN110958262A
Industrial field network security online monitoring system
CN120050104A