Novel power system terminal equipment network security protection method
By constructing a business trust base and performing grid topology analysis, the deviation and criticality of communication characteristics of power terminal equipment are dynamically assessed, and a risk response action index is generated. This solves the problems of existing technologies failing to identify unknown attacks and lacking differentiated responses, and achieves precise security protection for power terminal equipment.
Patent Information
- Application Number
- CN202511720149.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-21
- Publication Date
- 2026-02-10
AI Technical Summary
Existing network security protection methods for power terminal equipment cannot effectively identify unknown attacks, lack accurate modeling of normal business behavior of equipment, cannot distinguish between malicious operations and normal business fluctuations, and lack differentiated responses, resulting in security protection measures that are either too lenient or too strict and cannot adapt to the dynamic changes of the power system.
By constructing a trustworthy business foundation, analyzing the deviation of communication characteristics in real time, and combining the criticality assessment of equipment in the power grid, a network security risk response strategy is dynamically generated. Through multi-dimensional deviation analysis and power grid topology assessment, a risk response action index is generated to achieve accurate identification of abnormal behavior and intelligent hierarchical protection.
It enables accurate behavior identification and criticality assessment of power terminal equipment, dynamically adjusts protection measures, avoids misjudgment and over-protection, improves the accuracy and reliability of network security protection, and ensures stable operation of the power grid.
Smart Images

Figure CN121508994A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of power system network security technology, and in particular relates to a novel network security protection method for power system terminal equipment. Background Technology
[0002] With the rapid development of new power systems, the number of power terminal equipment has increased dramatically, and its role in power grid monitoring, control, and communication has become increasingly important. Power terminal equipment undertakes key functions such as data acquisition, status monitoring, and remote control, and is an important foundation for ensuring the safe and stable operation of the power grid.
[0003] However, power terminal equipment is typically deployed in open network environments, facing complex cybersecurity threats, including malicious code attacks, unauthorized intrusions, and data tampering. An attack could lead to abnormal power grid operation or even widespread paralysis, causing severe economic losses and social impact. Traditional security measures primarily employ signature-based intrusion detection technologies and static access control policies. These methods have significant limitations: signature-based detection technologies can only identify known attack patterns and lack the ability to identify new and variant attacks; static access control policies are ill-suited to the dynamically changing business needs of the power system. While existing technologies provide basic security through device authentication and communication encryption, risk assessment often relies on simple rule matching or threshold judgments, failing to fully consider the operational characteristics of power terminal equipment and its criticality within the power grid topology. A more significant problem is the lack of accurate modeling of normal operational behavior in existing protection methods, making it difficult to effectively distinguish between malicious operations and normal operational fluctuations. Furthermore, most protection schemes fail to differentiate responses based on the equipment's criticality within the power grid, resulting in security measures that are either too lenient to effectively prevent risks or too stringent, impacting normal business operations. This situation is particularly pronounced in the context of new power systems, necessitating the development of a cybersecurity protection method capable of accurate behavior identification, criticality assessment, and intelligent response. Summary of the Invention
[0004] To address the shortcomings of existing technologies, this invention provides a novel network security protection method for power system terminal equipment, solving the aforementioned problems.
[0005] To achieve the above objectives, the present invention provides the following technical solution: a novel network security protection method for power system terminal equipment, specifically comprising the following steps: An independent service trust base is constructed for power terminal equipment; the service trust base refers to the range of communication behaviors allowed for power terminal equipment under normal operating conditions; the service trust base includes the set of legitimate communication peers, the set of permitted service instructions, the range of normal communication cycles, and the range of typical data payload sizes; The system acquires communication data packets from power terminal equipment in real time and parses out the communication feature data in the data packets. The communication feature data includes the destination IP address of the current communication, the type of business instruction currently being executed, the time interval between the current communication and the previous communication, and the effective payload size of the current communication data packet. A deviation analysis model is established based on communication characteristic data and business credibility basis to generate a comprehensive deviation index of communication characteristics. Obtain the power grid structure of the power grid where the new power system terminal equipment is located and the corresponding node of the new power system terminal equipment in the power grid structure. Based on the power grid structure of the power grid where the new power system terminal equipment is located and the corresponding node of the new power system terminal equipment in the power grid structure, establish a business criticality analysis model and generate business criticality coefficients; the power grid structure refers to the physical connection structure of the power grid. A risk response action index is generated based on the business criticality coefficient and the comprehensive deviation index of communication characteristics; Based on the risk response action index, cybersecurity protection is provided for new power system terminal equipment.
[0006] Based on the above technical solutions, the present invention also provides the following optional technical solutions: Further technical solution: The comprehensive deviation index of communication features specifically includes: Based on the destination IP address of the current communication and the set of legitimate communication peers, generate an IP address deviation index; Based on the set of licensed business instructions and the type of business instruction currently being executed, an instruction type deviation index is generated; Based on the time interval between the current communication and the previous communication and the normal communication cycle range, a communication cycle deviation index is generated. A data volume deviation index is generated based on the typical data payload size range and the effective payload size of the current communication data packet. A deviation analysis model is established based on the IP address deviation index, instruction type deviation index, communication cycle deviation index, and data volume deviation index to generate a comprehensive deviation index of communication characteristics.
[0007] Further technical solution: The specific method for generating the IP address deviation index includes: Through the formula: ; Generate IP address deviation index ; In the formula, This indicates the destination IP address of the current communication. It represents the set of legitimate communication peers; The specific methods for generating the instruction type deviation index include: Through the formula: ; Generate instruction type deviation index ; In the formula, This indicates the type of business instruction currently being executed. This represents a set of licensed business instructions; The specific methods for generating the communication cycle deviation index include: Through the formula: ; Generate communication cycle deviation index ; In the formula, This indicates the time interval between the current communication and the previous communication. This indicates the normal communication cycle range. The median value, This indicates the normal communication cycle range. The upper limit; The specific methods for generating the data deviation index include: Through the formula: ; Data volume deviation index ; In the formula, This indicates the effective payload size of the current communication data packet. This represents the typical data payload size range. The median value, This represents the typical data payload size range. The upper limit.
[0008] Further technical solution: The expression of the deviation analysis model is specifically as follows: ; In the expression, This represents the comprehensive deviation index of communication characteristics. This represents the IP address deviation index. This represents the instruction type deviation index. This represents the communication cycle deviation index. This represents the data deviation index. , , , All are weighting coefficients, and .
[0009] Further technical solutions: The specific methods for generating the business criticality coefficient include: Obtain the power grid structure of the power grid where the new power system terminal equipment is located and the corresponding node of the new power system terminal equipment in the power grid structure; Obtain the number of shortest paths between two nodes in a power grid structure; the shortest path refers to the number of all existing paths with equal and minimum lengths from one node to another in the power grid structure; where the path length is calculated based on the line impedance; A business criticality analysis model is established based on the power grid structure of the power grid where the new power system terminal equipment is located, the node corresponding to the new power system terminal equipment in the power grid structure, and the number of shortest paths between two nodes in the power grid structure, and business criticality coefficients are generated.
[0010] Further technical solution: The specific expression of the business criticality analysis model is as follows: ; In the expression, This represents the business criticality coefficient, N represents the total number of nodes in the power grid structure, v represents the node corresponding to the new power system terminal equipment in the power grid structure, and s and t represent other nodes in the power grid structure. This represents the total number of shortest paths from node s to node t. It means that in The number of paths that pass through node v in the given path.
[0011] Further technical solutions: The specific methods for generating the risk response action index include: Through the formula: Generate a risk response action index ; In the formula, This represents the comprehensive deviation index of communication characteristics. This represents the business criticality coefficient.
[0012] This invention provides a novel network security protection method for power system terminal equipment, which has the following advantages compared with the prior art: This invention dynamically generates network security risk response strategies by constructing a business trust base, analyzing communication characteristic deviations in real time, and combining them with the criticality assessment of equipment in the power grid. It has the advantages of accurately identifying abnormal behavior, dynamically assessing the criticality of equipment, and achieving intelligent hierarchical protection. Attached Figure Description
[0013] Figure 1 This is a flowchart illustrating a novel network security protection method for power system terminal equipment provided by the present invention.
[0014] Figure 2 This is a flowchart illustrating step S30 of the present invention.
[0015] Figure 3 This is a flowchart illustrating step S40 of the present invention.
[0016] Figure 4 This invention provides a structural schematic diagram of a novel network security protection system for power system terminal equipment. Detailed Implementation
[0017] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.
[0018] The specific implementation of the present invention will be described in detail below with reference to specific embodiments.
[0019] Please see Figure 1 The present invention provides a novel network security protection method for power system terminal equipment, which specifically includes the following steps: Step S10: Construct an independent service trust base for the power terminal equipment; wherein, the service trust base refers to the range of communication behaviors allowed for the power terminal equipment under normal working conditions; the service trust base includes a set of legitimate communication peers, a set of permitted service instructions, a normal communication cycle range, and a typical data payload size range; Step S20: Acquire communication data packets from the power terminal equipment in real time and parse out the communication feature data in the communication data packets; wherein, the communication feature data includes the destination IP address of the current communication, the type of the currently executed business instruction, the time interval between the current communication and the previous communication, and the effective payload size of the current communication data packet; Step S30: Establish a deviation analysis model based on communication feature data and service trust basis, and generate a comprehensive deviation index of communication features; Step S40: Obtain the power grid structure of the power grid where the new power system terminal equipment is located and the corresponding node of the new power system terminal equipment in the power grid structure. Based on the power grid structure of the power grid where the new power system terminal equipment is located and the corresponding node of the new power system terminal equipment in the power grid structure, establish a business criticality analysis model and generate business criticality coefficients; the power grid structure refers to the physical connection structure of the power grid. Step S50: Generate a risk response action index based on the business criticality coefficient and the comprehensive deviation index of communication characteristics; Step S60: Protect the network security of new power system terminal equipment based on the risk response action index; Among them, the business trust base refers to the range of communication behaviors that power terminal equipment is allowed under normal working conditions. Specifically, it can be achieved by collecting historical operating data to statistically analyze the legitimate communication peers, permitted instruction types, communication cycles, and data payload range, providing a dynamic benchmark for subsequent deviation analysis. Communication characteristic data includes destination IP address, service instruction type, communication interval and payload size. Specifically, it can be achieved by extracting packet header and payload information through deep packet inspection technology, covering key dimensions that may be tampered with by attacks. The deviation analysis model is a calculation model that weights and integrates the deviations of each feature. Specifically, it can be implemented by using the analytic hierarchy process to determine the weight coefficients of each feature, thus overcoming the limitations of single threshold detection. The business criticality coefficient refers to the importance of a device node in the power grid topology. Specifically, it can be achieved by calculating the node betweenness centrality index, which quantifies the impact of device failure on power grid connectivity. The Risk Response Action Index is a comprehensive safety risk level assessment value. Specifically, it can be achieved by multiplying deviation and key indicators to realize dynamic matching between response intensity and risk level.
[0020] Specifically, this method first establishes a behavioral benchmark for normal device communication through long-term monitoring, including legitimate communication targets, authorized command types, typical communication cycles, and data volume ranges. During real-time communication, four key features are extracted: the current communication destination address, command type, time interval, and data volume. The degree of deviation from the behavioral benchmark is calculated for each feature. For example, when a large data packet is detected being sent to an unauthorized IP address, multiple deviation alarms are triggered. A weighted average of these deviation indicators is used to form an overall risk score. Simultaneously, the location characteristics of device nodes are analyzed based on the power grid topology to calculate the node's pivotal role in the power grid. Finally, the communication risk score is multiplied by the device's topological importance to generate a tiered response basis. For high-risk behaviors of highly critical devices, isolation protection is immediately initiated; for minor deviations of low-critical devices, current limiting and observation measures are implemented.
[0021] Compared to existing technologies, traditional methods rely solely on static rule bases to detect known attacks, while this solution identifies unknown threats through dynamic behavioral modeling. Existing technologies use a single threshold to determine anomalies, while this solution improves detection accuracy through comprehensive evaluation of multi-dimensional deviations. Existing protection measures apply the same response strategy to all devices, while this solution achieves differentiated protection based on the criticality of the power grid topology. For example, in substation automation systems, traditional firewalls may mistakenly block legitimate communication from protection devices, while this solution can accurately distinguish between normal parameter updates and malicious command injection.
[0022] Through the above technical solution, this application effectively solves the problem of insufficient ability of traditional protection methods to identify unknown attacks. It accurately distinguishes between normal business fluctuations and malicious operations through dynamic behavior modeling, and achieves focused protection for critical equipment by combining power grid topology analysis. This method can promptly detect complex abnormal communication behaviors, and initiate protection measures in a tiered manner according to the importance of equipment in the power grid, avoiding business interruptions caused by over-protection, while ensuring high-level security protection for critical nodes.
[0023] For preferred options, please refer to [link / reference]. Figure 2 The present invention further proposes that the comprehensive deviation index of the communication features specifically includes: Step S31: Generate an IP address deviation index based on the destination IP address of the current communication and the set of legitimate communication peers; Step S32: Generate an instruction type deviation index based on the set of licensed business instructions and the type of the currently executed business instruction; Step S33: Generate a communication cycle deviation index based on the time interval between the current communication and the previous communication and the normal communication cycle range; Step S34: Generate a data volume deviation index based on the typical data payload size range and the effective payload size of the current communication data packet; Step S35: Establish a deviation analysis model based on the IP address deviation index, instruction type deviation index, communication cycle deviation index, and data volume deviation index, and generate a comprehensive deviation index of communication characteristics; Among them, the set of legitimate communication peers refers to a pre-defined list of IP addresses that are allowed to establish communication connections with power terminal equipment. Specifically, a whitelist mechanism can be used to identify illegal device access behavior. The permitted service instruction set refers to the set of instruction types that power terminal equipment is allowed to execute under normal operating conditions. Specifically, it can be extracted and generated through the equipment function configuration file and is used to intercept unauthorized control instructions. The normal communication cycle range refers to the statistical distribution range of the time interval between two adjacent communications of a device in a typical working mode. It can be obtained by analyzing the time-series data of historical communication logs and is used to capture abnormal high-frequency or low-frequency communication behaviors. Typical data payload size range refers to the statistical range of the effective payload volume of data packets transmitted by the device under normal business scenarios. It can be set based on the business data traffic monitoring results and is used to identify data tampering or injection attacks.
[0024] Specifically, when a destination IP address is detected as not existing in the whitelist, the IP address deviation index is marked as an anomaly. If the current service instruction type exceeds the permitted set range, the instruction type deviation index triggers an alarm. For communication intervals within the normal cycle range, the cycle deviation index is zero; when it exceeds the range, the index is calculated based on the degree of deviation from the median value. No deviation is generated when the data load size is within the typical range; when it exceeds the range, an index is generated based on the proportion of the difference from the median value. The deviation indices of each dimension are linearly weighted by preset weighting coefficients to ultimately form a comprehensive index reflecting the overall degree of communication anomalies.
[0025] Compared to existing technologies, traditional methods typically rely on single-dimensional feature matching or fixed threshold judgments, such as verifying only the legitimacy of IP addresses or monitoring whether data traffic exceeds limits. This solution, however, integrates deviation analysis across four dimensions—communication object, command type, timing characteristics, and data payload—to construct a multi-dimensional feature space anomaly detection model capable of identifying complex attack patterns. For example, when dealing with attacks that masquerade as legitimate IP addresses but send abnormal commands, traditional methods may miss the attack due to the legitimate IP address, while this solution can effectively identify such attacks using a command type deviation index.
[0026] Through the above technical solution, this application achieves refined anomaly detection of communication behavior of power terminal equipment, solving the technical problem that traditional methods cannot distinguish between malicious operations and normal business fluctuations. Through the collaborative analysis of multi-dimensional deviation indicators, it can accurately identify attack behaviors such as unauthorized access, unauthorized commands, abnormal communication frequencies, and data tampering, while avoiding misjudgments caused by normal fluctuations in a single business parameter, thus improving the accuracy and timeliness of anomaly detection.
[0027] Preferably, the present invention further proposes a method for generating the IP address deviation index, specifically including: Through the formula: ; Generate IP address deviation index ; In the formula, This indicates the destination IP address of the current communication. It represents the set of legitimate communication peers; The specific methods for generating the instruction type deviation index include: Through the formula: ; Generate instruction type deviation index ; In the formula, This indicates the type of business instruction currently being executed. This represents a set of licensed business instructions; The specific methods for generating the communication cycle deviation index include: Through the formula: ; Generate communication cycle deviation index ; In the formula, This indicates the time interval between the current communication and the previous communication. This indicates the normal communication cycle range. The median value, This indicates the normal communication cycle range. The upper limit; The specific methods for generating the data deviation index include: Through the formula: ; Data volume deviation index ; In the formula, This indicates the effective payload size of the current communication data packet. This represents the typical data payload size range. The median value, This represents the typical data payload size range. The upper limit; Among them, the set of legitimate communication peers refers to the set of IP addresses that are allowed to communicate under normal working conditions of power terminal equipment. Specifically, it can be constructed by statistically filtering trusted IP addresses in the equipment's historical communication records, which is used to quickly identify illegal communication connections. The licensed service instruction set refers to the set of instruction types that the device is allowed to execute during normal operation. Specifically, it can be generated by parsing the legal opcodes in the device's service protocol and is used to intercept unauthorized control instructions. The normal communication cycle range refers to the statistical distribution interval of the time interval between adjacent communication behaviors of the device under normal conditions. Specifically, it can be determined by using a sliding time window to statistically analyze the mean and variance of historical communication time intervals, which is used to detect abnormal communication frequencies. Typical data payload size range refers to the statistical distribution range of the effective payload of data packets transmitted by the device during normal business interactions. It can be determined by analyzing the percentiles of historical communication data packet sizes and is used to identify abnormal data transmission behavior.
[0028] Specifically, when parsing communication data packets, the destination IP address is first compared with the set of legitimate communication peers. If a match is found, the IP address deviation index is set to zero; otherwise, it is marked as abnormal. For business instruction types, their legitimacy is determined by querying a predefined set of permitted instructions; illegal instruction types trigger the deviation index. In the calculation of communication cycle deviation, if the actual interval is within the normal range, there is no deviation; otherwise, normalization is performed by dividing the absolute difference between the interval value and the median value of the normal range by the upper limit of the range. Data payload deviation is calculated using a similar method, generating a standardized index by comparing the deviation of the actual payload from the median value of the typical range. The calculation of each deviation index uses the median value as a benchmark reference point, combined with the upper limit of the range for proportional scaling, making the characteristic deviations of different dimensions comparable.
[0029] Compared to existing technologies, traditional methods rely solely on fixed thresholds or single-dimensional features for anomaly detection, such as filtering by IP address blacklists or judging communication frequency anomalies by fixed time thresholds. These methods fail to adapt to the dynamic changes in device business behavior. This solution establishes a multi-dimensional feature quantification model, combined with the statistical distribution characteristics of normal business behavior, to achieve coordinated monitoring of IP addresses, command types, communication cycles, and data payloads. In particular, the use of intermediate value benchmarks and normalization effectively solves the misjudgment problem caused by business fluctuations in traditional methods. For example, it allows for reasonable time deviations in periodic businesses and distinguishes between normal fluctuations and abnormal mutations in data transmission.
[0030] Through the above technical solution, this application achieves refined anomaly detection of communication behavior of power terminal equipment, solving the technical deficiency of traditional methods in being unable to quantify the degree of deviation in multiple dimensions. A binary judgment mechanism based on IP address and command type is used to quickly screen suspicious communications, and combined with dynamic deviation calculations of communication cycle and data payload, highly concealed abnormal behaviors are accurately identified. The use of intermediate value benchmarks and normalization processing enhances the model's adaptability to normal business fluctuations, avoiding false alarms caused by unreasonable fixed threshold settings, and improving the detection accuracy and operational reliability of the security protection system.
[0031] Preferably, the present invention further proposes the following expression for the deviation analysis model: ; In the expression, This represents the comprehensive deviation index of communication characteristics. This represents the IP address deviation index. This represents the instruction type deviation index. This represents the communication cycle deviation index. This represents the data deviation index. , , , All are weighting coefficients, and ; Among them, the IP address deviation index is a binary judgment value generated by determining whether the current communication destination IP belongs to a preset legal set. Specifically, it can be implemented using a whitelist comparison algorithm to identify illegal communication peers. The instruction type deviation index is a binary judgment value generated by verifying whether the current business instruction is within the set of permitted instructions. Specifically, it can be implemented using instruction hash matching technology to detect unauthorized operations. The communication cycle deviation index is a continuous value generated by calculating the relative deviation between the current communication time interval and the normal cycle. It can be implemented using time series statistical analysis and is used to detect communication frequency anomalies. The data volume deviation index is a continuous value generated by measuring the degree of deviation between the current data load size and the typical range. It can be implemented by packet parsing and range comparison algorithms and is used to identify abnormal data traffic. Weighting coefficients are dynamic adjustment parameters assigned to each deviation index. They can be determined using the analytic hierarchy process or an expert system and are used to reflect the differences in importance of different characteristics in risk assessment.
[0032] Specifically, this solution achieves quantitative risk assessment by establishing a multi-dimensional feature fusion mechanism. When an illegal IP address or unauthorized command is detected, the corresponding binary deviation index directly triggers a security alarm; when abnormal fluctuations occur in the communication cycle or data volume, the continuous deviation index reflects the risk level proportionally. The contribution of each indicator is dynamically adjusted through weighting coefficients; for example, the weight of command type deviation can be increased at critical business nodes. All deviation indices are weighted and summed to generate a standardized comprehensive index, which retains the blocking capability of hard security rules while achieving a tiered risk assessment of abnormal behavior.
[0033] Compared to existing technologies, traditional methods typically employ single threshold judgments or independent feature detection, such as checking only IP legitimacy or instruction type, failing to quantify the cumulative effects of multi-dimensional anomalies. This solution, by establishing a configurable weighted model, can simultaneously handle both discrete and continuous security features, and adapts to the security needs of different scenarios through weight adjustments, effectively solving the problems of high false positive rates and coarse risk quantification inherent in traditional detection mechanisms.
[0034] Through the above technical solutions, this application achieves refined risk assessment of the communication behavior of power terminal equipment. By integrating multi-dimensional deviation indicators, the risk of protection failure due to misjudgment of a single feature is reduced; by dynamic weight configuration, the adaptability to the security requirements of different business scenarios is improved; and by standardized comprehensive index output, precise quantitative basis is provided for subsequent risk response, significantly improving the accuracy and reliability of network security protection.
[0035] For preferred options, please refer to [link / reference]. Figure 3 The present invention further proposes a method for generating the business criticality coefficient, specifically including: Step S41: Obtain the power grid structure of the power grid where the new power system terminal equipment is located and the node corresponding to the new power system terminal equipment in the power grid structure; Step S42: Obtain the number of shortest paths between two nodes in the power grid structure; the shortest path refers to the number of all existing paths from one node to another in the power grid structure that have equal and minimum path lengths; where the path length is calculated based on the line impedance; Step S43: Establish a business criticality analysis model based on the power grid structure of the power grid where the new power system terminal equipment is located, the node corresponding to the new power system terminal equipment in the power grid structure, and the number of shortest paths between two nodes in the power grid structure, and generate business criticality coefficients; Among them, the power grid structure refers to the physical connection relationship of the power grid. Specifically, it can be modeled using a topology graph structure, where nodes and edges represent the connection relationship between devices, and are used to reflect the power transmission path and communication dependency relationship. A node refers to the location identifier of a new type of power system terminal equipment in the power grid topology diagram. Specifically, it can be marked with a unique number to locate the physical location of the equipment in the power grid. The number of shortest paths refers to the total number of paths in a power grid where any two nodes have the same path length and are both the minimum value. Specifically, the path length can be calculated using the Dijkstra algorithm combined with line impedance. By statistically analyzing the proportion of paths passing through the current equipment node, the pivotal role of that node in the power grid can be reflected.
[0036] Specifically, the process begins by determining the node location of the equipment using power grid topology data, thus clarifying its physical connections within the grid. Next, the shortest paths between all nodes are calculated based on line impedance, and the ratio of the number of paths passing through the current equipment node to the total number of paths is statistically analyzed. If the equipment node is located at the intersection of multiple critical paths, this ratio will increase significantly, indicating that its failure could impact more power transmission channels. Finally, a business criticality analysis model quantifies the path statistics into a business criticality coefficient, which dynamically reflects the equipment's importance within the power grid. For example, when an equipment node is located at a core hub of the regional power grid, its business criticality coefficient will be higher than that of equipment nodes located at peripheral branches.
[0037] Compared to existing technologies, current methods typically assess importance based solely on equipment type or fixed rules, neglecting the dynamic impact of the power grid topology. This proposed solution, however, analyzes the path carrying capacity of equipment nodes within the power grid structure and quantifies criticality by combining real-time topology relationships. This enables more accurate identification of critical nodes affecting power grid stability, providing data support for differentiated protection.
[0038] Through the above technical solution, this application can dynamically assess the business criticality of the equipment based on its actual location and path dependence in the power grid, so that the security protection system can implement stricter abnormal communication blocking strategies for highly critical equipment, while adopting flexible measures such as alarms or current limiting for low-critical equipment, effectively balancing the strength of security protection and the needs of business continuity.
[0039] Preferably, the present invention further proposes the following expression for the business criticality analysis model: ; In the expression, This represents the business criticality coefficient, N represents the total number of nodes in the power grid structure, v represents the node corresponding to the new power system terminal equipment in the power grid structure, and s and t represent other nodes in the power grid structure. This represents the total number of shortest paths from node s to node t. It means that in The number of paths that pass through node v in the path; Among them, the business criticality coefficient is a quantitative indicator that dynamically calculates the hub status of equipment nodes in the communication path through the power grid topology. Specifically, it can be implemented using the shortest path statistical method based on graph theory. This indicator is used to reflect the degree of impact on the overall operation of the power grid when a node fails or is attacked. In a power grid structure, a node refers to a device access point in the physical connection topology of the power grid. Specifically, it can be modeled using an adjacency matrix or a graph database. The location of a node determines its communication path distribution in the power grid. The number of shortest paths refers to the total number of communication paths with the minimum impedance between two nodes in a power grid. Path count is used to evaluate the mediating role of nodes in global communication. This refers to the proportion of the shortest path passing through the target node to all shortest paths between the two nodes. Specifically, it can be achieved by traversing all non-target node pairs and counting the number of times the path is traversed. This proportion is used to measure the critical weight of a node in the power grid.
[0040] Specifically, the business criticality analysis model calculates the proportion of the target node appearing in the shortest paths by traversing all node pairs in the power grid except for the target equipment node. For each pair of nodes s and t, the total number of all shortest paths for them is first determined. Then count the number of paths that pass through node v. By accumulating all node pairs The ratio yields the business criticality coefficient of the device node. A larger coefficient indicates a stronger pivotal role for the device in power grid communication, and a wider impact on the system should a failure occur. The model excludes conditions s≠v and t≠v to prevent the device's own nodes from participating in the calculation, ensuring that the evaluation results only reflect the device's supporting role in communication between other nodes.
[0041] Compared to existing technologies, traditional methods often use fixed weights or simple connection counts to assess node importance, failing to consider the dynamic distribution of actual communication paths. This proposed solution, however, dynamically reflects the true pivotal role of equipment nodes in the power grid by statistically analyzing the frequency of node occurrences across all shortest paths. Existing technologies based on static rules for criticality assessment tend to overlook the impact of power grid topology changes, while the mathematical model established in this solution automatically updates assessment results as the power grid structure changes, improving the timeliness and accuracy of criticality judgment.
[0042] Through the above technical solution, this application achieves criticality assessment based on the dynamic characteristics of the power grid topology, solving the problem that traditional methods cannot accurately quantify the actual role of equipment nodes in the power grid. By calculating the proportion of nodes in the shortest path, the critical equipment that truly affects power grid connectivity can be identified, providing a precise basis for subsequent differentiated security responses. This technical solution avoids the misallocation of protection resources caused by criticality assessment biases, ensuring that highly critical nodes receive more stringent security protection while reducing over-protection of non-critical nodes.
[0043] Preferably, the present invention further proposes a method for generating the risk response action index, specifically including: Through the formula: ; Generate a risk response action index ; In the formula, This represents the comprehensive deviation index of communication characteristics. This represents the business criticality coefficient; The business criticality coefficient is an assessment value generated based on the importance of the equipment's location in the power grid topology. Specifically, it can be achieved by statistically analyzing the proportion of the shortest path between power grid nodes that passes through that node. This coefficient is used to characterize the degree of impact of equipment failure or anomaly on the overall operation of the power grid.
[0044] Specifically, the communication characteristic deviation index analyzes the destination address, command type, time interval, and payload size of communication data packets to determine whether they conform to the preset legal communication range. The business criticality coefficient calculates the pivotal role of the node where the equipment is located in the power grid connection through power grid topology analysis. Multiplying the two results generates a risk response action index. When the equipment's communication behavior is abnormal and it is located at a critical network node, the product result increases significantly, triggering a higher level of security response; if the equipment is located at a non-critical node or the deviation is low, the product result is smaller, and appropriate protective measures are taken. This dynamic quantification model avoids the limitations of a single threshold judgment, achieving a precise match between protection strength and risk level.
[0045] Compared to existing technologies, traditional methods typically employ fixed thresholds or static rules to assess risk, failing to consider the structural importance of equipment within the power grid. This leads to insufficient response to anomalous behavior in critical nodes or overprotection of non-critical nodes. This solution establishes a dynamic response mechanism by combining the product of behavioral deviation and topological criticality, enabling protective measures to adaptively adjust according to the actual risk level of the equipment.
[0046] Through the above technical solution, this application solves the problems of insufficient or excessive protection in traditional protection methods, and realizes differentiated security response for power terminal equipment. When communication anomalies occur in critical node equipment, the system automatically upgrades the protection level to promptly block potential attacks; for normal business fluctuations of non-critical equipment, unnecessary security interventions are reduced and resource allocation efficiency is optimized.
[0047] Please see Figure 4 The present invention also proposes a novel network security protection system for power system terminal equipment. This system is used to execute the aforementioned novel network security protection method for power system terminal equipment, specifically including: The service trust base creation unit 10 is used to build an independent service trust base for power terminal equipment; wherein, the service trust base refers to the range of communication behaviors allowed for power terminal equipment under normal working conditions; the service trust base includes a set of legitimate communication peers, a set of permitted service instructions, a normal communication cycle range, and a typical data payload size range; The data acquisition unit 20 is used to acquire communication data packets of the power terminal equipment in real time and parse the communication feature data in the communication data packets; wherein, the communication feature data includes the destination IP address of the current communication, the type of the currently executed business instruction, the time interval between the current communication and the previous communication, and the effective payload size of the current communication data packet; Feature analysis unit 30 is used to establish a deviation analysis model based on communication feature data and service credibility basis, and generate a comprehensive deviation index of communication features; The criticality analysis unit 40 is used to obtain the power grid structure of the power grid where the new power system terminal equipment is located and the corresponding node of the new power system terminal equipment in the power grid structure. Based on the power grid structure of the power grid where the new power system terminal equipment is located and the corresponding node of the new power system terminal equipment in the power grid structure, a business criticality analysis model is established to generate business criticality coefficients; the power grid structure refers to the physical connection structure of the power grid. The response analysis unit 50 is used to generate a risk response action index based on the business criticality coefficient and the comprehensive deviation index of communication characteristics. The protection response unit 60 is used to protect the network security of new power system terminal equipment based on the risk response action index.
[0048] Preferably, the present invention further proposes that the feature analysis unit 30 specifically includes: The IP address analysis module is used to generate an IP address deviation index based on the destination IP address of the current communication and the set of legitimate communication peers. The instruction type analysis module is used to generate an instruction type deviation index based on the set of licensed business instructions and the type of the currently executed business instruction. The communication cycle analysis module is used to generate a communication cycle deviation index based on the time interval between the current communication and the previous communication and the normal communication cycle range. The data volume analysis module is used to generate a data volume deviation index based on the typical data payload size range and the effective payload size of the current communication data packet. The comprehensive analysis module is used to establish a deviation analysis model based on the IP address deviation index, instruction type deviation index, communication cycle deviation index, and data volume deviation index, and generate a comprehensive deviation index of communication characteristics.
[0049] Preferably, the present invention further proposes that the key analysis unit 40 specifically includes: The power grid structure acquisition module is used to acquire the power grid structure of the power grid where the new power system terminal equipment is located and the corresponding node of the new power system terminal equipment in the power grid structure; The path acquisition module is used to obtain the number of shortest paths between two nodes in the power grid structure. The shortest path refers to the number of all existing paths with equal and minimum lengths from one node to another in the power grid structure. The path length is calculated based on the line impedance. The business criticality coefficient generation module is used to establish a business criticality analysis model and generate business criticality coefficients based on the power grid structure of the power grid where the new power system terminal equipment is located, the node corresponding to the new power system terminal equipment in the power grid structure, and the number of shortest paths between two nodes in the power grid structure.
[0050] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A novel network security protection method for power system terminal equipment, characterized in that, Specifically, the following steps are included: An independent service trust base is constructed for power terminal equipment; the service trust base refers to the range of communication behaviors allowed for power terminal equipment under normal operating conditions; the service trust base includes the set of legitimate communication peers, the set of permitted service instructions, the range of normal communication cycles, and the range of typical data payload sizes; The system acquires communication data packets from power terminal equipment in real time and parses out the communication feature data in the data packets. The communication feature data includes the destination IP address of the current communication, the type of business instruction currently being executed, the time interval between the current communication and the previous communication, and the effective payload size of the current communication data packet. A deviation analysis model is established based on communication characteristic data and business credibility basis to generate a comprehensive deviation index of communication characteristics. Obtain the power grid structure of the power grid where the new power system terminal equipment is located and the corresponding node of the new power system terminal equipment in the power grid structure. Based on the power grid structure of the power grid where the new power system terminal equipment is located and the corresponding node of the new power system terminal equipment in the power grid structure, establish a business criticality analysis model and generate business criticality coefficients; the power grid structure refers to the physical connection structure of the power grid. A risk response action index is generated based on the business criticality coefficient and the comprehensive deviation index of communication characteristics; Based on the risk response action index, cybersecurity protection is provided for new power system terminal equipment.
2. The novel network security protection method for power system terminal equipment according to claim 1, characterized in that, The comprehensive deviation index of communication characteristics specifically includes: Based on the destination IP address of the current communication and the set of legitimate communication peers, generate an IP address deviation index; Based on the set of licensed business instructions and the type of business instruction currently being executed, an instruction type deviation index is generated; Based on the time interval between the current communication and the previous communication and the normal communication cycle range, a communication cycle deviation index is generated. A data volume deviation index is generated based on the typical data payload size range and the effective payload size of the current communication data packet. A deviation analysis model is established based on the IP address deviation index, instruction type deviation index, communication cycle deviation index, and data volume deviation index to generate a comprehensive deviation index of communication characteristics.
3. The novel power system terminal equipment network security protection method according to claim 2, characterized in that, The specific methods for generating the IP address deviation index include: Through the formula: ; Generate IP address deviation index ; In the formula, This indicates the destination IP address of the current communication. It represents the set of legitimate communication peers; The specific methods for generating the instruction type deviation index include: Through the formula: ; Generate instruction type deviation index ; In the formula, This indicates the type of business instruction currently being executed. This represents a set of licensed business instructions; The specific methods for generating the communication cycle deviation index include: Through the formula: ; Generate communication cycle deviation index ; In the formula, This indicates the time interval between the current communication and the previous communication. This indicates the normal communication cycle range. The median value, This indicates the normal communication cycle range. The upper limit; The specific methods for generating the data deviation index include: Through the formula: ; Data volume deviation index ; In the formula, This indicates the effective payload size of the current communication data packet. This represents the typical data payload size range. The median value, This represents the typical data payload size range. The upper limit.
4. The novel power system terminal equipment network security protection method according to claim 2, characterized in that, The specific expression of the deviation analysis model is as follows: In the expression, This represents the comprehensive deviation index of communication characteristics. This represents the IP address deviation index. This represents the instruction type deviation index. This represents the communication cycle deviation index. This represents the data deviation index. , , , All are weighting coefficients, and .
5. The novel power system terminal equipment network security protection method according to claim 1, characterized in that, The specific methods for generating the business criticality coefficient include: Obtain the power grid structure of the power grid where the new power system terminal equipment is located and the corresponding node of the new power system terminal equipment in the power grid structure; Obtain the number of shortest paths between two nodes in a power grid structure; the shortest path refers to the number of all existing paths with equal and minimum lengths from one node to another in the power grid structure; where the path length is calculated based on the line impedance; A business criticality analysis model is established based on the power grid structure of the power grid where the new power system terminal equipment is located, the node corresponding to the new power system terminal equipment in the power grid structure, and the number of shortest paths between two nodes in the power grid structure, and business criticality coefficients are generated.
6. The novel power system terminal equipment network security protection method according to claim 5, characterized in that, The specific expression of the business criticality analysis model is as follows: ; In the expression, This represents the business criticality coefficient, N represents the total number of nodes in the power grid structure, v represents the node corresponding to the new power system terminal equipment in the power grid structure, and s and t represent other nodes in the power grid structure. This represents the total number of shortest paths from node s to node t. It means that in The number of paths that pass through node v in the given path.
7. The novel power system terminal equipment network security protection method according to claim 1, characterized in that, The specific methods for generating the risk response action index include: Through the formula: Generate a risk response action index ; In the formula, This represents the comprehensive deviation index of communication characteristics. This represents the business criticality coefficient.