Multi-source heterogeneous integrated network security emergency response system and method

Through a multi-source heterogeneous integrated network security emergency response system, efficient monitoring and rapid handling of network security risks in new power systems have been achieved, solving the network security problems that traditional technologies cannot handle in complex and multi-scenario situations, and ensuring the safe and stable operation of the power grid.

CN121530630APending Publication Date: 2026-02-13STATE GRID JIANGSU ELECTRIC POWER CO LIANYUNGANG POWER SUPPLY CO
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511547206.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-28
Publication Date
2026-02-13

AI Technical Summary

Technical Problem

Traditional security architectures are unable to effectively address the complex and multi-scenario cybersecurity risks in new power systems. Their insufficient automation and intelligence levels lead to cyberattacks impacting the safe and stable operation of the power grid.

Method used

The network security emergency response system adopts a multi-source heterogeneous integration approach. It acquires data through a multi-source data integration module and uses a business function collaboration module to monitor, analyze, and respond to network security incidents across levels. This includes dynamic monitoring of all assets, panoramic management of security equipment, visualization of threat paths, adaptive linkage response, and real-time monitoring of substation topology, enabling accurate risk identification and resource allocation.

Benefits of technology

It enables unified collection and analysis of security data across all scenarios, improves the decision-making efficiency of security personnel, and reduces response time from minutes to seconds, ensuring the safe and stable operation of power system facilities and meeting the security needs of major events.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121530630A_ABST
    Figure CN121530630A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-source heterogeneous integrated network security emergency response system and method, and the system comprises a multi-source data integration module and a service function cooperation module, and the service function collaboration module carries out monitoring, analysis, cross-level response and disposal on the network security event by using the acquired data. According to the system and the method of the scheme, an automatic disposal process closed loop is set, a multi-level banning rule based on an attack result, alarm times and attack frequency is preset, an automatic process from alarm discovery to strategy banning is realized, disposal time is compressed from a minute level of manual operation to a second level, the risk of manual misjudgment is reduced, and the efficiency of strategy banning is improved. The method can ensure safe and stable operation of important facilities and equipment of a power system, strengthen real-time cooperation and disposal capability, enrich an integrated cooperation support scene, fully cover network safety operation work, and meet guarantee support of various major activities.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of power system network security protection, specifically relating to a multi-source heterogeneous integrated network security emergency response system and method. Background Technology

[0002] As the digital wave sweeps the globe, the strategic value of cyberspace is becoming increasingly prominent, triggering profound changes at the international, national, and corporate levels. From international situations to corporate operations, cybersecurity has become a core issue concerning national security, economic development, and social stability, with its importance being particularly pronounced in the construction of new power systems.

[0003] In the current context of international competition, cyberspace has evolved into a new battleground for interstate rivalry. Countries are increasingly incorporating cybersecurity capabilities into their strategic competition, with critical infrastructure such as energy, transportation, and communications—serving as the "nerve center" of a nation's economic and social operations—becoming prime targets for cyberattacks. These attacks not only threaten the normal operation of specific facilities but can also trigger chain reactions affecting a nation's energy supply and social stability, even escalating into significant factors influencing the international landscape. The competition among nations in cyberspace encompasses not only technological and resource competition but also rule-making and the struggle for influence; cybersecurity capabilities have become a key indicator of a nation's comprehensive strength.

[0004] At the national level, the booming development of the digital economy is accelerating the digital transformation of the economy and society. To ensure the healthy and orderly development of the digital economy, the state has intensively introduced a series of laws and regulations, gradually building a comprehensive cybersecurity legal system, covering data security, personal information protection, and cybersecurity level protection. At the same time, enforcement and penalties have been continuously strengthened. Through strict enforcement and the deterrent effect of typical cases, various entities are urged to fulfill their cybersecurity responsibilities, creating a safe and trustworthy digital ecosystem. These measures not only demonstrate the state's high regard for cybersecurity but also provide legal basis and policy guidance for enterprises' cybersecurity construction.

[0005] Focusing on the enterprise level, the construction and development of new power systems pose unprecedented challenges to cybersecurity. These new power systems exhibit a significant characteristic of massive, fragmented grid connection, with particularly pronounced changes on both the power generation and load sides. On the power generation side, large-scale grid connection of new energy sources such as offshore wind power and onshore photovoltaics, along with the coordinated development of centralized and distributed power sources, are leading to an increasingly diversified energy structure. However, the intermittency and volatility of new energy power generation, coupled with the increasing intelligence of equipment, expose the power grid to more potential cybersecurity vulnerabilities. On the load side, the number of terminal devices such as smart homes, electric vehicle charging stations, and distributed energy storage is exploding. A large number of untrusted and semi-trusted terminals are connecting to the grid via the internet, indirectly participating in grid production and operation, resulting in increasingly blurred grid boundaries. Traditional protection models based on fixed boundaries are ill-equipped to cope with the dynamically changing network environment.

[0006] The construction of new power systems is essentially a process of deep integration of energy and digital technologies, characterized by multi-network interaction among power grids, information networks, and social networks, and the convergence of energy flows, business flows, and data flows. While this integration improves the operational efficiency and intelligence of the power system, it also tightly intertwines cybersecurity and power grid security risks. Cyberattacks can not only cause information leaks and system paralysis, but also directly affect power production and supply, leading to serious consequences such as widespread blackouts. Therefore, effectively preventing the transmission of cybersecurity risks to power grid security has become a key challenge that must be overcome in the construction of new power systems.

[0007] Against this backdrop, traditional security technology architectures and management systems are no longer sufficient to support today's complex multi-scenario applications and diversified data processing. In recent years, cybersecurity attack and defense drills have exposed problems such as insufficient automation and intelligence in cybersecurity monitoring and emergency response by municipal and county-level power companies, and excessively long response times. Therefore, effectively mitigating the impact of cybersecurity risks on the safe and stable operation of the power grid has become a crucial issue that urgently needs to be addressed in the construction of new power systems. Summary of the Invention

[0008] To address the aforementioned problems, the present invention aims to provide a multi-source heterogeneous integrated network security emergency response system and method.

[0009] The specific technical solution for achieving the objective of this invention is as follows:

[0010] A multi-source heterogeneous integrated network security emergency response system includes a multi-source data integration module and a business function collaboration module;

[0011] The multi-source data integration module uses standardized protocols to acquire various types of data.

[0012] The business function collaboration module uses the acquired data to monitor, analyze, respond to, and handle network security incidents across different levels.

[0013] Furthermore, the data acquired by the multi-source data integration module includes:

[0014] Integrate with an IP management and control system based on a RESTful API interface to obtain asset ledgers and online status data for network devices, office equipment, office auxiliary equipment, servers, and video equipment;

[0015] It collects raw data from various network attack detection systems and traffic analysis systems based on the Syslog protocol, filters duplicate entries and extracts key fields through regular expressions, collects firewall configuration and status information through the SNMPv3 protocol and vendor APIs, and realizes one-click policy distribution and callback through JSON format.

[0016] Real-time synchronization of task information at all levels is achieved through a web service interface.

[0017] Furthermore, the business function collaboration module includes a full asset dynamic monitoring unit, a security equipment panoramic management unit, a threat path visualization unit, an adaptive linkage response unit, a substation topology real-time monitoring unit, and a multi-task collaboration unit.

[0018] The full asset dynamic monitoring unit automatically calculates the status of various types of assets based on the data from the IP management system, determines the IP network segment collection rate, management rate, timeliness, completeness, and standardization rate of the ledger, and generates a dynamic asset key score.

[0019] The security device panoramic management unit is used to visually present the operating status of various network attack detection systems, traffic analysis systems, firewalls and other security devices;

[0020] The threat path visualization unit is used to dynamically draw attack trajectories based on GIS maps;

[0021] The adaptive linkage response unit determines the optimal response strategy by dynamically calculating the Comprehensive Threat Score (CTS) and Response Benefit Function (RUF), and links various firewalls and switches to achieve second-level blocking of the target IP. It then returns the results, including source IP, protocol type, policy name, blocking device, domain settings, configuration type, rule name, blocking duration, blocking time, unblocking time, result, status, CTS score, and RUF decision basis.

[0022] The substation topology real-time monitoring unit collects network device CPU load, memory utilization, port traffic and downlink device data through SNMP and ICMP protocols, displays the network topology in two dynamic dimensions, and issues alarms when an anomaly occurs.

[0023] The multi-task collaboration unit is used to achieve real-time data synchronization of multi-level work notifications, task orders, contact orders, and vulnerability warning orders.

[0024] Furthermore, the full-asset dynamic monitoring unit generates dynamic asset criticality scores based on a dynamic multi-dimensional asset criticality assessment algorithm, thereby achieving accurate risk identification and resource allocation.

[0025]

[0026]

[0027]

[0028] Where w1, w2, and w3 represent weights. This represents a static business attribute, used to characterize the importance of the business carried by asset node i. Represents the network topological centrality. N is the degree of node asset i, i.e., the number of connections, and N is the total number of asset nodes in the network. Indicates dynamic security risks. is the risk value of the j-th vulnerability on asset node i, and m is the total number of vulnerabilities.

[0029] Furthermore, the adaptive linkage response unit determines the optimal response strategy by calculating the Comprehensive Threat Score (CTS) and the Response Benefit Function (RUF).

[0030] Pre-set response strategy set for threat events Each strategy Each is associated with a disposal benefit value. A business impact cost ;

[0031] Each candidate disposition strategy is scored using the Response Benefit Function (RUF), and the strategy that maximizes the RUF value is selected as the final disposition instruction.

[0032]

[0033] ( , )

[0034] ( , )=

[0035]

[0036] in, It is an execution strategy The resulting security benefits are an increasing function of CTS. ( , ) represents the action to be performed. Potential business risk costs, The weighting coefficients of the impact factors for each CTS satisfy the following conditions: , This is the normalized scoring function for each influencing factor; Indicates IP reputation. Indicates the relevance of IP services. This represents the alarm confidence level, where q1, q2, and q3 are its weights, and P( ) represents the penalty factor of the disposal strategy, and λ represents the configurable risk preference coefficient.

[0037] Furthermore, the influencing factors include the threat level of attack technology, the importance of assets and business operations, the criticality of dynamic operation, and the credibility of multiple sources;

[0038] Among them, the threat level of the attack techniques Quantitative scoring is performed based on the Common Vulnerability Scoring System (CVSS) and the attack technology knowledge base for attack types.

[0039] The importance of the asset business The asset is determined based on the asset information obtained from the IP management system, its role in the power system business process, and the preset business importance level.

[0040] The key to dynamic operation Used to assess the real-time operational criticality of assets during an attack;

[0041] The multi-source credibility The determination is based on the number of heterogeneous security devices that report the same attack event within a preset time window and their respective device trust levels:

[0042]

[0043] Where m is the number of devices reporting the event. It is the credibility level of the j-th device.

[0044] This invention also provides a collaborative handling method for network security emergency response based on the above system, comprising the following steps:

[0045] Step 1: Full Asset Visualization and Analysis

[0046] Based on the asset ledger data of the IP management system synchronized by the full asset dynamic monitoring unit, the asset difference report is generated by comparing it with the real-time online status. Security domains are identified by IP segment affiliation, and the online status of important assets and key indicators are visualized. The operating status of various network attack detection systems, traffic analysis systems, firewalls and other security devices is presented.

[0047] Step 2: Multi-dimensional visualization analysis of the threat situation:

[0048] By parsing the raw alarm data from network attack detection systems and traffic analysis systems, and through processing such as timestamp alignment and source IP deduplication, a unified JSON format alarm event is generated, including system name, attack source IP, source port, destination IP, domain name, URL, application protocol, transport protocol, alarm time, alarm type, alarm status, business system, data source, interception status, attack technique, and operation.

[0049] In the GIS map, based on the IP attribution database and alarm event analysis, the geographical location of the attack source IP and the target district / county IP range are obtained, and attack path lines with arrows are dynamically generated. The brightness of the lines corresponds to the attack frequency. Clicking on the lines will bring up a secondary pop-up window, displaying details such as the attack source region, attack method, and the unit to which the target asset belongs.

[0050] The system updates key attack metrics in real time, including the number of successful attacks today, threats suffered this week, threats suffered today, suspicious events today, and the number of compromised hosts today. It also displays attack trends over time, attack type distribution in a pie chart, and a ranking of attack source IPs using ECharts composite charts.

[0051] Step 3: Automated processing and strategy closed loop:

[0052] When an event that matches the blocking rules is detected, the optimal handling strategy is automatically selected based on the existing data by dynamically calculating the Comprehensive Threat Score (CTS) and Response Benefit Function (RUF), and the corresponding firewall blocking command is triggered.

[0053] After the incident is resolved, an emergency response record is automatically generated, recording the event ID, response time, and strategy version number. This record is then synchronized to platforms at all levels via the task collaboration unit.

[0054] Step 4: Topology monitoring of critical equipment in the substation:

[0055] The substation topology real-time monitoring module obtains the CPU load, memory utilization, port traffic of each substation network device, as well as the information of each service device connected to the network device. It displays the network topology in a two-dimensional dynamic manner and highlights and pops up alarms when abnormal states such as network outages or traffic alarms occur.

[0056] Step 5, Multi-level Collaborative Response Process:

[0057] Based on the tasks issued by superiors, the task priorities are received and analyzed in real time. The physical location of relevant assets is located through the full asset dynamic monitoring unit and the task is assigned to specific regions to complete the task closed-loop process.

[0058] When initiating an emergency joint meeting, the cloud conferencing client is invoked to share threat situation data on the large screen, key attack events are marked, and a task assignment list is generated.

[0059] Step 6, Security Situation Assessment:

[0060] Regularly generate network security situation awareness and threat reports, including security scores, threat alerts, attack source statistics, asset vulnerabilities, attack types, and detailed alert information for each security device.

[0061] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0062] The solution of this invention adapts to more than 20 sets of equipment, such as IP management and control systems, network attack detection systems, traffic analysis systems, and multi-vendor firewalls, through standardized protocols, breaking down "data silos" and realizing unified collection and analysis of security data across all scenarios;

[0063] This solution is based on the dynamic display of attack paths and heat map analysis using GIS maps, combined with traffic monitoring, to build a "space-time-frequency" situational awareness system, thereby improving the decision-making efficiency of security personnel.

[0064] This solution achieves real-time collaboration across multiple levels of the power system in cybersecurity emergency response through task order synchronization between proactive defense platforms at different levels, cloud conferencing linkage, and report review processes, ensuring the achievement of the "three five-minute" goals.

[0065] This solution sets up an automated handling process loop, with preset multi-level blocking rules based on attack results, number of alarms, and attack frequency, realizing an automated process from alarm discovery to policy blocking, reducing the handling time from minutes of manual operation to seconds, and reducing the risk of human misjudgment;

[0066] The system and methods in this solution have passed the substation ring network topology monitoring, ensuring the safe and stable operation of important facilities and equipment in the power system, strengthening real-time coordination and handling capabilities, enriching integrated collaborative support scenarios, and comprehensively covering network security operations to meet the support needs of various major events.

[0067] The present invention will be further described below with reference to specific embodiments. Attached Figure Description

[0068] Figure 1 This is a schematic diagram of the architecture of the multi-source heterogeneous integrated network security emergency response system of the present invention.

[0069] Figure 2 This is a flowchart illustrating the matching process between alarm data and automatic blocking rules in the multi-source heterogeneous integrated network security emergency response system of the present invention.

[0070] Figure 3 This is a flowchart illustrating the collaborative handling method for network security emergency response according to the present invention. Detailed Implementation

[0071] Example

[0072] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. The described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0073] As indicated in this application and claims, unless the context clearly indicates otherwise, the words "a," "an," "an," and / or "the" do not specifically refer to the singular and may also include the plural. Generally speaking, the terms "comprising" and "including" only indicate the inclusion of explicitly identified steps and elements, which do not constitute an exclusive list, and the method or apparatus may also include other steps or elements.

[0074] Unless otherwise specifically stated, the relative arrangement, numerical expressions, and values ​​of the components and steps described in these embodiments do not limit the scope of this application. It should also be understood that, for ease of description, the dimensions of the various parts shown in the drawings are not drawn to actual scale. Techniques, methods, and devices known to those skilled in the art may not be discussed in detail, but where appropriate, such techniques, methods, and devices should be considered part of the specification. In all examples shown and discussed herein, any specific values ​​should be interpreted as merely exemplary and not as limitations. Therefore, other examples of exemplary embodiments may have different values. It should be noted that similar reference numerals and letters in the following drawings denote similar items; therefore, once an item is defined in one drawing, it need not be further discussed in subsequent drawings.

[0075] Combination Figure 1 and Figure 2 A multi-source heterogeneous integrated network security emergency response system, including a multi-source data integration module and a business function collaboration module;

[0076] The multi-source data integration module uses standardized protocols to acquire various types of data.

[0077] The business function collaboration module uses the acquired data to monitor, analyze, respond to, and handle network security incidents across different levels.

[0078] The data acquired by the multi-source data integration module includes:

[0079] Integrate with an IP management and control system based on a RESTful API interface to obtain asset ledgers and online status data for network devices, office equipment, office auxiliary equipment, servers, and video equipment;

[0080] It collects raw data from various network attack detection systems and traffic analysis systems based on the Syslog protocol, filters duplicate entries and extracts key fields through regular expressions, collects firewall configuration and status information through the SNMPv3 protocol and vendor APIs, and realizes one-click policy distribution and callback through JSON format.

[0081] Real-time synchronization of task information at all levels is achieved through a web service interface.

[0082] The business function collaboration module includes a full asset dynamic monitoring unit, a security equipment panoramic management unit, a threat path visualization unit, an adaptive linkage response unit, a substation topology real-time monitoring unit, and a multi-task collaboration unit.

[0083] The full asset dynamic monitoring unit automatically calculates the status of various types of assets based on the data from the IP management system, determines the IP network segment collection rate, management rate, timeliness, completeness, and standardization rate of the ledger, and generates a dynamic asset key score.

[0084] The security device panoramic management unit is used to visually present the operating status of various network attack detection systems, traffic analysis systems, firewalls and other security devices;

[0085] The threat path visualization unit is used to dynamically draw attack trajectories based on GIS maps;

[0086] The adaptive linkage response unit determines the optimal response strategy by dynamically calculating the Comprehensive Threat Score (CTS) and Response Benefit Function (RUF), and links various firewalls and switches to achieve second-level blocking of the target IP. It then returns the results, including source IP, protocol type, policy name, blocking device, domain settings, configuration type, rule name, blocking duration, blocking time, unblocking time, result, status, CTS score, and RUF decision basis.

[0087] The substation topology real-time monitoring unit collects network device CPU load, memory utilization, port traffic and downlink device data through SNMP and ICMP protocols, displays the network topology in two dynamic dimensions, and issues alarms when an anomaly occurs.

[0088] The multi-task collaboration unit is used to achieve real-time data synchronization of multi-level work notifications, task orders, contact orders, and vulnerability warning orders.

[0089] The dynamic asset monitoring unit generates dynamic asset criticality scores based on a dynamic multi-dimensional asset criticality assessment algorithm, thereby achieving accurate risk identification and resource allocation.

[0090]

[0091]

[0092]

[0093] Where w1, w2, and w3 represent weights. This represents static business attributes, used to characterize the importance of the business carried by asset node i. It is typically divided into four levels (e.g., core, important, general, unimportant), assigned values ​​of {1.0, 0.8, 0.6, 0.3} respectively. Examples include the production management layer: Production Management System (PMS), d5000, etc. =100. Information management layer: OA server, mail server, etc. =80.

[0094] It represents the network topology centrality, the importance of an asset in the network structure, and is calculated using the network topology graph;

[0095] N is the degree of node asset i, i.e., the number of connections, and N is the total number of asset nodes in the network.

[0096] It represents dynamic security risks and is used to characterize the real-time vulnerability and threat level of assets;

[0097] is the risk value of the j-th vulnerability on asset node i, and m is the total number of vulnerabilities.

[0098] The ACS(i) score changes dynamically based on vulnerability remediation, network architecture changes, or real-time alerts, enabling security operations personnel to focus on the most risky and highest-value assets in real time, thus achieving risk visualization.

[0099] The adaptive linkage response unit determines the optimal response strategy by calculating the Comprehensive Threat Score (CTS) and the Response Benefit Function (RUF).

[0100] Pre-set response strategy set for threat events Each strategy (For example: alert only, 1-hour ban, 1-day ban, permanent ban, port isolation) are all associated with a processing effectiveness value. A business impact cost ;

[0101] Each candidate disposition strategy is scored using the Response Benefit Function (RUF), and the strategy that maximizes the RUF value is selected as the final disposition instruction.

[0102]

[0103] ( , )

[0104] ( , )=

[0105]

[0106] in, It is an execution strategy The resulting security benefits are an increasing function of CTS. For example, a strong blocking strategy can bring significant security benefits to threats with high CTS values. The higher the CTS, the greater the benefit.

[0107] ( , ) represents the action to be performed. The higher the potential business risk cost, the greater the business loss caused by executing action a_k;

[0108] The weighting coefficients of the impact factors for each CTS satisfy the following conditions: , This is the normalized scoring function for each influencing factor;

[0109] exist Among the impact factors, This indicates the IP's reputation level. Low risk means that the IP has been marked as a "known malicious IP" or a "botnet C&C server" on various threat intelligence platforms of the provincial company. Blocking such IPs has almost no side effects.

[0110] A medium risk rating indicates that the IP address is a dynamic IP address originating from the company. A permanent ban may affect other users or employees using the same IP address in the future.

[0111] High risk indicates that the IP address is the address of a critical third-party service (such as public DNS, software update source, and various business systems of the provincial company) on which the system depends for normal operation;

[0112] This indicates the IP's business relevance. By analyzing historical traffic logs of various devices, it's determined whether the "attacking IP" has had a large amount of diverse normal business interactions with the internal system in the past. If an IP is identified as an attacker while also carrying normal business traffic, then blocking its business carries a high risk.

[0113] This indicates the confidence level of the alert. If the attack pattern is very clear (such as classic SQL injection characteristics), the confidence level is high, and the cost of false positives is low. If the pattern is ambiguous (such as "suspicious port scanning"), the confidence level is low, and the cost of false positives is high.

[0114] q1, q2, and q3 are respectively The weight of the impact factor, P( ) represents the penalty factor of the handling strategy, for example: P(alarm)=0, P(temporary ban)=5, P(permanent ban)=20, λ represents the configurable risk preference coefficient, which is used to adjust the balance between security benefits and business impact costs. >1 indicates a greater emphasis on business continuity. <1 indicates a greater emphasis on security.

[0115] The CTS impact factors include attack technology threat level, asset and business importance, dynamic operational criticality, and multi-source credibility.

[0116] The influencing factors include the threat level of attack technology, the importance of assets and business operations, the criticality of dynamic operation, and the credibility of multiple sources.

[0117] Among them, the threat level of the attack techniques The attack types are quantitatively scored based on the Common Vulnerability Scoring System (CVSS) and the Attack Technique Knowledge Base. The scoring takes into account the attack complexity, required privileges, and impact on confidentiality, integrity, and availability.

[0118] The importance of the asset business Based on the asset information obtained from the IP management system, and according to its role in the power system business process and the preset business importance level, a basic score is generally assigned to it first. For example, the production management layer: Production Management System (PMS), d5000, etc. =100.

[0119] The key to dynamic operation Introduce a time variable to assess the real-time operational criticality of assets during an attack, such as during major events like National Day or Spring Festival: According to the contingency plan, all externally serving web servers and core production systems will be... Assign a value of 1.0. During planned equipment maintenance: For equipment undergoing remote maintenance, its... It is assigned a value of 0.5 because it is more vulnerable to attack at this point;

[0120] The multi-source credibility The determination is based on the number of heterogeneous security devices (such as WAF, IDS, IPS) that report the same attack event within a preset time window (e.g., 5 minutes) and their respective device trust ratings (DRR):

[0121]

[0122] Where m is the number of devices reporting the event. It is the credibility level of the j-th device.

[0123] Automated execution and closed-loop verification of strategies:

[0124] After selecting the optimal handling strategy Then, the system automatically converts it into API commands (JSON format) adapted to the target firewall and switch manufacturers, and sends them out through standardized interfaces.

[0125] After the policy is issued, the system initiates a verification process, checking the firewall policy via API to confirm whether the blocking command was successfully applied. If verification fails within a preset time (e.g., 30 seconds), an alarm is triggered and the administrator is notified for manual intervention.

[0126] Combination Figure 3 This solution also provides a collaborative handling method for network security emergency response based on the above system, characterized by the following steps:

[0127] Step 1: Full Asset Visualization and Analysis

[0128] Based on the asset ledger data of the IP management system synchronized by the full asset dynamic monitoring unit, the asset difference report is generated by comparing it with the real-time online status. Security domains are identified by IP segment affiliation, and the online status of important assets and key indicators are visualized. The operating status of various network attack detection systems, traffic analysis systems, firewalls and other security devices is presented.

[0129] Step 2: Multi-dimensional visualization analysis of the threat situation:

[0130] By parsing the raw alarm data from network attack detection systems and traffic analysis systems, and through processing such as timestamp alignment and source IP deduplication, a unified JSON format alarm event is generated, including system name, attack source IP, source port, destination IP, domain name, URL, application protocol, transport protocol, alarm time, alarm type, alarm status, business system, data source, interception status, attack technique, and operation.

[0131] In the GIS map, based on the IP attribution database and alarm event analysis, the geographical location of the attack source IP and the target district / county IP range are obtained, and attack path lines with arrows are dynamically generated. The brightness of the lines corresponds to the attack frequency. Clicking on the lines will bring up a secondary pop-up window, displaying details such as the attack source region, attack method, and the unit to which the target asset belongs.

[0132] The system updates key attack metrics in real time, including the number of successful attacks today, threats suffered this week, threats suffered today, suspicious events today, and the number of compromised hosts today. It also displays attack trends over time, attack type distribution in a pie chart, and a ranking of attack source IPs using ECharts composite charts.

[0133] Step 3: Automated processing and strategy closed loop:

[0134] When an event that matches the blocking rules is detected, the optimal handling strategy is automatically selected based on the existing data by dynamically calculating the Comprehensive Threat Score (CTS) and Response Benefit Function (RUF), and the corresponding firewall blocking command is triggered.

[0135] After the incident is resolved, an emergency response record is automatically generated, recording the event ID, response time, and strategy version number. This record is then synchronized to platforms at all levels via the task collaboration unit.

[0136] Step 4: Topology monitoring of critical equipment in the substation:

[0137] The substation topology real-time monitoring module obtains the CPU load, memory utilization, port traffic of each substation network device, as well as the information of each service device connected to the network device. It displays the network topology in a two-dimensional dynamic manner and highlights and pops up alarms when abnormal states such as network outages or traffic alarms occur.

[0138] Step 5, Multi-level Collaborative Response Process:

[0139] Based on the tasks issued by superiors, the task priorities are received and analyzed in real time. The physical location of relevant assets is located through the full asset dynamic monitoring unit and the task is assigned to specific regions to complete the task closed-loop process.

[0140] When initiating an emergency joint meeting, the cloud conferencing client is invoked to share threat situation data on the large screen, key attack events are marked, and a task assignment list is generated.

[0141] Step 6, Security Situation Assessment:

[0142] Regularly generate network security situation awareness and threat reports, including security scores, threat alerts, attack source statistics, asset vulnerabilities, attack types, and detailed alert information for each security device.

[0143] The present invention also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to perform the above steps.

[0144] The present invention also provides a computer-storable medium having a computer program stored thereon, wherein the computer program, when executed by a processor, performs the above steps.

[0145] The embodiments described above are merely one implementation method of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of the invention patent. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this patent application should be determined by the appended claims.

Claims

1. A multi-source heterogeneous integrated network security emergency response system, characterized in that, This includes a multi-source data integration module and a business function collaboration module; The multi-source data integration module uses standardized protocols to acquire various types of data. The business function collaboration module uses the acquired data to monitor, analyze, respond to, and handle network security incidents across different levels.

2. The multi-source heterogeneous integrated network security emergency response system according to claim 1, characterized in that, The data acquired by the multi-source data integration module includes: Integrate with an IP management and control system based on a RESTful API interface to obtain asset ledgers and online status data for network devices, office equipment, office auxiliary equipment, servers, and video equipment; It collects raw data from various network attack detection systems and traffic analysis systems based on the Syslog protocol, filters duplicate entries and extracts key fields through regular expressions, collects firewall configuration and status information through the SNMPv3 protocol and vendor APIs, and realizes one-click policy distribution and callback through JSON format. Real-time synchronization of task information at all levels is achieved through a web service interface.

3. The multi-source heterogeneous integrated network security emergency response system according to claim 2, characterized in that, The business function collaboration module includes a full asset dynamic monitoring unit, a security equipment panoramic management unit, a threat path visualization unit, an adaptive linkage response unit, a substation topology real-time monitoring unit, and a multi-task collaboration unit. The full asset dynamic monitoring unit automatically calculates the status of various types of assets based on the data from the IP management system, determines the IP network segment collection rate, management rate, timeliness, completeness, and standardization rate of the ledger, and generates a dynamic asset key score. The security device panoramic management unit is used to visually present the operating status of various network attack detection systems, traffic analysis systems, firewalls and other security devices; The threat path visualization unit is used to dynamically draw attack trajectories based on GIS maps; The adaptive linkage response unit determines the optimal response strategy by dynamically calculating the Comprehensive Threat Score (CTS) and Response Benefit Function (RUF), and links various firewalls and switches to achieve second-level blocking of the target IP. It then returns the results, including source IP, protocol type, policy name, blocking device, domain settings, configuration type, rule name, blocking duration, blocking time, unblocking time, result, status, CTS score, and RUF decision basis. The substation topology real-time monitoring unit collects network device CPU load, memory utilization, port traffic and downlink device data through SNMP and ICMP protocols, displays the network topology in two dynamic dimensions, and issues alarms when an anomaly occurs. The multi-task collaboration unit is used to achieve real-time data synchronization of multi-level work notifications, task orders, contact orders, and vulnerability warning orders.

4. The multi-source heterogeneous integrated network security emergency response system according to claim 3, characterized in that, The dynamic asset monitoring unit generates dynamic asset criticality scores based on a dynamic multi-dimensional asset criticality assessment algorithm, thereby achieving accurate risk identification and resource allocation. ; ; ; Where w1, w2, and w3 represent weights. This represents a static business attribute, used to characterize the importance of the business carried by asset node i. Represents the network topological centrality. N is the degree of node asset i, i.e., the number of connections, and N is the total number of asset nodes in the network. Indicates dynamic security risks. is the risk value of the j-th vulnerability on asset node i, and m is the total number of vulnerabilities.

5. The multi-source heterogeneous integrated network security emergency response system according to claim 3, characterized in that, The adaptive linkage response unit determines the optimal response strategy by calculating the Comprehensive Threat Score (CTS) and the Response Benefit Function (RUF). Pre-set response strategy set for threat events Each strategy Each is associated with a disposal benefit value. A business impact cost ; Each candidate disposition strategy is scored using the Response Benefit Function (RUF), and the strategy that maximizes the RUF value is selected as the final disposition instruction. ; ( , ); ( , )= ; ; in, It is an execution strategy The resulting security benefits are an increasing function of CTS. ( , ) represents the action to be performed. Potential business risk costs, The weighting coefficients of the impact factors for each CTS satisfy the following conditions: , This is the normalized scoring function for each influencing factor; Indicates IP reputation. Indicates the relevance of IP services. This represents the alarm confidence level, where q1, q2, and q3 are its weights, and P( ) represents the penalty factor of the disposal strategy, and λ represents the configurable risk preference coefficient.

6. The multi-source heterogeneous integrated network security emergency response system according to claim 5, characterized in that, The influencing factors include the threat level of attack technology, the importance of assets and business operations, the criticality of dynamic operation, and the credibility of multiple sources. Among them, the threat level of the attack techniques Quantitative scoring is performed based on the Common Vulnerability Scoring System (CVSS) and the attack technology knowledge base for attack types. The importance of the asset business The asset is determined based on the asset information obtained from the IP management system, its role in the power system business process, and the preset business importance level. The key to dynamic operation Used to assess the real-time operational criticality of assets during an attack; The multi-source credibility The determination is based on the number of heterogeneous security devices that report the same attack event within a preset time window and their respective device trust levels: ; Where m is the number of devices reporting the event. It is the credibility level of the j-th device.

7. The network security emergency response collaborative handling method according to any one of claims 1-6, characterized in that, Includes the following steps: Step 1: Full Asset Visualization and Analysis Based on the asset ledger data of the IP management system synchronized by the full asset dynamic monitoring unit, the asset difference report is generated by comparing it with the real-time online status. Security domains are identified by IP segment affiliation, and the online status of important assets and key indicators are visualized. The operating status of various network attack detection systems, traffic analysis systems, firewalls and other security devices is presented. Step 2: Multi-dimensional visualization analysis of the threat situation: By parsing the raw alarm data from network attack detection systems and traffic analysis systems, and through processing such as timestamp alignment and source IP deduplication, a unified JSON format alarm event is generated, including system name, attack source IP, source port, destination IP, domain name, URL, application protocol, transport protocol, alarm time, alarm type, alarm status, business system, data source, interception status, attack technique, and operation.

8. In the GIS map, based on the IP attribution database and alarm event analysis, the geographical location of the attack source IP and the target county IP range are obtained. Attack path lines with arrows are dynamically generated, and the line brightness corresponds to the attack frequency. Clicking on the line will bring up a secondary pop-up box, displaying details such as the attack source region, attack method, and the unit to which the target asset belongs. The system updates key attack metrics in real time, including the number of successful attacks today, threats suffered this week, threats suffered today, suspicious events today, and the number of compromised hosts today. It also displays attack trends over time, attack type distribution in a pie chart, and a ranking of attack source IPs using ECharts composite charts. Step 3: Automated processing and strategy closed loop: When an event that matches the blocking rules is detected, the optimal handling strategy is automatically selected based on the existing data by dynamically calculating the Comprehensive Threat Score (CTS) and Response Benefit Function (RUF), and the corresponding firewall blocking command is triggered. After the incident is resolved, an emergency response record is automatically generated, recording the event ID, response time, and strategy version number. This record is then synchronized to platforms at all levels via the task collaboration unit. Step 4: Topology monitoring of critical equipment in the substation: The substation topology real-time monitoring module obtains the CPU load, memory utilization, port traffic of each substation network device, as well as the information of each service device connected to the network device. It displays the network topology in a two-dimensional dynamic manner and highlights and pops up alarms when abnormal states such as network outages or traffic alarms occur. Step 5, Multi-level Collaborative Response Process: Based on the tasks issued by superiors, the task priorities are received and analyzed in real time. The physical location of relevant assets is located through the full asset dynamic monitoring unit and the task is assigned to specific regions to complete the task closed-loop process. When initiating an emergency joint meeting, the cloud meeting client is invoked to share threat situation data on the large screen, key attack events are marked, and a task assignment list is generated. Step 6, Security Situation Assessment: Regularly generate cybersecurity situational awareness and threat reports, including security scores, threat alerts, attack source statistics, asset vulnerabilities, attack types, and detailed alert information for each security device.

9. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of any of the methods described in claim 1.

10. A computer-storable medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the method described in claim 1.