Security test system and method for electric power information system
By combining a multi-layered test execution engine and a digital twin simulation platform, comprehensive and in-depth security coverage and real-time non-destructive testing of power information systems are achieved. This solves the problem of incomplete test coverage in existing technologies, improves testing efficiency and the ability to make accurate decisions in security management, and is suitable for security testing of power information systems.
Patent Information
- Application Number
- CN202511793568.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-01
- Publication Date
- 2026-03-03
AI Technical Summary
Existing power information system security testing tools lack comprehensive testing coverage and in-depth testing of power system-specific industrial control protocols and physical layer devices. Furthermore, traditional testing methods are highly invasive, inefficient, and unable to perform continuous and routine security verification under real system operation conditions. They rely on expert experience and lack intelligent analysis of test results.
By employing a multi-layered test execution engine and a digital twin simulation test platform, combined with real-time non-destructive acquisition technology, we achieve comprehensive and in-depth security coverage of the power information system. Through intelligent analysis and decision engine, we conduct automated testing and utilize machine learning to optimize test strategies, providing real-time non-destructive security testing and intelligent decision support.
It achieves comprehensive and in-depth security coverage of the power system, ensuring high continuity and availability of power production operations, improving testing efficiency and accurate decision-making capabilities for security management, enabling routine security verification during normal system operation, detecting complex attacks and providing automated remediation suggestions.
Smart Images

Figure CN121603274A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power information technology, specifically to a power information system security testing system and method. Background Technology
[0002] With the rapid development of smart grids and the energy internet, power information systems have evolved from closed, isolated dedicated networks into complex cyber-physical systems deeply integrated with cloud computing, big data, and the Internet of Things (IoT). To ensure the security and reliability of power supply, the State Grid Corporation of China and power companies at all levels attach great importance to and continuously invest in the security protection and testing of their information systems. Currently, common security testing techniques mainly include vulnerability scanning, penetration testing, and compliance checks.
[0003] Although existing power information system security testing systems have many beneficial effects, the following problems still exist: most existing testing tools are derived from the general IT field, and their testing focus is on common vulnerabilities at the network layer and application layer, while lacking in-depth testing methods for the security of power system-specific industrial control protocols, physical layer devices, and real-time / historical databases. This makes it difficult to effectively detect and verify advanced persistent threats such as control command tampering, malicious manipulation of physical devices, and falsification of operational data, creating blind spots in security protection. Meanwhile, core business systems such as power dispatching and monitoring require 24 / 7 uninterrupted operation with response latency controlled to the millisecond level. However, traditional penetration testing and vulnerability scanning activities often need to be run directly on business systems, consuming significant computing and network resources and easily leading to system performance degradation or even service interruption. Therefore, these tests are usually forced to be scheduled within very short maintenance windows, making it impossible to conduct continuous and routine security verification under real system operation conditions, greatly limiting the timeliness and authenticity of the tests. Secondly, the current testing process, from test case generation and test execution to result analysis, heavily relies on the manual operation and experience judgment of security experts. This method is not only time-consuming and costly, but also difficult to cope with the rapidly evolving threat environment. Furthermore, test results are often presented as isolated vulnerability lists, lacking intelligent correlation analysis and visualization of attack paths and overall risk posture, and failing to provide automated remediation decision support, making it difficult to support rapid response and accurate decision-making for security management personnel. Summary of the Invention
[0004] The purpose of this section is to outline some aspects of the embodiments of the present invention and to briefly describe some preferred embodiments. Simplifications or omissions may be made in this section, as well as in the abstract and title of this application, to avoid obscuring the purpose of these documents; however, such simplifications or omissions should not be construed as limiting the scope of the invention.
[0005] 1. Technical problems to be solved: To address the problems of incomplete test coverage, invasive testing process, low testing efficiency, and reliance on expert experience mentioned above, this invention is proposed.
[0006] Therefore, the purpose of this invention is to provide a security testing system and method for power information systems, which achieves comprehensive and in-depth security coverage of power information systems, significantly improves the breadth and depth of vulnerability discovery, enables real-time security testing without business disruption, ensures high continuity and high availability of power production operations, and realizes intelligent and automated testing processes, greatly improving testing efficiency and accurate decision-making capabilities for security management.
[0007] 2. Technical Solution: To address the aforementioned technical problems, according to one aspect of the present invention, the present invention provides the following technical solution: A power information system security testing system and method, comprising: a test management and scheduling platform, a multi-level test execution engine, a real-time non-destructive acquisition and monitoring module, an intelligent analysis and decision engine, a digital twin simulation test platform, and a system self-protection and resilience assessment module; The test management and scheduling platform is used to provide a human-computer interaction interface and to schedule and manage the tasks and resources of the entire test system. The multi-layer test execution engine is connected to the test management and scheduling platform and is used to perform security tests on the target power information system from the physical layer to the data layer. The real-time non-destructive acquisition and monitoring module is connected to the test management and scheduling platform and the target power information system, and is used to non-destructively acquire system operation data and monitor the safety status in real time. The intelligent analysis and decision engine is connected to the test management and scheduling platform, and is used to perform intelligent analysis and risk assessment on test data and monitoring data and provide decision support. The digital twin simulation test platform is connected to the test management and scheduling platform and is used to build and run a virtual model of the target power information system to simulate high-risk test scenarios. The system self-protection and resilience assessment module is connected to the test management and scheduling platform to ensure the safety of the test system itself and to assess the security resilience of the target power information system.
[0008] As a preferred embodiment of the power information system security testing system and method of the present invention, the test management and scheduling platform includes: The unified portal interface module provides a graphical interface for test scenario orchestration, policy distribution, and 3D visualization of results. The task scheduling engine module is used to manage the orchestration, execution, and dynamic allocation of resources for test plans; The Assets and Management module is used to automatically discover and manage hardware, software, and data assets and their dependencies in the target system. The knowledge base module is used to store and maintain a vulnerability database, attack pattern database, compliance standard database, and remediation solution database for the power industry.
[0009] As a preferred embodiment of the power information system security testing system and method of the present invention, the multi-level test execution engine includes: The protocol fuzzing module is used to construct and send malformed data packets targeting power-specific protocols to uncover vulnerabilities. The penetration attack module is used to simulate a lateral movement attack chain from information networks to control networks; The physical layer simulation test module is used to test the impact of attacks on physical devices by interacting with the hardware-in-the-loop simulation platform. The data layer security testing module is used to test the integrity and confidentiality of the database, and to simulate data tampering and injection attacks. The application layer compliance scanning module is used to automatically check the configuration compliance of the operating system, middleware, and application software.
[0010] As a preferred embodiment of the power information system security testing system and method of the present invention, the real-time non-destructive acquisition and monitoring module includes: The traffic mirroring and parsing module is used to collect network traffic non-destructively through a bypass probe and perform in-depth parsing of industrial protocols. A lightweight agent collection module is used to collect system logs, process information, and performance data on authorized hosts; The abnormal behavior detection module is used to detect abnormal operations and access behaviors in the system in real time based on rules and baseline models. The performance impact assessment module is used to monitor the key performance indicators of the target system in real time during the testing process to ensure that the impact of the test is controllable.
[0011] As a preferred embodiment of the power information system security testing system and method of the present invention, the intelligent analysis and decision engine includes: The attack chain reasoning module is used to correlate isolated security events, construct and visualize potential attack paths; The dynamic risk assessment module is used to combine real-time threat intelligence with system status to calculate and output dynamically evolving risk values; The automated repair suggestion module is used to generate specific repair instructions based on the analysis results and supports linkage with external operation and maintenance platforms. The machine learning self-evolution module is used to learn from new test data and continuously optimize the detection model and testing strategy.
[0012] As a preferred embodiment of the power information system security testing system and method of the present invention, the digital twin simulation testing platform includes: The model building module is used to automatically build a high-fidelity virtual model of the target system based on its configuration file and network topology. A scenario simulation engine is used to simulate various normal and fault operating states of a power system in a virtual model; The virtual-real interaction interface is used to enable bidirectional data import and feedback between the real system and the virtual model.
[0013] As a preferred embodiment of the power information system security testing system and method of the present invention, the system self-protection and resilience assessment module includes: The test system's self-protection module is used to implement identity authentication, access control, and communication encryption for the test system itself. The resilience index assessment module is used to quantitatively assess the critical functional recovery capability of the target system after it has been attacked during the testing process. The security posture prediction module is used to predict the system security posture under specific future attacks based on historical and current test data.
[0014] As a preferred embodiment of the power information system security testing system and method of the present invention, the method includes the following steps: S1: Initialize test tasks and configure test parameters and strategies through the test management and scheduling platform; S2: Continuously collects the operating status data of the target power information system through the real-time lossless acquisition and monitoring module; S3: Through a multi-layered test execution engine, combined with a digital twin simulation test platform, multi-layered and comprehensive security tests are performed on the target system or its virtual model. S4: Analyze the data generated in steps S2 and S3 through an intelligent analysis and decision engine to identify vulnerabilities, attack chains and assess risks; S5: Through the system self-protection and resilience assessment module, the safety of the test system is ensured throughout the process, and the safety resilience of the target system is assessed. S6: Generate a comprehensive test report containing vulnerability details, risk level, and remediation suggestions through the test management and scheduling platform.
[0015] As a preferred embodiment of the power information system security testing system and method of the present invention, step S3 specifically includes: S31: Depending on the test task, choose to perform the test on the real target system or the digital twin virtual model; S32: If a digital twin virtual model is selected, the corresponding test scenario will be loaded through the scene simulation engine; S33: The multi-layered test execution engine calls the protocol fuzzing, penetration attack, physical layer simulation test, data layer security test and compliance scanning modules sequentially or in parallel according to the test strategy to initiate tests on the selected target; S34: Records all requests, responses, and system status changes generated during the testing process in real time.
[0016] As a preferred embodiment of the power information system security testing system and method of the present invention, the step S5 of evaluating the security resilience of the target system specifically includes: S51: During testing, monitor one or more key business function metrics of the target system; S52: Simulate one or more attack events, observe and record the degradation and recovery process of the key business function indicators; S53: Based on the recorded recovery time and functional recovery integrity data, a quantitative score of the system's resilience is calculated; S54: Compare the resilience score with historical data or industry benchmarks, and output resilience assessment conclusions and improvement suggestions.
[0017] 3. Beneficial effects: Compared with the prior art, the beneficial effects of the present invention are: This power information system security testing system and method, through an integrated multi-layered test execution engine and digital twin simulation test platform, overcomes the shortcomings of the narrow testing scope of existing technologies. Specifically, it can perform in-depth analysis and fuzz testing on the physical layer devices and industrial control protocols unique to power systems, discovering underlying protocol vulnerabilities and device firmware backdoors that cannot be detected by general IT testing tools. It effectively extends the testing scope from the traditional network and application layers to the data and business layers, realizing cross-domain security verification from cyberspace to physical space. Thus, it can more effectively discover complex attacks against critical infrastructure, fundamentally solving the problem of incomplete testing coverage in existing technologies. This power information system security testing system and method, by employing non-destructive acquisition technologies such as traffic mirroring and bypass probes, can acquire system operating status and network data in real time without installing agents or interrupting services on business systems, achieving "online testing with zero impact on business." For high-risk and high-destructive test projects, they can be conducted in a digital twin virtual model that is highly consistent with the real environment, completely eliminating the risk of production system downtime or performance degradation caused by test operations. This mechanism allows security testing to be carried out routinely during normal system operation, and can capture security threats that can only be exposed in dynamic operating environments, effectively solving the problems of poor timeliness and insufficient realism caused by the high intrusiveness of existing technologies. This power information system security testing system and method, by constructing an intelligent analysis and decision engine and utilizing artificial intelligence technologies such as machine learning, can automatically generate and optimize test cases, and dynamically adjust test strategies based on system feedback, achieving adaptive testing. This significantly reduces reliance on manual configuration and expert experience. It can intelligently correlate and integrate massive amounts of isolated test results and monitoring logs, automatically construct attack chains and conduct dynamic risk assessments, elevating a single vulnerability list to an intuitive, global security situation awareness. It can automatically generate specific and actionable remediation suggestions and link them with operation and maintenance processes, providing precise decision support for security management personnel. This achieves closed-loop management from "security detection" to "security operation," effectively addressing the challenges of low automation and slow response in existing technologies. Attached Figure Description
[0018] To more clearly illustrate the technical solutions of the embodiments of the present invention, the present invention will be described in detail below with reference to the accompanying drawings and detailed embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Wherein: Figure 1 This is a schematic diagram of the power information system security testing system structure of the power information system security testing system and method of the present invention; Figure 2 This is a schematic diagram of the test management and scheduling platform structure of a power information system security testing system and method according to the present invention; Figure 3 This is a schematic diagram of the multi-level test execution engine structure of a power information system security testing system and method according to the present invention; Figure 4 This is a schematic diagram of the real-time non-destructive acquisition and monitoring module structure of a power information system security testing system and method according to the present invention. Figure 5This is a schematic diagram of the intelligent analysis and decision engine structure of a power information system security testing system and method according to the present invention; Figure 6 This is a schematic diagram of the structure of a digital twin simulation test platform for a power information system security test system and method according to the present invention; Figure 7 This is a schematic diagram of the system self-protection and resilience assessment module of the power information system security testing system and method of the present invention; Figure 8 This is a flowchart of a test method for a power information system security test system and method according to the present invention. Detailed Implementation
[0019] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0020] This invention is described in detail with reference to the schematic diagrams. When describing the embodiments of this invention, for ease of explanation, the cross-sectional views illustrating the device structure may be partially enlarged, not according to the usual scale. Furthermore, the schematic diagrams are merely examples and should not be construed as limiting the scope of protection of this invention. In actual fabrication, the three-dimensional spatial dimensions of length, width, and depth should be included.
[0021] The orientation or positional relationship indicated in the terminology is based on the orientation or positional relationship shown in the accompanying drawings and is only for the convenience of describing the invention and simplifying the description, and is not intended to indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the invention.
[0022] The term "connection method" should be interpreted broadly. For example, "connection" can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium; it can be a connection within two components. Those skilled in the art can understand the specific meaning of the above terms in this invention based on the specific circumstances.
[0023] The embodiments of the present invention will now be described in further detail with reference to the accompanying drawings.
[0024] This invention provides a schematic diagram of the overall structure of an embodiment of a security testing system and method for power information systems, comprising: Please see Figures 1-8 This embodiment of a power information system security testing system and method includes a test management and scheduling platform, a multi-level test execution engine, a real-time non-destructive acquisition and monitoring module, an intelligent analysis and decision engine, a digital twin simulation test platform, and a system self-protection and resilience assessment module. The test management and scheduling platform is used to provide a human-computer interaction interface and to schedule and manage the tasks and resources of the entire test system. The multi-layer test execution engine is connected to the test management and scheduling platform and is used to perform security tests on the target power information system from the physical layer to the data layer. The real-time non-destructive acquisition and monitoring module is connected to the test management and scheduling platform and the target power information system, and is used to non-destructively acquire system operation data and monitor the safety status in real time. The intelligent analysis and decision engine is connected to the test management and scheduling platform, and is used to perform intelligent analysis and risk assessment on test data and monitoring data and provide decision support. The digital twin simulation test platform is connected to the test management and scheduling platform and is used to build and run a virtual model of the target power information system to simulate high-risk test scenarios. The system self-protection and resilience assessment module is connected to the test management and scheduling platform to ensure the safety of the test system itself and to assess the security resilience of the target power information system.
[0025] It is worth noting that, specifically, the test management and scheduling platform includes: The unified portal interface module provides a graphical interface for test scenario orchestration, policy distribution, and 3D visualization of results. The task scheduling engine module is used to manage the orchestration, execution, and dynamic allocation of resources for test plans; The Assets and Management module is used to automatically discover and manage hardware, software, and data assets and their dependencies in the target system. The knowledge base module is used to store and maintain a vulnerability database, attack pattern database, compliance standard database, and remediation solution database for the power industry.
[0026] Next, specifically, the multi-level test execution engine includes: The protocol fuzzing module is used to construct and send malformed data packets targeting power-specific protocols to uncover vulnerabilities. The penetration attack module is used to simulate a lateral movement attack chain from information networks to control networks; The physical layer simulation test module is used to test the impact of attacks on physical devices by interacting with the hardware-in-the-loop simulation platform. The data layer security testing module is used to test the integrity and confidentiality of the database, and to simulate data tampering and injection attacks. The application layer compliance scanning module is used to automatically check the configuration compliance of the operating system, middleware, and application software.
[0027] Example 1: Fuzzy Testing of Distribution Automation System Protocol Based on Digital Twin The distribution automation system of a municipal power supply company was used as the test target. The system uses the IEC 61850 protocol for communication between the station terminals and the master station.
[0028] Implementation steps: Model building: Using the "model building module" of the digital twin platform, import the actual SCD file and network topology diagram of the power distribution automation system, and build a high-fidelity virtual system in an isolated simulation environment, including a virtual master station, a virtual communication network and multiple virtual FTUs.
[0029] Test configuration: In the test management platform, select "Protocol Fuzzing Module" and specify fuzzing test for MMS service against IEC 61850 protocol.
[0030] Test execution: The test execution engine drives the fuzz testing module to continuously send a large number of abnormal and non-compliant MMS read / write request messages to the virtual FTU. The entire process takes place in the digital twin environment and does not affect the real, running power distribution automation system at all.
[0031] Results Analysis: Monitoring the running status of the virtual FTU revealed that when a malformed message of a specific format was received, the communication service process of a virtual FTU crashed. The intelligent analysis engine then recorded this vulnerability, assessed that it might cause the FTU to "lose contact", rated the risk level as "high risk", and generated a report.
[0032] Specifically, the real-time lossless acquisition and monitoring module includes: The traffic mirroring and parsing module is used to collect network traffic non-destructively through a bypass probe and perform in-depth parsing of industrial protocols. A lightweight agent collection module is used to collect system logs, process information, and performance data on authorized hosts; The abnormal behavior detection module is used to detect abnormal operations and access behaviors in the system in real time based on rules and baseline models. The performance impact assessment module is used to monitor the key performance indicators of the target system in real time during the testing process to ensure that the impact of the test is controllable.
[0033] Furthermore, specifically, the intelligent analysis and decision-making engine includes: The attack chain reasoning module is used to correlate isolated security events, construct and visualize potential attack paths; The dynamic risk assessment module is used to combine real-time threat intelligence with system status to calculate and output dynamically evolving risk values; The automated repair suggestion module is used to generate specific repair instructions based on the analysis results and supports linkage with external operation and maintenance platforms. The machine learning self-evolution module is used to learn from new test data and continuously optimize the detection model and testing strategy.
[0034] Example 2: Real-time lossless penetration and behavior monitoring of the dispatch master station Periodic safety assessments are conducted on the provincial energy management system, which requires that no service interruption be caused by testing activities.
[0035] Implementation steps: Lossless data acquisition: Through the "Traffic Mirroring and Parsing Module", the business traffic flowing to the EMS server is copied on the core switch using the port mirroring function and sent to the test system for analysis.
[0036] Simulated Attack: The "Penetration Attack Module" simulates an attacker, launching a slow, low-speed password brute-force attack disguised as a normal user login to the EMS's web service interface. All attack traffic runs in parallel with the mirror's business traffic and does not interfere with production traffic.
[0037] Real-time monitoring and alerts: The "abnormal behavior detection module" analyzes mirror traffic in real time and detects multiple failed login requests from the same IP address within a short period of time, triggering preset abnormal rules. The alert module immediately sends a real-time alert to the Security Operations Center (SOC) platform via API.
[0038] Intelligent Association: After receiving this alert, the "Attack Chain Inference Module" of the intelligent analysis engine associates the IP's previous attempts to scan network ports, outlining a clear "reconnaissance -> brute-force attack chain" on the situational awareness screen, and prompting security personnel to block the IP.
[0039] It is worth noting that, specifically, the digital twin simulation testing platform includes: The model building module is used to automatically build a high-fidelity virtual model of the target system based on its configuration file and network topology. A scenario simulation engine is used to simulate various normal and fault operating states of a power system in a virtual model; The virtual-real interaction interface is used to enable bidirectional data import and feedback between the real system and the virtual model.
[0040] Preferably, specifically, the system self-protection and resilience assessment module includes: The test system's self-protection module is used to implement identity authentication, access control, and communication encryption for the test system itself. The resilience index assessment module is used to quantitatively assess the critical functional recovery capability of the target system after it has been attacked during the testing process. The security posture prediction module is used to predict the system security posture under specific future attacks based on historical and current test data.
[0041] Example 3: Intelligent Risk Assessment and Resilience Quantitative Analysis After a comprehensive security test, assess the overall security status and resilience of the information systems of the entire municipal power supply company.
[0042] Implementation steps: Data aggregation: The "Dynamic Risk Assessment Module" of the intelligent analysis engine aggregates all vulnerabilities discovered in this test, abnormal events detected in real-time monitoring, and lists of servers, network devices, and business applications imported from the asset management system.
[0043] Risk Calculation: This module assigns a base score to each vulnerability and, in conjunction with factors such as the importance of the asset it belongs to and the existence of exploitable attack paths, calculates a dynamic and comprehensive system risk value, which is then displayed on a topology map in the form of a heatmap.
[0044] Resilience Assessment: The "Resilience Indicator Assessment Module" selects "SCADA System Data Acquisition Service" as a key business function. In the test, a DDoS attack against the database was simulated, causing the data service to be interrupted. The module automatically recorded the time from the start of the attack to the full recovery of the service and compared it with the baseline value to calculate the "Service Recovery Delay" resilience index.
[0045] Output Recommendations: The system will ultimately generate a report clearly stating that the primary risk is a high-risk vulnerability in the SCADA server; the system's core business recovery capabilities need to be strengthened in the event of an attack; and it recommends deploying appropriate vulnerability patches and enhancing the redundancy of data services. Meanwhile, a security testing method for a power information system specifically includes the following steps: S1: Initialize test tasks and configure test parameters and strategies through the test management and scheduling platform; S2: Continuously collects the operating status data of the target power information system through the real-time lossless acquisition and monitoring module; S3: Through a multi-layered test execution engine, combined with a digital twin simulation test platform, multi-layered and comprehensive security tests are performed on the target system or its virtual model. S4: Analyze the data generated in steps S2 and S3 through an intelligent analysis and decision engine to identify vulnerabilities, attack chains and assess risks; S5: Through the system self-protection and resilience assessment module, the safety of the test system is ensured throughout the process, and the safety resilience of the target system is assessed. S6: Generate a comprehensive test report containing vulnerability details, risk level, and remediation suggestions through the test management and scheduling platform.
[0046] Secondly, specifically, step S3 includes: S31: Depending on the test task, choose to perform the test on the real target system or the digital twin virtual model; S32: If a digital twin virtual model is selected, the corresponding test scenario will be loaded through the scene simulation engine; S33: The multi-layered test execution engine calls the protocol fuzzing, penetration attack, physical layer simulation test, data layer security test and compliance scanning modules sequentially or in parallel according to the test strategy to initiate tests on the selected target; S34: Records all requests, responses, and system status changes generated during the testing process in real time.
[0047] Finally, specifically, the assessment of the security resilience of the target system in step S5 includes: S51: During testing, monitor one or more key business function metrics of the target system; S52: Simulate one or more attack events, observe and record the degradation and recovery process of the key business function indicators; S53: Based on the recorded recovery time and functional recovery integrity data, a quantitative score of the system's resilience is calculated; S54: Compare the resilience score with historical data or industry benchmarks, and output resilience assessment conclusions and improvement suggestions.
[0048] In addition, the circuits, electronic components and modules involved in this invention are all existing technologies, which can be fully implemented by those skilled in the art, and need not be elaborated upon. The content protected by this invention does not involve any improvement to the internal structure and method. Although the present invention has been described above with reference to embodiments, various modifications can be made and components can be replaced with equivalents without departing from the scope of the invention. In particular, as long as there is no structural conflict, the features in the disclosed embodiments can be combined with each other in any manner. The lack of an exhaustive description of these combinations in this specification is merely for the sake of brevity and resource conservation. Therefore, the present invention is not limited to the specific embodiments disclosed herein, but includes all technical solutions falling within the scope of the claims.
Claims
1. A security testing system for a power information system, characterized in that, This includes: a test management and scheduling platform, a multi-level test execution engine, a real-time non-destructive acquisition and monitoring module, an intelligent analysis and decision engine, a digital twin simulation test platform, and a system self-protection and resilience assessment module; The test management and scheduling platform is used to provide a human-computer interaction interface and to schedule and manage the tasks and resources of the entire test system. The multi-layer test execution engine is connected to the test management and scheduling platform and is used to perform security tests on the target power information system from the physical layer to the data layer. The real-time non-destructive acquisition and monitoring module is connected to the test management and scheduling platform and the target power information system, and is used to non-destructively acquire system operation data and monitor the safety status in real time. The intelligent analysis and decision engine is connected to the test management and scheduling platform, and is used to perform intelligent analysis and risk assessment on test data and monitoring data and provide decision support. The digital twin simulation test platform is connected to the test management and scheduling platform and is used to build and run a virtual model of the target power information system to simulate high-risk test scenarios. The system self-protection and resilience assessment module is connected to the test management and scheduling platform to ensure the safety of the test system itself and to assess the security resilience of the target power information system.
2. The power information system security testing system according to claim 1, characterized in that, The test management and scheduling platform includes: The unified portal interface module provides a graphical interface for test scenario orchestration, policy distribution, and 3D visualization of results. The task scheduling engine module is used to manage the orchestration, execution, and dynamic allocation of resources for test plans; The Assets and Management module is used to automatically discover and manage hardware, software, and data assets and their dependencies in the target system; The knowledge base module is used to store and maintain a vulnerability database, attack pattern database, compliance standard database, and remediation solution database for the power industry.
3. The power information system security testing system according to claim 1, characterized in that, The multi-level test execution engine includes: The protocol fuzzing module is used to construct and send malformed data packets targeting power-specific protocols to uncover vulnerabilities. The penetration attack module is used to simulate a lateral movement attack chain from information networks to control networks; The physical layer simulation test module is used to test the impact of attacks on physical devices by interacting with the hardware-in-the-loop simulation platform. The data layer security testing module is used to test the integrity and confidentiality of the database, and to simulate data tampering and injection attacks. The application layer compliance scanning module is used to automatically check the configuration compliance of the operating system, middleware, and application software.
4. The power information system security testing system according to claim 1, characterized in that, The real-time non-destructive acquisition and monitoring module includes: The traffic mirroring and parsing module is used to collect network traffic non-destructively through a bypass probe and perform in-depth parsing of industrial protocols. A lightweight agent collection module is used to collect system logs, process information, and performance data on authorized hosts; The abnormal behavior detection module is used to detect abnormal operations and access behaviors in the system in real time based on rules and baseline models. The performance impact assessment module is used to monitor the key performance indicators of the target system in real time during the testing process to ensure that the impact of the test is controllable.
5. The power information system security testing system according to claim 1, characterized in that, The intelligent analysis and decision-making engine includes: The attack chain reasoning module is used to correlate isolated security events, construct and visualize potential attack paths; The dynamic risk assessment module is used to combine real-time threat intelligence with system status to calculate and output dynamically evolving risk values; The automated repair suggestion module is used to generate specific repair instructions based on the analysis results and supports linkage with external operation and maintenance platforms. The machine learning self-evolution module is used to learn from new test data and continuously optimize the detection model and testing strategy.
6. The power information system security testing system according to claim 1, characterized in that, The digital twin simulation testing platform includes: The model building module is used to automatically build a high-fidelity virtual model of the target system based on its configuration file and network topology. A scenario simulation engine is used to simulate various normal and fault operating states of a power system in a virtual model; The virtual-real interaction interface is used to enable bidirectional data import and feedback between the real system and the virtual model.
7. The power information system security testing system according to claim 1, characterized in that, The system self-protection and resilience assessment module includes: The test system's self-protection module is used to implement identity authentication, access control, and communication encryption for the test system itself. The resilience index assessment module is used to quantitatively assess the critical functional recovery capability of the target system after it has been attacked during the testing process. The security posture prediction module is used to predict the system security posture under specific future attacks based on historical and current test data.
8. A method for testing the security of a power information system, based on the power information system security testing system according to any one of claims 1-7, characterized in that, Includes the following steps: S1: Initialize test tasks and configure test parameters and strategies through the test management and scheduling platform; S2: Continuously collects the operating status data of the target power information system through the real-time lossless acquisition and monitoring module; S3: Through a multi-layered test execution engine, combined with a digital twin simulation test platform, multi-layered and comprehensive security tests are performed on the target system or its virtual model. S4: Analyze the data generated in steps S2 and S3 through an intelligent analysis and decision engine to identify vulnerabilities, attack chains and assess risks; S5: Through the system self-protection and resilience assessment module, the safety of the test system is ensured throughout the process, and the safety resilience of the target system is assessed. S6: Generate a comprehensive test report containing vulnerability details, risk level, and remediation suggestions through the test management and scheduling platform.
9. The power information system security testing method according to claim 8, characterized in that, Step S3 specifically includes: S31: Depending on the test task, choose to perform the test on the real target system or the digital twin virtual model; S32: If a digital twin virtual model is selected, the corresponding test scenario will be loaded through the scene simulation engine; S33: The multi-layered test execution engine calls the protocol fuzzing, penetration attack, physical layer simulation test, data layer security test and compliance scanning modules sequentially or in parallel according to the test strategy to initiate tests on the selected target; S34: Records all requests, responses, and system status changes generated during the testing process in real time.
10. The power information system security testing method according to claim 8, characterized in that, The assessment of the security resilience of the target system in step S5 specifically includes: S51: During testing, monitor one or more key business function metrics of the target system; S52: Simulate one or more attack events, observe and record the degradation and recovery process of the key business function indicators; S53: Based on the recorded recovery time and functional recovery integrity data, a quantitative score of the system's resilience is calculated; S54: Compare the resilience score with historical data or industry benchmarks, and output resilience assessment conclusions and improvement suggestions.
Citation Information
Cited By
Method and device for optimizing control strategy of power equipment, and electronic device
CN122219110A