Power grid intelligent terminal network security risk monitoring method based on business credibility

By combining SVM intrusion detection based on business trust and LSTM neural network analysis with the multi-layered structure of the power grid and terminal types, comprehensive security monitoring of smart terminals was achieved, solving the problem of identifying attacks at the power grid business level and improving detection efficiency and real-time performance.

CN121486079APending Publication Date: 2026-02-06国网黑龙江省电力有限公司信息通信公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511846612.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-09
Publication Date
2026-02-06

AI Technical Summary

Technical Problem

Existing cybersecurity protection strategies for smart power grid terminals are insufficient to effectively identify and prevent attacks launched at the business level, especially APT attacks, which threaten the stability of the power grid and the security of user information.

Method used

By employing an SVM intrusion detection module based on business trust, an LSTM neural network bypass information analysis module, and a business security module for intelligent terminal application systems, combined with the multi-layered network structure and multiple types of terminal equipment in the power grid, comprehensive network security risk monitoring is achieved through collaborative intrusion detection, device-level security monitoring, and real-time business behavior identification.

Benefits of technology

It improves the accuracy and real-time performance of intrusion detection, can respond to anomalies within 100 milliseconds, and achieves a detection rate of over 95%, ensuring the stable operation of the power grid and the security of user information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121486079A_ABST
    Figure CN121486079A_ABST
Patent Text Reader

Abstract

The invention discloses a power grid intelligent terminal network security risk monitoring method based on business credibility, and belongs to the technical field of power system network security. Comprising an SVM intrusion detection module based on service credibility, an intelligent terminal bypass information analysis module based on an LSTM neural network and a service security module of an intelligent terminal application system. Through the collaborative intrusion detection model, behavior detection of the upper-layer equipment on the lower-layer equipment is realized, and the detection efficiency is improved; through the bypass information analysis technology based on the LSTM, the equipment-level safety monitoring of the power terminal is realized; comprehensive network security risk monitoring is provided by combining a specific multi-layer network structure and multi-type terminal equipment of a power grid; when it is detected that the power terminal equipment is abnormal, the response time is controlled within 100 milliseconds; and the detection rate of abnormal application services reaches 95% or above.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of power system network security. BACKGROUND

[0002] With the in-depth application of digital technology and the development and change of security forms at home and abroad, the security threat faced by the power grid cannot be ignored. The power grid may be subject to many threats, and the security threats from intelligent terminal devices mainly come from two categories, one is illegal device access, and the other is illegal business operation after legal devices are attacked. For example, using illegal devices to tamper with power consumption information, intelligent compromise, denial of service, etc., which may lead to major problems such as power grid instability, power outage and user information leakage.

[0003] At the intelligent terminal level, about 20,000 mobile intelligent terminals access the information network through the security access platform, as shown in FIG. Figure 1 There are many security risks in the massive terminal devices. Attackers can penetrate into workstations and master stations through attacks on intelligent terminals, which will bring great challenges to the stable operation of the smart grid.

[0004] Traditional security protection strategies are mostly based on terminal access authentication to identify intelligent terminals, but current attackers prefer to launch attacks at the business level to bypass security defense mechanisms, such as many APT attacks that cannot be detected at the network level. Therefore, on the basis of the research on business trustworthiness, it is urgent to propose a security protection strategy for intelligent terminal business behavior detection to achieve comprehensive protection of intelligent terminal access. SUMMARY

[0005] In view of the characteristics of the multi-layer network structure, multi-type terminal device and coexistence of various application businesses of the smart grid, a power grid intelligent terminal network security risk monitoring method based on business trustworthiness is proposed. This method is a comprehensive network security risk monitoring technology that improves the accuracy and real-time performance of intrusion detection and simultaneously realizes device-level security monitoring of intelligent terminals.

[0006] The purpose of the application is achieved as follows:

[0007] The power grid intelligent terminal network security risk monitoring method based on business trustworthiness comprises a SVM intrusion detection module based on business trustworthiness, an intelligent terminal bypass information analysis module based on an LSTM neural network and a business security module of an intelligent terminal application system.

[0008] The aforementioned method for monitoring network security risks of smart terminals in power grids based on business trust is described above. The SVM intrusion detection module based on business trust is a collaborative intrusion detection model based on business trust. The devices in the power grid are divided into three types according to their functions: smart terminals, data collectors, and trust detection centers. Corresponding intrusion detection methods are adopted at different levels to realize the behavior detection of lower-level devices by upper-level devices.

[0009] The collaborative intrusion detection model based on business trust includes: a lower-level detection component, an upper-level detection component, and a collaborative layer component. The lower-level detection component includes a network between intelligent terminals and data collectors, enabling data collectors to determine the trust level of lower-level intelligent terminal behavior and calculate the supervisory trust value of data collectors for peer data collectors in adjacent areas. The upper-level detection component includes a network between data collectors and a trust detection center, enabling the control center to perform comprehensive trust level determination on its lower-level data collectors based on the calculated direct trust and the supervisory trust reported by the collaborative layer, and to perform SVM anomaly detection on non-whitelisted behaviors after trust level detection throughout the power grid. The collaborative layer component serves as a bridge between the upper and lower-level detection components, enabling them to collaborate in completing intrusion detection across the entire network.

[0010] The aforementioned method for monitoring network security risks of smart power grid terminals based on business trust, wherein the smart terminal bypass information analysis module based on LSTM neural network is a device-level security protection strategy for power smart terminals, which collects bypass information of power terminal devices and then captures the temporal changes of bypass information such as power consumption of power terminals through LSTM neural network to achieve device-level security monitoring of power smart terminals.

[0011] The LSTM neural network-based intelligent terminal bypass information analysis module includes a data acquisition module, a feature extraction module, and a security monitoring module. The data acquisition module collects side-channel information of the power terminal through a data acquisition device. The feature extraction module includes the construction of the original feature set and feature filtering. The security monitoring module uses an LSTM neural network model to realize the security monitoring of the power terminal equipment.

[0012] The aforementioned method for monitoring network security risks of smart grid terminals based on business trust involves the business security module of the smart terminal application system classifying and identifying business access behaviors using deep learning algorithms based on the business logic relationships of the smart grid terminal devices. This timely detection of abnormal business access behaviors enhances the real-time security protection capabilities of the application system and achieves real-time protection of the application system's business security.

[0013] The aforementioned method for monitoring network security risks of smart grid terminals based on business trust also includes a security authentication and intelligent analysis module. This module is designed to handle scenarios involving multiple terminal access and concurrent application of multiple services, taking into account the multi-layered structure, multiple service types, and multiple terminal categories of the smart grid, as well as its network structure and service characteristics.

[0014] The beneficial effects of this invention's power grid smart terminal network security risk monitoring method based on business trust are as follows: It achieves behavioral detection of lower-level devices by upper-level devices through a collaborative intrusion detection model, improving detection efficiency; it realizes device-level security monitoring of power terminals through LSTM-based bypass information analysis technology; it provides comprehensive network security risk monitoring by combining the unique multi-layer network structure and multiple types of terminal devices in the power grid; it controls the response time to within 100 milliseconds when anomalies are detected in power terminal devices; and it achieves a detection rate of over 95% for abnormal application services. Attached Figure Description

[0015] Figure 1 This is a diagram of the smart grid structure.

[0016] Figure 2 This is a diagram of the cyclic cell structure of an LSTM.

[0017] Figure 3 This is a diagram of an intrusion detection model.

[0018] Figure 4 Flowchart for collaborative intrusion detection.

[0019] Figure 5 Design diagram for power consumption information data acquisition. Detailed Implementation

[0020] The specific embodiments of the present invention will now be described in further detail with reference to the accompanying drawings.

[0021] Method 1

[0022] The specific implementation of the power grid smart terminal network security risk monitoring method based on business trust includes: an SVM intrusion detection module based on business trust, a smart terminal bypass information analysis module based on LSTM neural network, and a business security module of the smart terminal application system.

[0023] The aforementioned method for monitoring network security risks of smart terminals in power grids based on business trust is described above. The SVM intrusion detection module based on business trust is a collaborative intrusion detection model based on business trust. The devices in the power grid are divided into three types according to their functions: smart terminals, data collectors, and trust detection centers. Corresponding intrusion detection methods are adopted at different levels to realize the behavior detection of lower-level devices by upper-level devices.

[0024] The collaborative intrusion detection model based on business trust includes: a lower-level detection component, an upper-level detection component, and a collaborative layer component. The lower-level detection component includes a network between intelligent terminals and data collectors, enabling data collectors to determine the trust level of lower-level intelligent terminal behavior and calculate the supervisory trust value of data collectors for peer data collectors in adjacent areas. The upper-level detection component includes a network between data collectors and a trust detection center, enabling the control center to perform comprehensive trust level determination on its lower-level data collectors based on the calculated direct trust and the supervisory trust reported by the collaborative layer, and to perform SVM anomaly detection on non-whitelisted behaviors after trust level detection throughout the power grid. The collaborative layer component serves as a bridge between the upper and lower-level detection components, enabling them to collaborate in completing intrusion detection across the entire network.

[0025] The aforementioned method for monitoring network security risks of smart power grid terminals based on business trust, wherein the smart terminal bypass information analysis module based on LSTM neural network is a device-level security protection strategy for power smart terminals, which collects bypass information of power terminal devices and then captures the temporal changes of bypass information such as power consumption of power terminals through LSTM neural network to achieve device-level security monitoring of power smart terminals.

[0026] The LSTM neural network-based intelligent terminal bypass information analysis module includes a data acquisition module, a feature extraction module, and a security monitoring module. The data acquisition module collects side-channel information of the power terminal through a data acquisition device. The feature extraction module includes the construction of the original feature set and feature filtering. The security monitoring module uses an LSTM neural network model to realize the security monitoring of the power terminal equipment.

[0027] The aforementioned method for monitoring network security risks of smart grid terminals based on business trust involves the business security module of the smart terminal application system classifying and identifying business access behaviors using deep learning algorithms based on the business logic relationships of the smart grid terminal devices. This timely detection of abnormal business access behaviors enhances the real-time security protection capabilities of the application system and achieves real-time protection of the application system's business security.

[0028] The aforementioned method for monitoring network security risks of smart grid terminals based on business trust also includes a security authentication and intelligent analysis module. This module is designed to handle scenarios involving multiple terminal access and concurrent application of multiple services, taking into account the multi-layered structure, multiple service types, and multiple terminal categories of the smart grid, as well as its network structure and service characteristics.

[0029] Method 2

[0030] In this specific embodiment, the technical solution of the power grid smart terminal network security risk monitoring method based on business trust level of the present invention is described as follows:

[0031] First, an SVM intrusion detection algorithm based on business trust.

[0032] To address the issue that most current power grid intrusion detection technologies rely on single rule matching or machine learning techniques from traditional computer networks without considering the structural characteristics of smart grids, this paper proposes an SVM intrusion detection algorithm based on business trust, which combines the advantages of both detection technologies to improve the accuracy and real-time performance of intrusion detection.

[0033] Second, intelligent terminal bypass information analysis technology based on LSTM neural network.

[0034] This paper designs a device-level security protection strategy for power smart terminals. By collecting bypass information of power terminal devices and then using an LSTM neural network to capture the temporal changes of bypass information such as power consumption of power terminals, the paper realizes device-level security monitoring of power smart terminals.

[0035] Third, research on the business security issues of intelligent terminal application systems.

[0036] This study investigates the business logic relationships of smart terminal equipment in power grids, classifies and identifies business access behaviors using deep learning algorithms, promptly detects abnormal business access behaviors, enhances the real-time security protection capabilities of application systems, and achieves real-time assurance of application system business security.

[0037] Fourth, the system design of security authentication and intelligent analysis models.

[0038] In view of the network structure and service characteristics of smart grids, such as multi-layered structure, multiple service types, and multiple terminal categories, this paper studies a network framework for security authentication, designs application scenarios such as multi-terminal access and multi-service concurrency, and designs and implements the system based on the proposed service trust-based detection model.

[0039] Method 3

[0040] In this specific embodiment, the modules of the power grid smart terminal network security risk monitoring method based on business trust level of the present invention are described as follows:

[0041] First, collaborative intrusion detection models, such as Figure 3 As shown.

[0042] In the power grid, equipment is categorized into three types based on function: intelligent terminals, data collectors, and trust detection centers. Corresponding intrusion detection methods are designed for each level to enable upper-level devices to detect the behavior of lower-level devices.

[0043] Lower-level detection section

[0044] The network, including the smart terminal and the data collector, has two main functions: first, the data collector determines the trust level of the behavior of the lower-level smart terminal; second, the data collector calculates the supervision trust value of the data collectors of the same level in the adjacent area.

[0045] Upper-level detection section

[0046] The network, including the data acquisition unit and the trust detection center, is mainly responsible for two functions: first, the control center performs a comprehensive trust assessment on its subordinate data acquisition units based on the calculated direct trust and the supervisory trust reported by the collaboration level; second, it performs SVM anomaly detection on non-whitelisted behaviors after trust detection in the entire power grid to confirm whether the device behavior is an intrusion behavior.

[0047] Collaboration level section

[0048] It serves as a bridge between the upper and lower levels of detection, enabling them to collaborate in completing intrusion detection across the entire network. The upper-level detection needs to use the supervised trust values ​​it compiles to calculate the overall trust, and at the same time, the upper level will provide feedback based on the SVM detection results, and is responsible for notifying the lower-level detection to update the trust threshold.

[0049] Collaborative intrusion detection process as follows Figure 4 As shown.

[0050] Second, a safety monitoring scheme for power terminal equipment.

[0051] To achieve equipment-level safety monitoring of power terminals, a power terminal safety monitoring method based on bypass signals is proposed, which consists of three parts: a data acquisition module, a feature extraction module, and a safety monitoring module.

[0052] Data acquisition module, such as Figure 5 As shown

[0053] The side-channel information of the power terminal is collected through a data acquisition device, including information such as the device's working time period, working duration, power consumption, and connection frequency.

[0054] Feature extraction module

[0055] In constructing the power terminal safety monitoring model, it is viewed as a binary classification problem in machine learning. The feature extraction module consists of two parts: the construction of the original feature set and feature selection. Multidimensional original features are extracted through probability density distribution, while feature vectors based on mathematical statistics are also extracted.

[0056] Safety monitoring module

[0057] In power safety monitoring systems, the safety monitoring of equipment is viewed as a binary classification problem using machine learning. A Long Short Memory (LSTM) neural network model is employed to achieve safety monitoring of power terminal equipment, capturing the temporal characteristics of the side-channel information of the power terminal equipment. The LSTM's recurrent cell structure is as follows: Figure 2 As shown.

Claims

1. A method for monitoring network security risks of smart power grid terminals based on business trust levels, characterized in that, include: The system includes an SVM intrusion detection module based on business trust, an intelligent terminal bypass information analysis module based on LSTM neural network, and a business security module for intelligent terminal application systems.

2. The method for monitoring network security risks of smart power grid terminals based on business trust as described in claim 1, characterized in that, The SVM intrusion detection module based on business trust is a collaborative intrusion detection model based on business trust. The devices in the power grid are divided into three types according to their functions: intelligent terminals, data collectors, and trust detection centers. Corresponding intrusion detection methods are adopted at different levels to realize the behavior detection of lower-level devices by upper-level devices.

3. The method for monitoring network security risks of smart power grid terminals based on business trust as described in claim 2, characterized in that, The collaborative intrusion detection model based on business trust includes: a lower-level detection component, an upper-level detection component, and a collaborative layer component. The lower-level detection component includes a network between intelligent terminals and data collectors, enabling data collectors to determine the trust level of lower-level intelligent terminal behavior and calculate the supervisory trust value of data collectors for peer data collectors in adjacent areas. The upper-level detection component includes a network between data collectors and a trust detection center, enabling the control center to perform comprehensive trust level determination on its lower-level data collectors based on the calculated direct trust and the supervisory trust reported by the collaborative layer, and to perform SVM anomaly detection on non-whitelisted behaviors after trust level detection throughout the power grid. The collaborative layer component serves as a bridge between the upper and lower-level detection components, enabling them to collaborate in completing intrusion detection across the entire network.

4. The method for monitoring network security risks of smart power grid terminals based on business trust as described in claim 1, characterized in that, The LSTM neural network-based intelligent terminal bypass information analysis module is a device-level security protection strategy for power intelligent terminals. It collects bypass information of power terminal devices and then uses an LSTM neural network to capture the temporal changes of bypass information such as power consumption of power terminals, thereby realizing device-level security monitoring of power intelligent terminals.

5. The method for monitoring network security risks of smart power grid terminals based on business trust as described in claim 4, characterized in that, The LSTM neural network-based intelligent terminal bypass information analysis module includes a data acquisition module, a feature extraction module, and a security monitoring module. The data acquisition module collects side-channel information of the power terminal through a data acquisition device. The feature extraction module includes the construction of the original feature set and feature filtering. The security monitoring module uses an LSTM neural network model to realize the security monitoring of the power terminal equipment.

6. The method for monitoring network security risks of smart power grid terminals based on business trust as described in claim 1, characterized in that, The business security module of the intelligent terminal application system classifies and identifies business access behaviors based on the business logic relationships of the power grid intelligent terminal equipment using deep learning algorithms, promptly detects abnormal business access behaviors, enhances the real-time security protection capabilities of the application system, and achieves real-time protection of the application system's business security.

7. The method for monitoring network security risks of smart power grid terminals based on business trust as described in claim 1, characterized in that, It also includes a security authentication and intelligent analysis module, which is a module for handling multi-terminal access and multi-service concurrent application scenarios, in order to address the network structure and service characteristics of the smart grid with its multi-layered structure, multiple service types, and multiple terminal categories.