Strategy execution method and device, computer equipment, storage medium and product

By screening and implementing power system security policies across devices, and by optimizing policies using external threat data and system state parameters, the problem of insufficient protection in traditional power systems has been solved, enabling rapid response and effective protection of the power system.

CN121841673APending Publication Date: 2026-04-10CHINA SOUTHERN POWER GRID COMPANY
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA SOUTHERN POWER GRID COMPANY
Filing Date
2025-12-08
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

Traditional power system cybersecurity protection systems are inadequate in the face of complex network architectures and security threats, which may lead to the paralysis of critical business systems and affect the safe operation of the power grid.

Method used

This paper provides a policy execution method that obtains candidate security policies, selects target security policies that are suitable for the current situation of the power system, and executes them across devices. It uses external threat data and system status parameters to perform policy priority analysis and fine-tuning, and combines reinforcement learning network to generate policies to achieve rapid response and protection.

Benefits of technology

Without human intervention, the system ensures that the target security strategy conforms to the actual situation of the power system, enabling timely and effective protection and rapid response to threat events, thereby improving the network security of the power system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121841673A_ABST
    Figure CN121841673A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of electric power safety, in particular to a strategy execution method and device, computer equipment, a storage medium and a product. The method comprises the following steps: acquiring at least one candidate security policy for the power system; screening the candidate security policies to obtain a target security policy conforming to the current condition of the power system; and performing cross-device execution on the target security policy for the power system, thereby realizing screening for the target security policy without manual intervention, ensuring that the power system can timely and effectively perform protection for a threat event after executing the target security policy, and improving the security of the power system. The rapid and accurate response to the current threat event of the power system is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of power safety technology, and in particular to a strategy execution method, apparatus, computer equipment, storage medium, and product. Background Technology

[0002] With the widespread adoption of smart grids and industrial control systems, the network architecture of power systems is becoming increasingly complex, leading to a continuous increase in cybersecurity risks. Power systems are typically characterized by their distributed, hierarchical, and high real-time nature. Traditional cybersecurity protection systems often focus on independent protection of internal and external networks, using firewalls, intrusion detection systems, and other means to physically isolate different network areas.

[0003] Traditional power system protection measures are clearly inadequate in responding to security threats. If a security incident occurs, it may lead to the paralysis of critical business systems, thereby affecting the safe operation of the entire power grid. Summary of the Invention

[0004] Therefore, it is necessary to provide a strategy execution method, apparatus, computer equipment, storage medium, and product that can ensure the stable operation of the power system, addressing the aforementioned technical problems.

[0005] Firstly, this application provides a strategy execution method. The method includes:

[0006] Obtain at least one candidate security policy for the power system;

[0007] The candidate security strategies are screened to obtain the target security strategy that conforms to the current situation of the power system;

[0008] The target security policy is executed across devices within the power system.

[0009] In one embodiment, the step of filtering each of the candidate security strategies to obtain a target security strategy that conforms to the current situation of the power system includes:

[0010] Based on the external threat data of the power system, priority analysis is performed on each of the candidate security strategies to obtain the strategy priority corresponding to each of the candidate security strategies.

[0011] Based on the policy priority corresponding to each of the candidate security policies, a target security policy that conforms to the current situation of the power system is determined.

[0012] In one embodiment, determining the target security policy that conforms to the current situation of the power system based on the policy priority corresponding to each of the candidate security policies includes:

[0013] The candidate security policy with the highest priority among all the candidate security policies is taken as the reference security policy;

[0014] The reference security strategy is fine-tuned based on the equipment parameters of the internal equipment of the power system to obtain a target security strategy that conforms to the current situation of the power system.

[0015] In one embodiment, obtaining at least one candidate security policy for the power system includes:

[0016] Obtain system state parameters of the power system;

[0017] Based on the system state parameters, a security policy is generated to obtain at least one candidate security policy for the power system.

[0018] In one embodiment, obtaining at least one candidate security policy for the power system includes:

[0019] Based on a pre-set reinforcement learning network, a security policy is generated according to the system state parameters to obtain at least one candidate security policy for the power system.

[0020] In one embodiment, the method further includes:

[0021] After the power system executes the target security policy, the feedback data of the power system is obtained;

[0022] Based on the feedback data, a security event analysis is performed on the power system to obtain the probability of a security event occurring in the power system.

[0023] Secondly, this application also provides a strategy execution apparatus. The apparatus includes:

[0024] The acquisition module is used to acquire at least one candidate security policy for the power system.

[0025] The filtering module is used to filter the candidate security strategies to obtain the target security strategy that conforms to the current situation of the power system.

[0026] An execution module is used to perform the target security policy across devices within the power system.

[0027] Thirdly, this application also provides a computer device. The computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to perform the following steps:

[0028] Obtain at least one candidate security policy for the power system;

[0029] The candidate security strategies are screened to obtain the target security strategy that conforms to the current situation of the power system;

[0030] The target security policy is executed across devices within the power system.

[0031] Fourthly, this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, performs the following steps:

[0032] Obtain at least one candidate security policy for the power system;

[0033] The candidate security strategies are screened to obtain the target security strategy that conforms to the current situation of the power system;

[0034] The target security policy is executed across devices within the power system.

[0035] Fifthly, this application also provides a computer program product. The computer program product includes a computer program that, when executed by a processor, performs the following steps:

[0036] Obtain at least one candidate security policy for the power system;

[0037] The candidate security strategies are screened to obtain the target security strategy that conforms to the current situation of the power system;

[0038] The target security policy is executed across devices within the power system.

[0039] The aforementioned strategy execution method, apparatus, computer equipment, storage medium, and product acquire at least one candidate security strategy for the power system; screen each candidate security strategy to obtain a target security strategy that conforms to the current situation of the power system; and then execute the target security strategy across devices within the power system. This application, by screening each candidate security strategy, achieves the selection of a target security strategy, thereby obtaining a target security strategy that conforms to the current situation of the power system. This ensures that the determined target security strategy conforms to the actual situation of the power system, enables the screening of target security strategies without manual intervention, and ensures that the power system can effectively and promptly protect against threat events after executing the target security strategy, achieving rapid and accurate response to threat events currently occurring in the power system. Attached Figure Description

[0040] Figure 1 An application environment diagram of a strategy execution method provided in an embodiment of this application;

[0041] Figure 2 A flowchart illustrating the first strategy execution method provided in this application embodiment;

[0042] Figure 3 A flowchart illustrating the second strategy execution method provided in this application embodiment;

[0043] Figure 4 A flowchart illustrating the third strategy execution method provided in this application embodiment;

[0044] Figure 5 A flowchart illustrating the fourth strategy execution method provided in this application embodiment;

[0045] Figure 6 A structural block diagram of a strategy execution device provided in an embodiment of this application;

[0046] Figure 7 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0047] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0048] The strategy execution method provided in this application embodiment can be applied to, for example... Figure 1 In the application environment shown, terminal 102 communicates with server 104 via a network. A data storage system can store the data that server 104 needs to process. The data storage system can be integrated onto server 104 or placed on the cloud or other network servers. The system obtains at least one candidate security policy for the power system; filters these candidate policies to obtain a target security policy that fits the current situation of the power system; and then executes the target security policy across devices for the power system. Terminal 102 can be, but is not limited to, various personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices can include smart speakers, smart TVs, smart air conditioners, smart vehicle devices, etc. Portable wearable devices can include smartwatches, smart bracelets, head-mounted devices, etc. Server 104 can be implemented using a standalone server or a server cluster consisting of multiple servers.

[0049] In one embodiment, such as Figure 2 As shown, a strategy execution method is provided, which is applied to Figure 1 Taking server 104 as an example, the following steps are included:

[0050] S201, Obtain at least one candidate security policy for the power system.

[0051] The candidate security strategy includes at least one parameter setting for the power system, as well as usage parameters for different resources of the power system.

[0052] In one embodiment of this application, when it is necessary to obtain at least one candidate security strategy for a power system, the historical security strategy of the power system and the historical security strategy of a reference system can be obtained; wherein, the reference system refers to a system whose system similarity with the power system is greater than a similarity threshold; therefore, the historical security strategy of the power system and the historical security strategy of the reference system are used as usage parameters for different resources of the power system.

[0053] In one embodiment of this application, when it is necessary to obtain at least one candidate security strategy for a power system, the system state parameters of the power system can also be obtained; then, a security strategy is generated based on the system state parameters to obtain at least one candidate security strategy for the power system.

[0054] S202, the candidate security strategies are screened to obtain the target security strategy that conforms to the current situation of the power system.

[0055] In one embodiment of this application, when it is necessary to screen each candidate security strategy, the adaptability of each candidate security strategy to the power system can be determined. Then, the candidate security strategies are sorted in descending order of adaptability, and the candidate security strategy with the highest adaptability is taken as the target security strategy that conforms to the current situation of the power system.

[0056] In another embodiment of this application, when it is necessary to screen each candidate security strategy, the processing effect of each candidate security strategy on external threat data can also be determined, and then the candidate security strategy with the best processing effect can be taken as the target security strategy that conforms to the current situation of the power system.

[0057] S203, executes the target security policy across devices within the power system.

[0058] It should be noted that the target security policy is deployed to various network devices (such as firewalls, intrusion detection systems, gateways, etc.), and a cross-device collaboration mechanism ensures that the policy is executed synchronously across multiple protection devices. The platform distributes the policy to each device through inter-device communication protocols (such as REST API, SNMP, gRPC, etc.) and performs policy conflict detection to ensure that all devices execute a unified security policy.

[0059] In one embodiment of this application, the following algorithm can be used for policy conflict detection:

[0060] ;

[0061] in, and These are the protection rules for devices i and j, respectively. It is an indicator function that returns 1 if the rules intersect, indicating that a conflict exists.

[0062] To further explain, after the power system implements the target security strategy, the following may also be included: after the power system implements the target security strategy, obtaining feedback data from the power system; and conducting security event analysis on the power system based on the feedback data to obtain the probability of a security event occurring in the power system.

[0063] Specifically, security incidents can be analyzed using real-time threat assessment models (such as neural network-based classification models) corresponding to the following formulas:

[0064] ;

[0065] in, This represents the probability of a specific security event occurring at time t. Let w be the feature vector of the event, and w be the weight of the model. The system automatically adjusts protective measures based on the analysis results to improve protection effectiveness and provide support for post-event auditing. It outputs the real-time adjusted security policy to ensure the system can quickly respond to new security threats.

[0066] The aforementioned strategy execution method involves obtaining at least one candidate security strategy for the power system; screening these candidate strategies to obtain a target security strategy that conforms to the current situation of the power system; and then executing the target security strategy across devices within the power system. This application, by screening candidate security strategies, achieves the selection of a target security strategy, thereby obtaining a target security strategy that conforms to the current situation of the power system. This ensures that the determined target security strategy conforms to the actual situation of the power system, enables the screening of target security strategies without manual intervention, and guarantees that the power system can effectively and promptly protect against threat events after executing the target security strategy, achieving a rapid and accurate response to threat events currently occurring in the power system.

[0067] In one embodiment, such as Figure 3 As shown, when it is necessary to filter candidate security strategies to obtain a target security strategy that conforms to the current situation of the power system, the following can be included:

[0068] S301, based on the external threat data of the power system, performs priority analysis on each candidate security strategy to obtain the strategy priority corresponding to each candidate security strategy.

[0069] In one embodiment of this application, the following calculation formula is used to perform priority analysis on each candidate security strategy based on external threat data of the power system:

[0070] ;

[0071] in, This indicates the defensive decision at the current moment. The protection capability of the i-th device in the power system. Assign importance weights to equipment in the power system. This refers to the real-time status of equipment in a power system.

[0072] S302, determine the target security policy that conforms to the current situation of the power system based on the policy priority of each candidate security policy.

[0073] It should be noted that when it is necessary to determine the target security policy that conforms to the current situation of the power system based on the policy priority of each candidate security policy, the following may be included: taking the candidate security policy with the highest priority among the candidate security policies as the reference security policy; and fine-tuning the reference security policy according to the equipment parameters of the internal equipment of the power system to obtain the target security policy that conforms to the current situation of the power system.

[0074] In one embodiment of this application, the random forest algorithm can be used to implement policy fine-tuning operations for the reference security policy:

[0075] ;

[0076] in, This represents the generated decision function. This is the predicted output of the i-th decision tree. The weight of the tree.

[0077] The above-described strategy execution method determines the strategy priority of each candidate security strategy, thereby identifying the target security strategy that is suitable for the current situation of the power system based on the strategy priority of each candidate security strategy. This ensures that the determined target security strategy is in line with the actual situation of the power system and enables the screening of target security strategies without human intervention.

[0078] In one embodiment, such as Figure 4 As shown, when it is necessary to obtain at least one candidate security policy for a power system, the following may be included:

[0079] S401, obtain the system status parameters of the power system.

[0080] It should be noted that system status parameters may include, but are not limited to: network equipment parameters of the power system, system status of the power system, and service requirements of the power system.

[0081] S402, generate a security policy based on the system state parameters to obtain at least one candidate security policy for the power system.

[0082] It should be noted that when it is necessary to generate security policies based on system state parameters to obtain at least one candidate security policy for the power system, the following may be included: generating security policies based on system state parameters using a pre-set reinforcement learning network to obtain at least one candidate security policy for the power system.

[0083] ;

[0084] in, Representing state Take action value, As a reward value, For learning rate, This is the discount factor.

[0085] The above-mentioned strategy execution method obtains the system state parameters of the power system; it realizes the generation of security strategies based on the system state parameters, and obtains at least one candidate security strategy for the power system, providing a data foundation for the subsequent determination of the target security strategy and ensuring the smooth progress of subsequent processes.

[0086] In one embodiment, such as Figure 5 As shown, when it is necessary to enforce a target security policy across devices within a power system, the following may be included:

[0087] S501, obtain the system status parameters of the power system.

[0088] S502, based on a pre-set reinforcement learning network, generates security policies according to system state parameters, and obtains at least one candidate security policy for the power system.

[0089] S503 performs priority analysis on each candidate security strategy based on external threat data of the power system to obtain the strategy priority corresponding to each candidate security strategy.

[0090] S504 selects the candidate security policy with the highest priority among all candidate security policies as the reference security policy.

[0091] S505 adjusts the reference security policy based on the equipment parameters of the internal equipment of the power system to obtain a target security policy that conforms to the current situation of the power system.

[0092] S506 executes target security policies across devices within the power system.

[0093] S507 acquires feedback data from the power system after the power system executes the target security policy.

[0094] S508 analyzes security events in the power system based on feedback data to obtain the probability of security events occurring in the power system.

[0095] The aforementioned strategy execution method involves obtaining at least one candidate security strategy for the power system; screening these candidate strategies to obtain a target security strategy that conforms to the current situation of the power system; and then executing the target security strategy across devices within the power system. This application, by screening candidate security strategies, achieves the selection of a target security strategy, thereby obtaining a target security strategy that conforms to the current situation of the power system. This ensures that the determined target security strategy conforms to the actual situation of the power system, enables the screening of target security strategies without manual intervention, and guarantees that the power system can effectively and promptly protect against threat events after executing the target security strategy, achieving a rapid and accurate response to threat events currently occurring in the power system.

[0096] It should be understood that although the steps in the flowcharts of the above embodiments are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0097] Based on the same inventive concept, this application also provides a strategy execution apparatus for implementing the strategy execution method described above. The solution provided by this apparatus is similar to the implementation scheme described in the above method; therefore, the specific limitations in one or more strategy execution apparatus embodiments provided below can be found in the limitations of the strategy execution method described above, and will not be repeated here.

[0098] In one embodiment, such as Figure 6 As shown, a strategy execution device is provided, including: an acquisition module 10, a filtering module 20, and an execution module 30, wherein:

[0099] The acquisition module 10 is used to acquire at least one candidate security policy for the power system.

[0100] The filtering module 20 is used to filter the candidate security strategies to obtain the target security strategy that conforms to the current situation of the power system.

[0101] Execution module 30 is used to execute the target security policy across devices in the power system.

[0102] In one embodiment, priority analysis is performed on each candidate security strategy based on external threat data of the power system to obtain the strategy priority corresponding to each candidate security strategy.

[0103] Based on the policy priority of each candidate security policy, a target security policy that is suitable for the current situation of the power system is determined.

[0104] In one embodiment, the candidate security policy with the highest priority among all candidate security policies is used as the reference security policy;

[0105] The reference security strategy is fine-tuned based on the equipment parameters of the internal equipment of the power system to obtain a target security strategy that conforms to the current situation of the power system.

[0106] In one embodiment, system state parameters of the power system are obtained;

[0107] Security policies are generated based on system state parameters to obtain at least one candidate security policy for the power system.

[0108] In one embodiment, a security policy is generated based on a pre-set reinforcement learning network according to system state parameters, resulting in at least one candidate security policy for the power system.

[0109] In one embodiment, feedback data from the power system is acquired after the power system executes the target security policy;

[0110] Based on the feedback data, a security event analysis is performed on the power system to obtain the probability of a security event occurring in the power system.

[0111] The aforementioned strategy execution device acquires at least one candidate security strategy for the power system; filters each candidate security strategy to obtain a target security strategy that conforms to the current situation of the power system; and then executes the target security strategy across devices within the power system. This application, by filtering each candidate security strategy, achieves the selection of a target security strategy, thereby obtaining a target security strategy that conforms to the current situation of the power system. This ensures that the determined target security strategy conforms to the actual situation of the power system, enables the filtering of target security strategies without manual intervention, and ensures that the power system can effectively and promptly protect against threat events after executing the target security strategy, achieving a rapid and accurate response to threat events currently occurring in the power system.

[0112] Each module in the aforementioned strategy execution device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the operations corresponding to each module.

[0113] In one embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 7 As shown, the computer device includes a processor, memory, input / output interfaces, a communication interface, a display unit, and an input device. The processor, memory, and input / output interfaces are connected via a system bus, and the communication interface, display unit, and input device are also connected to the system bus via the input / output interfaces. The processor provides computational and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The input / output interfaces are used for exchanging information between the processor and external devices. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a policy execution method. The display unit is used to form a visually visible image and can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be an LCD screen or an e-ink screen. The input device of the computer device can be a touch layer covering the display screen, or buttons, trackballs, or touchpads set on the casing of the computer device, or external keyboards, touchpads, or mice, etc.

[0114] Those skilled in the art will understand that Figure 7The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0115] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:

[0116] Obtain at least one candidate security policy for the power system;

[0117] The candidate security strategies are screened to obtain the target security strategy that is suitable for the current situation of the power system;

[0118] The target security policy is executed across devices within the power system.

[0119] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0120] The candidate security strategies are screened to obtain the target security strategy that conforms to the current situation of the power system, including:

[0121] Based on the external threat data of the power system, priority analysis is performed on each candidate security strategy to obtain the strategy priority corresponding to each candidate security strategy.

[0122] Based on the policy priority of each candidate security policy, a target security policy that is suitable for the current situation of the power system is determined.

[0123] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0124] Based on the policy priority of each candidate security policy, a target security policy that conforms to the current situation of the power system is determined, including:

[0125] The candidate security policy with the highest priority among all candidate security policies shall be used as the reference security policy;

[0126] The reference security strategy is fine-tuned based on the equipment parameters of the internal equipment of the power system to obtain a target security strategy that conforms to the current situation of the power system.

[0127] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0128] Obtain system state parameters of the power system;

[0129] Security policies are generated based on system state parameters to obtain at least one candidate security policy for the power system.

[0130] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0131] Based on a pre-set reinforcement learning network, security policies are generated according to system state parameters, resulting in at least one candidate security policy for the power system.

[0132] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0133] After the power system implements the target security policy, obtain the feedback data from the power system;

[0134] Based on the feedback data, a security event analysis is performed on the power system to obtain the probability of a security event occurring in the power system.

[0135] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor:

[0136] Obtain at least one candidate security policy for the power system;

[0137] The candidate security strategies are screened to obtain the target security strategy that is suitable for the current situation of the power system;

[0138] The target security policy is executed across devices within the power system.

[0139] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0140] Based on the external threat data of the power system, priority analysis is performed on each candidate security strategy to obtain the strategy priority corresponding to each candidate security strategy.

[0141] Based on the policy priority of each candidate security policy, a target security policy that is suitable for the current situation of the power system is determined.

[0142] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0143] The candidate security policy with the highest priority among all candidate security policies shall be used as the reference security policy;

[0144] The reference security strategy is fine-tuned based on the equipment parameters of the internal equipment of the power system to obtain a target security strategy that conforms to the current situation of the power system.

[0145] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0146] Obtain system state parameters of the power system;

[0147] Security policies are generated based on system state parameters to obtain at least one candidate security policy for the power system.

[0148] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0149] Based on a pre-set reinforcement learning network, security policies are generated according to system state parameters, resulting in at least one candidate security policy for the power system.

[0150] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0151] After the power system implements the target security policy, obtain the feedback data from the power system;

[0152] Based on the feedback data, a security event analysis is performed on the power system to obtain the probability of a security event occurring in the power system.

[0153] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, performs the following steps:

[0154] Obtain at least one candidate security policy for the power system;

[0155] The candidate security strategies are screened to obtain the target security strategy that is suitable for the current situation of the power system;

[0156] The target security policy is executed across devices within the power system.

[0157] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0158] Based on the external threat data of the power system, priority analysis is performed on each candidate security strategy to obtain the strategy priority corresponding to each candidate security strategy.

[0159] Based on the policy priority of each candidate security policy, a target security policy that is suitable for the current situation of the power system is determined.

[0160] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0161] The candidate security policy with the highest priority among all candidate security policies shall be used as the reference security policy;

[0162] The reference security strategy is fine-tuned based on the equipment parameters of the internal equipment of the power system to obtain a target security strategy that conforms to the current situation of the power system.

[0163] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0164] Obtain system state parameters of the power system;

[0165] Security policies are generated based on system state parameters to obtain at least one candidate security policy for the power system.

[0166] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0167] Based on a pre-set reinforcement learning network, security policies are generated according to system state parameters, resulting in at least one candidate security policy for the power system.

[0168] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0169] After the power system implements the target security policy, obtain the feedback data from the power system;

[0170] Based on the feedback data, a security event analysis is performed on the power system to obtain the probability of a security event occurring in the power system.

[0171] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.

[0172] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.

[0173] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0174] The above embodiments are merely illustrative of several implementation methods of this application, and their descriptions are relatively specific and detailed. However, they should not be construed as limiting the scope of this application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A method of policy enforcement, the method comprising: The method comprises: obtaining at least one candidate security policy for a power system; screening each of the candidate security policies to obtain a target security policy conforming to a current situation of the power system; performing cross-device execution of the target security policy on the power system.

2. The method of claim 1, wherein, The screening of each of the candidate security policies to obtain the target security policy conforming to the current situation of the power system comprises: performing priority analysis of each of the candidate security policies according to external threat data of the power system to obtain a strategy priority corresponding to each of the candidate security policies; determining the target security policy conforming to the current situation of the power system according to the strategy priority corresponding to each of the candidate security policies.

3. The method of claim 2, wherein, The determining of the target security policy conforming to the current situation of the power system according to the strategy priority corresponding to each of the candidate security policies comprises: taking a candidate security policy with the highest priority among the candidate security policies as a reference security policy; performing strategy fine-tuning of the reference security policy according to device parameters of internal devices of the power system to obtain the target security policy conforming to the current situation of the power system.

4. The method of claim 1, wherein, The obtaining of at least one candidate security policy for the power system comprises: obtaining system state parameters of the power system; performing security policy generation according to the system state parameters to obtain at least one candidate security policy for the power system.

5. The method of claim 4, wherein, The obtaining of at least one candidate security policy for the power system comprises: performing security policy generation according to the system state parameters based on a pre-set reinforcement learning network to obtain at least one candidate security policy for the power system.

6. The method of claim 1, wherein, The method further comprises: obtaining feedback data of the power system after the power system executes the target security policy; performing security event analysis of the power system according to the feedback data to obtain a probability of a security event occurring in the power system.

7. A policy enforcement apparatus characterized by comprising: The device comprises: an obtaining module configured to obtain at least one candidate security policy for a power system; a screening module configured to screen each of the candidate security policies to obtain a target security policy conforming to a current situation of the power system; an execution module configured to perform cross-device execution of the target security policy on the power system. 8.A computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the computer device is configured to perform the method according to any one of claims 1-7. The processor executes the computer program to implement the steps of the method in any one of claims 1 to 6.

9. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method in any one of claims 1 to 6.

10. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method in any one of claims 1 to 6.