Primary equipment network security reinforcement method, computer equipment and storage medium

By setting up a dynamic threshold judgment and graded response mechanism in the power energy storage power station, and combining the dual judgment of the upper limit of the number of operations and the preset multiple, abnormal high-frequency operations are identified and blocked, and the attack traffic is proxied to the power honeypot, which solves the shortcomings of bypass traffic detection and achieves efficient network security hardening.

CN121547248APending Publication Date: 2026-02-17YISHITE ENERGY STORAGE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511731786.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-24
Publication Date
2026-02-17

AI Technical Summary

Technical Problem

In existing technologies, bypass flow detection in power storage power stations suffers from problems such as packet loss and incomplete flow types, making it unable to effectively detect abnormal behavior of edge devices and unable to automatically update the feature database, resulting in high network security risks and high false alarm rates.

Method used

By setting a dynamic threshold judgment and graded response mechanism in the instruction receiving stage, and combining the dual judgment of the upper limit of the number of operations and the preset multiple, abnormal high-frequency operations are identified, and the confirmed attack traffic is proxied to the power honeypot for accurate graded alarms and attack analysis.

Benefits of technology

It significantly reduces the risk to equipment operation caused by malicious commands, improves the accuracy of threat identification, reduces the false alarm rate, and enhances proactive defense capabilities in industrial network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121547248A_ABST
    Figure CN121547248A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, and discloses a primary equipment network security reinforcement method, computer equipment and a storage medium, by setting a dynamic threshold judgment and hierarchical response mechanism in an instruction receiving link, abnormal high-frequency operation for primary equipment can be effectively identified and blocked, and the security of the primary equipment is enhanced. The equipment operation risk caused by a malicious instruction is obviously reduced; meanwhile, in combination with double judgment of an upper limit of operation times and a preset multiple, accurate grading alarm from suspected attacks to confidential attacks is realized, the accuracy of threat identification is greatly improved, and false alarms are reduced; by intelligently agenting the confidential attack traffic to the electric power honeypot, the security of real equipment is protected, an effective environment is provided for analysis and tracking of attack behaviors, and the active defense capability of the system in an industrial network environment in which a feature library cannot be updated in real time is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a method for hardening the network security of primary equipment, a computer device, and a storage medium. Background Technology

[0002] In the field of power storage, especially in electrochemical energy storage power stations, small-scale commercial and industrial energy storage power stations are developing rapidly. These small power stations are characterized by small individual station power but numerous numbers. To facilitate operation and maintenance management, most projects have adopted cloud-based data migration, which means that the local energy management system (EMS) needs to be connected to an external network. However, this practice increases the asset exposure of on-site equipment, thereby significantly increasing cybersecurity risks.

[0003] Currently, small-scale commercial and industrial energy storage power stations generally use security audit and detection products based on bypass network traffic and product feature libraries for network auditing and security detection. However, bypass traffic detection has the following problems:

[0004] (1) Packet loss: Bypass traffic detection may lose some data packets, resulting in incomplete detection results.

[0005] (2) Incomplete traffic types: Bypass traffic detection cannot cover all types of network traffic, resulting in detection blind spots.

[0006] (3) Monitoring location problem: The monitoring location of bypass traffic detection is usually too close to the network core layer, making it difficult to detect abnormal behavior of edge devices.

[0007] These issues make bypass detection products ineffective in preventing complex cyberattacks and result in a high false positive rate. Furthermore, due to the isolated nature of networks in industrial environments, these products cannot automatically update their signature databases, leading to delays in attack detection.

[0008] Therefore, improvements to existing technologies are necessary.

[0009] The above information is provided as background information only to aid in understanding the present invention, and does not constitute an assertion or admission that any of the above content can be used as prior art relative to the present invention. Summary of the Invention

[0010] This invention provides a method for hardening network security of primary equipment, a computer device, and a storage medium to solve the problems existing in the prior art.

[0011] To achieve the above objectives, the present invention provides the following technical solution:

[0012] In a first aspect, the present invention provides a method for hardening the network security of primary equipment, the method comprising:

[0013] S101. When an operation instruction is received from the master station device, determine whether the operation instruction has reached the upper limit of the corresponding number of operation instructions; if not, execute S102; if yes, execute S103.

[0014] S102. The operation command is forwarded normally to the corresponding primary device;

[0015] S103. If the attack traffic is suspected to be sent by an attacker, a security alarm is issued, and it is further determined whether the operation command has reached a preset multiple of the upper limit value of the corresponding operation command count; if yes, then execute S104; if no, then continue to execute S103.

[0016] S104. Determine that the attack traffic was sent by the attacker and proxy the attack traffic to the power honeypot.

[0017] Furthermore, in the primary equipment network security hardening method, before step S101, the method further includes:

[0018] S100. Determine the upper limit of the number of operation commands for the master station device based on the historical data of operation commands.

[0019] Furthermore, in the primary equipment network security hardening method, step S100 includes:

[0020] S1001. Obtain historical data of operation instructions from a preset number of days prior to the current date; the historical data of operation instructions is the number of operation instructions within each preset time period.

[0021] S1002. Based on the historical data of operation instructions, calculate the average number of operation instructions per day within each preset time period. and standard deviation of the number of operation instructions ;

[0022] S1003. Standardize the calculated standard deviation of the number of operation commands to obtain values ​​in the interval [0, 1]. ;

[0023] S1004. Calculate and determine the maximum number of operation commands according to the following formula:

[0024] .

[0025] Furthermore, in the primary equipment network security hardening method, in step S1004, the calculated result is rounded to obtain the upper limit value of the number of operation commands.

[0026] Furthermore, in the primary equipment network security hardening method, the operation instructions include power on / off control instructions, power control instructions, other parameter setting instructions, and point information acquisition instructions.

[0027] Furthermore, in the primary equipment network security hardening method, after step S104, the method further includes:

[0028] S105. Send a fake response to the operation command issued by the power honeypot back to the master station device.

[0029] Furthermore, in the primary equipment network security hardening method, after step S105, the method further includes:

[0030] The method further includes:

[0031] S106. Continuously record the attacker's subsequent actions to form an attack chain evidence log.

[0032] Furthermore, in the primary equipment network security hardening method, after step S106, the method further includes:

[0033] S107. The attack chain evidence log is encrypted and uploaded to the scheduling security management center. Digital signature technology is used to solidify the integrity of the log for subsequent tracing and evidence collection.

[0034] In a second aspect, the present invention provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the primary device network security hardening method provided in the first aspect above.

[0035] Thirdly, the present invention provides a computer-readable storage medium having computer-executable instructions stored thereon, the computer-executable instructions being executed by a computer processor to implement the primary device network security hardening method provided in the first aspect above.

[0036] Compared with the prior art, the present invention has the following beneficial effects:

[0037] This invention provides a method for hardening the network security of primary equipment, a computer device, and a storage medium. By setting a dynamic threshold judgment and graded response mechanism in the command receiving stage, it can effectively identify and block abnormal high-frequency operations targeting primary equipment, significantly reducing the risk to equipment operation caused by malicious commands. At the same time, by combining the dual judgment of the upper limit of the number of operations and the preset multiple, it realizes accurate graded alarms from "suspected attack" to "confirmed attack", greatly improving the accuracy of threat identification and reducing false alarms. By intelligently proxying confirmed attack traffic to power honeypots, it not only protects the security of real equipment, but also provides an effective environment for the analysis and tracking of attack behavior, enhancing the system's proactive defense capabilities in industrial network environments where the signature database cannot be updated in real time.

[0038] The present invention has other features and advantages, which will be apparent from or will be set forth in detail in the accompanying drawings and the following detailed description, which together serve to explain the particular principles of the invention. Attached Figure Description

[0039] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0040] Figure 1 This is one of the flowcharts illustrating a method for hardening the network security of primary equipment provided in Embodiment 1 of the present invention;

[0041] Figure 2 This is a system topology diagram of the master station equipment, network security hardening device, power honeypot and primary equipment provided in Embodiment 1 of the present invention;

[0042] Figure 3 This is a communication flowchart between the master station device, network security hardening device, power honeypot and primary equipment provided in Embodiment 1 of the present invention;

[0043] Figure 4 This is a second schematic diagram of a method for hardening the network security of primary equipment provided in Embodiment 1 of the present invention;

[0044] Figure 5 This is the third flowchart of a method for hardening the network security of primary equipment provided in Embodiment 1 of the present invention;

[0045] Figure 6 This is a schematic diagram of the structure of a computer device provided in Embodiment 2 of the present invention. Detailed Implementation

[0046] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0047] Example 1

[0048] Please refer to Figure 1 This is a flowchart illustrating a method for hardening the network security of primary equipment according to Embodiment 1 of the present invention. This method can be implemented by software and / or hardware and applied to network security hardening devices, such as... Figure 2 As shown, the network security hardening device is installed between the main station equipment and the primary equipment (i.e., Figure 2 This method effectively protects primary equipment by connecting PCS devices, BMS devices, and EMS devices within the system. The specific steps include:

[0049] S101. When an operation instruction is received from the master station device, determine whether the operation instruction has reached the upper limit of the corresponding number of operation instructions; if not, execute S102; if yes, execute S103.

[0050] It should be noted that the master station equipment is usually the core equipment that controls and manages the primary equipment, and the operation commands it issues are used to control the operating status of the primary equipment.

[0051] Each operation command has a pre-set upper limit for the number of commands it can execute. This upper limit is determined based on a combination of factors, including the normal operating requirements of the primary equipment, historical data, and security considerations. For example, under normal operating conditions, certain operation commands should not exceed a certain number of times per unit time. Exceeding this number may indicate an anomaly. This is because attackers, in the initial stages of an attack, need to investigate the ports and communication protocols of the primary equipment. This investigation process involves continuously triggering invalid operation commands, and each invalid operation command is recorded as one operation command count. In other words, once an attacker launches an attack, the number of invalid operation commands they issue will inevitably reach the upper limit, thus becoming detectable. Therefore, in this step, the system will count the number of received operation commands and compare it with the preset upper limit.

[0052] If the number of operation commands does not reach the upper limit, it means that the command is within the normal operation frequency range, and the system will execute step S102 to forward the command normally; if the number of operation commands reaches the upper limit, it means that the sending frequency of the command may be abnormal, and the system will execute step S103 to further determine whether it is an attack.

[0053] S102. The operation command is forwarded normally to the corresponding primary device;

[0054] It should be noted that when step S101 determines that the number of operation commands has not reached the upper limit, the command is considered a normal operation command. In this case, the system will forward the operation command to the corresponding primary device according to the normal communication path and protocol, such as... Figure 3 As shown. By forwarding commands normally, the primary equipment is ensured to operate normally according to the control requirements of the master station equipment, thus guaranteeing the stable operation of the power system.

[0055] S103. If the attack traffic is suspected to be sent by an attacker, a security alarm is issued, and it is further determined whether the operation command has reached a preset multiple of the upper limit value of the corresponding operation command count; if yes, then execute S104; if no, then continue to execute S103.

[0056] It should be noted that when step S101 determines that the number of operation commands has reached the upper limit, the system initially determines that the command may be attack traffic sent by a suspected attacker. This is because normal operation is unlikely to send the same command frequently to reach the upper limit in a short period of time. In order to promptly alert relevant personnel to potential security threats, the system will issue a security alarm, which can take various forms such as sound prompts, log recordings, and notifications sent to the monitoring center.

[0057] After issuing an alarm, the system does not immediately confirm that this is a confirmed attack. Instead, it further determines whether the operation command has reached a preset multiple of the upper limit for the corresponding number of operation commands. This preset multiple is a threshold higher than the upper limit, used to further distinguish between suspected and confirmed attacks. For example, if the upper limit is 2 times, the preset multiple might be 1.5 times, or 3 times. If the number of operation commands reaches this preset multiple, it indicates a higher probability of an attack, and the system will execute step S104; if it does not reach the preset multiple, it indicates that although there is a possibility of a suspected attack, it cannot be confirmed yet, and the system will continue to execute step S103 to continuously monitor and judge the operation command.

[0058] S104. Determine that the attack traffic was sent by the attacker and proxy the attack traffic to the power honeypot.

[0059] It should be noted that when step S103 determines that the number of operation commands has reached a preset multiple of the upper limit, the system determines that the command is attack traffic sent by a known attacker. This means that the attacker is likely attempting to interfere with or disrupt the normal operation of primary equipment through high-frequency operation commands, posing a serious threat to power system security.

[0060] To protect real primary devices from attacks while simultaneously analyzing and tracking attack behavior, the system proxies confirmed attack traffic to powerline honeypots, such as... Figure 3 As shown, a power line honeypot is a cybersecurity technology that simulates a real-world primary equipment or system environment to attract attackers. Once attack traffic enters the honeypot, attackers can perform various operations without harming the real equipment. Simultaneously, the system can analyze the attack traffic to understand the attacker's methods and objectives, providing a basis for subsequent security protection and countermeasures, and enhancing the system's proactive defense capabilities in industrial network environments where signature databases cannot be updated in real time.

[0061] In summary, by setting a dynamic threshold determination and graded response mechanism in the instruction receiving stage, the embodiments of the present invention can effectively identify and block abnormal high-frequency operations targeting primary equipment, significantly reducing the risk to equipment operation caused by malicious instructions. At the same time, by combining the dual judgment of the upper limit of the number of operations and the preset multiple, accurate graded alarms from "suspected attack" to "confirmed attack" are achieved, greatly improving the accuracy of threat identification and reducing false alarms. By intelligently proxying confirmed attack traffic to power honeypots, the security of real equipment is protected, and an effective environment is provided for the analysis and tracking of attack behavior, enhancing the system's proactive defense capabilities in industrial network environments where the signature database cannot be updated in real time.

[0062] Please refer to Figure 4 In one embodiment of this invention, before step S101, the method further includes step S100, the core purpose of which is to provide a scientific and reasonable benchmark value for subsequent instruction count determination. By determining the upper limit of the number of various operation instructions for the master station device based on historical operation instruction data, the system can more accurately identify normal and abnormal operations, effectively enhancing the ability to harden the network security of primary equipment.

[0063] S100. Determine the upper limit of the number of operation commands for the master station device based on the historical data of operation commands.

[0064] It should be noted that the system needs to collect historical data of operation commands from the master station equipment over a period of time. This data includes various types of operation commands, such as power on / off control commands, power control commands, other parameter setting commands, and commands to obtain point information. In other words, for each type of operation command, a corresponding upper limit on the number of operation commands needs to be determined.

[0065] The collected data can come from the main station device's own logs, network device records that communicate with the main station device, or data collected by a dedicated security monitoring system.

[0066] In one embodiment of this example, S100 includes:

[0067] S1001. Obtain historical data of operation instructions from a preset number of days prior to the current date; the historical data of operation instructions is the number of operation instructions within each preset time period.

[0068] It should be noted that the system collects historical data of operation commands for a preset number of days (e.g., 30 days) prior to the current date, and counts the number of each type of command within a preset time period (e.g., every hour / every 15 minutes).

[0069] For example, if the preset time period is every 15 minutes, then there are 6 time periods per hour in a 24-hour day, and the number of times the operation command is triggered is recorded in each time period.

[0070] Understandably, the data types cover all command types (power on / off, power control, parameter setting, point information acquisition), ensuring that each command has an independent dataset.

[0071] By capturing normal operational patterns through data from multiple days and time periods, threshold distortion can be avoided due to single-day anomalies or time-period fluctuations.

[0072] S1002. Based on the historical data of operation instructions, calculate the average number of operation instructions per day within each preset time period. and standard deviation of the number of operation instructions ;

[0073] It should be noted that, for each instruction type, the average number of operation instructions within each preset time period per day is calculated separately. and standard deviation of the number of operation instructions .

[0074] For example, This represents the average number of operation commands for power on / off control. This represents the average number of operation instructions for the power control command. Set the average number of operation commands for other parameters. The average number of operation commands to obtain location information.

[0075] This represents the standard deviation of the number of operation commands for power on / off control. The standard deviation of the number of operation instructions for power control commands. The standard deviation of the number of operation instructions for setting other parameters. The standard deviation of the number of operation commands used to obtain location information.

[0076] S1003. Standardize the calculated standard deviation of the number of operation commands to obtain values ​​in the interval [0, 1]. ;

[0077] It should be noted that mapping the standard deviation to the [0,1] interval is also intended to eliminate the influence of dimensions.

[0078] For example, for After standardizing the extreme values, we get ,right After extreme value standardization, we get ,right After standardizing the extreme values, we get ,right After standardizing the extreme values, we get .

[0079] S1004. Calculate and determine the maximum number of operation commands according to the following formula:

[0080] .

[0081] It should be noted that this formula is an empirical formula, based on the analysis of historical anomalies, and is designed to balance the risks of false alarms and false negatives.

[0082] For example, the maximum number of operation commands corresponding to power on / off control commands is: .

[0083] Optionally, in S1004, the calculated result is rounded to obtain the upper limit value of the number of operation instructions.

[0084] It should be noted that the calculation result is rounded to ensure that the threshold is an integer, which facilitates the system's quick judgment.

[0085] For example, if the calculated result is 4.7, then it is rounded down to 5.

[0086] In summary, thresholds are automatically generated from historical data without the need for manual presets, and can adapt to the operating characteristics of different devices and at different times.

[0087] Please refer to Figure 5 In one embodiment of this invention, after step S104, the method further includes step S105, which involves having the power honeypot simulate a real device to produce a false response to the attack command and then sending this false response back to the master station device. This can mislead attackers, making them believe that the attack command has successfully acted on the real device, while simultaneously preventing the real device from being damaged by the attack and ensuring the stable operation of the power system.

[0088] S105. Send a fake response to the operation command issued by the power honeypot back to the master station device.

[0089] It should be noted that the power honeypot needs to be pre-configured with response templates and parameters similar to those of real primary equipment. These templates and parameters should be as realistic as possible, covering feedback information from the equipment under various normal and abnormal conditions. For example, for power-on / off control commands, the honeypot should prepare response data for different states (such as normal power-on, fault power-on, normal power-off, forced power-off, etc.), including response time, returned status codes, and changes in equipment parameters.

[0090] Honeypots also need to monitor their own operating status and resource usage in real time to ensure that there are no delays or errors when responding to fake responses due to insufficient resources.

[0091] Upon receiving an instruction deemed a confirmed attack by S104, the power honeypot generates a fake response based on the instruction type and a pre-defined response strategy. For example, if the attack instruction attempts to set the device power to a value outside the safe range, the honeypot can generate a fake response that appears to have successfully set the power, but in reality, the device power has not changed. Simultaneously, it returns some forged power parameters and device status information.

[0092] During the generation of fake responses, honeypots must ensure the logic and consistency of the responses. For example, for a series of related operation commands, the fake responses from the honeypot must conform to the normal flow and patterns of device operation to avoid arousing suspicion from attackers.

[0093] The powerline honeypot uses the same communication protocol and interface as the master device to accurately reply to the generated fake responses. During the reply process, it is crucial to ensure the stability and security of communication to prevent the fake responses from being tampered with or intercepted during transmission.

[0094] At the same time, the honeypot needs to record information such as the time and content of the fake response, as well as the reception status of the main station device, in order to conduct subsequent attack analysis and system optimization.

[0095] Please refer to this again. Figure 3 , Figure 3This demonstrates the communication flow between the master station device, the network security hardening device, the power system honeypot, and the primary equipment. Under normal circumstances, the master station device sends operation commands to the network security hardening device, which forwards them to the actual primary equipment. The primary equipment receives and executes the commands and returns a response. When the command sent by the master station device is determined to be a confirmed attack command, the flow changes. In this case, the network security hardening device intercepts the attack command and does not send it to the actual primary equipment. Instead, it forwards it to the power system honeypot for traffic proxying. Specifically, the power system honeypot generates a fake response based on the command type, and the network security hardening device replies to the master station device using the same communication path as the master station device. After receiving the fake response, the master station device may continue to send subsequent commands, while the power system honeypot continues to send fake response replies. The primary equipment remains unaffected by the attack commands and continues to operate normally, ensuring the safety and stability of the power system.

[0096] In one embodiment of this example, after step S105, the method further includes:

[0097] The method further includes:

[0098] S106. Continuously record the attacker's subsequent actions to form an attack chain evidence log.

[0099] It should be noted that, assuming a power system, the master station equipment is compromised by an attacker who sends a confirmation attack command. After S104 determines that the command is an attack command, the power honeypot replies with a false response to the attacker in S105. Upon receiving the false response, the attacker continues to send a series of operational commands, attempting to further control the equipment or obtain more information.

[0100] During phase S106, the power honeypot continuously records these subsequent actions of the attacker. For example, if the attacker first sends a power adjustment command, the honeypot records the type of the command, the target power value, and the sending time; then the attacker sends a parameter query command, and the honeypot records the type of the queried parameter and the forged parameter value returned; then the attacker attempts to send a malware injection command, and the honeypot similarly records the command content and related network communication information.

[0101] The power honeypot linked and integrated these recorded information according to time sequence and logical relationships, generating an attack chain evidence log. Security personnel analyzed this log and identified the attacker's attack pattern as first attempting to control device power, then querying device parameters, and finally implanting malware. Based on these analysis results, security personnel assessed the threat level of the attack, promptly patched potential system vulnerabilities, adjusted security policies, and preserved the log as evidence for subsequent legal investigation and accountability. The actual primary equipment, unaffected by the attack commands, continued to operate normally, ensuring a stable power supply to the power system.

[0102] In one embodiment of this example, after step S106, the method further includes:

[0103] S107. The attack chain evidence log is encrypted and uploaded to the scheduling security management center. Digital signature technology is used to solidify the integrity of the log for subsequent tracing and evidence collection.

[0104] It should be noted that in a power system security scenario, when the master station equipment is attacked, the power honeypot sequentially executes the following steps: S104 determines the attack command, S105 responds with a false response, and S106 records the attack chain evidence log. In stage S107, the power honeypot first encrypts the attack chain evidence log using the AES algorithm and a generated random key, converting the log into ciphertext. Then, it uploads the encrypted log to the dispatch security management center via a VPN secure channel. Simultaneously, it encrypts the SHA-256 hash value of the log using a private key, generates a digital signature, and appends it to the encrypted log.

[0105] After receiving the log, the dispatch security management center decrypts the digital signature using the corresponding public key to obtain the original hash value. Then, it recalculates the hash value of the received encrypted log and compares it with the decrypted hash value. If the two hash values ​​match, it indicates that the log has not been tampered with during transmission and is intact. Security personnel can use this reliable attack chain evidence log to trace the attack event, analyze the attacker's source and attack methods, and provide strong support for further security protection and legal evidence collection. Meanwhile, the actual primary equipment, thanks to the effective protection of the power honeypot, was not actually affected by the attack and continued to operate stably, ensuring the normal power supply of the power system.

[0106] Although this invention uses terms such as master station equipment and operation instructions frequently, the possibility of using other terms is not excluded. These terms are used merely for the convenience of describing and explaining the essence of this invention; interpreting them as any additional limitation would contradict the spirit of this invention.

[0107] Example 3

[0108] Figure 6 This is a schematic diagram of the structure of a computer device provided in Embodiment 3 of the present invention. Figure 6 A block diagram of an exemplary computer device 12 suitable for implementing embodiments of the present invention is shown. Figure 6 The computer device 12 shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of the present invention.

[0109] like Figure 6 As shown, the computer device 12 is represented in the form of a general-purpose computing device. The components of the computer device 12 may include, but are not limited to: one or more processors or processing units 16, system memory 28, and bus 18 connecting different system components (including system memory 28 and processing unit 16).

[0110] Bus 18 represents one or more of several bus architectures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the various bus architectures. For example, these architectures include, but are not limited to, the Industry Standard Architecture (ISA) bus, the Micro Channel Architecture (MAC) bus, the Enhanced ISA bus, the Video Electronics Standards Association (VESA) local bus, and the Peripheral Component Interconnect (PCI) bus.

[0111] Computer device 12 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by computer device 12, including volatile and non-volatile media, removable and non-removable media.

[0112] System memory 28 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache memory 32. Computer device 12 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 34 may be used to read and write non-removable, non-volatile magnetic media (…). Figure 6 Not shown; usually referred to as a "hard drive"). Although Figure 6 Not shown, a disk drive for reading and writing to a removable non-volatile disk (e.g., a "floppy disk") and an optical disk drive for reading and writing to a removable non-volatile optical disk (e.g., a CD-ROM, DVD-ROM, or other optical media) may be provided. In these cases, each drive may be connected to bus 18 via one or more data media interfaces. Memory 28 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the embodiments of the present invention.

[0113] A program / utility 40 having a set (at least one) of program modules 42 may be stored, for example, in memory 28. Such program modules 42 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. Program modules 42 typically perform the functions and / or methods described in the embodiments of the present invention.

[0114] Computer device 12 can also communicate with one or more external devices 14 (e.g., keyboard, pointing device, display 24, etc.), and with one or more devices that enable a user to interact with the computer device 12, and / or with any device that enables the computer device 12 to communicate with one or more other computing devices (e.g., network card, modem, etc.). This communication can be performed via input / output (I / O) interface 22. Furthermore, computer device 12 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 20. As shown, network adapter 20 communicates with other modules of computer device 12 via bus 18. It should be understood that, although... Figure 6 As not shown, it can be used in conjunction with computer device 12 with other hardware and / or software modules, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0115] The processing unit 16 executes various functional applications and data processing by running programs stored in the system memory 28, such as implementing the primary equipment network security hardening method provided in the embodiments of the present invention.

[0116] Example 4

[0117] Embodiment 4 of the present invention provides a computer-readable storage medium storing computer-executable instructions thereon, which, when executed by a processor, implement the primary device network security hardening method provided in all embodiments of the present invention.

[0118] Any combination of one or more computer-readable media may be used. A computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. A computer-readable storage medium can be, for example—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this document, a computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in connection with an instruction execution system, apparatus, or device.

[0119] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, capable of sending, propagating, or transmitting programs for use by or in connection with an instruction execution system, apparatus, or device.

[0120] The program code contained on a computer-readable medium may be transmitted using any suitable medium, including—but not limited to—wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.

[0121] Computer program code for performing the operations of this invention can be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as "C" or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0122] Finally, it should be noted that although the above embodiments have been described in the description and drawings of this invention, this should not limit the scope of patent protection of this invention. Any technical solutions that are based on the essential concept of this invention, utilize the content described in the description and drawings of this invention to make equivalent structural or procedural substitutions or modifications, as well as the direct or indirect application of the technical solutions of the above embodiments to other related technical fields, are all included within the scope of patent protection of this invention.

Claims

1. A method for network security hardening of one-time devices, characterized by, The method includes: S101. When an operation instruction is received from the master station device, determine whether the operation instruction has reached the upper limit of the corresponding number of operation instructions; if not, execute S102; if yes, execute S103. S102. The operation command is forwarded normally to the corresponding primary device; S103. If the attack traffic is suspected to be sent by an attacker, a security alarm is issued, and it is further determined whether the operation command has reached a preset multiple of the upper limit value of the corresponding operation command count; if yes, then execute S104; if no, then continue to execute S103. S104. Determine that the attack traffic was sent by the attacker and proxy the attack traffic to the power honeypot.

2. The network security hardening method for one-time devices according to claim 1, wherein, Prior to S101, the method further includes: S100. Determine the upper limit of the number of operation commands for the master station device based on the historical data of operation commands.

3. The method of claim 2, wherein, S100 includes: S1001. Obtain historical data of operation instructions from a preset number of days prior to the current date; the historical data of operation instructions is the number of operation instructions within each preset time period. S1002、according to the operation instruction history data, calculate an average value of the number of operation instructions in each preset time period per day and the standard deviation of the number of operation instructions ; S1003. Standardize the calculated standard deviation of the number of operation commands to obtain values ​​in the interval [0, 1]. ; S1004. Calculate and determine the maximum number of operation commands according to the following formula: 。 4. The method for hardening the network security of primary equipment according to claim 3, characterized in that, In step S1004, the calculated result is rounded to obtain the upper limit value of the number of operation instructions.

5. The method for hardening the network security of primary equipment according to claim 3, characterized in that, The operation instructions include power on / off control instructions, power control instructions, other parameter setting instructions, and instructions for obtaining point information.

6. The method for hardening the network security of primary equipment according to claim 1, characterized in that, Following S104, the method further includes: S105. Send a fake response to the operation command issued by the power honeypot back to the master station device.

7. The method for hardening the network security of primary equipment according to claim 6, characterized in that, Following S105, the method further includes: The method further includes: S106. Continuously record the attacker's subsequent actions to form an attack chain evidence log.

8. The method for hardening the network security of primary equipment according to claim 7, characterized in that, Following S106, the method further includes: S107. The attack chain evidence log is encrypted and uploaded to the scheduling security management center. Digital signature technology is used to solidify the integrity of the log for subsequent tracing and evidence collection.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the primary equipment network security hardening method as described in any one of claims 1-8.

10. A computer-readable storage medium having computer-executable instructions stored thereon, characterized in that, The computer-executable instructions are executed by a computer processor to implement the primary equipment network security hardening method as described in any one of claims 1-8.