Network security management and control method and device, terminal equipment and storage medium
Patent Information
- Application Number
- CN202511614045.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-06
- Publication Date
- 2026-02-03
Smart Images

Figure CN121462264A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and in particular to a network security management and control method and device, a terminal equipment and a storage medium. BACKGROUND
[0002] In the field of power grid dispatching control, with the rapid development of informationization and intelligentization technology, the number of data input ports, data output ports and communication interface ports contained in the power grid dispatching control center is increasing day by day, and these ports become the main way for potential attackers to invade the system.
[0003] The existing network security management and control method usually adopts a unified security strategy for protection. When an abnormal port occurs, it is difficult to determine the related potential threat abnormal port according to the propagation path of the abnormal port in the topology network and isolate it, resulting in poor effect of security management and control. SUMMARY
[0004] The present application provides a network security management and control method, device, terminal equipment and storage medium, which can solve the technical problem that the existing technology adopts a unified security strategy for protection, and when an abnormal port occurs, it is difficult to determine the related potential threat abnormal port according to the propagation path of the abnormal port in the topology network and isolate it, resulting in poor effect of security management and control.
[0005] The present application provides a network security management and control method, comprising: Obtaining a plurality of ports of a target power grid dispatching control center, and constructing a port topology graph according to the plurality of ports, wherein the target power grid dispatching control center is applied to a target power grid operation cockpit; Constructing a risk identification network corresponding to each port, and determining a port risk value of each port according to the risk identification network; Determining a port corresponding to a port risk value greater than or equal to a first risk threshold as a high-risk port, and isolating the high-risk port from the target power grid dispatching center; Determining a port corresponding to a port risk value less than the first risk threshold and greater than or equal to a second risk threshold as an abnormal port, and performing association verification and synchronization verification on the abnormal port based on the port topology graph to determine a threat port in the port topology graph, and isolating the threat port from the target power grid dispatching control center, wherein the first risk threshold is greater than the second risk threshold.
[0006] Further, the construction of the risk identification network corresponding to each port comprises: Determining the data type and port type of each port, collecting historical interaction data of the same type of port of the same data type as a constraint. constructing a sample port interaction data set according to the historical interaction data, performing risk labeling on the sample port interaction data set to obtain a sample port risk value set; performing neural network training based on the sample port interaction data set and the sample port risk value set to generate a risk identification network corresponding to the current port.
[0007] Further, the association verification and synchronization verification of the abnormal port based on the port topology graph to determine the threat port in the port topology graph, comprising: determining the port association link of the abnormal port according to the port topology graph; determining the associated port based on the port association link, the associated port including the upstream associated port and the downstream associated port; performing association verification on the associated port to determine the associated abnormal port, and performing synchronization verification on the associated port to determine the concurrent abnormal port, and determining the abnormal port, the associated abnormal port and the concurrent abnormal port as the threat port.
[0008] Further, the association verification of the associated port to determine the associated abnormal port, comprising: obtaining a first port risk value sequence of the abnormal port and the associated port within a first preset time window, the first port risk sequence including a first abnormal port risk value sequence and a first associated port risk value sequence, the first associated port risk value sequence including a first upstream associated port risk value sequence and a first downstream associated port risk value sequence; obtaining the data flow transfer delay from the abnormal port to the associated port according to the port topology graph; based on the first abnormal port risk value sequence, combining the data flow transfer delay to verify whether there is a corresponding risk anomaly in the corresponding first associated port risk value sequence; the associated port with risk anomaly as the associated abnormal port of the current abnormal port.
[0009] Further, the association verification of the associated port to determine the associated abnormal port based on the first abnormal port risk value sequence, combining the data flow transfer delay to verify whether there is a corresponding risk anomaly in the corresponding first associated port risk value sequence, comprising: extracting abnormal risk value fluctuation features according to the first abnormal port risk value sequence; determining the time delay offset of the abnormal risk value fluctuation features propagating to the associated port according to the data flow transfer delay; detecting whether there is a fluctuation feature similar to the abnormal risk value fluctuation features in the associated port risk value sequence according to the time delay offset, if there is, it is determined that there is a corresponding risk anomaly.
[0010] Further, the synchronization verification of the associated ports determines the concurrent abnormal ports, comprising: obtaining a second port risk value sequence of each of the ports within a second preset time window to obtain a plurality of second port risk value sequences; taking a second abnormal port risk value sequence of an abnormal port in the plurality of second port risk value sequences as a reference port risk value sequence, and taking the second port risk value sequences of the remaining ports as to-be-verified port risk value sequences; synchronously comparing each of the to-be-verified port risk value sequences with the reference port risk value sequence, and determining a port with a synchronous risk value fluctuation as the concurrent abnormal port when the to-be-verified port risk value sequence has a synchronous risk value fluctuation with the reference port risk value sequence.
[0011] Further, the synchronous comparison of each of the to-be-verified port risk value sequences with the reference port risk value sequence detects whether there is a synchronous risk value fluctuation, comprising: extracting a reference risk value fluctuation feature of the reference port risk value sequence, and extracting a to-be-verified risk value fluctuation feature corresponding to each of the to-be-verified port risk value sequences; determining a fluctuation feature similarity of each of the to-be-verified risk value fluctuation features and the reference risk value fluctuation feature; when the fluctuation feature similarity is greater than or equal to a synchronous similarity threshold, confirming that the corresponding port has a synchronous risk value fluctuation.
[0012] The application also provides a network security management and control device, comprising: a port topology graph construction module, configured to obtain a plurality of ports of a target power grid dispatching control center, and construct a port topology graph according to the plurality of ports, wherein the target power grid dispatching control center is applied to an operation cockpit of a target power grid; a port risk value determination module, configured to construct a risk identification network corresponding to each of the ports, and determine a port risk value of each of the ports according to the risk identification network; a high-risk port isolation module, configured to determine a port corresponding to a port risk value greater than or equal to a first risk threshold as a high-risk port, and isolate the high-risk port from the target power grid dispatching center; a threat port isolation module, configured to determine a port corresponding to a port risk value less than the first risk threshold and greater than or equal to a second risk threshold as an abnormal port, perform associated verification and synchronization verification on the abnormal port based on the port topology graph to determine a threat port in the port topology graph, and isolate the threat port from the target power grid dispatching control center, wherein the first risk threshold is greater than the second risk threshold.
[0013] The application further provides a terminal device comprising a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor implements the network security management method as described above when executing the computer program.
[0014] The application further provides a computer readable storage medium comprising a stored computer program, wherein the computer readable storage medium controls a device in which the computer readable storage medium is located to execute the network security management method as described above when the computer program is running.
[0015] The application has the following beneficial effects: The application can accurately determine high-risk ports and abnormal ports by constructing a corresponding risk identification network for each port to determine the port risk value of each port, and can determine relevant potential threat abnormal ports according to the propagation path of the abnormal ports in the topology network and isolate the abnormal ports, thereby effectively improving the effect of network security management.
[0016] Further, the application can accurately determine the associated abnormal ports affected by risk propagation by performing associativity verification on abnormal ports in combination with data flow, and can determine concurrent abnormal ports with synchronous risk value fluctuations by performing synchronous verification on abnormal ports, thereby comprehensively identifying threat ports in the power grid dispatching and control center and isolating the threat ports, and effectively improving the comprehensiveness and reliability of network security management. BRIEF DESCRIPTION OF DRAWINGS
[0017] In order to more clearly illustrate the technical solutions of the present application, the following will briefly introduce the drawings needed in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0018] Figure 1 is a flow diagram of a network security management method provided by an embodiment of the application; Figure 2 is a structural diagram of a network security management device provided by an embodiment of the application. DETAILED DESCRIPTION
[0019] In order to make the objects, technical solutions and advantages of the present application clearer, the following will clearly and completely describe the technical solutions in the present application in conjunction with the accompanying drawings of the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the present application.
[0020] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs; the terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of this application; the terms "comprising," "comprises" and "including" and "has" and any variations thereof used herein are intended to cover a non-exclusive inclusion.
[0021] In the description of the embodiments of the present application, the technical terms "first", "second", etc. are only used to distinguish different objects, and cannot be understood as indicating or implying relative importance or implicitly indicating the number, specific order or primary and secondary relationship of the indicated technical features. In the description of the embodiments of the present application, the meaning of "a plurality of" is two or more, unless otherwise explicitly and specifically limited.
[0022] Reference herein to "an embodiment" means that a particular feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of the present application. The appearance of the phrase in various places in the specification does not necessarily all refer to the same embodiment, nor is it necessarily independent or alternative embodiments to each other. Those skilled in the art explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.
[0023] In the description of the embodiments of the present application, the term "and / or" is only a description of the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which can represent the three cases of A alone, A and B together, and B alone. In addition, the character " / " in this paper generally represents that the front and rear associated objects are a "or" relationship.
[0024] In the description of the embodiments of the present application, the term "a plurality of" refers to two or more (including two), and similarly, "a plurality of groups" refers to two or more groups (including two groups), and "a plurality of pieces" refers to two or more pieces (including two pieces).
[0025] In the description of the embodiments of the present application, unless otherwise explicitly specified and limited, the technical terms "mounting", "connection", "connecting", "fixing" and the like should be understood in a broad sense, for example, can be fixed connection, can also be detachable connection, or integral; can be mechanical connection, can also be electrical connection; can be direct connection, can also be indirect connection through an intermediate medium, can be internal communication of two elements or interaction relationship between two elements. For those skilled in the art, the specific meanings of the above terms in the embodiments of the present application can be understood according to the specific circumstances.
[0026] Referring to Figure 1 To solve the technical problem that when a unified security policy is used for protection in the prior art, it is difficult to identify the propagation path of the risk in the topology network and the related threat when an exception occurs in a certain port, resulting in poor effect of security control, an embodiment of the present application provides a network security control method, comprising: S1, obtaining a plurality of ports of a target power grid dispatching control center, and constructing a port topology graph according to the plurality of ports, wherein the target power grid dispatching control center is applied to an operation cockpit of the target power grid; In the embodiments of the present application, the power grid dispatching control center can be taken as an execution scene. The power grid dispatching control center (i.e. the operation cockpit) is a key place for controlling and guaranteeing the safe and stable operation of the power grid, and is responsible for real-time monitoring, dispatching command and coordination of power production, transmission and distribution of the power system. The power grid dispatching control center contains a large number of data input ports, data output ports and communication interface ports, which are the main intrusion paths of attackers. In the embodiments of the present application, the cockpit network security control specifically refers to the comprehensive management and control of the network security in the power grid dispatching control center, including the security protection of the key nodes such as data input ports, data output ports and communication interface ports.
[0027] In the embodiments of the present application, according to the plurality of ports of the target power grid dispatching control center, a port atlas graph is constructed, and the port topology graph depicts the connection relationship and layout of all ports in the control center. The "port" is a key node for data transmission and communication as the "gate" of the computer, including physical ports such as serial ports, parallel ports, input / output device interfaces and adapter interfaces of the computer, etc., which directly correspond to hardware connections. The port also includes software ports such as TCP / UDP ports used in network communication, which are virtual channels for data exchange. Hackers use these ports as a breakthrough for intrusion to freely enter and exit the system to implement attacks.
[0028] The embodiment of the present application can clearly identify the position, function and interaction path of each port with other ports by constructing the port topology graph, and provides a basis for subsequent security protection strategy making. The embodiment of the present application is helpful to comprehensively understand the network architecture of the control center, and also enables security personnel to implement customized protection measures for specific ports, such as deploying firewall rules, setting access control lists, etc., thereby effectively resisting illegal intrusion and data theft from the outside, significantly improving the overall network security level of the target power grid dispatching control center, and ensuring the stability and reliability of the power grid operation.
[0029] S2, a risk identification network corresponding to each port is constructed, and a port risk value of each port is determined according to the risk identification network; In the embodiment of the present application, the data type, communication protocol and function role of each port in the system can be analyzed to ensure that the constructed risk identification network can accurately match the characteristics of each port. For example, for a port that processes sensitive data transmission, a risk identification network with high-precision data anomaly detection capability is constructed; and for a port that is mainly responsible for control instruction transmission, a network focusing on instruction legality verification and real-time threat monitoring is constructed.
[0030] Among them, a plurality of risk identification networks learn the patterns of normal and abnormal data interaction by collecting and analyzing historical interaction data of the same type of port, and then form accurate identification ability of the data interaction risk of each port. In the running process, these risk identification networks continuously monitor the data interaction activities of the port, use machine learning algorithms to evaluate the risk of real-time data, and quantify the port risk value of each port. The high and low of the port risk value directly reflects the degree of security threat currently faced by the port, and provides a key basis for subsequent security decision-making.
[0031] The embodiment of the present application can determine the port risk value of the corresponding port according to each risk identification network by constructing a risk identification network corresponding to each port, not only can accurately identify the data interaction risk of each port, but also can greatly improve the response speed and processing efficiency of the power grid dispatching control center to potential security threats, and ensure the stable operation and data security of the power grid system.
[0032] S3, the port corresponding to the port risk value greater than or equal to the first risk threshold is determined as a high-risk port, and the high-risk port is isolated from the target power grid dispatching center; In the embodiment of the present application, the first risk threshold value can be set based on historical data and security policy, and the first risk threshold value is used to define the critical point of the port risk level. When the port risk value of a certain port reaches or exceeds the threshold value, it is determined that the port is a high-risk port, which means that the current security threat faced by the port has reached an unacceptable level and may pose a serious threat to the stable operation of the power grid dispatching control center. For example, if the risk value of a certain data output port rises above the first risk threshold value due to frequent abnormal data interaction, it will be immediately identified as a high-risk port.
[0033] In the embodiment of the present application, after determining the high-risk ports, the positions of the high-risk ports in the overall network architecture can be located according to the pre-constructed port topology graph, and the high-risk ports can be isolated from the target power grid dispatching center to block the potential security threat propagation path and ensure the safe and stable operation of the power grid system.
[0034] S4, the port corresponding to the port risk value less than the first risk threshold value and greater than or equal to the second risk threshold value is determined as an abnormal port, and the abnormal port is verified and synchronized based on the port topology graph to determine the threat port in the port topology graph, and the threat port is isolated from the target power grid dispatching control center, wherein the first risk threshold value is greater than the second risk threshold value.
[0035] In the embodiment of the present application, when it is monitored that the port risk value of a certain port is between the first risk threshold value and the second risk threshold value, it is determined that the port is an abnormal port, which indicates that there is a certain degree of security risk but has not reached the high-risk standard of direct isolation. The first risk threshold value is set to be higher than the second risk threshold value, and the purpose of setting the second risk threshold value is to set a certain redundancy for the isolation decision to prevent the decision from being too arbitrary, but the potential risk needs to be concerned.
[0036] When the port risk value is less than the first risk threshold value and greater than or equal to the second risk threshold value, the associated analysis unit and the synchronization analysis unit can be intelligently configured according to the pre-constructed port topology graph to perform associated verification and synchronization verification, respectively.
[0037] The correlation analysis unit accurately identifies the associated ports directly or indirectly connected with the abnormal port by deeply analyzing the port topology graph, and further verifies whether the port risk value sequence of the associated ports has similar fluctuation characteristics as the abnormal port, to determine whether the risk is transmitted among the associated ports. That is, by verifying the mutual relationship between each port, it is determined whether a port is not only at risk itself, but also has a connection with other ports that may trigger or participate in a larger range of security threats, so as to determine whether the port is a real threat port. For example, a port may not be identified as a real threat port if it is found to have no direct or indirect association with other key system ports and does not trigger a larger range of security threats. However, if it is found that a port has a data interaction relationship with other multiple ports at risk, it may be identified as a real threat port.
[0038] The synchronization analysis unit focuses on monitoring the port risk value sequence of all ports, detecting whether there is a risk event that occurs synchronously with the abnormal port risk value fluctuation, to identify possible global threats or coordinated attack behaviors. That is, the synchronization verification is performed from different dimensions, such as real-time data transmission and consistent port response.
[0039] The embodiment of the present application can accurately locate the real threat port, i.e. the port that not only has a risk itself, but also may trigger or participate in a larger range of security threats, through a series of correlation verification and synchronization verification processes. After determining the location of the threat port, the threat port is isolated from the target power grid dispatching and control center, thereby effectively containing the spread of security threats and ensuring the overall safety and stable operation of the power grid system.
[0040] The embodiment of the present application can early and timely discover and handle potential security threats by performing correlation verification and synchronization verification on the abnormal port based on the port topology graph, determining the threat port in the port topology graph and performing isolation processing, thereby significantly improving the security and reliability of the power grid system.
[0041] The embodiment of the present application constructs a corresponding risk identification network for each port to determine the port risk value of each port, which can accurately determine high-risk ports and abnormal ports, and by performing correlation verification and synchronization verification on the abnormal port, it can determine the related potential threat abnormal ports according to the propagation path of the abnormal port in the topology network and perform isolation, thereby effectively improving the effect of network security management and control.
[0042] In one embodiment, step S2 of constructing a risk identification network corresponding to each port comprises: S21, determine the data type and port type of each port, and collect historical interaction data of the same type of port of the same data type as a constraint. In the embodiment of the present application, one port can be selected as the starting point port, i.e., the first port, among multiple ports, and after completing the risk identification network of the first port, the risk identification networks corresponding to other ports are completed one by one.
[0043] In the embodiment of the present application, data collection is performed for the first port, and first data types related to the port are extracted, which can include network traffic data, control instruction data, and state information data, etc., which reflect the characteristics of the port in different aspects such as network communication, device control, and state feedback. At the same time, the first port type of the first port needs to be obtained, such as SCADA control port, HMI interaction port, or protocol communication port, etc., and the port type determines the functional positioning and interaction mode of the port in the system.
[0044] In the embodiment of the present application, after the first port type and the first data type are determined, the historical interaction data of the same type of port of the same data type is further collected and processed as a constraint condition. For example, if the first port is a SCADA control port and the first data type is control instruction data, the historical interaction records of other SCADA control ports when processing control instruction data need to be collected.
[0045] S22, constructing a sample port interaction data set according to the historical interaction data, performing risk labeling on the sample port interaction data set, and obtaining a sample port risk value set; In the embodiment of the present application, the collected historical interaction data is integrated and constructed into a sample port interaction data set, which contains rich port interaction scenarios and modes. The interaction scenario refers to the specific situation of interaction between the port and other devices, programs or systems under different conditions, such as different software requesting data through the port and devices establishing connection through the port, etc. The mode refers to the way, rule or process followed by these interactions, such as synchronous interaction mode or asynchronous interaction mode, etc.
[0046] In the embodiment of the present application, the sample port interaction data set is labeled for risk, i.e., according to the abnormal conditions, security events and other information in the historical interaction data, each sample data in the sample port interaction data set is given a corresponding risk value, so as to obtain a sample port risk value set. The sample port risk value set is a specific risk quantization value given to each sample port interaction data according to the degree of security risk it may cause, such as low risk, medium risk, high risk, etc. These values together constitute the sample port risk value set, which can provide the basis for risk assessment for subsequent model training.
[0047] S23, performing neural network training based on the sample port interaction data set and the sample port risk value set to generate a risk identification network corresponding to the current port.
[0048] In the embodiment of the present application, based on the constructed sample port interaction data set and sample port risk value set, the model training is performed in combination with the neural network model, the model parameters are continuously adjusted, the model can learn the internal relationship between the port interaction data and the risk value, and finally the risk identification network for the first port is generated. The network can accurately identify the security risks that the first port may face when processing specific data types, and provide strong support for the security protection of the port. After completing the training of the risk identification network of the first port, it is deployed on the first port, so that it can monitor the port interaction data in real time, and timely discover and warn potential security risks.
[0049] In the embodiment of the present application, based on the technical concept of constructing the risk identification network of the first port, the corresponding risk identification networks of other ports are sequentially constructed and deployed. In this way, a corresponding risk identification network can be constructed for each port to achieve more accurate and efficient security protection. This customized risk identification network construction and deployment method for each port can significantly improve the identification accuracy and response speed of the system to port security risks, effectively reduce the probability of security incidents, and thus effectively protect the stable operation and data security of the system.
[0050] In one embodiment, step S4, based on the port topology graph, the abnormal port is verified and synchronized, the threat port in the port topology graph is determined, comprising: S41, determining the port association link of the abnormal port according to the port topology graph; In the embodiment of the present application, the port association link of the abnormal port is determined according to the port topology graph, which can reflect the connection relationship and data flow direction of the current abnormal port in the network.
[0051] S42, determining the associated port based on the port association link, the associated port including the upstream associated port and the downstream associated port; In the embodiment of the present application, the associated port, i.e. the upstream associated port and the downstream associated port, can be accurately determined based on the association link. The upstream associated port is usually a port that sends data or instructions to the abnormal port, and the downstream associated port is a port that receives data or instructions from the abnormal port.
[0052] S43, performing association verification on the associated port to determine the associated abnormal port, and performing synchronization verification on the associated port to determine the concurrent abnormal port, and determining the abnormal port, the associated abnormal port and the concurrent abnormal port as the threat port.
[0053] In the embodiments of the present application, the correlation analysis unit and the synchronization analysis unit can be configured according to the port topology graph, the output ends of the risk identification networks of the abnormal port, the upstream correlation port and the downstream correlation port are connected to the input ends of the correlation analysis unit to form an abnormal correlation verification network, and correlation verification is performed through the abnormal correlation verification network. For example, in an industrial control system, if a SCADA control port is identified as an abnormal port, the upstream sensor data acquisition port and the downstream actuator control port thereof are found through the port topology graph, the output ends of the three ports are connected to the correlation analysis unit, an abnormal correlation verification network is constructed, and the network can analyze the correlation risk between the abnormal port and the upstream and downstream ports to determine whether the abnormality is caused by the upstream port or whether it will be propagated to the downstream port.
[0054] The embodiments of the present application can also connect the output ends of the risk identification networks of the ports to the input ends of the synchronization analysis unit to form a global synchronization verification network, and synchronization verification is performed through the global synchronization verification network. The global synchronization verification network can monitor and analyze the risk states of all ports from a global perspective and consider the mutual influence and synergistic effect between the ports. That is, the output ends of the risk identification networks of multiple different types of ports are connected to the synchronization analysis unit to form a global synchronization verification network, the risk changes of the ports in the entire network can be analyzed in real time, and it is determined whether concurrent abnormality of multiple ports occurs simultaneously.
[0055] In the embodiments of the present application, the abnormal port is verified by the abnormal correlation verification network, and by analyzing the data interaction mode, risk propagation rule and the like between the abnormal port and the upstream and downstream ports, the correlation abnormal ports affected by the abnormal port can be found. For example, if the abnormal port is a key server port, after the abnormal port appears, multiple client ports connected to the abnormal port are found to have data access abnormality or performance decline through the abnormal correlation verification network, and these client ports are the correlation abnormal ports.
[0056] At the same time, the abnormal port is verified by the global synchronization verification network, and concurrent abnormal ports that appear abnormal simultaneously with the abnormal port in the same time period can be detected. For example, when the network is attacked by a large-scale attack, multiple ports may appear traffic abnormality, access abnormality and the like simultaneously, and these concurrent abnormal ports can be quickly identified through the global synchronization verification network.
[0057] Finally, the abnormal port, the associated abnormal port and the concurrent abnormal port are collectively taken as a threat port. The abnormal port, the associated abnormal port and the concurrent abnormal port are determined by the association verification of the associated port, the synchronization verification of the associated port and the embodiment of the method, so that the port threatened by security in the network can be comprehensively and accurately identified. Not only the risk of the abnormal port itself is considered, but also the risk propagation relationship between the abnormal port and the associated port and the synchronization abnormality of each port in the entire network are analyzed, so that the accuracy and comprehensiveness of the threat port identification can be effectively improved, a strong basis for subsequent security protection measures is provided, and the security and stability of the network system are effectively improved.
[0058] In one embodiment, the step S43 of performing association verification on the associated port to determine the associated abnormal port comprises: S4301, obtaining a first port risk value sequence of the abnormal port and the associated port within a first preset time window, the first port risk sequence comprising a first abnormal port risk value sequence and a first associated port risk value sequence, the first associated port risk value sequence comprising a first upstream associated port risk value sequence and a first downstream associated port risk value sequence; In the embodiment of the application, first, the first port risk value sequence of the abnormal port, the upstream associated port and the downstream associated port within the first preset time window needs to be obtained. The first preset time window can be set according to the security requirements and the risk change frequency of the actual network environment, for example, 5 minutes, 10 minutes, etc. The risk identification network of each port is used in the embodiment of the application to continuously monitor and record the risk value of the port within the set time window, so as to obtain the first abnormal port risk value sequence, the first upstream associated port risk value sequence and the first downstream associated port risk value sequence. These risk value sequences reflect the risk state of the port at different time points, and are an important data basis for subsequent association verification.
[0059] S4302, obtaining a data flow transfer delay from the abnormal port to the associated port according to the port topology graph; In the embodiment of the application, the port topology graph describes the connection relationship and data flow direction between each port in the network in detail, and the data flow transfer delay represents the time required for data to be transmitted from the abnormal port to the upstream associated port or the downstream associated port. For example, in an industrial control network, a control instruction is sent from a SCADA control port (abnormal port) to a sensor data acquisition port (upstream associated port), and there is a certain time delay in the network transmission of data. The time delay can be calculated by a network performance monitoring tool or according to the network topology structure and link bandwidth parameters.
[0060] S4303, based on the first abnormal port risk value sequence, verifying whether there is a corresponding risk anomaly in the corresponding first associated port risk value sequence in combination with the data flow transfer delay; In the embodiment of the present application, based on the first abnormal port risk value sequence, in combination with the obtained data flow transfer delay, it is verified whether there is a corresponding risk abnormality in the corresponding first upstream associated port risk value sequence and the first downstream associated port risk value sequence. Specifically, the risk change in the first abnormal port risk value sequence is combined with the data flow transfer delay, and the risk value change at the corresponding delay position is searched in the risk value sequence of the upstream associated port and the downstream associated port. For example, if the risk value of the abnormal port suddenly rises at a certain time, according to the data flow transfer delay, the position after the corresponding delay in the upstream associated port risk value sequence or the position before the corresponding delay in the downstream associated port risk value sequence is checked to check whether there is a similar risk abnormality change.
[0061] S4304, the associated port with the risk abnormality is taken as the associated abnormal port of the current abnormal port.
[0062] In the embodiment of the present application, when the first upstream associated port risk value sequence or the first downstream associated port risk value sequence has a risk abnormality at the corresponding delay position, the corresponding upstream associated port or downstream associated port is determined as the associated affected port. For example, if the abnormal port risk value sequence shows that the risk value rises sharply at time t, the data flow transfer delay is 2 seconds, and the risk value of the upstream associated port also rises abnormally at t+2 seconds, it is determined that the upstream associated port is the associated abnormal port.
[0063] In one embodiment, step S4303, based on the first abnormal port risk value sequence, in combination with the data flow transfer delay, verifies whether there is a corresponding risk abnormality in the corresponding first associated port risk value sequence, comprising: S43031, extracting abnormal risk value fluctuation characteristics according to the first abnormal port risk value sequence; In the embodiment of the present application, the abnormal risk value fluctuation characteristics are key information reflecting the change of the risk state of the abnormal port, including the rising amplitude, the falling amplitude, the fluctuation frequency, the fluctuation period, etc. For example, if the abnormal port risk value sequence shows that the risk value rises rapidly from a normal level to a higher value within a certain period of time, and the rising process has a clear steep trend, such rising amplitude and steep trend can be used as abnormal risk value fluctuation characteristics. The abnormal risk value fluctuation characteristics can quantitatively describe the change of the risk of the abnormal port, and provide an important basis for subsequent associated verification.
[0064] S43032, determining the delay offset amount of the abnormal risk value fluctuation characteristics propagated to the associated port according to the data flow transfer delay; In the embodiments of the present application, the data flow delay refers to the time required for data to be transmitted from the abnormal port to the upstream associated port or the downstream associated port, and the delay offset is a modified value of the abnormal risk value fluctuation feature propagation time after considering factors such as delay and buffering in the data transmission process. For example, in a complex network environment, data may pass through multiple network nodes and links, resulting in a difference between the actual transmission time and the theoretically calculated value. At this time, the delay offset is needed to more accurately determine the corresponding position of the abnormal risk value fluctuation feature in the associated port risk value sequence.
[0065] In the upstream associated port risk value sequence and the downstream associated port risk value sequence, whether there is a fluctuation feature similar to the abnormal risk value fluctuation feature is detected based on the determined delay offset. Specifically, the abnormal risk value fluctuation feature is taken as a template, and a sliding matching is performed in the associated port risk value sequence according to the time position corresponding to the delay offset to check whether there is a similar fluctuation feature. For example, if the abnormal risk value fluctuation feature is that the risk value rapidly rises and then slowly falls in a short time, then in the associated port risk value sequence, the corresponding time period is found according to the delay offset, and it is checked whether there is a similar fluctuation mode of rapidly rising and then slowly falling risk value.
[0066] S43033、In the associated port risk value sequence, whether there is a fluctuation feature similar to the abnormal risk value fluctuation feature is detected according to the delay offset, and if so, it is determined that there is a corresponding risk abnormality.
[0067] In the embodiments of the present application, when a fluctuation mode similar to the abnormal risk value fluctuation feature is detected in the upstream associated port risk value sequence or the downstream associated port risk value sequence, it is confirmed that the corresponding port has a corresponding risk abnormality. This associated verification method based on the abnormal risk value fluctuation feature and the delay offset can effectively identify the risk abnormality of the associated port caused by the risk propagation of the abnormal port, and improve the detection accuracy and accuracy of the risk propagation in the network. By discovering the risk abnormality of the associated port in a timely manner, more comprehensive risk information can be provided to the network security management personnel, which helps to take timely and effective security measures to prevent the further spread of risks and ensure the safe and stable operation of the network system.
[0068] In one embodiment, step S43, synchronously verifying the associated port to determine the concurrent abnormal port, includes: S4311、Obtain the second port risk value sequence of each port in the second preset time window to obtain a plurality of second port risk value sequences; In the embodiments of the present application, the second preset time window can be set according to the actual operation status of the network, safety monitoring requirements and other factors, and the length thereof is different from that of the first preset time window, and the collection frequency also differs. For example, if the network is in a high-risk activity period, the second preset time window can be set to a shorter 3 minutes to more timely capture the port risk changes; and the collection frequency can be determined according to the network bandwidth, data processing capacity and other factors, such as collecting the port risk value once per second. Through the special risk identification network of each port, the port risk values are continuously monitored and recorded within the set second preset time window, thereby forming a plurality of second port risk value sequences, and these sequences provide a comprehensive data basis for subsequent synchronization verification.
[0069] S4312, taking the second abnormal port risk value sequence of the abnormal port in the plurality of second port risk value sequences as a reference port risk value sequence, and taking the second port risk value sequences of the remaining ports as to-be-verified port risk value sequences; In the embodiments of the present application, among the plurality of enemy port risk value sequences obtained, the second port risk value sequence of the abnormal port is taken as a reference port risk value sequence, and the second port risk value sequences of the remaining ports are taken as to-be-verified port risk value sequences. The reference port risk value sequence serves as a benchmark for synchronization comparison and can reflect the risk change of the abnormal port in a specific time period, and the to-be-verified port risk value sequences are used to detect whether there is a risk fluctuation synchronized with the abnormal port.
[0070] S4313, taking the reference port risk value sequence as a benchmark, synchronously comparing each to-be-verified port risk value sequence, and when the to-be-verified port risk value sequence and the reference port risk value sequence have a synchronous risk value fluctuation, determining that the port with the synchronous risk value fluctuation is a concurrent abnormal port.
[0071] In the embodiments of the present application, synchronization comparison means that the risk value sequences of the reference port and the to-be-verified port are compared point by point or segment by segment in the same time dimension. For example, the reference port risk value sequence and the to-be-verified port risk value sequence are aligned according to the time axis, and it is checked whether the risk value of the to-be-verified port and the risk value of the reference port present a similar change trend at each time point or time period, regardless of the size of the fluctuation. For example, if the risk value of the reference port presents a trend of first rising and then falling in a certain time period, if there is also a similar trend of first rising and then falling in the corresponding time period of the to-be-verified port risk value sequence, it is considered that there is a synchronous risk value fluctuation.
[0072] When the to-be-verified port risk value sequence and the reference port risk value sequence exist synchronous risk value fluctuation, it can be determined that the corresponding port is a concurrent abnormal port. This synchronous verification form based on the global synchronous verification network can comprehensively and accurately detect the concurrent abnormal port which appears risk fluctuation at the same time as the abnormal port in the network, and is not affected by the fluctuation size. By timely finding the concurrent abnormal port, more comprehensive risk information can be provided for the network security management personnel, which helps to quickly locate the possible coordinated attack or large-scale risk event in the network, timely take effective security measures, prevent the further spread of risks, and ensure the safe and stable operation of the network system.
[0073] In one embodiment, step S4313, taking the reference port risk value sequence as a reference, synchronously comparing each to-be-verified port risk value sequence, detecting whether there is synchronous risk value fluctuation, includes: S43131, extracting the reference risk value fluctuation feature of the reference port risk value sequence, and extracting the to-be-verified risk value fluctuation feature corresponding to each to-be-verified port risk value sequence; In the embodiment of the application, when taking the reference port risk value sequence as a reference to synchronously compare each to-be-verified port risk value sequence and detect whether there is synchronous risk value fluctuation, the reference risk value fluctuation feature needs to be extracted according to the reference port risk value sequence. The reference risk value fluctuation feature is key information reflecting the risk change rule of the abnormal port in a specific time period, which may cover the rising rate, the falling rate, the fluctuation amplitude, the fluctuation period and the fluctuation form (such as sawtooth, pulse, etc.) of the risk value. For example, if the reference port risk value sequence shows that the risk value rises rapidly in a certain time period, then this rising rate, amplitude and ladder form can be used as the reference risk value fluctuation feature. These features can quantitatively describe the change mode of the abnormal port risk, and provide a basis for subsequent similarity calculation.
[0074] Synchronously, according to each to-be-verified port risk value sequence, a plurality of to-be-verified risk value fluctuation features are extracted. The same feature extraction operation as the reference port risk value sequence is performed on the to-be-verified port risk value sequence to obtain the risk value fluctuation feature of each to-be-verified port. For example, for the risk value sequence of a to-be-verified port, if its risk value also presents similar ladder rising in the same time period, but the rising amplitude and rate are slightly different from the reference port, then the rising rate, amplitude and ladder form of the to-be-verified port constitute its to-be-verified risk value fluctuation feature.
[0075] S43132, determining the fluctuation feature similarity of each to-be-verified risk value fluctuation feature and the reference risk value fluctuation feature; In the embodiments of the present application, the similarity calculation can adopt various algorithms, such as cosine similarity, Euclidean distance, etc. Taking the cosine similarity as an example, the cosine value between two feature vectors is calculated to measure their similarity, and the closer the cosine value is to 1, the more similar the two feature vectors are. For example, if the numerical values of the reference risk value fluctuation feature vector and the certain to-be-verified risk value fluctuation feature vector in each dimension are relatively close, the calculated cosine similarity will be higher.
[0076] S43133, when the fluctuation feature similarity is greater than or equal to the synchronization similarity threshold, it is determined that the corresponding port has a synchronous risk value fluctuation.
[0077] In the embodiments of the present application, when the fluctuation feature similarity is greater than or equal to the synchronization similarity threshold, it is determined that the corresponding port has a synchronous risk value fluctuation. The synchronization similarity threshold is a standard value set according to the actual network environment and security requirements, which is used to determine whether the risk value fluctuations of the to-be-verified port and the reference port are similar enough, so as to determine whether there is a synchronous risk. For example, if the synchronization similarity threshold is set to 0.8, when the similarity calculation result of a certain to-be-verified risk value fluctuation feature and a reference risk value fluctuation feature is 0.85, since 0.85 is greater than or equal to 0.8, it can be determined that the port corresponding to the to-be-verified port has a synchronous risk value fluctuation.
[0078] The embodiments of the present application can accurately detect concurrent abnormal ports similar to the abnormal port risk change mode in the network by calculating the similarity based on the reference risk value fluctuation feature and the to-be-verified risk value fluctuation feature, thereby improving the identification accuracy and efficiency of the concurrent abnormal ports.
[0079] In one embodiment, the determination of the first risk threshold and the second risk threshold of each port includes: S10, obtaining a sample port risk value set of each port; S20, performing data distribution analysis on the sample port risk value set to identify a natural breakpoint of the risk value distribution; S30, determining a normal interval, an abnormal interval and a high-risk interval based on the natural breakpoint; S40, setting the starting value of the abnormal interval as the second risk threshold, and setting the starting value of the high-risk interval as the first risk threshold.
[0080] In the network risk assessment and threshold setting process, in order to reasonably distinguish the port risk state, the first risk threshold is set to be greater than the second risk threshold.
[0081] The embodiments of the present application can determine the first preset threshold and the second preset threshold of the first port, and then based on the same technical concept, set the first risk threshold and the second risk threshold corresponding to each of the other ports.
[0082] In the embodiments of the present application, the determination of the first preset threshold and the second preset threshold of the first port can be: obtaining a sample port risk value set of the first port, which can be obtained by long-term and high-frequency risk monitoring of the first port, for example, collecting the port risk value of the first port every 5 minutes within a month, thereby forming a sample port risk value set containing a large amount of risk value data.
[0083] Then, data distribution analysis is performed on the sample port risk value set, and a natural breakpoint of the risk value distribution is identified by using the natural breakpoint method. The natural breakpoint method is a clustering analysis method based on the distribution characteristics of data itself, which can automatically divide different intervals according to the distribution of data values, so that the data in the same interval has smaller difference, and the data between different intervals has larger difference. For example, if most of the risk values in the sample port risk value set are concentrated in a lower value range, and the risk value shows an obvious jump growth after a certain value, then this jump point can be used as the natural breakpoint.
[0084] Further, based on the identified natural breakpoint, the risk value distribution is divided into a normal interval, an abnormal interval and a high-risk interval. The risk value in the normal interval indicates that the port is in a normal operating state and has low risk; the risk value in the abnormal interval indicates that the port may have potential risks and needs attention; and the risk value in the high-risk interval means that the port faces a higher security threat and needs to take immediate measures. For example, through the natural breakpoint method, the normal interval can be determined as risk value 0-20, the abnormal interval as 20-50, and the high-risk interval as 50 and above.
[0085] Then, the starting value of the abnormal interval is set as the second risk threshold, and the starting value of the high-risk interval is set as the first risk threshold. In the above example, the second risk threshold is 20, and the first risk threshold is 50. When the port risk value exceeds the second risk threshold but does not reach the first risk threshold, it is determined that the port is in an abnormal state; and when the port risk value exceeds the first risk threshold, it is determined that the port is in a high-risk state.
[0086] Finally, the corresponding first risk threshold and second risk threshold are set for other ports according to the threshold setting mode of the first port. Since the functions, importance and risk environment of different ports in the network may be different, setting the threshold for each port can more accurately reflect its risk state. For example, for a core port, a relatively low first risk threshold and second risk threshold can be set to ensure more sensitivity to its risk changes; and for an ordinary port, the threshold can be appropriately increased.
[0087] This invention employs the natural breakpoint method to analyze the data distribution of the sample port risk value set, determining normal, abnormal, and high-risk intervals. Based on this, a first risk threshold and a second risk threshold are set. This method can determine the thresholds based on the data's distribution characteristics to classify high-risk and abnormal ports, adapting to the risk characteristics of different ports and improving the accuracy of risk port classification. Consequently, it can effectively enhance the effectiveness of network security management.
[0088] Implementing the embodiments of the present invention has the following beneficial effects: This invention constructs a corresponding risk identification network for each port to determine the port risk value of each port. It can accurately identify high-risk ports and abnormal ports, and by performing correlation verification and synchronous verification on abnormal ports, it can identify and isolate related potential threat abnormal ports based on the propagation path of abnormal ports in the topology network, thereby effectively improving the effectiveness of network security management.
[0089] Furthermore, this embodiment of the invention combines data flow to perform correlation verification on abnormal ports, which can accurately identify associated abnormal ports affected by risk propagation, and perform synchronous verification on abnormal ports to identify concurrent abnormal ports that have synchronous risk value fluctuations with abnormal ports. This enables comprehensive identification and isolation of threat ports in the power grid dispatch and control center, and can effectively improve the comprehensiveness and reliability of network security management.
[0090] like Figure 2 As shown, based on the above method embodiments, corresponding apparatus embodiments are provided; An embodiment of the present invention provides a network security management and control device, comprising: The port topology construction module 10 is used to obtain multiple ports of the target power grid dispatch control center and construct a port topology map based on the multiple ports. The target power grid dispatch control center is used as the operation cockpit of the target power grid. The port risk value determination module 20 is used to construct a risk identification network corresponding to each port and determine the port risk value of each port based on the risk identification network. The high-risk port isolation module 30 is used to identify ports with a port risk value greater than or equal to a first risk threshold as high-risk ports and isolate the high-risk ports from the target power grid dispatch center. The threat port isolation module 40 is used to identify ports with risk values that are less than a first risk threshold and greater than or equal to a second risk threshold as abnormal ports, and to perform association verification and synchronization verification on the abnormal ports based on the port topology map to identify threat ports in the port topology map and isolate the threat ports from the target power grid dispatch control center, wherein the first risk threshold is greater than the second risk threshold.
[0091] In one embodiment, a risk identification network corresponding to each port is constructed, including: determining the data type and port type of each port, collecting historical interaction data of the same type of port of the same data type as a constraint of the data type and port type; constructing a sample port interaction data set according to the historical interaction data, performing risk labeling on the sample port interaction data set to obtain a sample port risk value set; based on the sample port interaction data set and the sample port risk value set, performing neural network training to generate a risk identification network corresponding to the current port.
[0092] In one embodiment, based on the port topology graph, the abnormal port is associated and verified, and the synchronous verification is performed to determine the threat port in the port topology graph, including: determining the port association link of the abnormal port according to the port topology graph; determining the associated port based on the port association link, the associated port including the upstream associated port and the downstream associated port; performing association verification on the associated port to determine the associated abnormal port, performing synchronous verification on the associated port to determine the concurrent abnormal port, and determining the abnormal port, the associated abnormal port and the concurrent abnormal port as the threat port.
[0093] In one embodiment, the associated port is associated and verified to determine the associated abnormal port, including: obtaining a first port risk value sequence of the abnormal port and the associated port in a first preset time window, the first port risk sequence including a first abnormal port risk value sequence and a first associated port risk value sequence, the first associated port risk value sequence including a first upstream associated port risk value sequence and a first downstream associated port risk value sequence; obtaining the data flow transfer delay of the abnormal port to the associated port according to the port topology graph; based on the first abnormal port risk value sequence, combining the data flow transfer delay, and verifying whether there is a corresponding risk anomaly in the corresponding first associated port risk value sequence; the associated port with the risk anomaly is taken as the associated abnormal port of the current abnormal port.
[0094] In one embodiment, based on the first abnormal port risk value sequence, combining the data flow transfer delay, and verifying whether there is a corresponding risk anomaly in the corresponding first associated port risk value sequence, including: extracting an abnormal risk value fluctuation feature according to the first abnormal port risk value sequence; determining a time delay offset of the abnormal risk value fluctuation feature propagating to the associated port according to the data flow transfer delay; In the correlation port risk value sequence, it is detected whether there is a fluctuation feature similar to the abnormal risk value fluctuation feature according to the time delay offset, and if so, it is determined that the corresponding risk abnormality exists.
[0095] In one embodiment, the correlation ports are synchronously verified to determine the concurrent abnormal ports, including: Obtaining a second port risk value sequence of each port in a second preset time window to obtain a plurality of second port risk value sequences; Taking the second abnormal port risk value sequence of the abnormal port in the plurality of second port risk value sequences as a reference port risk value sequence, and taking the second port risk value sequence of the remaining port as a to-be-verified port risk value sequence; Taking the reference port risk value sequence as a reference, synchronously comparing each to-be-verified port risk value sequence, when the to-be-verified port risk value sequence and the reference port risk value sequence exist synchronous risk value fluctuation, determining the port with synchronous risk value fluctuation as the concurrent abnormal port.
[0096] In one embodiment, taking the reference port risk value sequence as a reference, synchronously comparing each to-be-verified port risk value sequence, detecting whether there is a synchronous risk value fluctuation, including: Extracting a reference risk value fluctuation feature of the reference port risk value sequence, and extracting a to-be-verified risk value fluctuation feature corresponding to each to-be-verified port risk value sequence; Determining a fluctuation feature similarity of each to-be-verified risk value fluctuation feature and the reference risk value fluctuation feature; When the fluctuation feature similarity is greater than or equal to a synchronous similarity threshold, it is confirmed that the corresponding port exists synchronous risk value fluctuation.
[0097] It can be understood that the above device item embodiment is corresponding to the method item embodiment of the present application, which can realize the network security management and control method provided by any one of the above method item embodiments.
[0098] It should be noted that the device embodiments described above are only schematic, and part or all of the modules can be selected to achieve the purpose of the present embodiment scheme according to actual needs. In addition, in the device embodiment provided by the present application, the connection relationship between the modules indicates that there is a communication connection between them, which can be realized as one or more communication buses or signal lines. Those skilled in the art can understand and implement without creative labor.
[0099] On the basis of the above-mentioned embodiment of the network security management method, another embodiment of the present application provides a terminal device, which comprises a processor, a memory and a computer program stored in the memory and configured to be executed by the processor, and when the computer program is executed by the processor, the network security management method of any one of the embodiments of the present application is implemented.
[0100] For example, in this embodiment, the computer program can be divided into one or more modules, one or more modules are stored in the memory and executed by the processor to complete the present application. One or more module elements can be a series of computer program instruction segments capable of completing a specific function, which are used to describe the execution process of the computer program in the terminal device.
[0101] The terminal device can be a desktop computer, a notebook computer, a palm computer and a cloud server, etc. The terminal device can include, but is not limited to, a processor and a memory.
[0102] The processor can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor, etc. The processor is the control center of the terminal device, and connects all parts of the terminal device through various interfaces and lines.
[0103] On the basis of the above-mentioned embodiment of the method, another embodiment of the present application provides a computer readable storage medium, which comprises a stored computer program, wherein when the computer program runs, the device where the computer readable storage medium is located executes the network security management method of any one of the above-mentioned embodiments of the present application.
[0104] The modules / units integrated in the device / terminal equipment can be stored in a computer readable storage medium if they are realized in the form of software function units and sold or used as independent products. Based on this understanding, all or part of the processes in the above-mentioned embodiments can also be completed by a computer program instructing related hardware, and the computer program can be stored in a computer readable storage medium. When the computer program is executed by a processor, the steps of each method embodiment can be implemented. The computer program includes computer program code, which can be in the form of source code, object code, executable files or some intermediate forms, etc. The computer readable medium can include any entity or device capable of carrying computer program code, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal and software distribution medium, etc.
[0105] The above is the preferred embodiment of the present application. It should be pointed out that, for those skilled in the art, without departing from the principles of the present application, a number of improvements and refinements can be made, which are also considered within the scope of protection of the present application.
Claims
1. A network security management method, characterized in that, The method comprises: obtaining a plurality of ports of a target power grid dispatching control center, and constructing a port topology graph according to the plurality of ports, wherein the target power grid dispatching control center is applied to an operation cockpit of a target power grid; constructing a risk identification network corresponding to each port, and determining a port risk value of each port according to the risk identification network; determining a port corresponding to a port risk value greater than or equal to a first risk threshold as a high-risk port, and isolating the high-risk port from the target power grid dispatching center; determining a port corresponding to a port risk value less than the first risk threshold and greater than or equal to a second risk threshold as an abnormal port, performing association verification and synchronization verification on the abnormal port based on the port topology graph, determining a threat port in the port topology graph, and isolating the threat port from the target power grid dispatching control center, wherein the first risk threshold is greater than the second risk threshold.
2. The cyber-security management method of claim 1, wherein, The method further comprises: determining a data type and a port type of each port, collecting historical interaction data of the same type of port of the same data type as a constraint, constructing a sample port interaction data set according to the historical interaction data, performing risk labeling on the sample port interaction data set to obtain a sample port risk value set, and performing neural network training based on the sample port interaction data set and the sample port risk value set to generate a risk identification network corresponding to a current port. The method further comprises: determining a port association link of the abnormal port according to the port topology graph, determining an associated port based on the port association link, the associated port including an upstream associated port and a downstream associated port, performing association verification on the associated port to determine an associated abnormal port, performing synchronization verification on the associated port to determine a concurrent abnormal port, and determining the abnormal port, the associated abnormal port, and the concurrent abnormal port as a threat port.
3. The cyber-security management method of claim 1, wherein, The method further comprises: obtaining a first port risk value sequence of the abnormal port and the associated port within a first preset time window, the first port risk sequence including a first abnormal port risk value sequence and a first associated port risk value sequence, the first associated port risk value sequence including a first upstream associated port risk value sequence and a first downstream associated port risk value sequence, obtaining a data flow transfer delay of the abnormal port to the associated port according to the port topology graph, verifying whether there is a corresponding risk anomaly in the corresponding first associated port risk value sequence based on the first abnormal port risk value sequence and in combination with the data flow transfer delay, and taking the associated port with the risk anomaly as an associated abnormal port of the current abnormal port. 4. The cyber-security management method of claim 3, wherein, 5. The cyber-security management method of claim 4, wherein, extract an abnormal risk value fluctuation feature according to the first abnormal port risk value sequence; determine a time delay offset of the abnormal risk value fluctuation feature propagating to the associated port according to the data flow conversion time delay; in the associated port risk value sequence, detect whether there is a fluctuation feature similar to the abnormal risk value fluctuation feature according to the time delay offset, and if so, determine that there is a corresponding risk abnormality.
6. The cyber-security management method of claim 3, wherein, The synchronization verification of the associated port includes: obtaining a second port risk value sequence of each of the ports within a second preset time window to obtain a plurality of second port risk value sequences; taking the second abnormal port risk value sequence of the abnormal port in the plurality of second port risk value sequences as a reference port risk value sequence, and taking the second port risk value sequence of the remaining port as a to-be-verified port risk value sequence; synchronously comparing each of the to-be-verified port risk value sequences with the reference port risk value sequence, and determining that a port with a synchronous risk value fluctuation is the concurrent abnormal port when the to-be-verified port risk value sequence and the reference port risk value sequence have a synchronous risk value fluctuation.
7. The cyber-security management method of claim 6, wherein, The synchronous comparison of each of the to-be-verified port risk value sequences with the reference port risk value sequence includes: extracting a reference risk value fluctuation feature of the reference port risk value sequence and extracting a to-be-verified risk value fluctuation feature corresponding to each of the to-be-verified port risk value sequences; determining a fluctuation feature similarity of each of the to-be-verified risk value fluctuation features and the reference risk value fluctuation feature; when the fluctuation feature similarity is greater than or equal to a synchronous similarity threshold, confirming that the corresponding port has a synchronous risk value fluctuation.
8. A cyber-security management device, characterized by, including: a port topology graph construction module configured to obtain a plurality of ports of a target power grid dispatching and control center and construct a port topology graph according to the plurality of ports, wherein the target power grid dispatching and control center is applied to an operation cockpit of a target power grid; a port risk value determination module configured to construct a risk identification network corresponding to each of the ports and determine a port risk value of each of the ports according to the risk identification network; a high-risk port isolation module configured to determine a port corresponding to a port risk value greater than or equal to a first risk threshold as a high-risk port and isolate the high-risk port from the target power grid dispatching center; a threat port isolation module configured to determine a port corresponding to a port risk value less than the first risk threshold and greater than or equal to a second risk threshold as an abnormal port, perform associated verification and synchronization verification on the abnormal port based on the port topology graph, determine a threat port in the port topology graph, and isolate the threat port from the target power grid dispatching and control center, wherein the first risk threshold is greater than the second risk threshold.
9. A terminal device, comprising: including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, and when the processor executes the computer program, the network security management method of any one of claims 1-7 is implemented.
10. A computer-readable storage medium, characterized in that, including: A stored computer program, wherein the computer program, when executed, controls a device in which the computer readable storage medium is located to perform the network security management method according to any one of claims 1-7.