Method and system for evaluating and analyzing network security of transformer substation

By identifying the risk of spoofed messages in substations, and based on distributed data and similarity of network equipment, simulation targets are determined. By combining operating load variation data and virtual message identification data, the problem of reliable identification and assessment analysis of spoofed messages in substation network security is solved, improving the reliability and accuracy of the identification model.

CN121664541APending Publication Date: 2026-03-13STATE GRID HENAN ELECTRIC POWER CO FANGCHENG COUNTY POWER SUPPLY CO
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-16
Publication Date
2026-03-13

AI Technical Summary

Technical Problem

In substation network security assessment and analysis, differences in the operating status of different substations lead to differences in message data, making it difficult to effectively identify substations with significant impact from false messages and determine drill strategies. Existing technologies cannot guarantee the reliability and accuracy of identification models.

Method used

By identifying the risk of false messages in substations, and based on distributed data and similar network equipment, simulation targets are determined. By combining operating load variation data and virtual message identification data, simulation processing strategies are determined, thereby improving the reliability of the message identification model.

Benefits of technology

It enables reliable identification and assessment analysis of spoofed messages, ensuring the reliability of identification and processing in the event of cybersecurity risks and reducing the impact of spoofed messages on substations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121664541A_ABST
    Figure CN121664541A_ABST
Patent Text Reader

Abstract

The invention provides an assessment analysis method and system for transformer substation network security, and belongs to the technical field of network security. Determining a simulation target in the transformer substation except for the identified risk transformer substation, determining operation load change data of the simulation target in different dates, and identifying the risk transformer substation based on the operation load change data in the different transformer substations and the identification data of the virtual message in the identified risk transformer substation. According to the method, the simulation processing strategies of different simulation targets are determined, and the evaluation analysis method for identifying the network security of the risky transformer substation is determined based on the composition data of the simulation targets in the transformer substation and the simulation processing strategies, so that the network security in the operation process of the transformer substation is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network security technology, and in particular relates to an assessment and analysis method and system for substation network security. Background Technology

[0002] With the rapid development of smart substations, the three-layer network architecture based on the IEC 61850 standard—station control layer, bay layer, and process layer—is widely used, resulting in highly digitized and networked substation systems. This exposes them to increasingly severe cybersecurity threats, such as malicious code, unauthorized intrusion, denial-of-service attacks, and data tampering.

[0003] To address the aforementioned technical issues, the invention patent CN202510991832.2, "A Network Security Monitoring Method and System for Substation Automation Systems," utilizes a substation digital twin simulation model to perform anomaly simulation analysis on various abnormal messages, obtaining corresponding power grid threat analysis results. This enables timely and reliable detection of system anomalies, ensuring the accuracy and efficiency of identifying abnormal system messages and false tripping signals. However, the above technical solution suffers from the following technical problems: During the assessment and analysis of substation network security, the different operating states of different substations lead to differences in their message data. Therefore, substations that frequently generate messages are more affected when they are attacked by cyberattacks and receive false messages. This makes it an urgent technical problem to determine how to implement false message drills in substations based on the distribution data of substations that are more affected by false messages, and thus determine the reliability of the message recognition model.

[0004] To address the aforementioned technical issues, this application provides an assessment and analysis method and system for substation network security. Summary of the Invention

[0005] To achieve the objectives of this invention, the following technical solution is adopted: Specifically, this application provides an assessment and analysis method for substation network security, which includes: S1 uses the identification and processing results of different types of message data in the substation to determine the risk substations with false messages. Based on the distribution data of the risk substations and the similarity of network devices between the risk substations, the simulated targets in the substations other than the risk substations are determined. S3 determines the variation data of the operating load of the simulated target on different dates. Based on the variation data of the operating load in different substations and the identification data of virtual messages in risky substations, it determines the simulation processing strategy for different simulated targets. Based on the composition data of the simulated target in the substation and the simulation processing strategy, it determines the network security assessment and analysis method for identifying risky substations.

[0006] The beneficial effects of this invention are as follows: Based on the distribution data of identified high-risk substations and the similarity of network equipment among them, simulated targets in substations other than the identified high-risk substations are determined. This enables the identification of the number of high-risk substations and the degree of difference in their network equipment. The reliability of the virtual message identification model is then evaluated, and the number of virtual targets for drill processing is determined based on the verification requirements, thereby improving the reliability of the message identification model.

[0007] Based on the composition data of simulated targets in substations and the simulation processing strategy, a network security assessment and analysis method for identifying risky substations is determined. This method not only considers the differences in the reliability of message recognition model recognition processing caused by the number of virtual targets, but also the differences in the reliability of message recognition model recognition processing caused by the differences in simulation processing strategies. This enables the determination of a network security assessment and analysis method for identifying risky substations from the perspective of the reliability of message recognition model recognition processing, ensuring the reliability of identification processing when network security risks exist.

[0008] Furthermore, the type of the message data is determined based on the device that sent the message.

[0009] Furthermore, the identification and processing results of the message data are determined based on the types of messages sent from the substation on different dates.

[0010] Furthermore, the method for identifying risky substations and detecting spoofed messages in the substation is as follows: Based on the identification and processing results of different types of message data in the substation, the types of messages sent by the substation on different dates are determined. Based on the type of the sent message, determine the time period during which multiple types of messages are sent, and use this time period as the period during which false messages affect the message. Based on the distribution data of the time period affected by the false messages, it is determined whether the substation is a risk substation for identifying false messages.

[0011] Furthermore, the method for determining the network security assessment and analysis method for identifying risky substations is as follows: Based on the composition data of simulated targets in substations, the ratio of simulated targets in substations to identified risk substations is determined and used as the simulation ratio. Based on the simulation processing strategy of the simulated target, determine the number of simulated targets that adopt different simulation processing strategies; The assessment and analysis method for identifying risky substations is determined based on the simulation ratio and the number of simulated targets using different simulation processing strategies.

[0012] In a second aspect, the present invention provides a computer system comprising: a memory and a processor connected in communication, and a computer program stored in the memory and capable of running on the processor, wherein the processor executes the aforementioned assessment and analysis method for substation network security when running the computer program.

[0013] Other features and advantages will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention are realized and obtained through the structures particularly pointed out in the description and the drawings.

[0014] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description

[0015] The above and other features and advantages of the present invention will become more apparent from a detailed description of exemplary embodiments thereof with reference to the accompanying drawings.

[0016] Figure 1 This is a flowchart of an assessment and analysis method for substation network security; Figure 2 This is a flowchart illustrating the method for identifying risky substations by detecting false messages in substations. Figure 3 This is a flowchart of the method for determining the simulation processing strategy for the simulated target. Detailed Implementation

[0017] Exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, these exemplary embodiments can be implemented in many forms and should not be construed as limited to the embodiments set forth herein; rather, they are provided so that the invention will be thorough and complete, and the concept of the exemplary embodiments will be fully conveyed to those skilled in the art. The same reference numerals in the drawings denote the same or similar structures, and therefore their detailed description will be omitted.

[0018] The terms “a,” “one,” “the,” and “the” are used to indicate the existence of one or more elements / components / etc.; the terms “including” and “having” are used to indicate an open-ended meaning of inclusion and that other elements / components / etc. may exist in addition to the listed elements / components / etc.

[0019] Example 1 To solve the above problems, according to one aspect of the present invention, such as Figure 1 As shown, an assessment and analysis method for substation network security is provided, specifically including: S1 uses the identification and processing results of different types of message data in the substation to determine the risk substations with false messages. Based on the distribution data of the risk substations and the similarity of network devices between the risk substations, the simulated targets in the substations other than the risk substations are determined. S3 determines the variation data of the operating load of the simulated target on different dates. Based on the variation data of the operating load in different substations and the identification data of virtual messages in risky substations, it determines the simulation processing strategy for different simulated targets. Based on the composition data of the simulated target in the substation and the simulation processing strategy, it determines the network security assessment and analysis method for identifying risky substations.

[0020] Furthermore, the type of the message data is determined based on the device that sent the message.

[0021] Furthermore, the identification and processing results of the message data are determined based on the types of messages sent from the substation on different dates.

[0022] Specifically, such as Figure 2 As shown, the method for identifying risky substations that detect spoofed messages in the substation is as follows: S11 uses the identification and processing results of different types of message data in the substation to determine the type of messages sent by the substation on different dates; The "message data" in this step specifically refers to digital communication data frames circulating in the substation automation system that conform to international standards (such as IEC 61850). These mainly include GOOSE (General Object-Oriented Substation Event) messages, SV (Sample Value) messages, and MMS (Manufacturing Message Specification) messages. GOOSE messages are used to transmit emergency signals such as protection trips and switch positions, requiring millisecond-level delays; SV messages carry instantaneous current and voltage values ​​collected by the merging unit, enabling data sharing between protection and measurement; MMS messages are used for monitoring, configuration, and file transfer between station control layer devices. "Identification processing" of these messages refers to using deep packet inspection or protocol parsing techniques to accurately classify and extract information such as the protocol type, source / destination address, and application identifier of each message frame from network traffic. "Determining the types of messages sent on different dates" is significant in establishing a fine-grained baseline profile of communication behavior over a time series. This is not only the data foundation for subsequent anomaly detection, but also a prerequisite for understanding what kind of "health pulse" the internal communication of a substation should exhibit under different operating conditions such as normal operation, planned operation, and fault handling.

[0023] Example: Taking the "Yunling Station," a 220kV digital substation, as an example, its network recorder continuously captures the station's traffic. The analysis system processes data from the past 30 days daily: on typical non-operational workdays, the system identifies approximately 95% of the daily messages sent by the station as MMS (used for SCADA telemetry and remote signaling), approximately 4.5% as SV (used for metering and protection), and less than 0.5% as GOOSE messages. These GOOSE messages all correspond to recorded equipment periodic self-checks or harmless status changes. On specific dates, such as May 10th, during bus switching operations, the system identifies a sharp increase in the proportion of GOOSE messages (status switching commands) to 15% within five minutes from 09:30 to 09:35, along with slight fluctuations in the SV message flow and a corresponding decrease in the proportion of MMS messages. This change in type distribution perfectly matches the operation records in the dispatch log, thus verifying the accuracy of the type identification results and labeling each date with communication mode tags such as "normal workday" or "planned operation day."

[0024] S12 determines the time period for sending multiple types of messages based on the type of the sent messages, and uses this time period as the period of influence of false messages; "The period during which multiple types of messages are sent" does not refer to the simultaneous existence of different types of messages, but rather to a short time window (e.g., 1 minute) during which various types of messages, which should follow a strict sequence or be isolated by scenario, are sent concurrently or interleaved at a high frequency with no business logic connection. For example, under conditions of no faults and no operation, protection tripping GOOSE messages, high-refresh SV sampling messages, and background query MMS messages, which should be silent, simultaneously burst at a rate close to the network bandwidth limit. "The period affected by false messages" refers to this type of identified abnormal period. Its technical significance lies in the fact that it is a quantitative indicator of "communication noise" or "system disorder" within the power grid. The existence of such periods often indicates that the substation network has flooded, equipment has abnormally repeated packet transmission, or the clock system has lost synchronization, resulting in message timing disorder, creating an ideal "noise mask" for the injection and concealment of external false messages.

[0025] Example: Continuing the analysis of the "Yunling Station" data, on July 15th, the system detected two abnormal periods. The first period was from 02:17 to 02:19 AM. The algorithm found that within these two minutes, the proportions of GOOSE, SV, and MMS packets in network traffic reached an alarming 40%, 35%, and 25%, respectively, with chaotic sending intervals. The destination addresses of the GOOSE packets were scattered, pointing to multiple smart terminals that should not have been operating simultaneously. Investigation revealed no scheduling instructions or fault recordings during this period. The second period was from 14:05 to 14:08 PM, exhibiting similar characteristics. The system automatically labeled these two periods as "Spurious Packet Impact Period One" and "Period Two," recording their precise start and end times, the main packet types involved, and peak traffic. Crucially, these periods differ fundamentally from normal protection actions or remote control operation periods in their message sequence patterns: during normal operations, the message flow follows an ordered process of "triggering GOOSE -> related SV mutation -> MMS uploading event"; while during abnormal periods, various messages are a chaotic mess with no causal relationship.

[0026] S13 determines whether the substation is a risk substation for identifying false messages based on the distribution data of the time period affected by the false messages.

[0027] "Distributed data" is a key concept here, primarily referring to the divergent nature of the "periods affected by false messages" over time. The core indicator is the number of independent dates within the analysis period where such abnormal periods occurred. The determination of "identifying risky substations" is based on the breadth of this date distribution, rather than the total duration of the abnormal periods. The underlying security logic is: occasional anomalies may be due to transient external interference, which is easy to investigate and the risks are controllable; however, if anomalies recur on different dates like a "chronic disease," it indicates that there is a persistently active "lesion" in the substation—this could be a firmware defect in a piece of equipment, a buffer overflow problem in a network switch, or a periodic loss of lock on the GPS clock interface. This lesion continuously generates internal communication noise, causing the intrusion detection system within the substation to be constantly in a high-background-noise environment, forcing its detection threshold to be increased and its sensitivity to decrease. At this point, if a carefully disguised fake message (such as a malicious trip command with a perfectly compliant format) is injected by an external attacker, it is very easy for the system to misjudge it as another "internal noise" and ignore it, or to adopt a conservative strategy to avoid "misoperation" in a noisy environment and not to intercept it, thus causing the real attack command to be executed.

[0028] Example: A comprehensive analysis of 30 days of data from the Yunling Substation was conducted. System statistics revealed that "spurious message impact periods," similar to July 15th, occurred on 12 different dates, totaling 18 independent periods. Based on pre-set security policies (e.g., a risk threshold of "more than 2 days of abnormal periods within 30 days"), the Yunling Substation (12 days > 2 days) was officially marked by the system as a "substation at risk of spurious message identification."

[0029] It should be noted that the distribution data of the time period affected by the false messages includes the dates of the time period during which the false messages occurred.

[0030] It is understandable that, based on the distribution data of the time periods affected by the false messages, determining whether the substation is a risk substation for identifying false messages specifically includes: When the number of dates affected by false messages at the substation does not meet the requirements, any deviation in the identification of false messages will inevitably lead to the substation generating erroneous trip signals, making it difficult for the substation's operational stability to meet the requirements.

[0031] Specifically, the method for determining the simulated target in the substation is as follows: S31 Based on the distribution data of the identified risk substations, determine the proportion of the number of identified risk substations in the substations, and use it as the proportion of risk substations. Step 1: Definition and Technical Significance: "Risk Substation Percentage" refers to the proportion of "false message-identified risk substations" identified by the aforementioned methods within a specific regional power grid or management cluster, out of the total number of substations in that region. This percentage is a macro-level risk density indicator. Its significance lies in reflecting the degree of deterioration in the overall health of the regional power grid's communication network. A high percentage indicates a widespread distribution of risk points, potentially pointing to common regional problems, such as a common defect in a batch of deployed equipment of a certain model, or systemic flaws in the regional network architecture design. In this case, the focus of security defense should shift from repairing individual sites to adjusting regional strategies.

[0032] Example: Suppose that within the jurisdiction of a regional dispatch center under a provincial power grid, there are 50 digital substations with voltage levels of 110kV and above. Using the aforementioned message analysis method, 8 of these substations were identified as "risk substations" due to frequent occurrences of abnormal mixed message periods. Based on this, the percentage of risk substations in this area is calculated to be 8 / 50 = 16%. This value will be used for subsequent decision tree analysis.

[0033] S32 determines the similarity coefficient of the network equipment between the identified risk substations based on the similarity of the network equipment between the identified risk substations; Step Two: Determine the network equipment similarity coefficient between risky substations. "Network equipment" here specifically refers to the hardware devices that constitute the core of the substation's communication network, mainly including station control layer switches, process layer switches, industrial firewalls, vertical encryption devices, and communication modules of intelligent electronic devices such as protection / monitoring and control systems. The "similarity coefficient" is a quantitative indicator used to measure the degree of consistency in model, brand, and even firmware version of these key network devices used between any two risky substations. The calculation method is to count the number of network devices of the same model between the two substations, and then divide it by the total number of network devices in the other substation used as a reference (or use other normalization methods), obtaining a ratio between 0 and 1. Its core significance lies in discovering the common root causes of risk. If multiple risky substations exhibit high equipment similarity, it strongly suggests that the risk may stem from inherent vulnerabilities in that specific model of equipment or defects in the configuration template. Conversely, if the equipment models of the risky substations are different, the causes of the risk may be more dispersed and independent.

[0034] Example: Taking "Site A" and "Site B" from the aforementioned eight high-risk substations as examples, a similarity analysis is performed. Site A's core network equipment list includes: 3 S6720 switches (Brand X), 1 FG-100D firewall (Brand Y), and 5 PCS-985 protection devices (Brand Z). Site B's list includes: 4 S6720 switches (Brand X), 1 FG-100D firewall (Brand Y), and 6 PCS-982 protection devices (Brand Z). The two sites share the same S6720 switches and FG-100D firewalls. Assuming Site A is the baseline, its total network equipment is 3 + 1 + 5 = 9 devices, of which 3 (switches) + 1 (firewall) = 4 devices are identical to those in Site B. Therefore, the similarity coefficient between Site A and Site B is approximately 4 / 9 ≈ 0.44. Similarly, the pairwise similarity coefficient matrix between all high-risk substations can be calculated.

[0035] S33 determines the simulated targets in the substations based on the proportion of risky substations and the similarity coefficient of network equipment between the identified risky substations.

[0036] It should be noted that the similarity coefficient of the network equipment between the identified risk substation and other identified risk substations is determined based on the proportion of the number of network equipment of the same model between the identified risk substation and other identified risk substations in the number of network equipment in the other identified risk substations.

[0037] Step 3: Based on the proportion and similarity coefficient, determine the simulation targets. "Simulation targets" refer to normal substations within the regional power grid that are not marked as high-risk substations but need to be selected for "stress testing" or "attack simulation exercises." The purpose of selecting them is to verify whether the current power grid's defense system is equally effective against "seemingly normal" sites when facing known risk patterns (observed at high-risk substations), i.e., to test the coverage and universality of the defense. The logic for determining simulation targets is a multi-level decision tree, the core principle of which is to intelligently determine the scope and targeting of the test based on the overall risk situation (proportion) and the concentration of risk sources (similarity coefficient).

[0038] It should be noted that in the above steps, if the proportion of risky substations is greater than the preset substation proportion threshold, then all substations except for those identified as risky substations are determined to be simulation targets.

[0039] Additionally, it can be understood that if the proportion of risky substations is not greater than a preset substation proportion threshold, the number of identified risky substations is obtained. If the number of identified risky substations is less than a preset risky substation number threshold, a preset scheme is used to determine the simulated targets in the substations.

[0040] Furthermore, if the number of identified risky substations is not less than a preset risky substation number threshold, then the similarity coefficient of the network devices between the identified risky substations is determined. When the similarity coefficient of the network devices between different identified risky substations is less than the preset similarity coefficient threshold, then all substations except the identified risky substations are determined to be simulation targets.

[0041] Additionally, it can be understood that if the similarity coefficients of network devices between different risk-identifying substations are not all less than a preset similarity coefficient threshold, the average similarity coefficient of the risk-identifying substation is determined based on the average similarity coefficients of the network devices between the risk-identifying substation and other risk-identifying substations. When the average similarity coefficients of different risk-identifying substations are all less than the preset similarity threshold, then all substations except the risk-identifying substations are determined to be simulated targets.

[0042] Furthermore, if the average similarity coefficients of different risk-identifying substations are not all less than a preset similarity coefficient threshold, then a second preset scheme is used to determine the simulated target in the substation.

[0043] It should be noted that the preset scheme uses the number of identified risk substations as the number of simulated targets based on a preset multiple, uses the average similarity coefficient between different identified risk substations as the reference similarity coefficient, and uses the substation with the largest reference similarity coefficient, excluding the identified risk substations, as the simulated targets.

[0044] Furthermore, the second preset scheme uses the number of identified risk substations as the number of simulation targets based on the second preset multiple, takes the average similarity coefficient between different identified risk substations as the reference similarity coefficient, and takes the substations with the largest reference similarity coefficient, excluding the identified risk substations, as the simulation targets.

[0045] Several key decision thresholds are set: the preset substation ratio threshold T_ratio = 20%, the preset risk substation number threshold T_num = 5, the preset similarity coefficient threshold T_sim = 0.6, the preset multiple M1 = 1, and the second preset multiple M2 = 2.

[0046] Example 1: Wide range of risks, comprehensive testing, conditions: the proportion of risky substations (16%) is not greater than T_ratio (20%), but the number of risky substations (8) is not less than T_num (5). Proceed to similarity analysis.

[0047] Analysis: Calculations revealed that the similarity coefficients between all eight risky substations were not all less than T_sim (0.6). Among them, the coefficients between stations A, C, D, and F were all greater than 0.7, showing a strong correlation; the remaining stations had low similarity to other stations.

[0048] Calculate the average similarity coefficient: Taking station A as an example, calculate the average similarity coefficient between it and the other 7 stations, assuming it to be 0.65. Similarly, calculate the average similarity coefficient for the other stations. It is found that the average coefficient for stations A, C, D, and F is greater than 0.6, while the average coefficient for the remaining stations is less than 0.6.

[0049] Decision: Since the average similarity coefficient of different risk substations is not all less than the threshold (there are four stations A, C, D and F with a similarity coefficient greater than 0.6), the condition of "not all less than" is met, and the second preset scheme is triggered.

[0050] The second preset scheme is implemented as follows: Determine the number of simulation targets: Quantity = Number of risk stations (8) × Second preset multiple (M2=2) = 16. Calculate the reference similarity coefficient: For the remaining 42 (50-8) normal substations, calculate the average similarity coefficient between each substation and all risk substations. For example, for normal substation G, calculate the average of its similarity coefficients with the 8 risk substations A, B, ..., H to obtain its "reference similarity coefficient" Ref_sim_G.

[0051] Target selection: Sort all normal stations by Ref_sim from largest to smallest, and select the top 16. This ensures that the selected simulation targets are normal stations that are most similar to known risky stations in terms of network equipment configuration, making the test most targeted and aiming to verify whether those normal stations that "look" like risky stations also harbor the same vulnerabilities.

[0052] It is understood that the preset multiple is less than the second preset multiple.

[0053] Example 2 (Comparison): Isolated Risks, Random Sampling, Changed Assumptions: If the similarity coefficients between all pairs of the aforementioned 8 risky substations are less than 0.6, and the average similarity coefficient is also less than 0.6, the decision is: This indicates that the identified risks are isolated and have different causes. In this case, the defense system needs to test its universality. Therefore, the decision is to determine that all substations (42 in total) excluding the risky substations are included in the simulation targets, thereby improving the reliability of the simulation exercise.

[0054] Specifically, the variation data of the operating load of the simulated target is determined based on the deviation of the transport load of the simulated target between different adjacent dates.

[0055] Specifically, such as Figure 3 As shown, the method for determining the simulation processing strategy of the simulated target is as follows: S31 determines the deviation rate of the transport load of the simulated target between different adjacent dates based on the variation data of the operating load of the simulated target, and determines the load variation rate based on the average value of the deviation rate of the transport load. Step 1: Determine the load variation rate of the simulation target. "Operating load variation data" refers to the sequence of active power (unit: megawatts) of the substation's main transformer or outgoing lines changing over time. "Transmission load deviation rate" is a dimensionless relative change indicator. It is calculated by taking the maximum daily transmission load of two adjacent days (e.g., yesterday and today), calculating the absolute value of the difference, and then dividing it by the load value of one of those days (usually the following day). This eliminates the base effect of substations of different sizes, purely reflecting the severity of fluctuations. The "load variation rate" is the arithmetic mean of multiple such deviation rates for adjacent days, used to characterize the overall stability of the substation's load fluctuations over a period of time. Its technical significance lies in the fact that drastic load fluctuations often correspond to adjustments in grid operation modes, drastic fluctuations in renewable energy power, or the switching on / off of large users. During these periods, the electrical stress and control logic of the grid are more complex, which means that problems in the virtual simulation could have a significant impact, requiring greater caution.

[0056] Example: Taking the "Linhai Wind Farm Collection Station" selected as the simulation target as an example, we analyzed its maximum daily power output (unit: MW) records for the past 5 consecutive working days: Monday 210, Tuesday 185, Wednesday 245, Thursday 95 (due to planned maintenance of the wind farm), Friday 230.

[0057] Calculate the deviation rate between adjacent days: Tuesday relative to Monday: |185-210| / 185 = 25 / 185 ≈ 13.5%; Wednesday relative to Tuesday: |245-185| / 245 = 60 / 245 ≈ 24.5%; Thursday relative to Wednesday: |95-245| / 95 = 150 / 95 ≈ 157.9%; Friday relative to Thursday: |230-95| / 230 = 135 / 230 ≈ 58.7%. Calculate the load variation rate = (13.5% + 24.5% + 157.9% + 58.7%) / 4 = 254.6% / 4 = 63.65%.

[0058] This high rate of change of 63.65% clearly indicates that the station is a node that is greatly affected by wind resources and has an extremely unstable operating status. Its monitoring system and protection equipment need to frequently cope with the drastic changes in power flow.

[0059] S32 determines the average daily number of virtual messages identified in different risk-identifying substations based on the identification data of the virtual messages in the identified risk-identifying substations; Step Two: Determine the average daily number of virtual packet identifications for risky substations. "Virtual packet identification data" refers to the number of suspected fraudulent or malicious packets actively identified and alerted by the intrusion detection system or abnormal packet analysis module deployed within a site that was previously marked as a "risky substation" within a certain period. Here, "virtual packet" is used broadly, including all suspicious packets judged by the rule engine or AI model as having abnormal format, timing errors, source address spoofing, or violating business logic. The "average daily number of identifications" is the daily average of this number within the statistical period. This metric has a dual significance: First, it quantifies the activity level of the real network threats faced by the risky substation, thus reflecting the identification strength of the packet identification model and indicating the reliability of the packet identification model's verification processing in identifying risky substations.

[0060] Example: Continuing with the previous case, let's assume the number of virtual message identifications for the eight high-risk substations over the past seven days is as follows (times / day): Station A: 12, Station B: 3, Station C: 25, Station D: 8, Station E: 2, Station F: 18, Station G: 5, Station H: 4. Calculate their average daily recognition frequency: Station A: approximately 1.7 times / day, Station C: approximately 3.6 times / day, Station F: approximately 2.6 times / day, and the remaining stations are all less than 1 time / day.

[0061] The system sets a preset threshold for the number of identifications, for example, T_detect = 2 times / day. Therefore, the substations with a daily average number of identifications exceeding this threshold are: Substation A, Substation C, and Substation F, a total of 3 substations.

[0062] S33 determines the simulation processing strategy for the simulated target based on the average daily number of virtual message identifications in different risk-identifying substations and the load variation rate of each simulated target.

[0063] It should be noted that the deviation of the transport load between adjacent dates is determined by the ratio of the absolute value of the difference between the transport load of the date and the previous date to the transport load of the date.

[0064] The following decision thresholds are retained and supplemented: the preset substation ratio threshold T_ratio = 20%, the preset risk substation number threshold (referring to the number of high-threat substations) T_num_high_threat = 2, the preset change rate threshold T_variance = 30%, and the preset runtime threshold T_stable_hours = 6 (hours).

[0065] It is understood that the simulation processing strategy for the simulated targets is determined based on the average daily number of virtual message identifications in different risk-identifying substations and the load variation rate of each simulated target. Specifically, this includes: Case 1: If the proportion of risky substations is greater than the preset substation proportion threshold, then the simulation processing strategy for the virtual target is determined to be to perform simulation processing within the target load range, that is, to send virtual messages through drill processing to determine that the message recognition model can reliably recognize and process them.

[0066] Scenario 2: If the proportion of risky substations is not greater than the preset substation proportion threshold, then based on the average daily number of identifications of virtual messages in different risky substations, if it is determined that there are no risky substations with an average daily number of identifications greater than the preset identification number threshold, then the simulation processing strategy for the virtual target is to perform simulation processing within the target load range, that is, to send virtual messages through drill processing to determine that the message identification model can reliably identify and process them.

[0067] Scenario 3: If there are substations with a daily average number of identifications exceeding a preset identification threshold, then the number of substations with a daily average number of identifications exceeding the preset identification threshold is obtained. If the number of substations with a daily average number of identifications exceeding the preset identification threshold is not greater than the preset threshold for the number of substations with a risk, then the simulation processing strategy for the virtual target is determined to be to perform simulation processing within the target load range, that is, to send virtual messages through drill processing to determine that the message identification model can reliably identify and process them.

[0068] Scenario 4: If the number of identified risk substations is greater than the preset threshold for the number of identifications per day, and the average load change rate of different simulated targets is greater than the preset threshold for the number of risk substations, then the simulation processing strategy for the virtual target is determined to be to perform simulation processing within the target load range. That is, virtual messages are sent through drill processing to determine that the message identification model can reliably identify and process the messages.

[0069] Case 5: If the average load change rate of different simulated targets is not greater than the preset change rate threshold, then the simulation processing strategy of the simulated target is determined according to the load change rate of the simulated target.

[0070] In one embodiment: Given: Risk substation percentage = 16% (not greater than T_ratio 20%), Given: There are 3 risk substations with a daily average number of identifications greater than T_detect (2 times / day). Check: The number of high-threat substations (3) is greater than T_num_high_threat (2). Proceed to situation 4 for judgment. Calculate: The average load variation rate of all simulated targets (assuming 16 substations). Assume that the average load variation rate of these 16 substations is 25% as calculated.

[0071] Judgment: The average rate of change (25%) is not greater than T_variance (30%). Proceed to Case 5.

[0072] Scenario 5 Decision: In this case, the strategy needs to be customized based on the load variation rate of each simulated target.

[0073] It is understood that when the load variation rate of the simulated target is greater than the preset variation rate threshold, the simulation processing strategy of the virtual target is determined to be that when the runtime of the virtual target in the target load range is greater than the preset runtime threshold, simulation processing is performed in the target load range, that is, virtual messages are sent through drill processing to determine that the message recognition model can reliably recognize and process them.

[0074] Furthermore, if the load variation rate of the simulated target is not greater than a preset variation rate threshold, then the simulation processing strategy of the virtual target is determined to be the basic processing strategy, that is, simulation processing is performed within the target load range, that is, virtual messages are sent through drill processing to determine that the message recognition model can reliably recognize and process them.

[0075] Simulated target X: "Coastal wind farm aggregation station", its own load variation rate = 63.65%, judgment: 63.65% is greater than T_variance (30%).

[0076] Strategy: Adopt a "test after stabilization" strategy. That is, after the substation enters a lower target load range (e.g., the maximum value at the endpoint of the load range is less than 50% of the maximum value at the endpoint of the historical transmission load range of the substation), it will continue to operate stably for more than 2 hours (T_stable_hours) before a simulated attack test is initiated.

[0077] Drastic load fluctuations are common at wind farms, placing their monitoring and protection systems under high stress and constant adaptive adjustment during these periods. Injecting attack packets during this time, especially under high load conditions, can inevitably lead to a significant impact on the substation's operational scope. Conducting tests during a rare, long period of stable operation ensures a smaller impact on the substation and avoids unnecessary interference or even false triggering of systems already operating under complex conditions.

[0078] Simulated target Y: "Chengbei Industrial Zone Hub Station", its own load variation rate = 15% (industrial load, fluctuating regularly day and night but with small amplitude). Judgment: 15% is not greater than T_variance (30%).

[0079] Strategy: Adopt a "basic processing strategy", that is, arrange simulated attack tests throughout the entire preset target load range (e.g., the maximum value at the endpoint of the load range is less than 50% of the maximum value at the endpoint of the historical transmission load range of the substation).

[0080] The station operates smoothly with low background noise. Conducting comprehensive and undifferentiated stress tests on it can reduce the impact range in the event of anomalies.

[0081] Specifically, the method for determining the network security assessment and analysis method for identifying risky substations is as follows: Based on the composition data of simulated targets in substations, the ratio of simulated targets in substations to identified risk substations is determined and used as the simulation ratio. Step 1: Calculate the simulation ratio and statistically analyze the simulation strategy distribution. The simulation ratio is the ratio of the number of selected "simulated target" substations to the number of previously identified "risk substations." This ratio measures the coverage of the test scope relative to the known risk baseline. A higher simulation ratio (e.g., >1) means that the defense exercise has a broader testing scope and more thorough testing of normal sites; a lower ratio means that testing resources are concentrated or the testing scope is limited.

[0082] The number of simulated targets employing different simulation processing strategies: This quantifies the depth and granularity of the simulation testing. As mentioned earlier, the "basic processing strategy" represents comprehensive and universal testing, while "stabilization testing strategies," etc., represent precise testing for specific operating conditions. Statistical analysis of the number of targets using each strategy reflects the complexity of this exercise plan and its tendency to cover different risk scenarios.

[0083] Example: Following on from the previous case, we already know: Number of risky substations identified: N_risk = 8.

[0084] Number of simulated target substations: N_sim = 16 (selected by the second preset scheme).

[0085] The simulation processing strategies for the simulated targets are distributed as follows: Among the 16 simulated targets, it is assumed that 12 targets adopted the "basic processing strategy" because their load variation rate is not high; the other 4 targets (such as the "coastal wind farm aggregation station") adopted the "post-stabilization test strategy" because their load variation rate is greater than the threshold.

[0086] Therefore, the simulation ratio is calculated as follows: N_sim / N_risk = 16 / 8 = 2.0. The strategy statistics are as follows: the number of simulated targets using the basic processing strategy is N_basic = 12; the number of simulated targets using a strategy other than the basic processing strategy is N_other = 4.

[0087] Based on the simulation processing strategy of the simulated target, determine the number of simulated targets that adopt different simulation processing strategies; The assessment and analysis method for identifying risky substations is determined based on the simulation ratio and the number of simulated targets using different simulation processing strategies.

[0088] Specifically, the decision-making logic for determining the assessment and analysis methods involves assessing and analyzing the cybersecurity of risky substations. Here, "assessment and analysis" refers to a more aggressive and direct verification method: conducting controlled and cautious cyberattack simulations ("exercise processing") directly in the real production environment of substations marked as high-risk (identified risky substations) to actually test the real effectiveness and current status of their defense systems. This differs from "preventive" testing on simulated targets; rather, it is "diagnostic" stress testing of known problem areas.

[0089] "Testing is only necessary when the message recognition model has identification bias": This is a risk-based triggering mechanism. Its core idea is: if extensive testing on normal sites (simulated targets) proves the current defense model (message recognition model) works perfectly, then the defense system can be temporarily considered effective overall, and there's no need to immediately conduct direct testing on high-risk sites that might affect their operation. Conversely, if blind spots or misjudgments (identification biases) are found in testing on normal sites, it indicates undiscovered vulnerabilities in the defense system. In this case, direct testing on high-risk sites must be conducted to confirm whether these vulnerabilities have been exploited in a high-risk environment or could cause more serious consequences.

[0090] Identification Matching Factor: This is a composite indicator that integrates the breadth of test coverage (simulation ratio) and the depth of test foundation (basic strategy proportion). It quantifies the sufficiency and representativeness of the "stress tests" conducted on the simulated targets in the early stages. The higher the factor value, the more comprehensive and realistic the early tests were, and the higher the confidence level of the test results (whether the model is reliable). Therefore, it is more reliable as a basis for deciding whether to conduct cybersecurity risk assessment and analysis on high-risk sites.

[0091] It is understood that, based on the simulation ratio and the number of simulated targets employing different simulation processing strategies, the assessment and analysis method for identifying risky substations is determined, specifically including: Determine whether the simulated ratio is greater than the preset simulated ratio threshold. If so, the network security assessment and analysis of the risk substation is only required when the message recognition model has a recognition deviation, i.e., it fails to accurately identify false messages. In other words, the exercise is carried out in the risk substation to determine the network security assessment and analysis result of the risk substation. If not, proceed to the next step. Determine whether the number of simulated targets is less than the number of identified risky substations. If so, determine the network security assessment and analysis method for the substation based on the identification data of false messages in the substation. If not, proceed to the next step. Based on the number of simulated targets using different simulation processing strategies, determine the number of simulated targets using the basic processing strategy. Determine whether the number of simulated targets using the basic processing strategy is less than the number of identified risk substations. If yes, proceed to the next step. If no, network security assessment and analysis of the identified risk substations is only required when the message identification model has identification bias, i.e., it fails to accurately identify false messages. In other words, an exercise is conducted in the identified risk substations to determine the network security assessment and analysis results of the identified risk substations. Based on the proportion of simulated targets using the basic processing strategy to the total number of simulated targets, and the simulated ratio, an identification matching factor is determined, and an assessment and analysis method for network security in the identified risk substation is determined based on the identification matching factor.

[0092] Furthermore, when the identification matching factor is greater than the preset matching factor threshold, the network security assessment and analysis of the risky substation is only required when the message identification model has an identification bias, i.e., it fails to accurately identify false messages. In other words, the network security assessment and analysis results of the risky substation are determined by conducting a drill in the risky substation. If the identification matching factor is not greater than the preset matching factor threshold, the network security assessment and analysis method of the substation is determined based on the identification data of false messages in the substation.

[0093] Overall decision-making logic and implementation example deduction: Setting decision thresholds: The preset simulation ratio threshold T_sim_ratio = 1.5, and the preset matching factor threshold T_match_factor = 0.3; Substituting the data from the example: First step judgment: Simulation ratio = 2.0, which is greater than T_sim_ratio (1.5), decision: enter the path "Only when there is a recognition deviation in the message recognition model is it necessary to perform...".

[0094] Because the test coverage is extensive (the simulation target is twice the number of risky sites), we have high confidence in the model's performance evaluation on normal sites. We only consider it necessary to risk direct testing on high-risk sites if this extensive testing reveals problems with the model. If the model performs well in the extensive testing, direct testing on high-risk sites can be postponed, and other hardening measures can be prioritized.

[0095] Assuming the scenario changes: if the simulation ratio = 1.0 (equal to the number of risk stations), then proceed to the next step of judgment.

[0096] The second step is to determine if the number of simulated targets (16) is not less than the number of risk stations (16). Proceed to the next step.

[0097] The third step is to determine: the number of simulated targets using the basic processing strategy, N_basic = 12, is less than the number of risk stations, N_risk = 16.

[0098] Calculate the matching factor (example formula): Assume the factor calculation formula is: Identification matching factor = (N_basic / N_sim) (simulated ratio / 2). Where (N_basic / N_sim) represents the purity of the basic test, and (simulated ratio / 2) is a normalization process (because the previous ratio threshold was 1.5, dividing it by 2 makes it fall to about 0.75, which is convenient for comparison with the threshold of 0.7).

[0099] Substitute the data: (12 / 16) (1 / 2) = 0.75 0.5 = 0.325, judgment: 0.325 is greater than T_match_factor (0.3). Decision: still enter the path of "only when there is a recognition bias in the message recognition model is it necessary to perform...".

[0100] Only when all the above "buffer" criteria are not met, namely: insufficient coverage of simulation tests (low ratio), and few sites tested comprehensively (low proportion of basic strategies), resulting in a low comprehensive identification and matching factor (≤0.3), will the system decide not to wait for the results of simulation tests and directly trigger the assessment based on the current status of the risk site.

[0101] Furthermore, based on the identification data of spoofed messages in the substation, an assessment and analysis method for network security in the substation is determined, specifically including: If no virtual message identification result is found for the identified risk substation within the most recent preset time period, then the network security assessment and analysis of the identified risk substation will be performed.

[0102] When sufficient simulation testing cannot be used to indirectly determine the risk, the system will revert to the most direct monitoring indicator—the substation's own "spoof (virtual) message identification data." Here, "identification results" refers to whether the substation's internal defense system has recently issued alerts for suspicious attacks.

[0103] Example: Suppose that under a certain decision path, the final determination requires "to determine the evaluation and analysis method based on the identification data of false messages in the substation".

[0104] We examined the virtual message identification logs of eight high-risk substations within the most recent preset time period (e.g., the past two weeks).

[0105] Scenario A: The inspection revealed that 5 out of the 8 stations had at least one virtual message identification alarm record (i.e., "identification result exists") in the past 2 weeks.

[0106] The system believes that a drill should be conducted at risk substations where no identification data for spoofed messages exists to determine whether it can accurately identify false messages.

[0107] Core objective: To construct a message identification model capable of identifying spoofed messages in power system networks (especially substation process and control layers) in real time. This model needs to distinguish between three types of messages: 1) normal business messages; 2) "background noise" messages generated due to equipment malfunctions or configuration errors; and 3) "spoofed attack messages" injected by malicious attackers.

[0108] Application scenario: The model is deployed on the monitoring host or network probe of the substation to analyze network mirror traffic online, classify and assess the risks of each packet or packet sequence in real time, and issue alarms to the operation and maintenance personnel.

[0109] Multi-source data acquisition: Network traffic mirroring: Collect all GOOSE, SV, and MMS packets from the mirror ports of the station control layer and process layer switches. Record the complete frame content (including Layer 2 header) and precise timestamps (nanosecond level).

[0110] Business status synchronization: Obtain switch position, protection pressure plate status, and power flow data from the SCADA system; obtain transient event records from the fault recorder.

[0111] Equipment asset information: Import the full-site system configuration description file (SCD) to obtain the logical address, application identifier, dataset definition and other legal configuration information of all intelligent electronic devices.

[0112] Data preprocessing and feature engineering: Message parsing and field extraction: Strictly following IEC 61850, IEC 62439 (PRP / HSR) and other protocol specifications, each message is parsed, key fields are extracted, and a structured log is formed. Key fields include: Common fields: source / destination MAC / IP, APPID, message type, length, arrival time interval.

[0113] GOOSE-specific fields: GoCBRef, StNum, SqNum, status number, and boolean / integer values ​​for all datasets.

[0114] SV-specific fields: SvID, sample count, sample value array, synchronization flag.

[0115] Temporal feature construction: Single device behavior: Calculate the periodic stability of sending the same type of packets from the same source address (such as the increasing pattern of StNum in GOOSE packets, the cyclical pattern of SqNum, and the sampling rate stability of SV packets).

[0116] Cross-device correlation: Calculate the action logic delay of key signals (for example, the time from the protection start GOOSE to the corresponding circuit breaker trip GOOSE should be within a reasonable range).

[0117] Contextual feature construction: Business logic features: Based on the SCADA status, determine whether the current message content contradicts the real-time operating status of the power grid (for example, the switch is actually in the open position, but a remote control message for "closing" is received).

[0118] Configure compliance features: Compare whether the source address, APPID, and dataset structure of the message match the valid configuration in the SCD file.

[0119] This model adopts a three-layer cascaded architecture of "rule filtering + unsupervised anomaly detection + supervised classification" to achieve progressive analysis from rapid interception to fine discrimination.

[0120] First layer: Real-time rule filtering engine (whitelist / blacklist basic defense), technical implementation: based on a high-performance rule matching engine (such as Hyperscan accelerated by DPDK).

[0121] Rule base: Static whitelist: Based on the SCD file, a MAC-APPID mapping table for legitimate devices is generated. Packets with source addresses not in this table are directly intercepted and alerted.

[0122] Dynamic blacklist: a database of known attack signatures (such as hash values ​​of specific malware payloads and illegal function codes).

[0123] Syntax rules: Check the validity of basic fields such as message length, CRC, and protocol version.

[0124] Output: Quickly filters out forged and erroneous messages at the lowest level, reducing the computational burden on the backend.

[0125] Second layer: Unsupervised temporal anomaly detection model (identifying unknown threats and internal disorder), technology selection: adopting autoencoder or isolated forest model.

[0126] Input features: mainly time-series features, such as the StNum jump interval sequence of a specific GOOSE control block, the sampled arrival jitter sequence of SV messages, and the short-term entropy values ​​of various message traffic.

[0127] Training and Operation: Training Phase: The autoencoder is trained using message flow data from historical normal periods, enabling it to reconstruct normal timing patterns.

[0128] Inference phase: Input real-time time-series window data and calculate the reconstruction error. If the error exceeds the dynamic threshold (calculated based on moving percentiles), it is judged as an anomaly.

[0129] Advantages: No attack samples are required; it can discover previously unseen attack patterns or anomalous behaviors that occur silently within the device itself (such as a clock gradually losing synchronization).

[0130] The third layer: supervised fine-grained classification model (precise qualitative classification), technology selection: gradient boosting decision tree or temporal convolutional neural network.

[0131] Input features: Integrating full features—parsing fields, time-series features, and contextual business logic features.

[0132] Sample construction and labeling: Normal samples: extracted from historical traffic without event logs.

[0133] Background noise samples: extracted from abnormally mixed time periods marked as “identifying risky substations” and confirmed by experts to be not caused by an attack.

[0134] Fake attack samples: On a simulation testing platform, various attack packets (replay, tampering, forgery, delayed injection, etc.) are generated using professional tools (such as a customized version of SCAPY in Kali Linux or ICS-specific testing tools) and the traffic is recorded.

[0135] Model output: a three-class probability output (normal / background noise / fake attack), and an interpretable feature importance analysis (e.g., indicating that the main basis for judging this as an attack is "the APPID is valid but the dataset value range is abnormal").

[0136] Phased training: First, the third-layer classification model is pre-trained on a large number of attack samples and generated normal samples on the simulation platform. Then, the pre-trained model is fine-tuned on historical normal data from the target substation to adapt to its specific business model and communication characteristics.

[0137] The second-layer unsupervised model is trained entirely using historical normal data from the target station.

[0138] Edge-Cloud Collaborative Deployment: Edge Side (within the substation): Deploy a complete lightweight three-layer model for real-time online detection and Level 1 alerts. Handle all local traffic. Cloud Security Brain: Receive model inference results, alert logs, and some suspicious packet samples from each site. Incremental Model Updates: Aggregate newly emerging attack samples and false positive samples from each site in the cloud, retrain the model periodically, and distribute the updated model parameters to each edge node. Threat Intelligence Sharing: New attack patterns discovered at one site can be quickly analyzed in the cloud to generate feature rules or update the model, and then distributed to all substations across the network.

[0139] Feedback loop and model self-evolution: The system records the results of operations personnel's handling of alarms (confirmed as an attack, confirmed as a false alarm, confirmed as an internal fault). These manually labeled samples automatically flow into the retraining sample pool in the cloud. The model periodically uses new samples for iterative optimization, achieving the ability to become more accurate with use.

[0140] The model constructed in this embodiment is not only a classifier, but also an intelligent defense system that integrates real-time defense, unknown threat detection, accurate attribution, and adaptive evolution, building a deep and intelligent network security defense line for substations.

[0141] Example 2 In a second aspect, the present invention provides a computer system comprising: a memory and a processor connected in communication, and a computer program stored in the memory and capable of running on the processor, wherein the processor executes the aforementioned assessment and analysis method for substation network security when running the computer program.

[0142] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the embodiments of apparatus, devices, and non-volatile computer storage media are basically similar to the method embodiments, so the descriptions are relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0143] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.

[0144] The above description is merely one or more embodiments of this specification and is not intended to limit this specification. Various modifications and variations can be made to the one or more embodiments of this specification by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of one or more embodiments of this specification should be included within the scope of the claims of this specification.

Claims

1. An assessment and analysis method for substation network security, characterized in that, Specifically, it includes: Based on the identification and processing results of different types of message data in the substation, the risk substations of false messages are identified. Based on the distribution data of the risk substations and the similarity of network devices between the risk substations, the simulated targets in the substations other than the risk substations are determined. The system determines the variation data of the operating load of the simulated targets on different dates. Based on the variation data of the operating load in different substations and the identification data of virtual messages in risky substations, it determines the simulation processing strategies for different simulated targets. Based on the composition data of the simulated targets in the substations and the simulation processing strategies, it determines the network security assessment and analysis methods for identifying risky substations.

2. The assessment and analysis method for substation network security as described in claim 1, characterized in that, The type of message data is determined based on the device that sent the message.

3. The assessment and analysis method for substation network security as described in claim 1, characterized in that, The identification and processing results of the message data are determined based on the types of messages sent from the substation on different dates.

4. The assessment and analysis method for substation network security as described in claim 1, characterized in that, The method for identifying and determining the risk of false messages in the substation is as follows: Based on the identification and processing results of different types of message data in the substation, the types of messages sent by the substation on different dates are determined. Based on the type of the sent message, determine the time period during which multiple types of messages are sent, and use this time period as the period during which false messages affect the message. Based on the distribution data of the time period affected by the false messages, it is determined whether the substation is a risk substation for identifying false messages.

5. The assessment and analysis method for substation network security as described in claim 4, characterized in that, The distribution data of the time period affected by the false message includes the dates during which the false message affected the period.

6. The assessment and analysis method for substation network security as described in claim 4, characterized in that, Based on the distribution data of the time periods affected by the false messages, it is determined whether the substation is a risk substation for identifying false messages, specifically including: When the number of dates affected by false messages at the substation does not meet the requirements, any deviation in the identification of false messages will inevitably lead to the substation generating erroneous trip signals, making it difficult for the substation's operational stability to meet the requirements.

7. The assessment and analysis method for substation network security as described in claim 1, characterized in that, The method for determining the simulated target in the substation is as follows: Based on the distribution data of the identified risk substations, the proportion of the identified risk substations in the substations is determined and used as the proportion of risk substations. Based on the similarity of the network devices between the identified risk substations, a similarity coefficient is determined for the network devices between the identified risk substations. Based on the proportion of risky substations and the similarity coefficient of network equipment among the identified risky substations, the simulated targets in the substations are determined.

8. The assessment and analysis method for substation network security as described in claim 7, characterized in that, The similarity coefficient of the network equipment between the identified risk substation and other identified risk substations is determined based on the proportion of the number of network equipment of the same model between the identified risk substation and other identified risk substations.

9. The assessment and analysis method for substation network security as described in claim 1, characterized in that, The method for determining the network security assessment and analysis method for identifying risky substations is as follows: Based on the composition data of simulated targets in substations, the ratio of simulated targets in substations to identified risk substations is determined and used as the simulation ratio. Based on the simulation processing strategy of the simulated target, determine the number of simulated targets that adopt different simulation processing strategies; The assessment and analysis method for identifying risky substations is determined based on the simulation ratio and the number of simulated targets using different simulation processing strategies.

10. A computer system, comprising: A memory and processor connected by communication, and a computer program stored in the memory and capable of running on the processor, characterized in that, when the processor runs the computer program, it executes an assessment and analysis method for substation network security as described in any one of claims 1-9.

Citation Information

Patent Citations

  • A network security monitoring method and system for a substation automation system

    CN120498909B

  • A packaging system

    IE61850B1