Dynamic risk early warning method and system oriented to cross-network and cross-domain

By constructing a cross-network and cross-domain business topology association model and differentiated risk assessment, the problem of accuracy in early warning of power grid business risks in cross-network and cross-domain environments has been solved, achieving transparent management and control of cross-layer resources and dynamic and accurate early warning, thereby improving the security assurance capabilities of key power grid businesses.

CN121814539APending Publication Date: 2026-04-07STATE GRID HEBEI ELECTRIC POWER CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-01
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

In cross-network and cross-domain environments, existing risk warning systems face the problem of data silos, which leads to limited warning scope and single evaluation standards. This results in insufficient warning accuracy, an inability to accurately trace the root cause of failures, and the underreporting or over-warning of risks in critical business operations, posing security risks.

Method used

By acquiring performance and topology data of transmission and data networks, a business topology association model is constructed and updated to generate business profiles, conduct differentiated risk analysis, realize cross-network and cross-domain collaborative early warning, break down data silos, accurately depict the mapping dependency relationship between business logic paths and underlying transmission channels, and conduct differentiated dynamic risk assessment and collaborative early warning.

Benefits of technology

It significantly reduced the false alarm and false alarm rates, improved the accuracy of power grid business risk warning in cross-grid and cross-domain environments, and comprehensively enhanced the security assurance capabilities for key power grid businesses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121814539A_ABST
    Figure CN121814539A_ABST
Patent Text Reader

Abstract

The invention provides a cross-network and cross-domain-oriented dynamic risk early warning method and system, and relates to the technical field of power grids. According to the method, the performance and topological data of the transmission network and the data network are acquired, and the service topological association model is constructed and dynamically updated, so that cross-network and cross-domain data islands are broken, comprehensive risks of the data are realized, the mapping dependency relationship of a service logic path on a bottom transmission channel is accurately described, and transparent management and control of cross-layer resources are realized; on this basis, risk assessment is carried out by using a service portrait including a service type and a real-time operation state, so that simple network performance early warning is jumped to service influence level early warning; finally, differentiated dynamic risk assessment and collaborative early warning are carried out, and dynamic accurate early warning and disposal which are different from services are realized, so that the false alarm rate and the missing report rate are remarkably reduced in a complex cross-network and cross-domain environment, the accuracy of power grid service risk early warning in the cross-network and cross-domain environment is improved, and the safety guarantee capability of power grid key services is comprehensively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power grid technology, and in particular to a dynamic risk early warning method and system for cross-grid and cross-domain applications. Background Technology

[0002] With the continuous improvement of the intelligence level of power systems, the operation and management of power grids increasingly rely on extensive and complex dedicated communication networks. These networks typically consist of a transmission network (including the optical and transport layers) responsible for the transmission of underlying optical signals and a data network (IP layer) carrying the forwarding of upper-layer data packets, forming a typical "cross-network" architecture. Simultaneously, core services supporting power grid production and control, such as relay protection, energy management, and wide-area measurement, often require data flows to traverse multiple network areas managed by different agencies, achieving "cross-domain" transmission.

[0003] In this complex cross-network and cross-domain environment, existing risk warning systems face two prominent technical bottlenecks. One is the limited scope of warnings due to data silos. Transmission networks and data networks typically employ independent management systems, with performance data, topology information, and alarm events being fragmented and lacking a unified perspective for correlation analysis. For example, bit error rate degradation in the transmission network's optical path and the corresponding routing congestion alarm in the data network are considered isolated events under current technology and cannot be effectively correlated. This incomplete cross-network and cross-domain data analysis makes it difficult for the system to accurately trace the root cause of faults, hindering risk warning.

[0004] On the other hand, the lack of accuracy in early warning stems from the reliance on a single assessment standard. Existing risk assessment methods often employ generic models based on fixed thresholds, failing to adequately consider the significant differences in functional importance, safety tolerance, and traffic characteristics among various power services. For example, relay protection services, which are extremely sensitive to latency jitter, and video surveillance services, which have high requirements for bandwidth stability, will exhibit drastically different actual risk levels when encountering the same network fluctuations. Traditional methods neglect the need for different risk assessment standards for different services, adopting a one-size-fits-all early warning strategy. This leads to excessive early warnings for non-critical services, generating numerous invalid alarms, or underreporting risks in critical services, creating serious security vulnerabilities.

[0005] Currently, the accuracy of early warning for power grid business risks in cross-network and cross-domain environments needs to be improved. Summary of the Invention

[0006] This invention provides a dynamic risk early warning method and system for cross-network and cross-domain environments, which solves the problem of low accuracy of power grid business risk early warning in cross-network and cross-domain environments and improves the accuracy of power grid business risk early warning in cross-network and cross-domain environments.

[0007] In a first aspect, the present invention provides a dynamic risk early warning method for cross-network and cross-domain applications. The method includes: acquiring performance data and topology data of the transmission network and data network in the target area power grid; updating the cross-network and cross-domain service topology association model based on the topology data; the service topology association model characterizing the mapping dependency between the service logical paths of the data network and the transmission channels of the transmission network; generating a service profile of the target service based on the performance data and the updated service topology association model, the service profile including service type and real-time operating status; performing differentiated risk analysis based on the performance data, service profile, and risk assessment standards for each service type to determine the dynamic risk value of the target service; and conducting cross-network and cross-domain collaborative early warning based on the dynamic risk value of the target service.

[0008] Secondly, embodiments of the present invention provide a dynamic risk early warning device for cross-network and cross-domain applications. The device includes a communication module and a processing module. The communication module is used to acquire performance data and topology data of the transmission network and data network in the target area power grid. The processing module is used to update a cross-network and cross-domain service topology association model based on the topology data. The service topology association model represents the mapping dependency between the service logical path of the data network and the transmission channel of the transmission network. Based on the performance data and the updated service topology association model, a service profile of the target service is generated, including the service type and real-time operating status. Based on the performance data and the service profile, as well as the risk assessment standards for each service type, differentiated risk analysis is performed to determine the dynamic risk value of the target service. Based on the dynamic risk value of the target service, cross-network and cross-domain collaborative early warning is performed.

[0009] Thirdly, embodiments of the present invention provide an electronic device including a memory and a processor. The memory stores a computer program, and the processor is configured to call and run the computer program stored in the memory to perform the steps of the method as described in the first aspect and any possible implementation thereof.

[0010] Fourthly, embodiments of the present invention provide a computer-readable storage medium storing a computer program, characterized in that, when the computer program is executed by a processor, it implements the steps of the method as described in the first aspect and any possible implementation thereof.

[0011] This invention provides a dynamic risk early warning method and system for cross-network and cross-domain applications. By acquiring performance and topology data from transmission and data networks and constructing and dynamically updating a business topology association model, this invention breaks down data silos across networks and domains, achieving comprehensive data risk assessment and accurately depicting the mapping dependency of business logic paths on underlying transmission channels, thus realizing transparent management and control of cross-layer resources. Based on this, risk assessment is conducted using business profiles that include business types and real-time operating status, moving from simple network performance early warning to early warning at the business impact level. Finally, differentiated dynamic risk assessment and collaborative early warning are performed, enabling dynamic and accurate early warning and handling tailored to different business needs. This significantly reduces false alarms and missed alarms in complex cross-network and cross-domain environments, improves the accuracy of power grid business risk early warning in such environments, and comprehensively enhances the security assurance capabilities for critical power grid businesses. Attached Figure Description

[0012] To more clearly illustrate the technical solutions in the embodiments of the present invention, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0013] Figure 1 This is a flowchart illustrating a dynamic risk warning method for cross-network and cross-domain scenarios provided in an embodiment of the present invention. Figure 2 This is a schematic diagram of a backbone communication network structure provided in an embodiment of the present invention; Figure 3 This is a schematic diagram of the structure of a dynamic risk early warning device for cross-network and cross-domain applications provided in an embodiment of the present invention; Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0014] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of the invention. However, those skilled in the art will understand that the invention can be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods are omitted so as not to obscure the description of the invention with unnecessary detail.

[0015] In the description of this invention, unless otherwise stated, " / " means "or". For example, A / B can mean A or B. The term "and / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone. Furthermore, "at least one" and "more than one" refer to two or more. The terms "first," "second," etc., do not limit the quantity or order of execution, and "first," "second," etc., do not necessarily imply differences.

[0016] In the embodiments of this application, the terms "exemplary" or "for example" are used to indicate that something is an example, illustration, or description. Any embodiment or design that is described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design. Specifically, the use of terms such as "exemplary" or "for example" is intended to present the relevant concepts in a specific manner to facilitate understanding.

[0017] Furthermore, the terms "comprising" and "having," and any variations thereof, used in the description of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or modules is not limited to the steps or modules listed, but may optionally include other steps or modules not listed, or may optionally include other steps or modules inherent to such process, method, product, or device.

[0018] To make the objectives, technical solutions, and advantages of the present invention clearer, the following description will be provided in conjunction with the accompanying drawings and specific embodiments.

[0019] like Figure 1 As shown, this embodiment of the invention provides a dynamic risk warning method for cross-network and cross-domain applications. The method includes steps S101-S105.

[0020] S101. Obtain performance data and topology data of the transmission network and data network in the target area power grid.

[0021] In some embodiments, performance data refers to quantitative indicators reflecting network operational quality, including optical layer performance parameters of the transmission network and IP layer performance parameters of the data network. Topology data refers to structured data describing the physical and logical connections of the network, including connection relationships between network devices, link attributes, and path configuration information. Target area power grid: refers to the power communication network system formed within a specific geographical area, including two heterogeneous network domains: the transmission network and the data network.

[0022] For example, embodiments of the present invention can achieve multi-source data collection through performance probes deployed on optical conversion equipment in the transmission network and traffic mirroring interfaces of core routers and switches in the data network. Transmission network performance data includes optical layer parameters such as optical power, signal-to-noise ratio, and bit error rate; data network performance data includes network layer parameters such as IP packet latency, jitter, and packet loss rate. Topology data is obtained from both the transmission network management system and the data network management system, including the physical connection relationships of transmission channels and the logical interconnection topology of data network nodes.

[0023] like Figure 2 As shown in the figure, an embodiment of the present invention provides a schematic diagram of a backbone communication network structure. Figure 2 Each circle in the diagram represents a station. The backbone of this communication network is typically composed of a dual-fiber ring network. This is mainly because the backbone has high requirements for network reliability and latency. Stations on the ring are generally dispatch centers, monitoring centers, power plants, and substations—sites with high reliability and latency requirements. In the branch networks of the entire backbone communication network, star network structures and link network structures are generally used. These branches outside the rings are generally small substations with lower requirements for network reliability and latency, and have little impact on the overall communication network.

[0024] S102. Based on topology data, update the cross-network and cross-domain business topology association model.

[0025] In this embodiment, the service topology association model represents the mapping dependency between the service logic path of the data network and the transmission channel of the transmission network.

[0026] In some embodiments, mapping dependencies refer to the bearer relationship between a business logic path and the underlying transmission channel, including two types: exclusive dependencies and shared dependencies. Cross-network / cross-domain: refers to collaborative operations between network domains involving two different technical systems: transmission networks and data networks.

[0027] As one possible implementation, step S102 can be specifically implemented as steps S1021-S1024.

[0028] S1021. Based on the topology data of the transmission network, determine the physical devices and logical link information of the transmission channels of the transmission network.

[0029] In some embodiments, a transmission channel refers to a logical channel in a transmission network that provides end-to-end transmission services for services. Physical device: refers to the hardware device entity that constitutes the transmission channel. Logical link: refers to the logical connection relationship established between physical devices.

[0030] For example, embodiments of the present invention can extract the composition information of the transmission channel by parsing the topology data provided by the transmission network management system, including physical devices such as optical transceivers, optical amplifiers, and optical cross-connect devices, as well as the optical fiber connection relationships between devices. Simultaneously, the logical link attributes of the transmission channel are identified, including parameters such as link capacity, available bandwidth, and link status. Through structured processing of the topology data, a complete resource list for the transmission channel is established.

[0031] S1022. Based on the topology data of the data network, determine the network nodes and routing information that carry the business logic path in the data network.

[0032] In some embodiments, a service logic path refers to an end-to-end forwarding path established in a data network for a specific service. A network node refers to a network device in a data network that handles service forwarding. Routing information refers to the forwarding path information of service flows in the data network.

[0033] For example, embodiments of the present invention can identify network nodes carrying business logic paths, including devices such as routers and switches, by parsing topology data provided by the data network management system. Simultaneously, routing information of the business flow is extracted, including the sequence of network nodes traversed by the path, link utilization, and routing policies. Real-time routing table information is obtained through a topology discovery protocol to ensure the accuracy and timeliness of the routing information.

[0034] S1023. Based on the network node and routing information carrying the business logic path, as well as the physical device and logical link information of the transmission channel, the mapping dependency between the business logic path and the transmission channel is determined through a path matching algorithm.

[0035] In some embodiments, path matching algorithm refers to a matching algorithm that identifies the correspondence between business logic paths and transmission channels. Spatiotemporal feature matching refers to path similarity matching based on time and spatial features.

[0036] For example, step S1023 can be specifically implemented as steps A1-A4.

[0037] A1. Construct a unified cross-network topology graph with network nodes as vertices and logical link information as edges.

[0038] In some embodiments, logical link information refers to descriptive information about the logical connections established between network devices, including link attributes and connection status. A unified cross-network topology map refers to a graphical data model that uniformly represents the topology information of both the transport network and the data network.

[0039] For example, embodiments of the present invention can construct a unified network topology representation model by integrating the topology information of the transmission network and the data network. Physical devices such as optical cross-connect devices in the transmission network and routers and switches in the data network are abstracted as topology vertices, and fiber optic connections, logical channels, and data links between devices are abstracted as topology edges. Each vertex contains attributes such as device type, management domain, and geographical location, while each edge contains parameters such as link type, bandwidth capacity, and current load. Through topology abstraction, a unified topology structure supporting cross-network path analysis is formed, providing a foundation for subsequent path discovery and feature matching.

[0040] A2. In the cross-network unified topology map, perform end-to-end path discovery for business logic paths and determine the data forwarding trajectory of business logic paths.

[0041] In some embodiments, end-to-end path discovery refers to the process of completely identifying the network path traversed by a service flow from its origin to its destination. Data forwarding trajectory refers to the sequence of network nodes and links that a service data packet passes through during transmission in the network. Graph traversal algorithm refers to a search algorithm that systematically visits all connected nodes in a topology graph.

[0042] For example, embodiments of the present invention can be based on a unified topology graph and employ a graph traversal algorithm to trace the service flow hop-by-hop along the logical link from the service source node to the destination node, thus completely reconstructing the actual forwarding path of the service flow. During path discovery, routing strategies, load balancing strategies, and traffic engineering constraints are comprehensively considered to accurately identify each intermediate node and transmission link traversed by the service flow. For complex service flows with multiple parallel paths, all possible forwarding paths are identified simultaneously, forming a complete set of data forwarding trajectories.

[0043] A3. Perform spatiotemporal feature matching between the data forwarding trajectory and the physical devices and logical link information of each transmission channel to determine the path matching result.

[0044] In some embodiments, spatiotemporal features include path delay and shared risk link group information; path matching results include a set of transmission channels associated with the business logic path, as well as the spatiotemporal feature matching degree, dependency type, and dependency strength of each transmission channel; dependency strength characterizes the proportion of resource occupancy or the degree of fault impact of the business logic path on the transmission channel.

[0045] In some embodiments, path delay refers to the time delay experienced by a data packet from the source node to the destination node. Shared risk link group information refers to the packet identification information of optical fibers or links that share the same physical risk.

[0046] For example, embodiments of the present invention can use a multi-dimensional feature comparison algorithm to accurately match the data forwarding trajectory of the business logic path with the physical path of the transmission channel. Spatiotemporal feature matching includes two dimensions: temporal feature matching and spatial feature matching. Temporal feature matching analyzes the consistency between the end-to-end delay of the business flow and the cumulative delay of the transmission channel by comparing path delay characteristics. Spatial feature matching identifies the co-location risk of the business path and the transmission channel on the physical infrastructure by analyzing the overlap of shared risk link groups. A confidence assessment mechanism is used during the matching process to quantify the reliability of the matching results.

[0047] A4. Based on the path matching results, determine the mapping dependency between the business logic path and one or more transmission channels.

[0048] For example, embodiments of the present invention can establish a precise mapping relationship between business logic paths and transmission channels based on the degree of matching of spatiotemporal features in the path matching results. For path pairs with high matching confidence, a strong mapping dependency is established; for path pairs with partial feature deviations, a weak mapping dependency is established. Simultaneously, the type of dependency is identified, distinguishing between exclusive dependencies and shared dependencies. The dependency strength is quantified based on the resource occupancy ratio or fault impact of the business logic path on the transmission channel, providing an accurate topological dependency basis for subsequent risk assessment.

[0049] S1024. Based on the mapping dependency between business logic paths and transmission channels, determine the updated business topology association model.

[0050] For example, embodiments of the present invention can persistently store the identified mapping dependencies in a business topology association model. Graph database technology is used to maintain multi-layered associations between business logic paths and transmission channels, supporting efficient topology queries and path tracing. When the network topology changes, the affected mapping relationships are locally updated through an incremental update mechanism to ensure that the model remains consistent with the actual situation.

[0051] S103. Based on performance data and the updated business topology association model, generate a business profile for the target business.

[0052] In this embodiment of the application, the business profile includes the business type and the real-time operating status.

[0053] In some embodiments, service type refers to a category classified according to the functional characteristics of the service, including relay protection service, energy management system service, and electricity consumption information collection service, etc. Real-time operating status: refers to dynamic indicators reflecting the current operating quality of the service, including traffic characteristics, transmission quality, and reliability indicators.

[0054] As one possible implementation, step S103 can be specifically implemented as steps S1031-S1035.

[0055] S1031. Based on the updated business topology association model, identify the business logic path and underlying transmission channel on which the target business depends.

[0056] In some embodiments, the underlying transmission channel refers to the optical path or transmission link that provides physical support for upper-layer services at the transmission network level.

[0057] For example, step S1031 can be specifically implemented as steps B1-B4.

[0058] B1. Using the business identifier of the target business as input, query the updated business topology association model to obtain the path identifiers of all business logic paths carrying the target business.

[0059] For example, embodiments of the present invention can retrieve all path records related to a service in a service topology association model using a service identifier. The query process employs an efficient index-based retrieval mechanism to quickly locate the relevant entries for the service in the model. The retrieval results return unique identifiers for all business logical paths used by the service in the current network environment, providing an entry point for subsequent detailed path analysis.

[0060] B2. For the path identifier of each business logic path, in the updated business topology association model, the network nodes and logical links traversed by each business logic path are parsed hop by hop using a graph traversal algorithm.

[0061] In some embodiments, a graph traversal algorithm refers to an algorithm that systematically visits all connected nodes in a topology graph. Hop-by-hop parsing refers to the process of sequentially analyzing each connection segment on a path. Path topology description refers to a complete description of the network nodes and links traversed by the path.

[0062] For example, embodiments of the present invention can perform a graph traversal operation on each path identifier, starting from the starting node of the path and visiting each network node and connection link on the path hop by hop along the topological connection relationship. During the traversal, the device attributes of each node and the connection characteristics of each link are recorded to construct a complete topological description of the path. For complex multi-path scenarios, a depth-first or breadth-first strategy is adopted to ensure that all possible path branches are fully explored.

[0063] B3. Based on the network nodes and logical links traversed by each business logical path, query the mapping dependencies in the updated business topology association model to determine the channel identifier of the underlying transmission channel carrying each logical link.

[0064] For example, embodiments of the present invention can query the mapping relationship between each identified logical link and the underlying transmission channel in the service topology association model. Through the mapping dependency table, all transmission channels supporting data transmission for that logical link are found. The query results return the unique identifier of the transmission channel, as well as the channel's key attribute information, establishing a complete mapping chain from the data network logical link to the transmission network physical channel.

[0065] B4. Aggregate the path identifier of each business logic path and the channel identifier of the underlying transmission channel to generate an end-to-end resource dependency list for the target business.

[0066] In some embodiments, the end-to-end resource dependency list includes business logic paths and underlying transport channels, referring to a detailed list of network resources that a business depends on.

[0067] For example, embodiments of the present invention can integrate and merge the path identifiers and channel identifiers obtained in the preceding steps, remove duplicate entries, and establish a complete dependency graph between services and network resources. The generated resource dependency list is organized in a hierarchical structure, clearly showing the bearer relationship between the service logic path and the underlying transmission channel. This list serves as an authoritative record of service resource dependencies, providing accurate basic data for subsequent risk impact scope analysis.

[0068] S1032. Based on performance data, extract the sequence of performance indicators associated with the business logic path and underlying transmission channel on which the target service depends.

[0069] In some embodiments, a performance metric sequence refers to a sequence of performance measurements arranged in chronological order. Performance data association refers to the process of establishing a correspondence between performance data and specific network resources. Temporal characteristics refer to the sequential and continuous characteristics of data over time.

[0070] For example, embodiments of the present invention can retrieve performance data records related to identified business logic paths and transmission channels from a performance data warehouse. Performance metrics are organized chronologically to form a sequence of metrics with time-series characteristics. For business logic paths, performance metrics at the data network layer are extracted; for underlying transmission channels, performance metrics at the transmission network layer are extracted. Time window alignment technology ensures that performance data from different sources remain consistent over time.

[0071] S1033. Based on the preset business feature library and performance indicator sequence, the business type of the target business is determined through a classification algorithm.

[0072] The business types include relay protection services, energy management system services, and electricity consumption information collection services.

[0073] In some embodiments, a business feature library refers to a knowledge base that stores templates of typical features for various businesses. A classification algorithm refers to an intelligent algorithm that automatically identifies business categories based on input features.

[0074] For example, step S1033 can be specifically implemented as steps C1-C3.

[0075] C1. Extract multi-dimensional feature vectors for business classification from the performance index sequence.

[0076] In some embodiments, the multidimensional feature vector includes source IP address, destination IP address, source port number, destination port number, periodicity pattern characteristics of service traffic, packet length distribution characteristics, and transmission delay and jitter range.

[0077] For example, embodiments of the present invention can perform feature engineering on the collected performance indicator sequences to extract a feature set with class distinguishing capabilities. Communication endpoint features include network layer features such as source and destination IP addresses and port numbers; traffic pattern features are obtained by analyzing the periodicity and burstiness of service traffic; data packet features include the distribution characteristics of statistical packet lengths; transmission quality features include performance indicators such as latency and jitter. The extracted feature vectors are standardized to eliminate the influence of different feature units.

[0078] C2. Match the multidimensional feature vector with the standard feature templates of various business types pre-stored in the business feature library to obtain the type matching result.

[0079] In some embodiments, the type matching result includes the probability that the target business belongs to each business type.

[0080] For example, embodiments of the present invention can calculate the similarity between the extracted feature vectors and standard templates in a business feature library. A multi-dimensional weighted similarity algorithm is employed to comprehensively consider the differences in the contribution of different features to business type determination. The matching process calculates the matching score between the business to be classified and each standard business type, forming a set of type matching results. The matching results include a probability estimate of whether the business belongs to each predefined type, providing a quantitative basis for the final type determination.

[0081] C3. Based on the type matching results, determine the business type of the target business.

[0082] For example, embodiments of the present invention can determine the final business type based on the probability distribution in the type matching results, using the principle of maximum probability. For cases where the probability distribution is relatively even, a multi-classifier fusion mechanism is activated, combining the outputs of multiple classification models for a comprehensive judgment. The judgment result undergoes a confidence assessment; only judgments reaching a confidence threshold are adopted, otherwise they are marked as unknown types for manual confirmation. The final determined business type, along with the confidence information, is output for subsequent risk assessment.

[0083] S1034. Based on the performance indicator sequence, determine the real-time operating status of the target service.

[0084] In some embodiments, real-time operating status includes mean traffic, traffic variance, communication interruption frequency, and transmission delay jitter, indicating the operational quality of the service at the current moment. Traffic characteristic parameters refer to statistical quantities describing the characteristics of service traffic. Transmission quality indicators refer to quantitative parameters reflecting the transmission performance of the service.

[0085] For example, embodiments of the present invention can calculate state parameters reflecting the quality of service operation by statistically analyzing a series of performance indicators. The mean traffic reflects the average data rate of the service flow, the traffic variance characterizes the burstiness of the service flow, the communication interruption frequency records the stability of the service connection, and the transmission delay jitter measures the uniformity of service transmission. Each state parameter is updated in real time through a sliding time window mechanism to ensure that dynamic changes in the service operation status can be captured promptly.

[0086] S1035. Generate a business profile for the target business based on the business type and real-time operating status.

[0087] For example, embodiments of the present invention can integrate business type determination results with real-time operational status parameters to construct a structured business profile data object. The business profile adopts a unified descriptive framework, including information from multiple dimensions such as basic business attributes, type characteristics, operational status indicators, and resource dependencies. The generated business profile serves as the basic input for subsequent risk assessment, providing a comprehensive description of business characteristics for differentiated risk analysis.

[0088] S104. Based on performance data and business profiles, as well as risk assessment standards for each business type, conduct differentiated risk analysis to determine the dynamic risk value of the target business.

[0089] For example, embodiments of the present invention may first calculate network infrastructure risk factors, including performance degradation degree and failure probability, wherein the performance degradation degree is calculated by the deviation of real-time performance indicators from historical baselines. Simultaneously, operational status risk factors are calculated based on the real-time operational status in the service profile. Then, corresponding assessment strategies, including basic risk weights and risk fusion weights, are matched from a risk assessment standard library according to the service type. Finally, an initial risk value is calculated through weighted fusion and corrected based on the changing trends of the risk factors to obtain a dynamic risk value.

[0090] As one possible implementation, step S104 can be specifically implemented as steps S1041-S1045.

[0091] S1041. Based on performance data, calculate the network infrastructure risk factors of the business logic path and transmission channel on which the target service depends.

[0092] In some embodiments, the network infrastructure risk factor refers to a comprehensive indicator that quantifies the risk level of the underlying network infrastructure, including performance degradation and failure probability. Performance degradation characterizes the degree of deviation between performance data and historical performance data, that is, the degree of deviation of current performance from historical normal levels. Failure probability refers to the estimate of the likelihood of network equipment or links failing.

[0093] For example, embodiments of the present invention can calculate risk factors reflecting the health of infrastructure by analyzing performance data of network paths and transmission channels on which services depend. Performance degradation is obtained by comparing the deviation of real-time performance indicators from historical baseline data, and an abnormal fluctuation in performance indicators is identified using a sliding time window statistical method. Failure probability is calculated using a probabilistic risk assessment model based on multi-dimensional information such as equipment runtime, historical failure records, and environmental factors. The calculation process comprehensively considers the performance indicators of both the transmission network and the data network to ensure that the risk factors fully reflect the operational status of the cross-network infrastructure.

[0094] S1042. Calculate the operational status risk factor based on the real-time operational status in the business profile.

[0095] In some embodiments, the operational status risk factor refers to a comprehensive indicator reflecting the real-time operational quality risk of a service, including a traffic stability risk component, a communication reliability risk component, and a transmission quality risk component. Traffic stability refers to the stability of service traffic over time. Transmission quality fluctuation refers to the changes in quality parameters during service transmission.

[0096] For example, embodiments of the present invention can extract real-time operational status parameters from service profiles to calculate risk components reflecting service operational quality. The traffic stability risk component identifies the suddenness and instability of service traffic by analyzing abnormal changes in the mean and variance of traffic; the communication reliability risk component assesses the reliability of service connections based on communication interruption frequency and historical connectivity data; and the transmission quality risk component measures the quality fluctuation of service transmission through latency jitter statistical characteristics.

[0097] S1043. Based on the business types in the business profile and the functional importance of each business type in the target area power grid, risk assessment standards corresponding to the target business are selected.

[0098] In some embodiments, risk assessment criteria include basic risk weights that characterize the importance of each risk factor, and risk fusion weights that characterize the importance of each risk factor; and parameter configuration and calculation rules for business risk calculation.

[0099] For example, embodiments of the present invention can retrieve corresponding assessment parameters from a pre-set risk assessment standard library based on the business type identifier. Basic risk weights are pre-set according to the functional importance and safety requirements of the business within the power grid system, with different basic risk levels corresponding to different business types. Risk fusion weights define the relative importance of each risk factor in the comprehensive assessment and are configured differently according to business characteristics. The selection of assessment standards fully considers the characteristics of power grid businesses, ensuring that key businesses receive appropriate risk attention.

[0100] S1044. Based on network infrastructure risk factors, operational status risk factors, and risk assessment standards corresponding to the target business, a weighted fusion is performed to determine the initial risk value of the target business.

[0101] For example, embodiments of the present invention can employ a multi-level weighted fusion algorithm to comprehensively calculate network infrastructure risk factors and operational status risk factors according to the weights defined in the risk assessment criteria. The fusion process first standardizes various risk factors to eliminate dimensional differences; then, it performs a weighted summation according to the specific fusion weights for each business type; finally, it is calibrated by combining the basic risk weights to obtain an initial risk value. The fusion algorithm ensures that the contribution of different types of risk factors is reasonably reflected.

[0102] S1045. Based on the initial risk value of the target business and the changing trends of various risk factors over a historical period, the initial risk value is corrected to obtain the dynamic risk value of the target business.

[0103] In some embodiments, risk trend analysis refers to the process of analyzing the patterns of change in risk indicators over time.

[0104] For example, step S1045 can be specifically implemented as steps D1-D5.

[0105] D1. Extract network infrastructure risk factors and operational status risk factors within a preset time window during historical periods, and generate historical data sequences.

[0106] In some embodiments, a set of risk factor observations arranged in chronological order from historical data sequences.

[0107] For example, embodiments of the present invention can extract time-series data of network infrastructure risk factors and operational status risk factors from a risk factor database within a preset time window range.

[0108] D2. Input the historical data sequence into the pre-trained Long Short-Term Memory network model to predict the predicted values ​​of each risk factor in the future period.

[0109] In some embodiments, the Long Short-Term Memory Network (LSTM) is a time-series data prediction model with memory function. Risk factor prediction: the process of inferring future risk conditions based on historical data.

[0110] For example, embodiments of the present invention can input preprocessed historical data sequences into a pre-trained Long Short-Term Memory (LSTM) network model, utilizing the model's temporal feature learning ability to predict changes in various risk factors over future periods. The prediction model generates a sequence of predicted risk factor values ​​by analyzing long-term dependencies and short-term fluctuation characteristics in historical data. The prediction process employs a rolling prediction mechanism, continuously updating the input data to ensure the timeliness of the prediction results.

[0111] D3. Based on the predicted values ​​of each risk factor, calculate the predicted risk value of the target business.

[0112] In some embodiments, the predicted risk value is a risk estimate calculated based on the predicted values ​​of risk factors.

[0113] For example, embodiments of the present invention can calculate the predicted risk value of a target business in future periods based on the predicted values ​​of each risk factor and according to the weight configuration defined in the risk assessment criteria. The calculation process refers to the fusion method of the initial risk values ​​to ensure the consistency of the predicted risk value and the initial risk value in the calculation logic. The predicted risk value reflects the potential risk level of the business in future periods.

[0114] D4. Determine the risk trend coefficient based on the difference between the predicted risk value and the initial risk value.

[0115] In some embodiments, the risk trend coefficient is an adjustment parameter that quantifies the trend of risk change. The degree of difference is a measure of the difference between the predicted value and the current value.

[0116] For example, embodiments of the present invention can quantify the development trend of risk by comparing the degree of difference between the predicted risk value and the initial risk value. The calculation of the trend coefficient comprehensively considers the absolute value of the difference and the relative rate of change, and uses a piecewise function mapping mechanism to convert the difference value into a standardized trend coefficient. An upward risk trend is assigned a coefficient greater than one, and a downward risk trend is assigned a coefficient less than one, thereby achieving a quantitative representation of the trend.

[0117] D5. The initial risk value is weighted and corrected based on the risk trend coefficient to obtain the dynamic risk value.

[0118] For example, in this embodiment of the invention, the risk trend coefficient can be used as a correction factor in this step to weight and adjust the initial risk value, generating the final dynamic risk value. The adjustment process uses coefficient multiplication to ensure that the change in risk value is proportional to the trend strength. For a strong deterioration trend, the risk value is increased significantly; for an improvement trend, the risk value is appropriately decreased. The final generated dynamic risk value reflects both the current risk situation and information on the risk development trend.

[0119] S105. Based on the dynamic risk value of the target business, conduct cross-network and cross-domain collaborative early warning.

[0120] As one possible implementation, step S105 can be specifically implemented as steps S1051-S1055.

[0121] S1051. Based on the dynamic risk value of the target business and the preset risk threshold range, match them to determine the early warning level of the target business.

[0122] In some embodiments, the warning level includes a notification level, a warning level, and an alarm level. Risk threshold range: refers to the range of risk values ​​that divides different warning levels. Warning level determination: refers to the decision-making process of determining the warning level based on the risk value.

[0123] For example, embodiments of the present invention can compare the calculated dynamic risk value with preset multi-level risk thresholds, and determine the corresponding early warning level based on the range of the risk value. The risk threshold range is set according to the requirements of power grid safe operation and the level of business importance, and different business types can adopt differentiated threshold configurations. The classification of early warning levels comprehensively considers the severity and urgency of the risk to ensure the scientific and practical nature of the early warning classification. The determination process adopts a hysteresis comparison mechanism to prevent frequent switching of early warning levels caused by fluctuations in the risk value near the threshold.

[0124] S1052. Based on the target business and early warning level, as well as the preset linkage strategy library, generate a cross-domain collaborative processing solution.

[0125] In some embodiments, the cross-domain collaborative processing scheme includes logging and visualizing the data, adding reserved backup resources and increasing monitoring frequency, or, forcibly switching optical paths and re-converging service routes. Linkage strategy library: refers to a knowledge base storing early warning and handling strategies.

[0126] For example, embodiments of the present invention can retrieve matching handling strategy templates from the linkage strategy library based on service characteristics and warning levels. For alert levels, a mild response plan focusing on monitoring and logging is configured; for warning levels, a preventative resource adjustment and monitoring enhancement plan is configured; and for alarm levels, an emergency protective operation and fault handling plan is configured. The strategy generation process fully considers the coordination requirements of the transmission network and data network to ensure the feasibility and effectiveness of the handling plan in a cross-network environment.

[0127] S1053. Based on the warning level of the target business and the cross-domain collaborative processing scheme, generate cross-domain collaborative warning instructions.

[0128] In some embodiments, the cross-domain collaborative early warning instruction includes the target business identifier, dynamic risk value, early warning level, timestamp, cross-domain collaborative processing scheme, and a list of affected resources.

[0129] For example, embodiments of the present invention can encapsulate early warning information and response plans into a standardized early warning instruction data structure. The early warning instruction includes complete identification information of the target service, accurate risk quantification value, clear early warning level identifier, accurate timestamp information, detailed response plan description, and a list of affected resources.

[0130] S1054. Through the cross-domain information bus, the cross-domain collaborative early warning instructions are distributed in parallel to the transmission network risk handling unit and the data network risk handling unit.

[0131] In some embodiments, a cross-domain information bus refers to an information transmission channel connecting different network domains. A parallel distribution mechanism refers to a distribution method that simultaneously sends information to multiple targets.

[0132] For example, embodiments of the present invention can employ a parallel distribution mechanism via a cross-domain information bus to simultaneously send warning instructions to the risk handling units of both the transmission network and the data network. The distribution process uses a reliable transmission protocol to ensure the timeliness and accuracy of the instructions. Upon receiving the instruction, the transmission network handling unit parses the transmission network-related operation content, and the data network handling unit parses the data network-related operation content. This parallel distribution mechanism ensures that both network domains can initiate handling processes simultaneously, achieving true cross-domain collaboration.

[0133] This invention provides a dynamic risk early warning method for cross-network and cross-domain applications. By acquiring performance and topology data of transmission and data networks and constructing and dynamically updating a business topology association model, it breaks down data silos across networks and domains, achieving comprehensive data risk assessment and accurately depicting the mapping dependency relationship between business logic paths and underlying transmission channels, thus realizing transparent management and control of cross-layer resources. Based on this, risk assessment is conducted using business profiles that include business types and real-time operating status, moving from simple network performance early warning to early warning at the business impact level. Finally, differentiated dynamic risk assessment and collaborative early warning are performed, enabling dynamic and accurate early warning and handling tailored to different business needs. This significantly reduces false alarms and missed alarms in complex cross-network and cross-domain environments, improves the accuracy of power grid business risk early warning in such environments, and comprehensively enhances the security assurance capabilities for critical power grid businesses.

[0134] Optionally, the dynamic risk warning method for cross-network and cross-domain applications provided in this embodiment of the invention further includes steps S201-S203 after step S105.

[0135] S201. After executing the collaborative warning, start timing. When the preset verification time window is reached, reacquire the performance data and topology data of the target business.

[0136] For example, embodiments of the present invention can immediately initiate a timing monitoring mechanism after completing cross-network and cross-domain collaborative early warning operations. This mechanism, based on a preset verification time window configuration, uses a countdown method to precisely control the timing of verifying the effectiveness of the early warning response. The length of the verification time window is differentiated according to the early warning level and service type; a shorter verification window is set for high-level early warnings and critical services to ensure timely evaluation of the response effectiveness. During the timing process, network status changes are continuously monitored to provide a time benchmark for subsequent verification analysis.

[0137] S202. Based on the reacquired performance and topology data of the target business, conduct a new differentiated risk analysis to obtain the verification risk value of the target business.

[0138] For example, in this embodiment of the invention, a data acquisition process can be automatically triggered when a preset verification time window is reached to reacquire the latest performance and topology data of the target service. Performance data acquisition covers real-time operational metrics of the business logic path and quality parameters of the transmission channel, while topology data acquisition focuses on changes in network connectivity. Based on the newly acquired data, a complete differentiated risk analysis process is executed, including steps such as updating the business topology association model, generating a business profile, and calculating risk factors, ultimately yielding a verified risk value. This process ensures that the risk assessment is based on the latest network status data.

[0139] S203. If the verified risk value is greater than the preset risk threshold, and the risk difference between the dynamic risk value and the verified risk value is less than the preset difference, then the warning level of the target business is increased.

[0140] For example, embodiments of the present invention can determine whether to raise the warning level through a dual-criteria mechanism. First, the verified risk value is compared with a preset risk threshold to confirm whether the risk level is still high; second, the degree of difference between the dynamic risk value and the verified risk value is calculated to determine whether the risk change trend is slowing down. When both conditions of persistently high risk and slowing down change are met simultaneously, it is determined that the initial warning level is insufficient, and the warning level escalation mechanism is automatically triggered. The escalation decision adopts a gradual adjustment strategy to avoid drastic fluctuations in the warning level.

[0141] Thus, this invention achieves a closed-loop evaluation of risk management effectiveness by establishing a post-early warning verification mechanism. Its technical advantage lies in its ability to promptly identify situations where management is inadequate, and to intelligently determine the necessity of escalating the early warning level through dual criteria, effectively preventing risk escalation. This design ensures that the early warning system can dynamically adapt to changes in risk, significantly improving the accuracy of early warnings and the effectiveness of management, forming a complete closed-loop management system of early warning, verification, and escalation.

[0142] Optionally, the dynamic risk warning method for cross-network and cross-domain applications provided in this embodiment of the invention further includes steps S301-S303 after step S105.

[0143] S301. Continuously collect complete data records of historical early warning events to form an early warning sample set.

[0144] In some embodiments, each record in the early warning sample set includes a business profile, the risk assessment criteria that were triggered, the cross-domain collaborative processing scheme, and the final rating of the handling effect.

[0145] For example, embodiments of the present invention can construct a sample dataset for machine learning training by continuously collecting complete data records of historical early warning events. Each sample record includes the business profile features of the early warning event, the triggered risk assessment standard parameters, the executed cross-domain collaborative processing scheme, and a comprehensive rating based on the handling effect. The sample data is organized in chronological order and labeled with the key feature attributes of the events, forming a training sample set with temporal characteristics. The data collection process employs an automated mechanism to ensure the completeness and accuracy of the samples.

[0146] S302. Based on the early warning sample set, with the optimization of the handling effect rating as the training objective, a reinforcement learning algorithm is used to conduct iterative learning and dynamically adjust the basic risk weights and risk fusion weights corresponding to various business types in the risk assessment standard library.

[0147] For example, embodiments of the present invention may employ a reinforcement learning algorithm, with the optimization of the handling effect rating as the training objective, to iteratively optimize the parameters in the risk assessment standard library. The learning process automatically adjusts the basic risk weights and risk fusion weights corresponding to each business type by analyzing the correlation between handling plans and effect ratings in the sample data. The optimization algorithm, based on the policy gradient method, gradually explores the optimal weight configuration scheme to ensure that the risk assessment standard can adapt to changes in the network environment and continuously improve the accuracy of early warnings.

[0148] S303. Based on the dynamically adjusted risk assessment standard library, perform dynamic risk value calculation and cross-network and cross-domain collaborative early warning.

[0149] For example, embodiments of the present invention can apply the optimized risk assessment standard library to a real-time dynamic risk early warning process. The system uses updated weight parameters when calculating dynamic risk values ​​to ensure that the risk assessment results more accurately reflect the actual risk situation. The collaborative early warning mechanism generates more effective response plans based on the optimized risk assessment standards, forming a closed loop for continuous improvement of early warning effectiveness. The update process employs hot-swapping technology to ensure that the standard library is upgraded and switched without system downtime.

[0150] Thus, this invention achieves self-optimization of risk assessment standards by introducing a reinforcement learning mechanism. Its technical effect lies in the system's ability to autonomously learn from historical warning events, continuously adjusting risk weight parameters to make risk assessment more accurate. This adaptive learning capability enables the system to continuously improve its warning performance, reduce false alarm and false negative rates, and significantly enhance the system's intelligence level and long-term reliability.

[0151] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0152] The following are device embodiments of the present invention. For details not described in detail, please refer to the corresponding method embodiments described above.

[0153] Figure 3 This diagram illustrates the structure of a dynamic risk warning device for cross-network and cross-domain applications provided by an embodiment of the present invention. The warning device 400 includes a communication module 401 and a processing module 402.

[0154] The communication module 401 is used to acquire performance data and topology data of the transmission network and data network in the target area power grid.

[0155] Processing module 402 is used to update the cross-network and cross-domain service topology association model based on topology data; the service topology association model represents the mapping dependency between the service logical path of the data network and the transmission channel of the transmission network; based on performance data and the updated service topology association model, a service profile of the target service is generated, which includes the service type and real-time operating status; based on performance data and service profile, as well as the risk assessment standards of each service type, differentiated risk analysis is performed to determine the dynamic risk value of the target service; based on the dynamic risk value of the target service, cross-network and cross-domain collaborative early warning is performed.

[0156] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. The electronic device 500 includes: a processor 501, a memory 502, and a computer program 503 stored in the memory 502 and executable on the processor 501. When the processor 501 executes the computer program 503, it implements the steps in the above-described method embodiments. Alternatively, when the processor 501 executes the computer program 503, it implements the functions of each module / unit in the above-described device embodiments.

[0157] For example, the computer program 503 may be divided into one or more modules / units, which are stored in the memory 502 and executed by the processor 501 to complete the present invention. The one or more modules / units may be a series of computer program instruction segments capable of performing specific functions, which describe the execution process of the computer program 503 in the electronic device 500.

[0158] The processor 501 may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.

[0159] The memory 502 can be an internal storage unit of the electronic device 500, such as a hard disk or memory of the electronic device 500. The memory 502 can also be an external storage device of the electronic device 500, such as a plug-in hard disk, smart media card (SMC), secure digital card (SD), flash card, etc., equipped on the electronic device 500. Furthermore, the memory 502 can include both internal and external storage units of the electronic device 500. The memory 502 is used to store the computer program and other programs and data required by the terminal. The memory 502 can also be used to temporarily store data that has been output or will be output.

[0160] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.

Claims

1. A dynamic risk early warning method for cross-network and cross-domain applications, characterized in that, include: Acquire performance and topology data of the transmission network and data network in the target area's power grid; Based on the aforementioned topology data, update the cross-network and cross-domain business topology association model; The business topology association model represents the mapping dependency between the business logic path of the data network and the transmission channel of the transmission network; Based on the performance data and the updated business topology association model, a business profile of the target business is generated, which includes the business type and real-time operating status. Based on the performance data and business profiles, as well as the risk assessment standards for each business type, differentiated risk analysis is conducted to determine the dynamic risk value of the target business. Based on the dynamic risk value of the target business, cross-network and cross-domain collaborative early warning is carried out.

2. The dynamic risk early warning method for cross-network and cross-domain applications according to claim 1, characterized in that, The step of updating the cross-network and cross-domain business topology association model based on the topology data includes: Based on the topology data of the transmission network, determine the physical devices and logical link information of the transmission channels of the transmission network; Based on the topology data of the data network, determine the network nodes and routing information that carry the business logic path in the data network; Based on the network node and routing information that carries the business logic path, as well as the physical device and logical link information of the transmission channel, the mapping dependency between the business logic path and the transmission channel is determined through a path matching algorithm. Based on the mapping dependency between business logic paths and transmission channels, the updated business topology association model is determined.

3. The dynamic risk early warning method for cross-network and cross-domain applications according to claim 2, characterized in that, The network node and routing information based on the business logic path, as well as the physical device and logical link information of the transmission channel, are used to determine the mapping dependency between the business logic path and the transmission channel through a path matching algorithm, including: Construct a unified cross-network topology graph with network nodes as vertices and logical link information as edges; In the cross-network unified topology map, end-to-end path discovery is performed for the business logic path to determine the data forwarding trajectory of the business logic path; The data forwarding trajectory is matched with the physical devices and logical link information of each transmission channel using spatiotemporal features to determine the path matching result. The spatiotemporal features include path delay and shared risk link group information. The path matching result includes the set of transmission channels associated with the business logic path, as well as the spatiotemporal feature matching degree, dependency type, and dependency strength of each transmission channel. The dependency strength characterizes the proportion of resource consumption or the degree of fault impact of the business logic path on the transmission channel. Based on the path matching results, the mapping dependency between the business logic path and one or more transmission channels is determined.

4. The dynamic risk early warning method for cross-network and cross-domain applications according to claim 1, characterized in that, The step of generating a business profile for the target business based on the performance data and the updated business topology association model includes: Based on the updated business topology association model, the business logic path and underlying transmission channel on which the target business depends are identified; Based on the performance data, extract a sequence of performance metrics associated with the business logic path and underlying transmission channel upon which the target service depends; Based on a preset business feature library and the performance index sequence, a classification algorithm is used to determine the business type of the target business; wherein, the business type includes relay protection business, energy management system business, and electricity consumption information collection business; Based on the performance index sequence, the real-time operating status of the target service is determined, including the average traffic, traffic variance, communication interruption frequency, and transmission delay jitter. Based on the business type and the real-time operating status, a business profile of the target business is generated.

5. The dynamic risk early warning method for cross-network and cross-domain applications according to claim 4, characterized in that, The method of identifying the business logic path and underlying transmission channel upon which the target service depends, based on the updated business topology association model, includes: Using the business identifier of the target business as input, query the updated business topology association model to obtain the path identifiers of all business logic paths carrying the target business; For each business logic path's path identifier, in the updated business topology association model, the network nodes and logical links traversed by each business logic path are parsed hop by hop using a graph traversal algorithm. Based on the network nodes and logical links traversed by each business logical path, query the mapping dependencies in the updated business topology association model to determine the channel identifier of the underlying transmission channel carrying each logical link. The path identifier of each business logic path and the channel identifier of the underlying transmission channel are aggregated to generate an end-to-end resource dependency list for the target business; the end-to-end resource dependency list includes the business logic path and the underlying transmission channel.

6. The dynamic risk early warning method for cross-network and cross-domain applications according to claim 4, characterized in that, The process of determining the business type of the target business based on a preset business feature library and the performance indicator sequence using a classification algorithm includes: From the performance index sequence, a multidimensional feature vector for service classification is extracted. The multidimensional feature vector includes source IP address, destination IP address, source port number, destination port number, periodicity pattern of service traffic, data packet length distribution, and transmission delay and jitter range. The multidimensional feature vector is matched with the standard feature templates of various business types pre-stored in the business feature library to obtain the type matching result, which includes the probability that the target business belongs to each business type; Based on the type matching results, the business type of the target business is determined.

7. The dynamic risk early warning method for cross-network and cross-domain applications according to claim 1, characterized in that, Based on the performance data and business profiles, as well as the risk assessment standards for each business type, differentiated risk analysis is conducted to determine the dynamic risk value of the target business, including: Based on the performance data, calculate the network infrastructure risk factors for the business logic path and transmission channel on which the target service depends; the network infrastructure risk factors include performance degradation degree and failure probability, and the performance degradation degree characterizes the degree of deviation between the performance data and historical performance data; Based on the real-time operating status in the business profile, the operating status risk factor is calculated, which includes traffic stability risk component, communication reliability risk component and transmission quality risk component. Based on the business types in the business profile and the functional importance of each business type in the target area power grid, risk assessment criteria corresponding to the target business are selected; the risk assessment criteria include basic risk weights that characterize the importance of each risk factor, and risk fusion weights that characterize the importance of each risk factor. Based on network infrastructure risk factors, operational status risk factors, and risk assessment standards corresponding to the target service, a weighted fusion is performed to determine the initial risk value of the target service. Based on the initial risk value of the target business and the changing trends of various risk factors over a historical period, the initial risk value is corrected to obtain the dynamic risk value of the target business.

8. The dynamic risk early warning method for cross-network and cross-domain applications according to claim 7, characterized in that, The process of revising the initial risk value based on the initial risk value of the target business and the changing trends of various risk factors over historical periods to obtain the dynamic risk value of the target business includes: Extract the network infrastructure risk factors and operational status risk factors within a preset time window in the historical period, and generate a historical data sequence; The historical data sequence is input into a pre-trained long short-term memory network model to predict the predicted values ​​of each risk factor in the future period. Based on the predicted values ​​of each risk factor, the predicted risk value of the target business is calculated; The risk trend coefficient is determined based on the difference between the predicted risk value and the initial risk value; The initial risk value is weighted and corrected based on the risk trend coefficient to obtain the dynamic risk value.

9. The dynamic risk early warning method for cross-network and cross-domain applications according to any one of claims 1 to 8, characterized in that, The cross-network and cross-domain collaborative early warning based on the dynamic risk value of the target service includes: Based on the dynamic risk value of the target service and the preset risk threshold range, a matching process is performed to determine the early warning level of the target service; the early warning level includes the prompt level, the warning level, and the alarm level. Based on the target business and early warning level, as well as the preset linkage strategy library, a cross-domain collaborative processing solution is generated. The cross-domain collaborative processing solution includes logging and visual display, adding reserved backup resources and increasing monitoring frequency, or, forced optical path switching and service routing re-convergence. Based on the warning level of the target business and the cross-domain collaborative processing scheme, a cross-domain collaborative warning instruction is generated. The cross-domain collaborative warning instruction includes the target business identifier, dynamic risk value, warning level, timestamp, cross-domain collaborative processing scheme, and list of affected resources. The cross-domain collaborative early warning instructions are distributed in parallel to the transmission network risk handling unit and the data network risk handling unit via the cross-domain information bus.

10. A dynamic risk early warning system for cross-network and cross-domain applications, characterized in that, The system includes an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor is configured to invoke and run the computer program stored in the memory to perform the method as described in any one of claims 1 to 9.