Threat behavior association analysis method for power network security situation awareness

By normalizing and aligning IT and OT data in the power network, and combining this with correlation analysis rules to identify threatening behavior events, the problem of identifying and responding to multi-stage combined attacks in the power system has been solved, thereby improving the security and reliability of the power network.

CN121864355APending Publication Date: 2026-04-14GUANGXI POWER GRID CORP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-01
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

Existing technologies are unable to effectively identify and respond to multi-stage combined attacks that span the information and control layers, resulting in non-compliant power transmission, untimely early warnings, and a lack of targeted response measures, which affects the reliability and security of power production and operation.

Method used

By acquiring IT and OT side data from the power network, normalizing and aligning the data to generate standardized security event sequences, and using preset correlation analysis rules to match the causal, temporal, and logical relationships of different types of security events, threat behavior events are generated, and finally, power system alarm signals are generated.

Benefits of technology

It enables complete identification and prediction of attacks on power grids, significantly enhancing the ability of power grids to operate their core functions normally after being attacked, and improving the pertinence of response measures and the timeliness of early warning.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121864355A_ABST
    Figure CN121864355A_ABST
Patent Text Reader

Abstract

The invention is suitable for the technical field of power network security, and provides a threat behavior association analysis method for power network security situation awareness, and the method comprises the steps: obtaining IT side data and OT side data in a power network; after processing, generating a standardized security event sequence; matching the standardized security event sequence with a plurality of preset association analysis rules; the correlation analysis rule is used for defining causal, time sequence and logic relationships among different types of security events; generating at least one threat behavior event according to the matching result; according to the generated threat behavior event type and risk level, generating a corresponding power system alarm signal; and sending the generated power system alarm signal to an alarm device to execute early warning feedback. According to the method, an ongoing attack and a possible target can be identified, an abstract network security threat is converted into a specific risk value or grade, and the capability of maintaining normal operation of a core function after the power network is subjected to the network attack is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power network security technology, and in particular to a threat behavior correlation analysis method for power network security situational awareness. Background Technology

[0002] With the deepening of the energy internet, the digitalization and networking levels of power systems are continuously improving, and the deep integration of cyberspace and physical systems presents increasingly severe cybersecurity threats. Existing technologies use various probes and security devices deployed in information networks and industrial control networks to collect network traffic, security alarms, system logs, and industrial control operation data, and perform anomaly detection and alarm generation based on predefined single rules or static thresholds. Due to the isolated analysis of information network and industrial control network data and the lack of cross-domain correlation capabilities, multi-stage combined attacks targeting power systems that span the information and control layers are difficult to fully identify and reconstruct, resulting in a large number of missing attack chains. The generated alarm signals often fail to be closely linked to the actual risk status and compliance requirements of power physical equipment, leading to non-compliant transmission, untimely warnings, and a lack of targeted response measures. Operators find it difficult to quickly assess the real dangers from massive amounts of isolated alarms and take effective measures, seriously affecting the reliability and safety of power production and operation. Summary of the Invention

[0003] This invention provides a threat behavior correlation analysis method for power network security situation awareness, which addresses issues such as non-compliant transmission, untimely early warning, and lack of targeted response measures.

[0004] This invention provides a threat behavior correlation analysis method for power network security situation awareness, comprising: Acquire IT-side and OT-side data in the power network; The acquired IT and OT data are normalized and time-series aligned to generate a standardized security event sequence. The standardized security event sequence is matched with multiple preset correlation analysis rules; these rules define the causal, temporal, and logical relationships between different types of security events; at least one threat behavior event is generated based on the matching results; wherein, the threat behavior event includes: The first type of threat behavior event is caused independently by IT-side data anomalies or OT-side data anomalies. The second type of threat behavior event is caused by the combined effect of IT-side data anomalies and OT-side data anomalies. The third type of threatening behavior event is caused by abnormal external environmental factors; Based on the type and risk level of the generated threat events, corresponding power system alarm signals are generated; The generated power system alarm signal is sent to the alarm device to perform early warning feedback.

[0005] Furthermore, the normalization and time-series alignment of the acquired IT-side and OT-side data to generate a standardized security event sequence includes: Extract the timestamps of various security events from the IT-side data and OT-side data, and convert all timestamps to an absolute time format in a standard time zone. Based on the unified timestamp, IT-side security events and OT-side security events belonging to the same time window are aligned and associated to generate a standardized security event sequence arranged in chronological order.

[0006] Furthermore, the preset multiple correlation analysis rules include causal correlation rules, temporal correlation rules, and logical correlation rules; the causal correlation rules are used to match whether there is a causal relationship in the standardized security event sequence where a first security event leads to a second security event; the temporal correlation rules are used to match whether the occurrence order of multiple security events in the standardized security event sequence conforms to a preset attack phase timing model; the logical correlation rules are used to match whether security events originating from the IT side and the OT side in the standardized security event sequence logically cooperate to act on the same target power equipment.

[0007] Furthermore, the causal association rule is used to match whether there is a causal relationship in the standardized security event sequence where the first security event causes the second security event, including: Candidate event pairs are extracted from the standardized security event sequence, the candidate event pairs including a first security event that occurs first and a second security event that occurs later; Determine whether the type of the first security event and the type of the second security event match a preset causal event type pair; If the conditions are met, it is determined whether the occurrence time of the first security event is earlier than the occurrence time of the second security event, and the time difference is less than or equal to a preset causal time threshold; if the occurrence time of the first security event is earlier than the occurrence time of the second security event, and the time difference is less than or equal to the preset causal time threshold, then it is confirmed that there is a causal relationship between the first security event and the second security event.

[0008] Furthermore, the temporal association rule is used to match whether the order of occurrence of multiple security events in the standardized security event sequence conforms to a preset attack phase temporal model, including: Obtain a preset attack phase sequence model, which defines the typical security event types and their order of occurrence for each phase of a network attack; The standardized security event sequence is divided into multiple consecutive time windows in chronological order; Identify all types of security events that occur within each time window; The identified security event type sequence is matched with the attack phase time series model to check whether the order of occurrence of various events in the security event type sequence is consistent with the phase order defined in the model. If they match, then the standardized security event sequence is confirmed to conform to the attack phase timing model.

[0009] Furthermore, the logical association rules are used to match whether security events originating from the IT side and the OT side in the standardized security event sequence logically synergistically affect the same target power device, including: From the standardized security event sequence, abnormal security events originating from the IT side and abnormal security events originating from the OT side are filtered out; Extract the identifiers of the target objects accessed or attempted to be accessed by the aforementioned IT-side abnormal security events; Extract the identifiers of the power equipment affected or attempted to be controlled by the abnormal security events on the OT side; Determine whether the target object identifier and the power equipment identifier point to the same entity, or determine whether there is a logical relationship between the two based on a preset mapping table; If there is a connection or logical relationship between the same entity, it is confirmed that the security events on the IT side and the OT side work together to target the same power equipment.

[0010] Furthermore, the generation of at least one threat behavior event based on the matching result includes: If the matching result indicates that the anomaly exists only in the IT side data or only in the OT side data, then the first type of threat behavior event is generated.

[0011] Furthermore, the step of generating at least one threat behavior event based on the matching result also includes: If the matching results indicate that the IT-side data anomalies and the OT-side data anomalies are related in both time sequence and logic, then the second type of threat behavior event is generated.

[0012] Furthermore, the generation of corresponding power system alarm signals based on the generated threat behavior event type and risk level includes: The target object of the alarm signal is determined based on the type of threat behavior event, and the target object includes specific power equipment, regional power grid or the entire power network; Based on the risk level, the alarm signal level and content are determined, and a power system alarm signal containing the target object, alarm level, and handling suggestions is generated.

[0013] Furthermore, determining the level and content of the alarm signal based on the risk level includes: If the risk level is Level 1, a Level 1 alarm signal is generated. The content of the Level 1 alarm signal includes operation instructions for instructing the implementation of equipment isolation or emergency shutdown. If the risk level is Level 2, a Level 2 alarm signal is generated. The content of the Level 2 alarm signal includes a warning instruction to indicate whether to upgrade the network protection level or carry out security hardening. If the risk level is level three, a level three alarm signal is generated. The content of the level three alarm signal includes a warning instruction to indicate whether to conduct security monitoring or log auditing.

[0014] As can be seen from the above technical solutions, the present invention has the following advantages: This invention processes data from both the information network and the industrial control network to generate a standardized security time series. This series is then matched against multiple preset correlation analysis rules, which define the causal, temporal, and logical relationships between different types of security events. Based on the matching results, at least one of three types of threat behavior events (first, second, and third types) is generated. Then, based on the generated threat behavior event type and risk level, a corresponding power system alarm signal is generated. Finally, the generated power system alarm signal is sent to an alarm device to perform early warning feedback. This invention reconstructs the attack chain through correlation analysis, enabling not only the identification of ongoing attacks but also the prediction of the attacker's next intentions and possible targets based on their behavioral patterns. By assessing the risk level of the threat behavior chain, abstract network security threats are transformed into specific risk values ​​or levels, significantly enhancing the ability of the power network to maintain normal operation of its core functions after a network attack. Attached Figure Description

[0015] Figure 1 This is a schematic flowchart of an embodiment of a threat behavior correlation analysis method for power network security situation awareness in this invention; Figure 2 This is a schematic flowchart of another embodiment of a threat behavior correlation analysis method for power network security situation awareness in this invention; Figure 3 This is a schematic flowchart of another embodiment of a threat behavior correlation analysis method for power network security situation awareness in this invention; Figure 4 This is a schematic flowchart of another embodiment of a threat behavior correlation analysis method for power network security situation awareness in this invention. Detailed Implementation

[0016] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “corresponding to,” and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0017] Example 1 The implementation method in this embodiment can be implemented in a system, on a server, or on a terminal; no specific limitation is made. The following section will describe the threat behavior correlation analysis method for power network security situational awareness in this application from the perspective of system implementation. Please refer to... Figures 1 to 4 The method provided in this application includes the following steps: S1. Acquire IT-side data and OT-side data in the power network; Here, IT-side data refers to network security-related data from traditional computing environments such as power company information management zones and internet zones. This data primarily reflects access control, intrusion behavior, system status, and user activities at the information network layer. IT-side data includes network traffic logs, security device alarm logs, and host system logs. Various technologies, such as proxy-based methods, network port mirroring, Syslog transmission, and API calls, are used to aggregate dispersed IT-side security data in real-time or near real-time to a unified upstream data bus or big data platform.

[0018] Here, OT-side data refers to data generated by industrial control systems and IoT devices directly involved in the monitoring and control of physical production processes such as power generation, transmission, distribution, and consumption within the production control area. This data reflects the operating status of power production equipment and changes in control commands, serving as direct evidence for identifying attacks targeting physical equipment. OT-side data includes industrial control system logs, sensor measurement data, and switch status change data. Given the high real-time and security requirements of OT networks, dedicated, protocol-compatible acquisition probes are deployed to non-intrusively collect control traffic and data from the network using a bypass mirroring method; alternatively, data can be collected through the log interface provided by the industrial control system itself. Data is transmitted unidirectionally to the analysis platform via a secure isolation device, ensuring the absolute security of the production control system.

[0019] S2. Normalize and time-series aligned the acquired IT and OT data to generate a standardized security event sequence; The principle behind this step is to eliminate heterogeneity through data normalization and establish a unified timeline through time alignment. This allows for the comparison of network attack events on the IT side and physical anomalies on the OT side within the same spatiotemporal context, laying the foundation for the subsequent accurate discovery of cross-domain related threat behavior chains.

[0020] 1. Extract timestamps of various security events from IT and OT data, and convert all timestamps to an absolute time format in a standard time zone; The original timestamp field is parsed from each IT-side alarm log, network flow record, OT-side industrial control log, and sensor data. Given that the data may originate from data centers or devices in different time zones, or that timestamp formats may vary, all timestamps must be uniformly converted to the absolute time format of Coordinated Universal Time (UTC). This conversion process must consider factors such as time zone offsets and daylight saving time to ensure that every security event can be located on a globally unified and unambiguous timeline.

[0021] 2. Based on the unified timestamp, IT-side security events and OT-side security events belonging to the same time window are aligned and associated to generate a standardized security event sequence arranged in chronological order.

[0022] Based on the typical response time and business continuity requirements of power system attacks, a reasonable time window size is set. Using unified Coordinated Universal Time (UTC) as the reference, all IT and OT security events are divided into consecutive time windows according to their occurrence time. Within each time window, previously isolated IT and OT events form potentially related event groups. The system arranges all events within all time windows in chronological order, generating a standardized security event sequence. Each event in this sequence has been normalized into a unified data object containing key fields such as a standardized timestamp, event source (IT / OT), event type, source / target object, and detailed content.

[0023] S3. Match the standardized security event sequence with multiple preset correlation analysis rules; the correlation analysis rules are used to define the causal, temporal, and logical relationships between different types of security events; This step uses a predefined set of correlation analysis rules for power system attack chains to evaluate pre-processed standard event sequences, thereby identifying genuine, threatening attacks from a massive number of isolated events. The principle is that complex cyberattacks are not composed of single events, but rather a chain of attack steps that are causally, temporally, and logically interconnected. These rules describe the complex relationships between different types of security events, including but not limited to: whether one event can lead to another (causal correlation), whether the order of multiple events conforms to known attack patterns (temporal correlation), and whether events occurring in IT and OT networks, respectively, logically point to the same target (logical correlation). By matching standardized event sequences with these rule sets, the system can accurately reconstruct the complete attack chain.

[0024] Specifically, the pre-defined association analysis rules include causal association rules, temporal association rules, and logical association rules. These rules exist in the form of executable language or logical predicates and are stored in a dedicated rule base.

[0025] S31. Causal association rules are used to match whether there is a causal relationship in a standardized security event sequence in which the first security event causes the second security event to occur; S311. Extract candidate event pairs from a standardized security event sequence, where each candidate event pair includes a first security event that occurs first and a second security event that occurs later; The system iterates through the entire event sequence, filtering out all event combinations that satisfy the "first occurred" and "last occurred" relationship based on a unified timestamp, forming candidate event pairs to be analyzed. For example, if event A (IT side: abnormal database login) occurs at 08:00:00 and event B (OT side: control system configuration modified) occurs at 08:00:30, then (A, B) constitutes a candidate event pair.

[0026] S312. Determine whether the type of the first security event and the type of the second security event match the preset causal event type pair; The rule base predefines a large number of causal event type pairs, reflecting expert experience. For example, a rule might define: if the event types "successful VPN brute-force login on the IT side" and "abnormal startup of the engineer's workstation process on the OT side" occur in pairs, then they may be causally related. This step performs rapid event type matching, filtering out a large number of obviously irrelevant event pairs.

[0027] S313. If the conditions are met, determine whether the occurrence time of the first security event is earlier than the occurrence time of the second security event, and the time difference is less than or equal to the preset causal time threshold. For a causal relationship to be valid, it must satisfy both temporal sequence and proximity. The causal time threshold here is set based on the specific business scenario and attack type. For example, a successful login and subsequent operations may occur within minutes, so the threshold could be set to 5 minutes. This step performs a second round of time-based filtering.

[0028] S314. If the occurrence time of the first security event is earlier than the occurrence time of the second security event, and the time difference is less than or equal to a preset causal time threshold, then it is confirmed that there is a causal relationship between the first security event and the second security event.

[0029] At this point, the system links these two previously isolated events, marking them as a preliminary causal link. This result will be output for subsequent higher-level correlation analysis or directly used to generate low-risk threat behavior events. If the first security event occurs later than the second security event, or the time difference between the two is greater than the causal time threshold, the system determines that there is no direct causal relationship between the candidate event pair and terminates the current causal correlation analysis for this event pair. Such event pairs will be marked as irrelevant and temporarily stored, but the events themselves are still retained in the sequence and can be used as input data for other correlation analysis rules.

[0030] S32. The temporal association rule is used to match whether the order of occurrence of multiple security events in a standardized security event sequence conforms to the preset attack phase temporal model; Complex cyberattacks, such as Advanced Persistent Threats (APPTs), typically consist of multiple ordered stages. Attackers must complete the tasks of each stage to proceed to the next, forming an attack chain with inherent temporal logic, such as the classic cyber kill chain model. Temporal correlation rules determine whether a collected event sequence exhibits this staged attack characteristic. The principle is to match the order of event types in a standardized security event sequence with the stage order specified in a predefined attack stage temporal model. If they match, it indicates that the observed event flow is not random noise, but a staged attack with a clear tactical objective, thus greatly improving the confidence level of threat identification and helping to predict the attacker's next move.

[0031] S321. Obtain a preset attack phase sequence model, which defines the typical security event types and their order of occurrence for each phase of a network attack; The system loads pre-configured attack phase sequence models from the rule base. These models are stored in an extensible markup language or database tables, with each model corresponding to a specific attack script, such as data theft or control disruption. The models define the various phases an attack must go through (e.g., reconnaissance, weaponization, delivery, exploitation, installation, command and control, and action), and specify one or more typical security event types that may be triggered for each phase. For example, the "reconnaissance" phase might correspond to event types such as "IT side: port scan alert" or "OT side: network topology discovery request"; the "exploitation" phase might correspond to event types such as "IT side: vulnerability exploitation attack alert" or "OT side: abnormal command injection". The order of the phases is fixed and forms the matching benchmark.

[0032] S322. Divide the standardized security event sequence into multiple consecutive time windows in chronological order; To handle attacks with longer durations more flexibly, the system divides the entire event sequence into a series of consecutive, potentially overlapping time windows, either with fixed durations or dynamically adaptively. Each window represents an analysis unit, designed to capture a relatively complete attack sub-process.

[0033] S323. Identify all types of security events that occur within each time window; The system scans all security events within a time window, extracts the event type field for each event, and forms a sequence of event types arranged chronologically. For example, a window might yield the sequence [port scan, successful brute-force attack, user login, abnormal database query].

[0034] S324. Match the identified security event type sequence with the attack phase time series model, and check whether the order of occurrence of various events in the security event type sequence is consistent with the phase sequence defined in the model; The event type sequence obtained in step S323 is compared with the model loaded in step S321. The matching algorithm does not require the sequence to contain all stages of the model, but rather requires that the order in which the event types appear in the sequence must conform to the stage evolution order specified in the model. For example, if the model specifies the stage order as A->B->C, then the sequence [A, C] conforms (B is skipped), and the sequence [A, B, D] also conforms (D is added), but the sequence [B, A, C] does not conform (the order is incorrect).

[0035] S325. If consistent, then the standardized security event sequence is confirmed to conform to the attack phase timing model.

[0036] When a sequence of event types within a certain time window passes the aforementioned sequential consistency check, the system determines that the activities within that time period match a known attack pattern, confirming a potential, ongoing multi-stage attack. This matching result will be output to generate high-risk threat events (such as second-type threat events) and provide crucial information for predicting the next stage of the attack.

[0037] S33. Logical association rules are used to match whether security events originating from the IT side and the OT side in a standardized security event sequence logically synergistically affect the same target power equipment.

[0038] In cross-domain attacks targeting power systems, attackers' initial intrusion into the IT network ultimately aims to influence or control specific physical devices in the OT network. Logical association rules penetrate network boundaries to reveal the inherent business logic consistency between IT-side network activities and OT-side physical activities, determining whether both are attacking the same ultimate target. The principle is to separately analyze the object identifiers operated on or affected by IT and OT events, using a pre-defined knowledge base reflecting the physical mapping relationship of power grid information, to determine whether these two object identifiers from different domains represent the same entity or are closely related in business logic. Once this association is confirmed, it can be determined that the observed IT and OT anomalies are not independent events, but rather coordinated steps in the same attack chain, thus accurately identifying the most destructive cross-domain attack intent.

[0039] S331. Filter out abnormal security events from the IT side and abnormal security events from the OT side from the standardized security event sequence; The system first filters the event sequence, separating all events marked as abnormal or alarm. Then, based on the data source field of the event, it filters out security events from the IT side (such as IDS alarms, firewall blocking) and the OT side (such as abnormal operation of industrial control system, malfunction of protection device), forming two sets to be analyzed.

[0040] S332. Extract the identifier of the target object accessed or attempted to be accessed by the IT-side abnormal security event; Analyze the details of each IT-side anomaly to extract the target object identifier to which the network activity points. For example: the IP address of the server subjected to a brute-force attack, the URL of the compromised application, the name of the sensitive database table accessed, or the username of the stolen credentials.

[0041] S333. Extract the identifiers of electrical equipment affected or attempted to be controlled by abnormal security events on the OT side; Analyze the details of each abnormal event on the OT side to extract the identifiers of the power equipment affected by the operation or state change. For example: a specific circuit breaker number (such as "CB-101"), a generator set ID, a substation name, a line protection device model and installation location, or a programmable logic controller station address.

[0042] S334. Determine whether the target object identifier and the power equipment identifier point to the same entity, or determine whether there is a logical relationship between the two based on the preset mapping relationship table; The system compares the target identifier of the IT event with the device identifier of the OT event. The comparison is performed in two ways: 1. Directly pointing to the same entity: For example, an IT event is an attack launched against an HMI with a specific IP address, while an OT event is an unexpected tripping of a circuit breaker controlled by the HMI corresponding to that IP address. In this case, the IP address and the circuit breaker are directly associated through the HMI.

[0043] 2. Association via Mapping Table: Query the pre-configured IT-OT asset logical mapping table, a pre-configured knowledge base that defines the logical control relationships between information system assets and physical power equipment. For example, it records mapping relationships such as "A database server (IP: 192.168.1.10) stores control commands for substation A-circuit breaker 101" and "A SCADA workstation (hostname: SCADA-OP01) is responsible for monitoring generator set G5." Through this table, an SQL injection attack on the database server (IT event) can be associated with a circuit breaker malfunction (OT event).

[0044] S335. If there are points to the same entity or a logical relationship, then it is confirmed that the security events on the IT side and the OT side work together to target the same power equipment.

[0045] When the above conditions are met, the system confirms that the two security events, which occurred in the information space and the physical space respectively, are coordinated in their attack intent and together constitute a cross-domain attack. This determination is the most direct and powerful evidence for generating a Type II threat event (caused by the abnormal coordination of data from the IT side and the OT side), and should immediately trigger the highest level of security alert.

[0046] After completing the association rule matching analysis in S31 to S33, the system obtained multiple chains of evidence regarding the causal, temporal, and logical relationships between security events. Based on the combination and comprehensive analysis of these matching results, the scattered association clues are aggregated, abstracted, and classified into threat behavior events with clear semantics.

[0047] In this embodiment, at least one threat behavior event is generated based on the matching result; the threat behavior events include: a first type of threat behavior event, which is caused independently by IT-side data anomalies or OT-side data anomalies; a second type of threat behavior event, which is caused by the combined effect of IT-side data anomalies and OT-side data anomalies; and a third type of threat behavior event, which is caused by anomalies in external environmental factors. Specifically, the first type of threat behavior event represents a localized threat confined to a single network domain and not yet having cross-domain impact. For example, a scanning attack targeting only an enterprise's intranet server, or a false alarm within an OT system caused by a temporary sensor malfunction. The second type of threat behavior event indicates a successful cross-domain attack chain, meaning the attack has penetrated from the information network to the production control network and poses a direct threat to physical equipment or processes. Its generation must be based on the joint verification of multi-dimensional evidence such as S32 (temporal correlation) and S33 (logical correlation). The third type of threat behavior event represents non-malicious anomalies caused by natural environmental or accidental factors, and its identification helps reduce false alarms. For example, a substation communication outage caused by lightning strikes, or data loss caused by fiber optic cables being severed during municipal construction.

[0048] The system's generation logic is: 1. If the matching result indicates that the anomaly exists only in IT-side data or only in OT-side data, a Type I threat behavior event is generated; for example, if only the causal association rule on the IT side is matched, or if the event on the OT side fails to establish a temporal or logical association with any IT event, it is determined to be a local threat and a Type I threat behavior event is generated.

[0049] 2. If the matching results indicate that the IT-side data anomalies and OT-side data anomalies are related both temporally and logically, a second-type threat behavior event is generated. For example, if the attack phase timing is verified by rule S32 and the coordinated action on the same physical target is confirmed by rule S33, it is determined to be a successful cross-domain attack, generating a second-type threat behavior event. This is the highest-risk alert requiring immediate action.

[0050] S4. Generate corresponding power system alarm signals based on the type and risk level of the generated threat behavior events; 1. Determine the target object of the alarm signal based on the type of threat behavior event. The target object may include specific power equipment, regional power grid, or the entire power network. Specific electrical equipment: When a threatening event (especially a Type II event) is clearly directed at a specific physical device (such as a circuit breaker, a generator, or a protection device), the alarm signal will be precisely located to that device.

[0051] Regional power grid: When a threat event indicates that an attack affects a subsystem or a power supply area (such as a substation or a feeder), the alarm signal will be directed to the regional power grid.

[0052] The entire power network: When a large-scale cyberattack or a network-wide security vulnerability is detected (such as the core server being compromised in the first type of event), the alarm signal will issue the highest level of warning to the entire network.

[0053] 2. Determine the level and content of the alarm signal based on the risk level, and generate a power system alarm signal that includes the target object, alarm level, and handling suggestions.

[0054] Level 1 risk is the highest, requiring immediate intervention with disruptive or physical measures to prevent substantial damage; Level 2 risk is next, requiring rapid implementation of technical safeguards to contain the spread of the attack; Level 3 risk is a warning level, requiring enhanced monitoring and auditing to detect potential risks or subsequent attack activities. The specific classification and response strategies are as follows: If the risk level is Level 1, a Level 1 alarm signal will be generated. The content of the Level 1 alarm signal includes operation instructions to indicate the execution of equipment isolation or emergency shutdown. Its content mainly includes operation instructions to indicate the execution of the fastest and most direct protective actions such as equipment isolation or emergency shutdown, which are intended to immediately block the hazard and protect personal and equipment safety. If the risk level is Level 2, a Level 2 alarm signal will be generated. The Level 2 alarm signal includes warning instructions to instruct the network protection level to be upgraded or security hardening to be carried out. Its content mainly includes technical control instructions to instruct the network protection level to be upgraded (such as enabling advanced firewall policies) and security hardening to be carried out (such as emergency patch distribution and permission review), which aim to quickly build a defense barrier and curb the further development of the attack chain. If the risk level is Level 3, a Level 3 alarm signal will be generated. The Level 3 alarm signal includes warning instructions to instruct security monitoring or log auditing. Its content mainly includes warning instructions to instruct security monitoring (such as starting enhanced monitoring for a specific target) or log auditing (such as tracing all operation logs of a user), aiming to confirm the scope of risk or obtain further evidence through in-depth monitoring and analysis.

[0055] S5. Send the generated power system alarm signal to the alarm device to perform early warning feedback.

[0056] The system uses a built-in communication interface or message middleware to send power system alarm signal messages, generated in step S4 and conforming to a predetermined format, to one or more predefined alarm devices in real time. These devices, depending on their deployment location and function, perform one or more of the following early warning feedback actions: triggering audible and visual alarms, displaying alarm information and handling suggestions on the monitoring screen, and sending early warning notifications to the terminal devices of safety maintenance personnel.

[0057] By implementing this step, the output of the network security analysis system is successfully transformed into practical and effective security actions, ultimately improving the overall security protection capabilities and emergency response efficiency of the power system.

[0058] It is understood that those skilled in the art can combine various implementation methods in the above embodiments under the guidance of the above examples to obtain technical solutions with multiple implementation methods.

[0059] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A threat behavior correlation analysis method for power network security situational awareness, characterized in that, include: Acquire IT-side and OT-side data in the power network; The acquired IT and OT data are normalized and time-series aligned to generate a standardized security event sequence. The standardized security event sequence is matched with multiple preset correlation analysis rules; the correlation analysis rules are used to define the causal, temporal, and logical relationships between different types of security events. At least one threat behavior event is generated based on the matching results; wherein, the threat behavior event includes: The first type of threat behavior event is caused independently by IT-side data anomalies or OT-side data anomalies. The second type of threat behavior event is caused by the combined effect of IT-side data anomalies and OT-side data anomalies. The third type of threatening behavior event is caused by abnormal external environmental factors; Based on the type and risk level of the generated threat events, corresponding power system alarm signals are generated; The generated power system alarm signal is sent to the alarm device to perform early warning feedback.

2. The threat behavior correlation analysis method for power network security situational awareness according to claim 1, characterized in that, The process of normalizing and aligning the acquired IT-side and OT-side data to generate a standardized security event sequence includes: Extract the timestamps of various security events from the IT-side data and OT-side data, and convert all timestamps to an absolute time format in a standard time zone. Based on the unified timestamp, IT-side security events and OT-side security events belonging to the same time window are aligned and associated to generate a standardized security event sequence arranged in chronological order.

3. The threat behavior correlation analysis method for power network security situational awareness according to claim 1, characterized in that, The preset multiple correlation analysis rules include causal correlation rules, temporal correlation rules, and logical correlation rules; the causal correlation rules are used to match whether there is a causal relationship in the standardized security event sequence in which the first security event causes the second security event to occur; The temporal association rule is used to match whether the occurrence order of multiple security events in the standardized security event sequence conforms to the preset attack phase temporal model; the logical association rule is used to match whether security events originating from the IT side and the OT side in the standardized security event sequence logically cooperate to act on the same target power equipment.

4. The threat behavior correlation analysis method for power network security situational awareness according to claim 3, characterized in that, The causal association rule is used to match whether there is a causal relationship in the standardized security event sequence where the first security event causes the second security event, including: Candidate event pairs are extracted from the standardized security event sequence, the candidate event pairs including a first security event that occurs first and a second security event that occurs later; Determine whether the type of the first security event and the type of the second security event match a preset causal event type pair; If the conditions are met, it is determined whether the occurrence time of the first security event is earlier than the occurrence time of the second security event, and the time difference is less than or equal to a preset causal time threshold; if the occurrence time of the first security event is earlier than the occurrence time of the second security event, and the time difference is less than or equal to the preset causal time threshold, then it is confirmed that there is a causal relationship between the first security event and the second security event.

5. The threat behavior correlation analysis method for power network security situational awareness according to claim 3, characterized in that, The temporal association rules are used to match whether the order of occurrence of multiple security events in the standardized security event sequence conforms to a preset attack phase temporal model, including: Obtain a preset attack phase sequence model, which defines the typical security event types and their order of occurrence for each phase of a network attack. The standardized security event sequence is divided into multiple consecutive time windows in chronological order; Identify all types of security events that occur within each time window; The identified security event type sequence is matched with the attack phase time series model to check whether the order of occurrence of various events in the security event type sequence is consistent with the phase order defined in the model. If they match, then the standardized security event sequence is confirmed to conform to the attack phase timing model.

6. The threat behavior correlation analysis method for power network security situational awareness according to claim 3, characterized in that, The logical association rules are used to match whether security events originating from the IT side and the OT side in the standardized security event sequence logically synergistically affect the same target power device, including: From the standardized security event sequence, abnormal security events originating from the IT side and abnormal security events originating from the OT side are filtered out; Extract the identifiers of the target objects accessed or attempted to be accessed by the aforementioned IT-side abnormal security events; Extract the identifiers of the power equipment affected or attempted to be controlled by the abnormal security events on the OT side; Determine whether the target object identifier and the power equipment identifier point to the same entity, or determine whether there is a logical relationship between the two based on a preset mapping table; If there is a connection or logical relationship between the same entity, it is confirmed that the security events on the IT side and the OT side work together to target the same power equipment.

7. The threat behavior correlation analysis method for power network security situational awareness according to any one of claims 1-6, characterized in that, The generation of at least one threat behavior event based on the matching result includes: If the matching result indicates that the anomaly exists only in the IT side data or only in the OT side data, then the first type of threat behavior event is generated.

8. The threat behavior correlation analysis method for power network security situational awareness according to any one of claims 1-6, characterized in that, The step of generating at least one threat behavior event based on the matching result further includes: If the matching results indicate that the IT-side data anomalies and the OT-side data anomalies are related in both time sequence and logic, then the second type of threat behavior event is generated.

9. The threat behavior correlation analysis method for power network security situational awareness according to claim 1, characterized in that, The generation of corresponding power system alarm signals based on the generated threat behavior event type and risk level includes: The target object of the alarm signal is determined based on the type of threat behavior event, and the target object includes specific power equipment, regional power grid or the entire power network; Based on the risk level, the alarm signal level and content are determined, and a power system alarm signal containing the target object, alarm level, and handling suggestions is generated.

10. The threat behavior correlation analysis method for power network security situational awareness according to claim 9, characterized in that, The process of determining the level and content of the alarm signal based on the risk level includes: If the risk level is Level 1, a Level 1 alarm signal is generated. The content of the Level 1 alarm signal includes operation instructions for instructing the implementation of equipment isolation or emergency shutdown. If the risk level is Level 2, a Level 2 alarm signal is generated. The content of the Level 2 alarm signal includes a warning instruction to indicate whether to upgrade the network protection level or carry out security hardening. If the risk level is level three, a level three alarm signal is generated. The content of the level three alarm signal includes a warning instruction to indicate whether to conduct security monitoring or log auditing.