Power asset risk perception method and device based on multi-dimensional time sequence and large model, and medium

By collecting asset fingerprints from the power system and matching them with a standard component knowledge base, a standardized ledger database and a structured intelligence database are constructed. Combined with vectorized computing and a process engine, this solves the problems of insufficient dynamic perception and closed-loop management in power system risk awareness, and improves asset location efficiency and risk response speed.

CN121744331APending Publication Date: 2026-03-27国网宁夏电力有限公司信息通信公司
View PDF 0 Cites 2 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-17
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing risk perception technologies in the power system lack the ability to dynamically perceive the evolution of threats over time, and cannot effectively identify long-term trends, periodic fluctuations, and short-term mutations of threats. Furthermore, the assessment results do not closely match the actual risks, asset visibility is insufficient, intelligence processing efficiency is low, and it is difficult to form a closed loop for risk management.

Method used

By collecting asset fingerprints from the power information system and matching them with a standard component knowledge base, a standardized asset fingerprint ledger is formed; vulnerability features are extracted from multi-source unstructured risk warning information to build a structured risk intelligence information database; asset features and vulnerability-affected component features are vectorized, similarity is calculated, and an asset risk list is generated; and a process engine drives the risk handling process to achieve full closed-loop management.

Benefits of technology

It improved the efficiency of asset location, reduced labor costs, ensured the timeliness and accuracy of intelligence processing, shortened the risk response cycle, improved the alignment between assessment results and actual operational risks, and achieved automatic correlation between threat warnings and asset information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121744331A_ABST
    Figure CN121744331A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of electric power system risk perception, in particular to an electric power asset risk perception method and device based on a multi-dimensional time sequence and a large model and a medium, and the method comprises the steps: collecting asset fingerprints of an electric power information system, matching the asset fingerprints with a standard component knowledge base, and standardizing the asset fingerprints; obtaining a standardized asset fingerprint ledger library; extracting vulnerability feature information from the multi-source unstructured risk early warning information to obtain a structured risk intelligence information base; performing vectorization representation on asset features in the standardized asset fingerprint machine account library and vulnerability influence component features in the risk information library, calculating vector similarity between the asset features and the vulnerability influence component features, performing feature matching according to the vector similarity, positioning affected assets, and generating an asset risk list; and driving a risk disposal process through a process engine based on the asset risk list. The asset risk perception efficiency is improved, and the response period is shortened.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power system risk perception technology, specifically to a method, device, and medium for power asset risk perception based on multi-dimensional time series and large model. Background Technology

[0002] With the deepening of the construction of new power systems, digital technologies such as cloud computing, the Internet of Things, and big data are deeply integrated with power operations, and power networks have evolved into complex, asset-heavy, and highly interconnected systems. Currently, power system security protection mainly relies on traditional technical systems such as open vulnerability assessment languages, general vulnerability scoring systems, and national vulnerability databases. Open vulnerability assessment languages ​​focus on standardizing detection processes, general vulnerability scoring systems aim to provide static risk scores for individual vulnerabilities, and vulnerability databases are mainly used for information collection. However, these methods have significant limitations: First, they are essentially static assessment models, lacking the dynamic perception capability of threat evolution patterns over time, and cannot effectively identify long-term trends, periodic fluctuations, and short-term mutations of threats; second, the assessment dimensions are mostly general attributes, failing to fully integrate the unique business scenarios, industrial control protocols, and asset importance of the power system, resulting in assessment results that do not adequately match actual risks.

[0003] In the daily safety operation practices of power companies, the aforementioned technical limitations present the following problems: First, insufficient asset visibility. Traditional ledgers only record basic information such as IP addresses and hostnames, lacking key fingerprints such as software components and versions, making it impossible to quickly locate assets affected by vulnerabilities. Second, low intelligence processing efficiency. Risk intelligence sources are scattered and in inconsistent formats, relying on manual analysis, making it difficult to achieve automated and large-scale analysis. Third, difficulty in forming a closed loop for risk handling. Threat warnings cannot be automatically linked to assets, and investigation, remediation, and verification processes rely on manual coordination, resulting in long response cycles. Summary of the Invention

[0004] To address the technical problems of low efficiency and long response cycles in asset risk perception, the present invention aims to provide a method, device, and medium for power asset risk perception based on multi-dimensional time series and large-scale models. The specific technical solution adopted is as follows:

[0005] In a first aspect, embodiments of the present invention disclose a method for power asset risk perception based on multi-dimensional time series and large-scale models. This method includes: collecting asset fingerprints from a power information system, matching and standardizing these fingerprints with a standard component knowledge base to obtain a standardized asset fingerprint ledger; extracting vulnerability feature information from multi-source unstructured risk warning information to obtain a structured risk intelligence information base; vectorizing the asset features in the standardized asset fingerprint ledger and the vulnerability-affected component features in the risk intelligence information base, calculating the vector similarity between the asset features and the vulnerability-affected component features, and performing feature matching and locating affected assets based on the vector similarity to generate an asset risk list; and driving a risk disposal process through a process engine based on the asset risk list. The risk disposal process includes a closed-loop process of asset hazard discovery, location, disposal, and verification.

[0006] In a second aspect, embodiments of the present invention disclose an electronic device, including: a processor and a memory; wherein the memory is used to store a computer program that can run on the processor; the processor is used to execute the program stored in the memory to implement the steps of the power asset risk perception method based on multi-dimensional time series and large model mentioned in the first aspect.

[0007] Thirdly, embodiments of the present invention disclose a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the power asset risk perception method based on multi-dimensional time series and large model mentioned in the first aspect.

[0008] The technical solution disclosed in this invention, by collecting asset fingerprints and matching and standardizing them with a standard component knowledge base, solves the problem of asset ledgers only recording basic records such as IP addresses and hostnames, and comprehensively covers key fingerprint information such as software components and versions. The standardized asset fingerprint ledger library provides data support for risk localization, allowing for faster identification of affected assets when vulnerabilities occur, improving the efficiency of locating affected assets, avoiding blind spots in investigation due to missing information, and enhancing the directionality of risk response. Furthermore, this invention, by extracting vulnerability features in a targeted manner to form a structured intelligence database, replaces the traditional manual analysis mode, achieving automated and large-scale processing of risk intelligence, significantly reducing labor costs, and avoiding oversights in manual operations, ensuring the timeliness and accuracy of intelligence processing. Moreover, based on multi-dimensional temporal characteristics and large model capabilities, this invention vectorizes asset features and vulnerability-affected component features and calculates similarity, incorporating the unique industrial control protocols, business scenarios, and asset importance dimensions of the power system, while implicitly associating the time patterns of threat evolution, resulting in assessment results that highly align with actual operational risks. By driving the entire process of asset hazard discovery, location, handling, and verification through a process engine, threat warnings and asset information are automatically linked, replacing the traditional model of manual coordination between various stages. This closed-loop mechanism not only reduces cross-stage communication costs but also improves the efficiency of handling actions through standardized processes, effectively shortening the risk response cycle. Attached Figure Description

[0009] Figure 1 A flowchart illustrating a power asset risk perception method based on multi-dimensional time series and large model provided in an embodiment of the present invention;

[0010] Figure 2 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0011] To further illustrate the technical means and effects adopted by the present invention to achieve its intended purpose, the following, in conjunction with the accompanying drawings and preferred embodiments, details the specific implementation, structure, features, and effects of a power asset risk perception method, device, and medium based on multi-dimensional time series and large-scale models proposed according to the present invention. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. Furthermore, specific features, structures, or characteristics in one or more embodiments can be combined in any suitable form.

[0012] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. The following detailed description, in conjunction with the accompanying drawings, illustrates a specific scheme for a method, device, and medium for power asset risk perception based on multi-dimensional time series and large-scale models provided by this invention.

[0013] Please see Figure 1 , Figure 1 This invention provides a flowchart illustrating a method for risk perception of power assets based on multi-dimensional time series and large-scale models, which includes:

[0014] Step S101: Collect asset fingerprints from the power information system, match and standardize the asset fingerprints with the standard component knowledge base, and obtain a standardized asset fingerprint ledger.

[0015] Specifically, asset fingerprints include, but are not limited to, fingerprint information such as the asset's Internet Protocol Address (IP) address, open ports, component type, and version number. The standard component knowledge base is based on the internationally recognized Common Platform Enumeration (CPE) library, integrating information on domestically produced software components (such as power industry-specific industrial control software and databases) to form a standardized component knowledge base. The standard component knowledge base contains structured fields such as component name, version range, and vendor information.

[0016] Furthermore, as an optional embodiment of the present invention, collecting asset fingerprints of the power information system includes: obtaining the IP address, open port, running services, software components and version information of assets in the Internet region and production control region of the power information system to obtain asset fingerprints.

[0017] Specifically, in this embodiment of the invention, asset fingerprints are collected through key equipment of the power information system, such as substation monitoring equipment, dispatch center servers, and distribution terminals. The collected asset fingerprints are vectorized using the same Embedding technology (BERT model) to generate fingerprint vectors.

[0018] Furthermore, as an optional embodiment of the present invention, matching and standardizing asset fingerprints with a standard component knowledge base to obtain a standardized asset fingerprint ledger includes: constructing a standard component knowledge base that integrates general platform enumerations and mainstream software information, and converting the standard component knowledge base into standard vectors using a pre-trained language model and storing them in a vector database; converting the software component and version information in the collected asset fingerprints into fingerprint vectors using the same pre-trained language model; calculating the cosine similarity between the fingerprint vectors and the standard vectors in the vector database, and updating the standard component and version information corresponding to the matching results with cosine similarity exceeding a preset threshold to the standardized asset fingerprint ledger.

[0019] Specifically, this invention uses a CPE library as its core, integrating mainstream software information from the power industry (such as domestically produced chemical control software and power-specific databases) to form a comprehensive standard component knowledge base. The standard component knowledge base contains structured fields such as component name, version number, vendor, and vulnerability association information. Then, a pre-trained language model (such as BERT, Word2Vec, FastGPT, LLaMA, etc.) is used to transform the component text information in the standard component knowledge base into high-dimensional vectors.

[0020] Furthermore, this embodiment of the invention collects asset fingerprints from multi-source data of the power information system based on spatial mapping technology. The collected fingerprints are then cleaned: duplicates are removed, missing values ​​are filled, and standardized software component and version strings are extracted using a rule engine (such as regular expressions). Finally, using the same pre-trained language model as the standard component knowledge base, the cleaned component version information is converted into fingerprint vectors.

[0021] Furthermore, in this embodiment of the invention, the cosine similarity between the fingerprint vector and the standard vector in the vector database is calculated. The preset threshold needs to be dynamically set according to the actual needs of the power system (e.g., the dynamic threshold is set to 0.85), and the initial preset threshold is adjusted by verifying historical data through a vector distance calculation algorithm to obtain the preset threshold. For the matching results, multi-factor verification is required.

[0022] The initial preset threshold is set based on historical matching data and expert experience. For example, for high-risk components of the power information system (such as industrial control software), the initial preset threshold is set to 0.85. For general components, the threshold can be appropriately reduced to 0.7. Adjustments to the initial preset threshold can be made through feedback loop optimization: specifically, at regular intervals, the system collects matching result samples and calculates the mismatch rate (number of incorrect matches / total number of matches) through manual review or expert verification. If the mismatch rate exceeds the preset tolerance, the threshold adjustment is automatically triggered. When the mismatch rate increases, the initial preset threshold is raised to improve accuracy. Alternatively, adjustments can be made through multi-factor weighted analysis: specifically, adjustments are made in conjunction with the business characteristics of the power system, such as increasing the initial preset threshold for core equipment by 0.05 to avoid security risks caused by mismatches.

[0023] Furthermore, traditional rule-based matching (such as exact string matching) cannot handle version differences. Therefore, this embodiment of the invention uses multi-factor semantic fuzzy matching. Specifically, it maps the component name and version strings into high-dimensional vectors using a pre-trained language model (such as BERT) to capture semantic information. Then, it calculates the cosine similarity between the fingerprint vector and the standard vector, allowing for non-exact matching. For example, if the similarity is 0.75 (below the preset threshold of 0.88), the fuzzy matching process is initiated. Specifically, it uses nearest neighbor search in the word embedding space to find candidate vectors in the standard component knowledge base whose cosine similarity is close to the preset threshold (such as finding the Top 5 nearest neighbors using the k-NN algorithm), and verifies the semantic rationality. The candidate vector is then used as the standard component and version information for matching with the fingerprint vector.

[0024] Furthermore, the Lewinstein distance between the fingerprint vector and the standard vector in the vector database can be calculated. If the Lewinstein distance is ≤2, it is considered a successful fuzzy match, and the standard vector with a Lewinstein distance ≤2 is used as the vector that matches the fingerprint vector.

[0025] Furthermore, for matching results with similarity exceeding a threshold, the corresponding standard component names, version numbers, and vulnerability association information are updated in the asset fingerprint ledger. The asset fingerprint ledger is stored using a relational database, with fields including asset ID, IP address, standardized component, version, matching precision, and update time. For unmatched asset fingerprints, a manual review process is initiated or features are supplemented using a machine learning model, and these fingerprints are categorized as items awaiting verification, subsequently updated iteratively through the standard component knowledge base.

[0026] Step S102: Extract vulnerability feature information from multi-source unstructured risk warning information to obtain a structured risk intelligence information database.

[0027] Specifically, this invention first integrates multi-source unstructured risk warning information, including State Grid risk warning notices, regional government notifications, network intrusion detection system alarm data, system log data, and external threat intelligence data. Redundant information is removed through text cleaning, and a unified encoding format is implemented to filter stop words and segment the text. Next, an international CPE asset component library and domestically produced software asset information are integrated to construct a Chinese CPE standard library adapted to the power industry scenario, including core entity categories such as vulnerability identifiers, technical entities, and risk information.

[0028] Secondly, a large-scale tokenizer and named entity recognition technology are used to parse the preprocessed unstructured text, extracting core features such as vulnerability name, CVE number, affected components and versions, vulnerability type, attack complexity, permission requirements, and scope of impact. Referring to preset feature attribute value ranges, each feature is simplified and weighted, removing low-weight redundant values. Finally, the extracted and standardized vulnerability feature information is organized in a structured format of "vulnerability identifier - technical attribute - risk attribute - handling association." Finally, based on data warehouse storage technology, the feature information is classified, archived, and indexed to construct a risk intelligence information database containing multi-dimensional structured features.

[0029] Furthermore, as an optional embodiment of the present invention, extracting vulnerability feature information from multi-source unstructured risk warning information to obtain a structured risk intelligence information database includes: using a large language model to perform named entity recognition and relation extraction on risk warning documents and security notification texts from different sources and in different formats to obtain vulnerability number, affected component name and version range, vulnerability type, score and remediation suggestions from a general vulnerability scoring system, where the multi-source unstructured risk warning information includes risk warning documents and security notification texts; and structuring at least one of the following information: vulnerability number, affected component name and version range, vulnerability type, score and remediation suggestions from a general vulnerability scoring system.

[0030] Specifically, this invention employs named entity recognition technology based on a large language model to identify vulnerability identifiers, technical entities, risk information, and remediation information. It also extracts and organizes relationships such as "vulnerability number - affected component" and "vulnerability type - remediation suggestion." Next, a Chinese CPE standard library is established, and the extracted affected component names and version ranges are matched and calibrated against the standard library, organized in a structured format of "vulnerability identifier - technical attribute - risk attribute - remediation attribute," with unified field definitions and value specifications. Finally, based on data warehouse storage technology, a risk intelligence information database is constructed, with raw text, extracted features, and related information managed separately. Simultaneously, structured features are transformed into multi-dimensional vector storage using embedding technology, establishing vector indexes and keyword indexes.

[0031] Step S103: The asset features in the standardized asset fingerprint ledger and the vulnerability impact component features in the risk intelligence information database are vectorized respectively. The vector similarity between the asset features and the vulnerability impact component features is calculated. Based on the vector similarity, feature matching is performed and the affected assets are located to generate an asset risk list.

[0032] Specifically, this embodiment of the invention extracts core asset characteristics from a standardized asset fingerprint ledger, including IP address, hardware device type, software component name and version, compatible industrial control protocols, asset importance level, and business module affiliation, while removing redundant and invalid fields; and calibrates component names and versions using a Chinese CPE standard library. It also extracts core vulnerability-related characteristics from a risk intelligence database, including the affected component name and version range, compatible system environment, required industrial control protocol type for triggering, vulnerability type, and CVSS score, simplifying the process based on predefined characteristic attribute value ranges while retaining key characteristics that significantly impact the matching results.

[0033] Then, a customized embedding model for the power sector is adopted to transform the standardized asset features into multi-dimensional vectors. A graph neural network is used to optimize vector quality. The graph neural network topology is constructed based on the physical connections between power system devices (devices as nodes, communication links as edges). Neighborhood node information aggregation corrects data biases caused by device isolation, outputting asset feature vectors, which are stored in vector databases such as Milvus and indexed. Furthermore, an embedding model with the same origin as the asset features is used to semantically encode the features of components affected by vulnerabilities, generating vulnerability feature vectors. For interval-type features such as version ranges, interval discretization is performed to transform them into vector dimensions, ensuring alignment between the vector dimensions and the asset feature vectors.

[0034] Furthermore, a cosine similarity algorithm is used to calculate the basic similarity between asset feature vectors and vulnerability feature vectors. Fuzzy matching calculations are supported for key features such as component versions. Adaptation weights are then assigned to different feature dimensions: for the asset side, asset importance (weight 0.3) and industrial control protocol compatibility (weight 0.25) are emphasized; for the vulnerability side, CVSS score (weight 0.2) and impact scope (weight 0.15) are emphasized. The final comprehensive similarity score is obtained by weighted summation, using the formula: Comprehensive Similarity = Basic Similarity × 0.3 + Asset Importance Matching Weight × 0.3 + Protocol Compatibility Weight × 0.25 + Vulnerability Risk Weight × 0.15.

[0035] Furthermore, as an optional embodiment of the present invention, before driving the risk disposal process through a process engine based on the asset risk list, the method further includes: calculating the risk level of each asset risk in the asset risk list through a multi-factor weighted evaluation algorithm based on the asset's network exposure, business importance, historical vulnerability data, and vulnerability severity level in the risk intelligence information database; and determining the guiding disposal priority for each asset risk according to the risk level.

[0036] Furthermore, this embodiment of the invention sets a dynamic matching threshold. Assets with a comprehensive similarity score higher than the dynamic matching threshold are judged as high-matching assets and directly included in the candidate list. Duplicate matches are eliminated by associating the master data of the asset fingerprint ledger and the risk intelligence information database (e.g., mapping asset IDs to vulnerability intelligence IDs). The final generated asset risk list includes basic asset information, vulnerability information, matching details, and risk level (calculated based on the asset's business importance and historical vulnerability data, categorized into low, medium, high, and extremely high levels). It also incorporates factors such as network exposure, vulnerability severity level in the risk intelligence information database, and non-shutdownability for multi-factor weighted evaluation, assigning a disposal priority to each affected asset. When data changes occur in the asset fingerprint ledger or risk intelligence information database, vector updates and similarity recalculation are automatically triggered, synchronously updating the asset risk list to ensure real-time risk awareness.

[0037] Furthermore, as an optional embodiment of the present invention, the asset features in the standardized asset fingerprint ledger and the vulnerability-affected component features in the risk intelligence information database are respectively vectorized. The vector similarity between the asset features and the vulnerability-affected component features is calculated, and feature matching and affected assets are located based on the vector similarity to generate an asset risk list. This includes: converting the component and version asset features in the asset fingerprint ledger and the affected component and version-range vulnerability-affected component features in the risk intelligence information database into high-dimensional semantic vectors, where the high-dimensional semantic vectors include asset vectors and risk vectors; constructing a searchable vector index library by combining the asset vectors, risk vectors, and the vector similarity between asset vectors and risk vectors; when new risk intelligence is added or periodic checks are performed, the risk vector to be queried is used as the query input, and a target asset vector similar to the risk vector to be queried is retrieved in the vector index library using an approximate nearest neighbor search algorithm, thereby achieving the matching of the target asset vector with the risk vector to be queried. The target asset vector is an asset vector whose vector similarity with the risk vector to be queried is greater than a threshold.

[0038] Specifically, core asset features are extracted from the standardized asset fingerprint ledger database. In addition to component names and versions, key features specific to the power sector are added, including compatible industrial control protocols, asset importance level, business module affiliation, network exposure, and non-shutdown indicators. The core features of affected component names and version ranges are extracted from the risk intelligence database, and supplemented with auxiliary features such as vulnerability type, CVSS score, attack complexity, and environmental dependency. A customized embedding model for the power sector is used to transform the standardized asset features into high-dimensional semantic vectors, which are then stored in the Milvus vector database.

[0039] Furthermore, a customized embedding model derived from asset features is employed to semantically encode the regularized vulnerability impact component features, generating risk vectors of the same dimension. For version range features, interval discretization is used to transform them into multiple sets of sub-vectors, ensuring alignment with the asset vector dimension and improving fuzzy matching compatibility. The asset vector, risk vector, and their initial cosine similarity results are batch-imported into the Milvus vector database, and a searchable vector index is constructed using the IVF_FLAT index type. Combining the power scenario feature weighting strategy, normalized weights are assigned to different feature dimensions, and the initial cosine similarity is weighted and fused with the feature weights to obtain a weighted similarity score, which serves as the core retrieval basis for the index.

[0040] Furthermore, establish dynamic index update rules so that when new assets are added to the asset fingerprint ledger, component versions are updated, or new vulnerability information is entered into the risk intelligence information database, the corresponding vectors are automatically updated and the index is rebuilt.

[0041] Furthermore, when new risk intelligence is added or routine checks are performed, the risk vector to be queried is used as input. The approximate nearest neighbor search algorithm built into FAISS or Milvus is invoked. Asset vectors with a weighted similarity score higher than a threshold are identified as "high-matching assets" and directly included in the candidate list of affected assets. For "medium-matching assets" with a weighted similarity score between 60% and 80%, a multivariate time series model is used to analyze the temporal correlation strength between the asset and the vulnerability. For example, data such as the recent attack frequency of this type of vulnerability, historical vulnerability trigger records of the asset, and the vulnerability infection rate of assets in the same business domain are retrieved to eliminate false matches with a temporal correlation score lower than 0.3. A correlation mapping is established based on the asset ID and vulnerability intelligence ID, duplicate matches are eliminated, and finally, the effective affected assets are identified.

[0042] Finally, this embodiment of the invention updates the asset risk list. When the asset fingerprint ledger database undergoes component version updates, asset importance adjustments, or the risk intelligence information database adds vulnerability fix patches or changes in risk levels, vector updates, similarity recalculations, and list iterations are automatically triggered. Regular screening tasks are also set (such as every morning) to perform batch matching and retrieval of all risk vectors and asset vectors, ensuring that the list covers newly added assets and vulnerability intelligence, and achieving continuity of risk perception.

[0043] Step S104: Based on the asset risk list, drive the risk disposal process through the process engine. The risk disposal process includes a closed-loop process of asset hazard discovery, location, disposal and verification.

[0044] Specifically, this embodiment of the invention employs a low-code workflow engine (such as Camunda or Flowable) to construct the risk handling process. The engine obtains key fields from the asset risk list in real time through an API interface: asset ID, risk level, vulnerability CVE number, and handling time limit. The driving logic is implemented based on a rule engine (such as Drools): for example, when the risk level is "high risk", the emergency handling process is automatically triggered.

[0045] Furthermore, as an optional embodiment of the present invention, the risk handling process driven by the process engine based on the asset risk list includes: converting the asset risk list into standardized safety work orders, and locating and assigning standardized safety work orders according to the responsible department or preset rules to which the assets belong in the asset risk list; tracking the risk handling process of the standardized safety work orders through the process engine, and automatically escalating alarms when timeouts occur, until the status of the standardized safety work order is marked as repaired or verified, and then automatically closing the standardized safety work order to complete the closed loop.

[0046] Specifically, in this embodiment of the invention, the priority of disposal is determined based on the prediction results of a multi-scale time model, and then the responsible person is automatically assigned according to the department to which the asset belongs. The disposal time limit is then set, and the overdue information is automatically reported to the superior administrator.

[0047] Furthermore, the process engine parses the structured data in the asset risk list and automatically generates standardized security work orders. Standardized security work orders must include: a risk description, handling instructions, and related information. The responsible person is then notified via SMS / email, and the work order is synchronized to the mobile operations and maintenance app. For low-risk projects that can be standardized (such as software version updates), the engine directly executes the repair by calling an automated script library and verifies the handling result through an asset fingerprint database. For complex risks (such as industrial control protocol configuration vulnerabilities), the engine guides operations and maintenance personnel to operate step by step and records operation logs. When a risk crosses departments (such as simultaneously affecting the intranet and monitoring network), the engine initiates a multi-party approval process, requiring confirmation from all parties before proceeding. After handling is completed, the asset component version is rescanned using spatial mapping technology and compared with the expected results in the risk list. For high-risk projects, a secondary assessment is conducted to ensure no residual threats. After verification, the process instance status is updated to "closed loop," the corresponding entry in the risk list is archived, and a handling report is generated.

[0048] Furthermore, when a handling fails (such as a timeout), the engine automatically escalates the alarm and attempts to handle the issue again according to a preset strategy, until the standardized safety work order is marked as repaired and verified, at which point it is automatically closed, completing the closed loop. In this way, by using the automated drive of the process engine, the efficiency of risk handling is improved and the error of human intervention is reduced.

[0049] Furthermore, as an optional embodiment of the present invention, the risk handling process driven by the process engine based on the asset risk list includes: converting the asset risk list into standardized safety work orders, and locating and assigning standardized safety work orders according to the responsible department or preset rules to which the assets belong in the asset risk list; tracking the risk handling process of the standardized safety work orders through the process engine, and automatically escalating alarms when timeouts occur, until the status of the standardized safety work order is marked as repaired or verified, and then automatically closing the standardized safety work order to complete the closed loop.

[0050] The technical solution disclosed in this invention, by collecting asset fingerprints and matching and standardizing them with a standard component knowledge base, enables the asset ledger to break through the limitations of traditional basic records of IP addresses and hostnames, and fully cover key fingerprint information such as software components and versions. The standardized asset fingerprint ledger library provides data support for risk localization. When a vulnerability occurs, the scope of affected assets can be quickly identified, improving the efficiency of locating affected assets, avoiding blind spots in investigation due to missing information, and enhancing the directionality of risk response. Furthermore, this invention, by extracting vulnerability features in a targeted manner to form a structured intelligence database, replaces the traditional manual analysis mode, achieving automated and large-scale processing of risk intelligence, significantly reducing labor costs, and avoiding oversights in manual operations, ensuring the timeliness and accuracy of intelligence processing. Moreover, based on multi-dimensional temporal characteristics and large model capabilities, this invention vectorizes asset features and vulnerability-affected component features and calculates similarity, incorporating the unique industrial control protocols, business scenarios, and asset importance dimensions of the power system, while implicitly associating the time patterns of threat evolution, resulting in assessment results that highly align with actual operational risks. By driving the entire process of asset hazard discovery, location, handling, and verification through a process engine, threat warnings and asset information are automatically linked, replacing the traditional model of manual coordination between various stages. This closed-loop mechanism not only reduces cross-stage communication costs but also improves the efficiency of handling actions through standardized processes, effectively shortening the risk response cycle.

[0051] Furthermore, as an optional embodiment of the present invention, the power asset risk perception method based on multi-dimensional time series and large model further includes: acquiring multi-dimensional time series data reflecting the security status of the power system;

[0052] The comprehensive threat score is calculated based on multi-dimensional time-series data and varies over time. Based on the comprehensive threat score, a threat time series is constructed and predicted using a multi-scale time analysis model. Security threats are identified based on the prediction results and anomaly detection algorithms, and threat alerts and situation reports are generated. Among these, threat alerts and / or situation reports work in conjunction with the asset risk list to support decision-making and scheduling in risk management.

[0053] Specifically, the multi-dimensional time-series data on the security status of the power system comes from sources including, but not limited to, real-time attack behaviors such as port scanning and abnormal access, the operating status and error information of operating systems, databases, and application systems, and the latest threat information integrated with vulnerability databases such as CNNVD and CVE. The data from these sources are then used to construct a multi-dimensional time series indexed by time, based on preset time intervals (e.g., 5 minutes).

[0054] Furthermore, in this embodiment of the invention, 5-8 power security experts independently score each dimension, and the average is taken after removing the highest and lowest 20% extreme values. Weights are assigned according to the importance of each dimension in the power system, and a weighted sum is calculated to obtain a comprehensive threat score. The comprehensive threat scores are then aggregated at the hourly granularity to form a continuous threat time series. Finally, a multi-scale time model is used for time-scale decomposition, specifically wavelet transform to decompose the multi-dimensional time series into short-term (1-24 hours), medium-term (1-7 days), and long-term (7-30 days) subsequences. The short-term series uses an LSTM model to capture sudden threats such as DDoS attacks. The medium-term series uses a Prophet model to identify periodic attack patterns. The long-term series uses a SARIMA model to analyze seasonal trends. Next, the predicted sequence is decomposed into a trend term, a seasonal term, and a residual term. The isolated forest algorithm is applied to the residual term to identify anomalies deviating from the normal pattern by more than 3σ. The anomaly score threshold is dynamically adjusted according to the power system operating status. When the anomaly score exceeds the threshold, an alarm message containing the threat type, affected equipment, and handling suggestions is automatically generated.

[0055] Furthermore, threat alerts are automatically linked to corresponding assets in the asset risk list using key fields such as IP address and device identifier. A handling priority index is calculated by combining threat scores and asset importance. The process engine automatically assigns high-priority risks to the appropriate operations and maintenance teams according to preset rules and sets processing deadlines. After handling is completed, the risk elimination is verified by retesting the asset fingerprint, forming a closed-loop record. Finally, a multi-dimensional security posture report is output, specifically generating daily / weekly / monthly reports on threat trend analysis and handling effectiveness statistics, displaying multi-dimensional threat change trends through time-series curves, heatmaps, and other formats. Finally, based on the prediction results, suggestions for adjusting protection strategies are provided, such as "strengthening substation monitoring network protection in the coming week."

[0056] Furthermore, as an optional embodiment of the present invention, calculating the comprehensive threat score that changes over time based on multi-dimensional time-series data includes: defining multiple characteristic attribute dimensions related to vulnerabilities and attacks in the power information system to form a set of characteristic attributes. The characteristic attribute dimensions include at least one of connection environment, attack complexity, permission requirements, user interaction required, scope of impact, number of affected targets, existing patches, exploitable code verification, environmental dependence, and source credibility; simplifying the value range of each characteristic attribute dimension based on predefined key values; collecting data corresponding to each characteristic attribute dimension from the multi-dimensional time-series data based on the simplified value range; scoring the collected data of each characteristic attribute dimension to obtain the score value of each dimension; and using a predefined statistical function to aggregate and calculate the score values ​​of each dimension to obtain the comprehensive threat score at each sampling time point.

[0057] Specifically, this embodiment of the invention establishes a complete set of values ​​for each feature dimension. For example, "Influence Range" includes four values: {Unknown, Small, Medium, Large}. Key values ​​are selected through expert voting and weighted accordingly. For example, for the "Existing Patches" dimension: key value selection: "None" (weight 0.6), "Yes" (weight 0.3), "Many" (weight 0.1), "Unknown" is not included due to uncertain information, and "No Patches" means the highest risk of continued vulnerability exposure. Next, the weighted values ​​of the quantified key values ​​are calculated. The bottom 20% of key values ​​in terms of weighted value ranking are merged into the "Other" category, but high-risk values ​​are ensured not to be merged. A mapping relationship between feature dimensions and multi-source data is established.

[0058] Furthermore, 5-8 experts with experience in power system security were selected to provide them with complete multi-source data context, such as specific descriptions of attack methods when scoring "attack complexity". A truncated average method was used to remove the highest and lowest 20% of extreme values ​​in each dimension's score.

[0059] Furthermore, a value weight allocation based on power system characteristics is established, with high-weight dimensions: "Scope of Influence" (weight 0.16) and "Attack Complexity" (weight 0.14). Medium-weight dimensions: "Connectivity Environment" (weight 0.12) and "Access Requirement" (weight 0.10). Low-weight dimensions: "Source Credibility" (weight 0.06) and "Exploitable Code Verification" (weight 0.05). The formula used is: Overall Threat Score = Σ(Dimensional Final Score × Dimensional Normalized Weight). The overall threat score is divided into 0-2 points (low risk), 2-4 points (medium risk), and 4-5 points (high risk).

[0060] Corresponding to the power asset risk perception method based on multi-dimensional time series and large model provided in the above embodiments, based on the same technical concept, this embodiment of the invention also provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the steps of the power asset risk perception method based on multi-dimensional time series and large model mentioned in the above embodiments.

[0061] It should be noted that the computer-readable storage medium provided in the embodiments of the present invention and the power asset risk perception method based on multi-dimensional time series and large model provided in the embodiments of the present invention are based on the same application concept. Therefore, the specific implementation of this embodiment can refer to the implementation of the aforementioned power asset risk perception method based on multi-dimensional time series and large model, and has the same or similar beneficial effects. Repeated parts will not be repeated.

[0062] Corresponding to the power asset risk perception method based on multi-dimensional time series and large model provided in the above embodiments, based on the same technical concept, this embodiment of the invention also provides an electronic device for executing the above-mentioned power asset risk perception method based on multi-dimensional time series and large model. Figure 2 A schematic diagram of the structure of an electronic device provided for another embodiment of the present invention, as shown below. Figure 2 As shown. Electronic devices can vary considerably due to differences in configuration or performance, and may include one or more processors 201 and memory 202. The memory 202 stores computer programs that can run on the processor 201, and the processor 201 executes the programs stored in the memory 202 to achieve the above. Figure 1 The various steps in the method embodiment are described. The memory 202 can be temporary or persistent storage. The application stored in the memory 202 may include one or more modules (not shown), each module may include a series of computer-executable instructions for the electronic device.

[0063] Furthermore, the processor 201 may be configured to communicate with the memory 202 and execute a series of computer-executable instructions stored in the memory 202 on the electronic device. The electronic device may also include one or more power supplies 203, one or more wired or wireless network interfaces 204, one or more input / output interfaces 205, and one or more keyboards 206.

[0064] Specifically, in this embodiment, the electronic device includes a processor, a communication interface, a memory, and a communication bus; wherein, the processor, the communication interface, and the memory communicate with each other via the bus; the memory is used to store computer programs; and the processor is used to execute the programs stored in the memory to achieve the above. Figure 1The various steps in the method embodiments are the same as those in the above method embodiments, and have the same beneficial effects. To avoid repetition, the embodiments of the present invention will not be described again here.

[0065] It should be noted that the electronic device provided in this embodiment of the invention and the power asset risk perception method based on multi-dimensional time series and large model provided in this embodiment of the invention are based on the same application concept. Therefore, the specific implementation of this embodiment can refer to the implementation of the aforementioned power asset risk perception method based on multi-dimensional time series and large model, and has the same or similar beneficial effects. Repeated parts will not be repeated.

[0066] It should be noted that the order of the above embodiments of the present invention is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. The processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0067] The various embodiments in this specification are described in a progressive manner. The same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on describing the differences from other embodiments.

Claims

1. A method for risk perception of power assets based on multi-dimensional time series and large-scale models, characterized in that, The power asset risk perception method based on multi-dimensional time series and large model includes: Collect asset fingerprints from the power information system, match and standardize the asset fingerprints with the standard component knowledge base, and obtain a standardized asset fingerprint ledger database. Vulnerability feature information is extracted from multi-source unstructured risk warning information to obtain a structured risk intelligence information database; The asset features in the standardized asset fingerprint ledger and the vulnerability impact component features in the risk intelligence information database are vectorized respectively. The vector similarity between the asset features and the vulnerability impact component features is calculated. Based on the vector similarity, feature matching is performed and the affected assets are located to generate an asset risk list. Based on the asset risk list, a risk management process is driven by a process engine. The risk management process includes a closed-loop process of asset hazard discovery, location, management and verification.

2. The power asset risk perception method based on multi-dimensional time series and large model as described in claim 1, characterized in that, The asset fingerprint of the power information collection system includes: Obtain the IP address, open ports, operating services, software components, and version information of the assets in the Internet region and production control region of the power information system to obtain the asset fingerprint; The process of matching and standardizing the asset fingerprints with the standard component knowledge base to obtain a standardized asset fingerprint ledger includes: A standard component knowledge base integrating general platform enumeration and mainstream software information is constructed, and the standard component knowledge base is transformed into standard vectors through a pre-trained language model and stored in a vector database; the software component and version information in the collected asset fingerprints are transformed into fingerprint vectors through the same pre-trained language model; the cosine similarity between the fingerprint vectors and the standard vectors in the vector database is calculated, and the standard component and version information corresponding to the matching results with cosine similarity exceeding a preset threshold are updated to the standardized asset fingerprint ledger database.

3. The power asset risk perception method based on multi-dimensional time series and large model according to claim 1, characterized in that, Prior to driving the risk management process via a process engine based on the asset risk list, the method further includes: Based on the asset's online exposure, business importance, historical vulnerability data, and vulnerability severity levels in the aforementioned risk intelligence database, the risk level of each asset risk in the asset risk list is calculated using a multi-factor weighted evaluation algorithm. The priority of guiding the handling of each asset risk is determined based on the risk level.

4. The power asset risk perception method based on multi-dimensional time series and large model as described in claim 1, characterized in that, The process of extracting vulnerability feature information from multi-source unstructured risk warning information to obtain a structured risk intelligence information database includes: Using a large language model, named entity recognition and relation extraction are performed on risk warnings and security notification texts from different sources and in different formats to obtain vulnerability numbers, affected component names and version ranges, vulnerability types, scores from a general vulnerability scoring system, and remediation suggestions. The multi-source unstructured risk warning information includes the risk warnings and security notification texts. The information is structured based on at least one of the following: vulnerability number, affected component name and version range, vulnerability type, score from the general vulnerability scoring system, and remediation recommendations.

5. The power asset risk perception method based on multi-dimensional time series and large model according to claim 1, characterized in that, The process involves vectorizing the asset features in the standardized asset fingerprint ledger and the vulnerability impact component features in the risk intelligence information database, calculating the vector similarity between the asset features and the vulnerability impact component features, and performing feature matching and locating affected assets based on the vector similarity to generate an asset risk list. The asset characteristics of components and versions in the asset fingerprint ledger and the vulnerability impact characteristics of affected components and version ranges in the risk intelligence information database are respectively converted into high-dimensional semantic vectors, which include asset vectors and risk vectors. Construct a searchable vector index library from the asset vector, the risk vector, and the vector similarity between the asset vector and the risk vector; When new risk intelligence is added or a periodic review is performed, the risk vector to be queried is used as the query input. The approximate nearest neighbor search algorithm is used to retrieve target asset vectors that are similar to the risk vector to be queried from the vector index library, thereby matching the target asset vector with the risk vector to be queried. The target asset vector is an asset vector whose vector similarity to the risk vector to be queried is greater than a threshold.

6. The power asset risk perception method based on multi-dimensional time series and large model according to claim 1, characterized in that, The risk management process driven by the process engine based on the asset risk list includes: The asset risk list is converted into standardized safety work orders, and the standardized safety work orders are located and assigned according to the responsible department of the asset in the asset risk list or preset rules. The process engine tracks the risk handling process of the standardized safety work order and its verification, and automatically escalates the alarm when it times out. The standardized safety work order is automatically closed after its status is marked as repaired and verified, thus completing the closed loop.

7. The power asset risk perception method based on multi-dimensional time series and large model according to claim 1, characterized in that, The power asset risk perception method based on multi-dimensional time series and large model also includes: Acquire multi-dimensional time-series data reflecting the safety status of the power system; The comprehensive threat score that changes over time is calculated based on the aforementioned multi-dimensional time-series data; Based on the comprehensive threat score, a threat time series is constructed, and a multi-scale time analysis model is used to predict it; Security threats are identified based on prediction results and anomaly detection algorithms, and threat alerts and situation reports are generated. The threat alerts and / or situation reports, together with the asset risk list, work in conjunction with the decision-making and scheduling of risk management.

8. The power asset risk perception method based on multi-dimensional time series and large model according to claim 7, characterized in that, The calculation of the comprehensive threat score over time based on the multi-dimensional time-series data includes: Multiple characteristic attribute dimensions related to vulnerabilities and attacks in power information systems are defined to form a set of characteristic attributes. The characteristic attribute dimensions include at least one of the following: connection environment, attack complexity, whether there are permission requirements, whether user interaction is required, scope of impact, number of affected targets, existing patch, exploitable code verification, environmental dependence, and source credibility. The value range of each characteristic attribute dimension is simplified based on predefined key values. Based on the simplified value range, data corresponding to each feature attribute dimension is collected from the multi-dimensional time series data; The data for each feature attribute dimension collected is scored to obtain the score value for each dimension; The scores for each dimension are aggregated and calculated using predefined statistical functions to obtain the comprehensive threat score for each sampling time point.

9. An electronic device, characterized in that, include: Processor and memory; wherein the memory is used to store computer programs that can run on the processor; A processor is used to execute a program stored in memory to implement the steps of the power asset risk perception method based on multi-dimensional time series and large model as described in any one of claims 1-8.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the power asset risk perception method based on multi-dimensional time series and large model as described in any one of claims 1 to 8.

Citation Information

Cited By

  • Intelligent tracing and automatic detection method and system for vulnerability of power information system based on LLM

    CN122174245A

  • A low-code change impact analysis method and system

    CN122364100A