Method for determining semantic security information packet for power distribution network and related equipment
By using hardware roots of trust and lightweight models to generate structured security intelligence events at distribution network endpoints and conducting multiple rounds of investigations with the cloud, the risk assessment and trust issues of distribution networks under network threats are resolved, achieving efficient and accurate risk defense and intelligence packet transmission.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- FIBRLINK NETWORKS
- Filing Date
- 2025-11-28
- Publication Date
- 2026-04-17
AI Technical Summary
When facing network threats, modern power distribution networks cannot fully reflect current risks through business events that are difficult to verify using existing technologies, resulting in ineffective subsequent defense measures. Furthermore, cloud-based large language models cannot understand endpoint data, leading to trust paradoxes and issues with the authenticity of data sources, and lacking dynamic closed-loop investigation capabilities.
At the distribution network endpoints, hardware trust roots and lightweight models are used for multiple rounds of verification to generate structured security intelligence events. Multiple rounds of investigations are conducted with the cloud through trusted interactive agents to ensure the accuracy and comprehensiveness of the intelligence packages. The lightweight model is used for local risk assessment and selective communication, and the cloud-based large language model is combined for dynamic supplementary investigations.
It enables efficient and accurate risk assessment of distribution network endpoints and secure transmission of intelligence packets, reduces communication overhead, enhances the richness of threat intelligence and the dynamism of the defense system, resolves the data representation gap and trust paradox, and ensures the comprehensiveness and accuracy of security intelligence packets.
Smart Images

Figure CN121887435A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data processing technology, and in particular to a method and related equipment for determining semantic security information packets for power distribution networks. Background Technology
[0002] Modern power distribution networks are evolving towards greater informatization and intelligence, with a large number of intelligent terminal devices (IEDs) and remote terminal units (RTUs) being widely deployed, forming a complex physical-information fusion system. However, this openness and interconnectivity also increasingly exposes them to cyber threats. These attacks are highly covert, dynamic, and context-dependent, posing a fundamental challenge to traditional rule-based or signature-based security defense systems. Therefore, risk verification of business events at power distribution network endpoints is necessary.
[0003] If a business event fails risk verification, further analysis is required to enable subsequent risk mitigation. Current technologies typically treat business events as security intelligence packages; however, the mere existence of a business event does not fully reflect the potential risks, hindering effective subsequent risk mitigation. Summary of the Invention
[0004] In view of this, the purpose of this application is to propose a method and related equipment for determining semantic security information packets for power distribution networks, so as to overcome all or part of the shortcomings of the prior art.
[0005] To achieve the above objectives, this application provides a method for determining semantic security intelligence packets for distribution networks, applied to distribution network endpoints that are communicatively connected to a cloud. The method includes: in response to receiving an event to be security verified, performing multiple rounds of verification operations based on the event, each round of verification operations performing the following: encoding the event to obtain multiple event codes, and generating a security intelligence event based on the multiple event codes; determining the risk level corresponding to the security intelligence event through a pre-trained lightweight model; in response to determining that the risk level is greater than a first predetermined value, encapsulating and encrypting the security intelligence event to obtain an initial security intelligence packet; and then... An initial security intelligence packet is sent to the cloud; in response to receiving an investigation instruction from the cloud for the initial security intelligence packet within a predetermined time, multiple rounds of first investigation operations are performed based on the investigation instruction to obtain investigation results; in response to detecting a new event in the investigation results, the new event is used as the event in the next round of verification operations, and the next round of verification operations is performed; in response to detecting that the new event does not exist in the investigation results, or in response to determining that no investigation instruction from the cloud is received within the predetermined time, the initial security intelligence packet in all rounds of verification operations is identified as the security intelligence packet corresponding to the event, and at least one round of verification operations is exited.
[0006] Optionally, the step of performing multiple rounds of first survey operations based on the survey instruction to obtain survey results includes: each round of first survey operations performing the following: performing security verification on the survey instruction; in response to determining that the survey instruction passes the security verification, and in response to determining that the survey instruction is a closed-ended query instruction, determining the closed-ended answer corresponding to the closed-ended query instruction based on the closed-ended query instruction, encrypting the closed-ended answer and sending it to the cloud; in response to determining that a feedback survey instruction for receiving the closed-ended answer is received within the predetermined time, using the feedback survey instruction as the survey instruction in the next round of first survey operations, and executing the next round of first survey operations; in response to determining that no feedback survey instruction for receiving the closed-ended answer is received within the predetermined time, using all determined closed-ended answers as the survey results, and exiting at least one round of first survey operations; in response to determining that the survey instruction passes the security verification, and in response to determining that the survey instruction is an event supplement instruction, determining the new event corresponding to the event supplement instruction based on the event supplement instruction, using the new event as the survey results, and exiting at least one round of first survey operations.
[0007] Optionally, encoding the event to obtain multiple event codes includes: dividing the event into a sequence containing multiple sub-events according to a predetermined order; obtaining the data source of each sub-event in the sequence; determining the key data of the sub-event using a predetermined algorithm; and performing atomic-level encoding on the event based on the data source and key data corresponding to the sub-event to obtain the event code corresponding to the sub-event.
[0008] Optionally, generating a security intelligence event based on the plurality of event codes includes: connecting the plurality of event codes causally in a predetermined order to obtain an aggregated event; determining the importance of each event code and the risk value of the aggregated event based on the plurality of event codes; for each event code, in response to determining that the importance of the event code is greater than a second predetermined value, determining the event code as a target event code; and generating the security intelligence event based on the importance of each target event code, the risk value, the aggregated event, and each target event code.
[0009] Optionally, determining the importance of each event code and the risk value of the aggregated event based on the plurality of event codes includes: for each event code, determining a sensitivity score based on the event code and predefined high-sensitivity operation events; calculating the usage rate of the event code based on the event codes corresponding to historical events and the event code, and determining a rarity score based on the usage rate; determining at least one adjacent event code based on the event code and the sequence, and determining an association score based on the event code and all adjacent event codes; calculating the importance of the event code based on the sensitivity score, rarity score, and association score; determining a sub-risk value based on the event code using a predetermined function; and determining the risk value of the aggregated event based on all sub-risk values.
[0010] Optionally, the step of encapsulating and encrypting the security intelligence event to obtain an initial security intelligence package includes: obtaining a proof report corresponding to the distribution network endpoint and identification information corresponding to the security intelligence event; encapsulating the proof report, the security intelligence event, and the identification information to obtain an encapsulation package; and encrypting the encapsulation package to obtain the initial security intelligence package.
[0011] Optionally, after determining the initial security intelligence packet in all rounds of verification operations as the security intelligence packet corresponding to the event, the method includes: generating and sending a warning message based on the security intelligence packet corresponding to the event.
[0012] Based on the same inventive concept, this application also provides a method for determining semantic security intelligence packets for power distribution networks, applied in the cloud, wherein the cloud is communicatively connected to a power distribution network endpoint. The method includes: in response to determining that an initial security intelligence packet sent by the power distribution network endpoint has been received, taking the initial security intelligence packet as a target initial security intelligence packet; performing multiple rounds of second investigation operations based on the target initial security intelligence packet, each round of second investigation operations performing the following: performing security verification on the target initial security intelligence packet; in response to determining that the target initial security intelligence packet passes the security verification, inputting the target initial security intelligence packet into a pre-trained large language model, generating and outputting processing instructions corresponding to the target initial security intelligence packet through the large language model; in response to If the processing instruction is determined to be an investigation instruction, the investigation instruction is encrypted and sent to the distribution network endpoint; in response to determining that a new initial security intelligence packet corresponding to the investigation instruction sent by the distribution network endpoint is received within a predetermined time, the target initial security intelligence packet and the new initial security intelligence packet are used as the target initial security intelligence packet in the next round of the second investigation operation, and the next round of the second investigation operation is performed; in response to determining that a closed-ended answer corresponding to the investigation instruction sent by the distribution network endpoint is received within the predetermined time, the target initial security intelligence packet and the closed-ended answer are used as the target initial security intelligence packet in the next round of the second investigation operation, and the next round of the second investigation operation is performed; in response to determining that the processing instruction is an investigation termination instruction, at least one round of the second investigation operation is exited.
[0013] Based on the same inventive concept, this application also provides a device for determining semantic security intelligence packets for a power distribution network, applied to a power distribution network endpoint, the endpoint being communicatively connected to a cloud. The device includes: in response to receiving an event to be security verified, performing multiple rounds of verification operations based on the event, each round of verification operations being executed as follows: a first generation module, configured to encode the event to obtain multiple event codes, and generate a security intelligence event based on the multiple event codes; a first sending module, configured to determine the risk level corresponding to the security intelligence event through a pre-trained lightweight model, and in response to determining that the risk level is greater than a first predetermined value, encapsulating and encrypting the security intelligence event to obtain an initial security intelligence packet, and sending the initial... A security intelligence package is sent to the cloud; an investigation module is configured to, in response to receiving an investigation instruction from the cloud for the initial security intelligence package within a predetermined time, perform multiple rounds of first investigation operations based on the investigation instruction to obtain investigation results; a verification module is configured to, in response to detecting a new event in the investigation results, use the new event as an event in the next round of verification operations and perform the next round of verification operations; the verification module is further configured to, in response to detecting that the new event does not exist in the investigation results, or in response to determining that no investigation instruction from the cloud has been received within the predetermined time, identify the initial security intelligence package in all rounds of verification operations as the security intelligence package corresponding to the event, and exit at least one round of verification operations.
[0014] Based on the same inventive concept, this application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable by the processor, wherein the processor implements the method described above when executing the computer program.
[0015] As can be seen from the above, the method and related equipment for determining semantic security intelligence packets for power distribution networks provided in this application include the following steps: In response to receiving an event to be verified for security, multiple rounds of verification operations are performed based on the event. Each round of verification operations is performed as follows: the event is encoded to obtain multiple event codes, and a security intelligence event is generated based on the multiple event codes. Dispersed single encoded events are associated into an intelligence chain with contextual logic, reducing information silos and achieving accurate integration of all encoded events. A pre-trained lightweight model is used to determine the risk level corresponding to the security intelligence event, achieving accurate determination of the risk level of the security intelligence event. In response to determining that the risk level is greater than a first predetermined value, the security intelligence event is encapsulated and encrypted to obtain an initial security intelligence packet, which is then sent to the cloud, effectively preventing the security intelligence event from being tampered with and ensuring the security of the security intelligence event transmission. In response to determining that an investigation instruction for the initial security intelligence packet is received from the cloud within a predetermined time, multiple rounds of first investigation operations are performed based on the investigation instruction to obtain investigation results, which helps to enhance the richness of threat intelligence. In response to the detection of a new event in the investigation results, the new event is used as the event in the next round of verification operations, enabling dynamic expansion of the event. In response to the detection of no new event in the investigation results, or in response to the determination that no investigation instruction sent from the cloud has been received within the predetermined time, the initial security intelligence package in all rounds of verification operations is identified as the security intelligence package corresponding to the event, and at least one round of verification operations is exited, ensuring the comprehensiveness and accuracy of the security intelligence package. Attached Figure Description
[0016] To more clearly illustrate the technical solutions in this application or related technologies, the drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0017] Figure 1 This is a flowchart illustrating a method for determining semantic security information packets for power distribution networks according to an embodiment of this application. Figure 2 This is a schematic diagram illustrating the construction of an encrypted communication channel according to an embodiment of this application; Figure 3 This is a flowchart illustrating a method for determining semantic security information packets for a power distribution network according to another embodiment of this application. Figure 4 This is a schematic diagram illustrating the attack chain detection accuracy of three systems according to embodiments of this application; Figure 5 This is a detailed flowchart illustrating the method for determining semantic security information packets for power distribution networks according to an embodiment of this application. Figure 6 A schematic diagram illustrating the process of generating security intelligence events for events that pass security verification in this application embodiment; Figure 7 This is a schematic diagram of the structure of a semantic security information packet determination device for a power distribution network according to an embodiment of this application; Figure 8 This is a schematic diagram of the structure of a semantic security information packet determination device for a power distribution network according to another embodiment of this application; Figure 9 This is a schematic diagram of the hardware structure of an electronic device according to an embodiment of this application. Detailed Implementation
[0018] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with specific embodiments and the accompanying drawings.
[0019] It should be noted that, unless otherwise defined, the technical or scientific terms used in the embodiments of this application should have the ordinary meaning understood by one of ordinary skill in the art to which this application pertains. The terms "first," "second," and similar terms used in the embodiments of this application do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Terms such as "comprising" or "including" mean that the element or object preceding the word encompasses the elements or objects listed after the word and their equivalents, without excluding other elements or objects. Terms such as "connected" or "linked" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. Terms such as "upper," "lower," "left," and "right" are only used to indicate relative positional relationships; when the absolute position of the described object changes, the relative positional relationship may also change accordingly.
[0020] As described in the background section, modern power distribution networks are developing towards high levels of informatization and intelligence, with a large number of intelligent terminal devices (IEDs) and remote terminal units (RTUs) being widely deployed, forming a complex physical-information fusion system. However, this openness and interconnectivity also exposes them to emerging network threats such as advanced persistent threats (APTs) and LotL attacks. These attacks are highly covert, dynamic, and context-dependent, posing a fundamental challenge to traditional rule-based or signature-based security defense systems. Therefore, risk verification of business events at power distribution network endpoints is necessary. If a business event fails risk verification, further analysis is required to enable subsequent risk defense. Existing technologies typically treat business events as security intelligence packages; however, the existence of business events does not fully reflect the potential risks currently faced, leading to ineffective subsequent risk defense.
[0021] In recent years, Large Language Models (LLMs) have emerged as a promising new paradigm due to their unprecedented semantic understanding and complex reasoning capabilities. An ideal next-generation security paradigm should be able to simulate the investigative process of human experts, enabling dynamic and iterative intelligent interaction with potential threat events. However, to achieve this ideal, the interaction gap hindering efficient collaboration in current edge-cloud architectures must first be overcome. This gap consists of two intertwined deep contradictions. First, there is a representational gap at the semantic level: cloud-based LLMs, designed for natural language, cannot directly understand the raw, heterogeneous, and numerically rich machine data generated by endpoints, resulting in a lack of a unified linguistic foundation for meaningful dialogue. Second, there is a trust paradox at the trust level: cloud-based analysis relies entirely on the authenticity of endpoint data, but the endpoints themselves are the primary targets of attacks, and the integrity of their data cannot be guaranteed. This makes any interaction built on fragile or even false trust.
[0022] Even with the introduction of large language models into deterministic security intelligence packages, several problems remain: cloud-based collaborative defense systems for power distribution networks suffer from difficulties in understanding heterogeneous endpoint data (representational gap), the authenticity of data sources cannot be guaranteed (trust paradox), massive data reporting brings huge costs and privacy risks, and there is a fundamental deficiency in the lack of dynamic closed-loop investigation capabilities. These problems prevent the accurate determination of the security intelligence package corresponding to an event. Furthermore, real security investigations are not one-off static analyses, but a dynamic, iterative process of "proposing hypotheses, finding new evidence, and verifying findings"—a capability generally lacking in existing AI security architectures.
[0023] In view of this, embodiments of this application propose a method for determining semantic security information packets for power distribution networks, referring to... Figure 1The method, applied to a distribution network endpoint that is connected to a cloud communication network, includes the following steps: Step 101: In response to receiving an event to be verified for security, perform multiple rounds of verification operations based on the event. Each round of verification operations is performed as follows: encode the event to obtain multiple event codes, and generate a security intelligence event based on the multiple event codes.
[0024] In this step, the distribution network endpoint is a key node in the power system connecting the user side and the power grid, undertaking the core functions of power distribution, data exchange, and two-way interaction. The distribution network endpoint implements these functions through business events. If a business event carries risks, these functions may not be accurately implemented, necessitating risk verification. In cases where a business event poses a risk, further security analysis is required to effectively mitigate the risk. However, because the security intelligence package corresponding to a business event is not comprehensive enough, accurate further security analysis cannot be performed. Therefore, this application requires determining the security intelligence package corresponding to the business event. This security intelligence package comprehensively reflects the risk data of the business event, and subsequent analysis of the security intelligence package ensures effective risk mitigation.
[0025] To ensure the accuracy of the security intelligence packet determination process, the distribution network endpoint needs to pre-establish a robust and unforgeable hardware root of trust, forming a Trusted Environment (TEE): a hardware-isolated environment. The process of determining the security intelligence packet is executed through a trusted interaction proxy corresponding to the endpoint within the hardware-isolated environment, fundamentally eliminating the risk of tampering and interference from privileged operating systems or malicious software. The distribution network endpoint possesses the capability of a trustworthy data source, forming the first line of defense in the system, enabling rapid and reliable initial judgment and handling at the source of a threat. Utilizing the unique Physically Unclonable Function (PUF) of the distribution network endpoint, an uncopyable hardware "fingerprint" is generated for the hardware root of trust. This fingerprint is used as an entropy source, deriving a unique asymmetric key pair for subsequent signing and authentication processes. This cryptographically ensures that the interaction is with an untampered, authorized proxy instance running on real hardware, thus establishing a trust starting point for the entire interaction process and eliminating the trust paradox of the distribution network endpoint.
[0026] Upon receiving an event to be verified, multiple rounds of security verification are performed based on the event. These rounds ensure the accuracy and comprehensiveness of the security intelligence package corresponding to the event. Each verification round involves the following steps: encoding the event to obtain an encoded event. By transforming unstructured events into structured vector representations, richer semantic connotations are condensed within a low-dimensional representation. Encoding events solves the efficiency bottleneck of unstructured data processing while providing richer semantic information. Security intelligence events are generated based on multiple event codes. By integrating the semantic features and relationships of multi-source heterogeneous event codes, explicit threat pattern modeling and context awareness are achieved, resulting in security intelligence events. This links scattered, single encoded events into an intelligence chain with contextual logic, reducing information silos and achieving accurate integration of all encoded events.
[0027] Step 102: Determine the risk level corresponding to the security intelligence event using a pre-trained lightweight model; in response to determining that the risk level is greater than a first predetermined value, encapsulate and encrypt the security intelligence event to obtain an initial security intelligence package, and send the initial security intelligence package to the cloud.
[0028] In this step, due to limited memory and computing resources, large-scale models cannot be deployed at the distribution network endpoints. Therefore, pre-trained lightweight models are deployed within the distribution network endpoints to process security intelligence events. Security intelligence events are input into the lightweight model, which determines the risk level of the event. For example, the lightweight model is a small, quantized and distilled language model (a variant of DistilBERT) that performs real-time local risk assessment of security intelligence events. The process of determining the risk level of a security intelligence event using a lightweight model can be formally described as: calculating a conditional probability. That is, the assumption that a threat exists given the observation of a security intelligence event S. The possibility of its validity. Accordingly, This indicates that the security intelligence incident is a benign assumption. The possibility of its establishment, among which + =1. A preliminary risk level assessment is performed using a lightweight model, such as {risk: "low", reason: "common_system_activity"} (low risk level) or {risk: "high", reason: "obfuscated_powershell_execution"} (high risk level). Based on the risk level, the degree of risk is determined. A stratification function D(P) based on a preset threshold is defined as follows: Formula 1 in, and It is a configurable risk decision threshold. This function maps conditional probability values to discrete, explicit actions, for example, (Local archive) (Reporting to the cloud) and (Report and implement local mitigation). Risk levels correspond to low-risk events, medium-risk or unknown events, and high-risk events. In response to determining a low-risk level, the risk level of the events corresponding to the low-risk level is mapped to less than [a certain threshold]. The value is less than the first predetermined value; in response to determining the risk level as medium risk or unknown, the risk level of the event corresponding to the medium risk or unknown level is mapped to a value greater than or equal to the first predetermined value; The value, The value of . In response to determining a risk level as high risk, the risk level of the event corresponding to the high risk level is mapped to greater than or equal to . The value. Medium-risk or unknown events need to be reported to the cloud, which provides richer context for advanced cloud analytics. High-risk events: Emergency events judged to be high-risk are reported to the cloud with the fastest response speed. Under certain preset strategies, it can also perform low-risk, atomic mitigation actions locally, such as isolating suspicious processes, to achieve initial autonomous response.
[0029] Because the lightweight model only determines the risk level of security intelligence events and does not consume relatively large computing resources, it achieves the goal of accurately determining the risk level of security intelligence events. If the risk level exceeds a first predetermined value, it indicates that the security intelligence event poses a risk. Due to the limited resources at the distribution network endpoints, the cloud, with its unrestricted resources, is used to process security intelligence events with potential risks. The lightweight model is deployed to perform local real-time risk assessments on generated security intelligence events. Only medium-to-high-risk or suspicious events are encapsulated and reported. The agent initiates interaction with the cloud only when the local assessment determines that reporting is necessary. This significantly reduces cloud load and communication overhead and protects the privacy of routine operations. This interaction is regulated by a two-way trusted protocol to ensure the authenticity, integrity, and confidentiality of all communications. Risky security intelligence events are encapsulated and encrypted to obtain an initial security intelligence packet. This initial security intelligence packet is sent to the cloud via a secure uplink data stream, effectively preventing tampering of security intelligence events and ensuring the security of security intelligence event transmission.
[0030] After generating a structured security intelligence event, the core interaction logic of the endpoint trusted interaction agent is initiated. Its purpose is to autonomously decide locally at the endpoint how to handle the security intelligence event and to communicate with the cloud only when necessary. Local autonomous judgment and decision-making enable efficient selective communication to optimize system resources and protect user privacy. The endpoint autonomously decides whether and how to communicate with the cloud. The goal of this step is to rapidly filter massive amounts of benign events at the network edge, submitting only investigatively valuable intelligence to subsequent interaction protocols.
[0031] It should be noted that if the risk level is less than or equal to the first predetermined value, it indicates that the security intelligence event poses no risk and no further security analysis is required. Low-risk events, such as routine operations judged as benign with high confidence, are only archived in the local protection log and are not communicated with the cloud. Distribution network endpoints communicate with the cloud through a pre-built encrypted communication channel, such as... Figure 2 As shown, the construction process of the encrypted communication channel is as follows: (1) Cloud initiates challenge: The cloud sends a challenge with a random number to the distribution network endpoint. (2) Distribution network endpoint requests hardware: The distribution network endpoint requests the underlying hardware of the distribution network endpoint to measure the current environment. (3) Hardware generates proof: The hardware performs the measurement and generates a proof report by signing it with the device's private key. (4) Hardware returns to distribution network endpoint: The hardware securely returns the signed proof report to the distribution network endpoint. (5) Distribution network endpoint reports to cloud: The distribution network endpoint forwards the proof report to the cloud for verification. (6) Cloud completes verification: The cloud verifies the signature and measurement value of the report and confirms that the endpoint is trustworthy. (7) Trusted channel established: After verification, the two parties establish a trusted encrypted communication channel.
[0032] Step 103: In response to determining that an investigation instruction for the initial security intelligence package has been received from the cloud within a predetermined time, multiple rounds of first investigation operations are performed based on the investigation instruction to obtain investigation results.
[0033] In this step, the cloud processes the received initial security intelligence packet. If the cloud determines that the risk data contained in the initial security intelligence packet is incomplete, it generates an investigation instruction. Upon receiving the investigation instruction from the cloud to investigate the initial security intelligence packet within a predetermined time, multiple rounds of first-stage investigation operations are performed based on the investigation instruction to obtain investigation results. Through these multiple rounds of first-stage investigation operations, a deep investigation of the initial security intelligence packet is conducted, dynamically supplementing the threat context and enhancing the richness of threat intelligence. Utilizing cloud-based collaborative correlation judgment and continuous optimization, the initial security intelligence packet generated by the distribution network endpoint is a standardized, hardware-verified, universal intelligence language. The attack hypotheses formed by the cloud-based large model based on the initial security intelligence packet are transformed into specific 'intelligence optimization instructions' (i.e., investigation instructions) and sent to the distribution network endpoint. The distribution network endpoint then performs targeted feedback collection based on the instructions, reporting more valuable new evidence as investigation results. This 'analysis-instruction-reanalysis' cycle constitutes the core dynamic mechanism of continuous defense.
[0034] Step 1041: In response to the detection of a new event in the survey results, the new event is used as the event in the next round of verification operations, and the next round of verification operations is performed.
[0035] In this step, because the risk information contained in the initial security intelligence package may not be comprehensive, the cloud investigation needs to receive more events to accurately determine the corresponding security intelligence package. Therefore, new events may appear in the investigation results. If new events are found in the investigation results, the new events also need to be processed in the same way as the original events before being sent to the cloud. The new events will then be used as events in the next round of verification operations, achieving dynamic expansion of events.
[0036] Step 1042: In response to the detection that the new event does not exist in the investigation results, or in response to the determination that no investigation instruction sent by the cloud is received within the predetermined time, the initial security intelligence packet in all rounds of verification operations is identified as the security intelligence packet corresponding to the event, and at least one round of verification operations is exited.
[0037] In this step, the investigation command generated by the cloud may also be a closed-ended query command, and the investigation result will only contain a statement of yes or no. In this case, there are no new events in the investigation result. If there are no new events in the investigation result, the initial security intelligence package in all rounds of verification operations is identified as the security intelligence package corresponding to the event, and at least one round of verification operations is exited. If no investigation command is received from the cloud within the predetermined time, it means that the cloud no longer has an investigation need for the initial security intelligence package. The initial security intelligence package in all rounds of verification operations is identified as the security intelligence package corresponding to the event, and at least one round of verification operations is exited. Through multiple rounds of verification operations and multiple rounds of first investigation operations, the security intelligence package corresponding to the event is obtained, ensuring the comprehensiveness and accuracy of the security intelligence package.
[0038] Starting at the hardware level, the system systematically addresses two major issues: the data representation gap and the trust paradox. Through the aforementioned steps, the trusted interactive agent ultimately generates a multi-layered, structured initial security intelligence package. Through the closed-loop process of "reporting the initial security intelligence package → cloud analysis and distribution of optimization strategies → generating optimized intelligence at the distribution network endpoint," the distribution network endpoint evolves from a passive data source into an intelligent agent capable of proactively generating high-value intelligence under the guidance of a large cloud model. This continuous optimization process is crucial for achieving efficient and accurate attack chain analysis and identification. A two-way trusted interactive protocol is established, supporting the cloud-based large model to securely issue supplementary investigation instructions to the endpoint based on analysis needs. The distribution network endpoint dynamically generates more targeted intelligence in response, achieving continuous intelligence optimization and closed-loop investigation. By combining the trust judgment capabilities of the distribution network endpoint with the global situational awareness capabilities of the cloud, information exchange and collaborative analysis are conducted through standardized semantic security intelligence, ultimately forming a multi-layered collaborative continuous defense strategy of "distribution network endpoint-cloud."
[0039] The endpoint trusted interaction proxy is responsible for transforming raw, untrusted data into a structured "semantic security intelligence" with cryptographic trustworthiness and optimized for a large language model. This proxy handles raw, untrusted business behavior data from active power distribution network terminals, such as IED operation logs and network traffic characteristics, as well as hardware information like PUF physical characteristics and TEE integrity metrics, into a security intelligence package with cryptographic trustworthiness, standardized semantic identifiers, and dynamic optimization capabilities. This ultimately enables collaborative judgment and continuous defense between the endpoint-side and cloud-side. This design addresses multiple challenges, including data source trust, representation gaps, cloud load, and privacy protection. Through a rigorous bidirectional trusted interaction protocol, it achieves efficient and intelligent endpoint-cloud collaborative security analysis and response. By utilizing a hardware root of trust to ensure data processing purity and combining it with a lightweight model of the power distribution network endpoints for autonomous risk assessment, it enables selective encapsulation and reporting of semantic security intelligence events, fundamentally resolving the trust paradox and reducing communication overhead.
[0040] The above scheme, in response to receiving an event to be verified for security, performs multiple rounds of verification operations based on the event. Each round of verification operations is as follows: the event is encoded to obtain multiple event codes, and a security intelligence event is generated based on the multiple event codes. This links scattered, single-coded events into an intelligence chain with contextual logic, reducing information silos and achieving accurate integration of all encoded events. A pre-trained lightweight model determines the risk level corresponding to the security intelligence event, achieving accurate determination of the risk level. In response to determining that the risk level is greater than a first predetermined value, the security intelligence event is encapsulated and encrypted to obtain an initial security intelligence package. The initial security intelligence package is sent to the cloud, effectively preventing tampering of the security intelligence event and ensuring the security of security intelligence event transmission. In response to receiving an investigation instruction from the cloud regarding the initial security intelligence package within a predetermined time, multiple rounds of first investigation operations are performed based on the investigation instruction to obtain investigation results, which helps to enhance the richness of threat intelligence. In response to the detection of a new event in the investigation results, the new event is used as the event in the next round of verification operations, enabling dynamic expansion of the event. In response to the detection of no new event in the investigation results, or in response to the determination that no investigation instruction sent from the cloud has been received within the predetermined time, the initial security intelligence package in all rounds of verification operations is identified as the security intelligence package corresponding to the event, and at least one round of verification operations is exited, ensuring the comprehensiveness and accuracy of the security intelligence package.
[0041] In some embodiments, the step of performing multiple rounds of first survey operations based on the survey instruction to obtain survey results includes: each round of first survey operations performing the following: performing security verification on the survey instruction; in response to determining that the survey instruction passes the security verification, and in response to determining that the survey instruction is a closed-ended query instruction, determining a closed-ended answer corresponding to the closed-ended query instruction based on the closed-ended query instruction, encrypting the closed-ended answer and sending it to the cloud; in response to determining that a feedback survey instruction for receiving the closed-ended answer is received within the predetermined time, using the feedback survey instruction as the survey instruction in the next round of first survey operations, and executing the next round of first survey operations; in response to determining that no feedback survey instruction for receiving the closed-ended answer is received within the predetermined time, using all determined closed-ended answers as the survey results, and exiting at least one round of first survey operations; in response to determining that the survey instruction passes the security verification, and in response to determining that the survey instruction is an event supplement instruction, determining a new event corresponding to the event supplement instruction based on the event supplement instruction, using the new event as the survey results, and exiting at least one round of first survey operations. In this embodiment, each round of the first survey operation is performed as follows: The survey instruction is securely verified, i.e., decrypted using a public key. If the survey instruction passes the security verification and is a closed-ended query instruction, the answer corresponding to the closed-ended query instruction is determined. A closed-ended query instruction is an instruction that only allows "yes" or "no" (or a limited set of specific options) as an answer. By simplifying the answer format, the survey scope is quickly narrowed, avoiding ambiguity or redundant information that might arise from open-ended questions. The closed-ended answer is encrypted using the private key of the distribution network endpoint and sent to the cloud. The cloud may continue to send survey instructions to the distribution network endpoint for closed-ended answers. If a feedback survey instruction for a closed-ended answer is received within a predetermined time, the feedback survey instruction is used as the survey instruction for the next round of the first survey operation, and the next round of the first survey operation is executed. Alternatively, the cloud may stop sending survey instructions to the distribution network endpoint for closed-ended answers. If no feedback survey instruction for a closed-ended answer is received within a predetermined time, all determined closed-ended answers are used as the survey result, and the process exits at least one round of the first survey operation.
[0042] If the investigation command passes security verification and is a supplementary command to the event, a new event corresponding to the supplementary command is determined. The supplementary command is used to dynamically expand the scope of the original event and supplement key risk information. After security verification, the investigation command is strictly executed, dynamically adjusting its monitoring scope and data collection granularity. Focused data collection is performed based on cloud-based optimization strategies to generate a new, more refined event. The new event has stronger contextual relevance, its content is directly related to the current attack assumptions in the cloud, and a large amount of redundant information irrelevant to the current investigation is eliminated, resulting in a significantly improved signal-to-noise ratio. This provides crucial evidence for verifying or refuting the core assumptions of the large cloud model. The new event is used as the investigation result, and at least one round of the first investigation operation is completed. Through multiple rounds of the first investigation operation, a dynamic feedback mechanism adapts to threat changes, ensuring the comprehensiveness of the information covered by the investigation results.
[0043] In some embodiments, encoding the event to obtain multiple event codes includes: dividing the event in a predetermined order to obtain a sequence containing multiple sub-events; for each sub-event in the sequence, obtaining the data source of the sub-event; determining the key data of the sub-event using a predetermined algorithm; and performing atomic-level encoding on the event based on the data source and key data corresponding to the sub-event to obtain the event code corresponding to the sub-event. In this embodiment, real-world security events, such as APT attacks and data breaches, often involve multi-stage and multi-dimensional behavioral events, such as login, file operations, and network communication, and these events exhibit a sequential nature. Therefore, events are divided according to a predetermined order, resulting in multiple sequences containing sub-events. These sequences fully record the temporal order and logical relationships of the sub-events, providing a data foundation for subsequent analysis. Each sub-event is associated with a specific data source; for example, login behavior relies on authentication logs, and file operations rely on process monitoring. The data source for the sub-event is obtained, and key data, such as abnormal geographical location during login or excessive permissions during file operations, is extracted using a customized algorithm. Based on the data source and key data corresponding to the sub-event, the event is atomically encoded to obtain the event code corresponding to the sub-event, providing a standardized basic unit for generating security intelligence events. The event code includes a domain prefix and feature encoding. The domain prefix is a specific domain prefix added to the event data source, such as LOG:, PROC:, or NET:. Introducing the data source corresponding to the sub-event aims to provide a basis for fast routing in the cloud. Feature encoding: For key data within a sub-event, the data is concatenated using the format "key data feature name = key data feature value," followed by hashing or retaining some readable fields to generate a privacy-preserving textual representation. For example, a process creation event (ParentPID: 123, PID: 456, Cmd: "svchost.exe") can be encoded as a string of text: PROC:ParentPID_hash(...) PID_hash(...) Cmd_hash(...). Atomic encoding is a technique that breaks down complex events or data into the smallest indivisible logical units (i.e., "atomic events"). By decomposing events at an extremely fine granular level, data standardization, redundancy removal, and analyzability are achieved.
[0044] In some embodiments, generating a security intelligence event based on the plurality of event codes includes: connecting the plurality of event codes causally in a predetermined order to obtain an aggregated event; determining the importance of each event code and the risk value of the aggregated event based on the plurality of event codes; for each event code, in response to determining that the importance of the event code is greater than a second predetermined value, determining the event code as a target event code; and generating the security intelligence event based on the importance of each target event code, the risk value, the aggregated event, and each target event code. In this embodiment, to chain independent atomic-level events into a logically related "story," multiple event codes are causally linked in a predetermined order to obtain aggregated events. A causal graph between events is constructed by tracing key identifiers such as process ID (PID), parent process ID (PPID), and file handles. It uses predefined structured delimiters to explicitly represent these relationships, for example, using... <spawns>To indicate process creation relationships, use<WRITES_TO> To indicate file write relationships, use<CONNECTS_TO> It represents network connectivity. By connecting disparate codes through causal relationships, it aggregates them into complete event chains. It efficiently transforms raw, heterogeneous power distribution network data into standardized aggregated events rich in causal semantics, designed specifically for large models, bridging the representation gap. Employing Temporal, Causal, and Hierarchical Encoding (TCHE), it converts fragmented events into LLM-friendly structured text. The core innovation of this method lies in encoding not only the events themselves, but more importantly, the relationships between them.
[0045] Different event codes and risk values of different aggregated events contribute differently to cloud-based investigations. To ensure efficient and accurate investigations in the cloud, the importance of each event code and the risk value of the aggregated event are determined, quantifying the event's risk. If the importance of an event code exceeds a second predetermined value, that event code is designated as the target event code. To ensure the consistency and parsability of the "security intelligence event" text, its standard format is defined as follows, consisting of three parts: 1) a global feature header, 2) a causal event chain, and 3) a set of key events. The importance of each target event code reflects its significance, and the risk value reflects the risk level of the aggregated event. The importance and risk value of each target event code are used to generate the global feature header of the security intelligence event. The global feature header helps the cloud prioritize processing tasks, providing a rapid macro-level basis for judgment. It should be noted that to improve cloud processing efficiency, a predetermined algorithm is used to determine the global statistical characteristics of the aggregated event, such as the total number of network connections for a process and the frequency of child process creation, and these are placed in the global feature header as a summary. In addition to global features, the agent also needs to automatically filter out several representative local key events within the time window. This process is implemented through an event priority function L(e), where e represents the event code within the window, intelligently identifying and prioritizing local key events, such as the first external network connection and modifications to sensitive registry entries. For example, the global feature header text begins with a [GLOBAL: ...] structure, containing a series of semicolon-separated key-value pairs. These key-value pairs represent the global statistical features and risk scores calculated in the "intelligence-level structured aggregation" stage, such as ScoreGlobal=0.85; NetConnections=12.
[0046] Aggregated events embody the logical structure of events, generating a causal event chain for security intelligence events, forming the core of the security intelligence event. Following the global feature header, the causal event chain constitutes the main body of the intelligence. This part consists of multiple event codes that have undergone "event-level atomic coding," through... <spawns>,<CONNECTS_TO> ,<FOLLOWED_BY> Standardized causal linkers are used to connect events, forming a coherent narrative. Each target event is encoded as a relatively important event code, and each target event code generates a critical event set for the security intelligence event, serving as the conclusion of the event. The critical event set is located at the end of the text and may include a summary of critical events defined by the [CRITICAL:...] structure. This section lists the target event codes that require priority, selected by the event priority function L(e). The target event codes are appended to the body of the security intelligence event, ensuring that the event includes both global macro-aggregated events and retains a fine-grained characterization of the critical event codes in the attack chain.
[0047] Through structured aggregation, risk quantification, and key information extraction, scattered atomic-level events are encoded and transformed into security intelligence events with actionable guidance. These security intelligence events not only record isolated events, but more importantly, they clearly reveal to the cloud-based LLM the causal and temporal relationships of a series of actions, such as "process A creates process B, and subsequently process A initiates a network connection," providing a macro-level context (global characteristics). This significantly reduces the difficulty for LLMs to perform complex attack chain reasoning. Security intelligence events encompass relatively comprehensive event information, facilitating precise processing in the cloud.
[0048] In some embodiments, determining the importance of each event code and the risk value of the aggregated event based on the plurality of event codes includes: for each event code, determining a sensitivity score based on the event code and predefined high-sensitivity operation events; calculating the usage rate of the event code based on the event codes corresponding to historical events and the event code, and determining a rarity score based on the usage rate; determining at least one adjacent event code based on the event code and the sequence, and determining an association score based on the event code and all adjacent event codes; calculating the importance of the event code based on the sensitivity score, rarity score, and association score; determining a sub-risk value based on the event code using a predetermined function; and determining the risk value of the aggregated event based on all sub-risk values. In this embodiment, if an event code satisfies a predefined high-sensitivity operation, such as the first external network connection, modification of the system startup registry, or injection of a security process, its priority is directly elevated to the highest. Therefore, based on the event code and the predefined high-sensitivity operation event, a sensitivity score corresponding to the event code is determined. Specifically: in response to determining that the event code is a predefined high-sensitivity operation event, the first score corresponding to the event code is used as the sensitivity score; in response to determining that the event code is not a predefined high-sensitivity operation event, the second score corresponding to the event code is used as the sensitivity score, wherein the first score is greater than the second score.
[0049] The frequency of use of the event code within the historical window is statistically analyzed. If such event codes are rare or significantly deviate from the baseline, they are assigned higher priority. Therefore, the event code is searched for in the historical event codes, and its usage rate is calculated. Based on the usage rate, a rarity score is determined for the event code. Specifically: if the usage rate of the event code is determined to be less than a predetermined usage rate, the third score is determined as the rarity score; if the usage rate of the event code is determined to be greater than or equal to the predetermined usage rate, the fourth score is determined as the rarity score, where the third score is greater than the fourth score.
[0050] If an event code is located at a critical causal chain node, such as the source of a process creation chain or the entry point of a network connection, it is given additional weight through a causal graph. Therefore, based on the event code and the sequence, at least one neighboring event code is determined, and based on the event code and all neighboring event codes, the association score corresponding to the event code is determined. Specifically: in response to determining that the connectivity between the event code and all neighboring event codes is greater than or equal to a predetermined connectivity, the fifth score corresponding to the event code is determined as the association score; in response to determining that the connectivity is less than the predetermined connectivity, the sixth score corresponding to the event code is determined as the association score, where the fifth score is greater than the sixth score.
[0051] The importance of an event code is calculated based on its sensitivity score, rarity score, and relevance score. The importance of an event code is calculated using the following formula: Formula 2 in, The importance of event coding, Indicates sensitivity score, Rarity score For related scores, These are configurable weight coefficients.
[0052] Using a predefined function, the sub-risk value corresponding to the event code is determined. Based on all sub-risk values, the risk value corresponding to the aggregated event is determined. The risk value of the aggregated event is calculated using the following formula: Formula 3 in, It is the risk value of the aggregated events within that time window. It is the first Predefined weights for class features, for example, external network connections are given a higher weight than file read / write operations. This represents a function that calculates the risk of a certain type of feature, such as calculating the frequency or entropy of a certain type of event.
[0053] By quantitatively assessing the importance of event coding and aggregating event risk values from multiple dimensions, security analysis is transformed from subjective judgment into data-driven, precise decision-making, ensuring the accuracy of the importance of event coding and the risk values of aggregated events.
[0054] In some embodiments, encapsulating and encrypting the security intelligence event to obtain an initial security intelligence package includes: obtaining a proof report corresponding to the distribution network endpoint and identification information corresponding to the security intelligence event; encapsulating the proof report, the security intelligence event, and the identification information to obtain an encapsulation package; and encrypting the encapsulation package to obtain the initial security intelligence package. In this embodiment, the verification report corresponding to the distribution network endpoint and the identification information corresponding to the security intelligence event are obtained. The verification report is pre-generated and ensures the credibility of the endpoint's identity, while the identification information enables precise location and tracking of the intelligence event. The verification report, security intelligence event, and identification information are then encapsulated to obtain a package, ensuring the integrity and credibility of the package. The package is then encrypted using the private key of the distribution network endpoint, ensuring the secure transmission of the initial security intelligence package obtained after encryption.
[0055] When a decision requires reporting, an initial security intelligence package is obtained. This package's data structure comprises three parts: 1) a security intelligence event; 2) a hardware verification report generated by the TEE; and 3) identification information such as timestamps and device identifiers. A digital signature is generated using a device-unique private key derived from a physically non-cloning function, thus providing the cloud with an unforgeable, verifiable, and complete security intelligence report. Through temporal causality and hierarchical coding, fragmented events are reconstructed into structured security intelligence events embedded with causal relationships. Finally, this security intelligence event, the hardware verification report generated by the TEE, the identification information, and a digital signature generated from a device-unique key derived from a physically non-cloning function are collectively encapsulated into a unified and unforgeable initial security intelligence package.
[0056] In some embodiments, after determining the initial security intelligence packet in all rounds of verification operations as the security intelligence packet corresponding to the event, the method includes: generating and sending a warning message based on the security intelligence packet corresponding to the event. In this embodiment, within the power distribution network security protection system, the security intelligence package corresponding to an event serves as the core carrier for threat perception and response, and must comprehensively cover the risk data throughout the entire lifecycle of the event, from triggering to handling. Specifically, the security intelligence package not only includes basic information from the initial detection phase but also dynamically supplements related data through multiple rounds of verification operations. The security intelligence package corresponding to the event covers all risk data related to the event. After determining the security intelligence package as the final version, an early warning message is generated and sent based on the security intelligence package corresponding to the event. Further analysis of the security intelligence package based on the early warning message is a core means of responding to dynamic threats and filling missing links in the attack chain in power distribution network security protection, thereby optimizing threat detection rules, adjusting defense strategy weights, and ultimately achieving a leap in security capabilities from "passive response" to "proactive prediction." After receiving the early warning message, the defense system initiates defense analysis. Based on the security intelligence package obtained through continuous interaction between the power distribution network endpoints and the cloud, the defense system can issue more precise and coordinated response strategies. This end-to-cloud collaborative mechanism based on standardized intelligence interaction elevates the traditional passive, single-point response to proactive, systematic, and continuous collaborative defense.
[0057] It should be noted that the intelligence richness of security intelligence packets can be calculated: Formula 4 in, For the intelligence richness of security intelligence package S, The number of events encoded. To use structured delimiters (such as...) <spawns>The number of causal links is represented by α, and β are weighting coefficients. This is because the contextual information provided by a causal link is far more valuable than an isolated event. Compared to traditional log formats (its... ≈0), this application maximizes This greatly enhances the richness of intelligence, thus providing a higher information gain for accurate inference in subsequent LLM.
[0058] This application proposes a method for determining semantic security information packets for power distribution networks, referring to... Figure 3 The method, applied in the cloud and communicatively connected to the distribution network endpoints, includes the following steps: Step 201: In response to determining that an initial security intelligence packet has been received from the distribution network endpoint, the initial security intelligence packet is taken as the target initial security intelligence packet.
[0059] In this step, when the cloud receives the initial security intelligence packet sent by the distribution network endpoint, it is necessary to process the initial security intelligence packet. First, the initial security intelligence packet is used as the target initial security intelligence packet.
[0060] Step 202: Perform multiple rounds of second investigation operations based on the target initial security intelligence package. Each round of second investigation operations is performed as follows: perform security verification on the target initial security intelligence package; in response to determining that the target initial security intelligence package passes the security verification, input the target initial security intelligence package into a pre-trained large language model, and generate and output the processing instructions corresponding to the target initial security intelligence package through the large language model.
[0061] In this step, multiple rounds of second investigation operations are performed based on the initial security intelligence packet of the target. Each round of second investigation operations is as follows: the initial security intelligence packet of the target is security verified, and the initial security intelligence packet of the target is decrypted using a public key. Due to the excellent analytical capabilities of the large language model, if the initial security intelligence packet of the target passes security verification, it is input into a pre-trained large language model. Based on its powerful knowledge base and correlation analysis capabilities, the cloud-based large language model performs deep reasoning on the initial security intelligence packet of the target, and may derive one or more attack hypotheses to be verified. For example, if the initial security intelligence packet of the target indicates that "an office software created a PowerShell process and initiated a network connection," the large language model may generate the hypothesis that "this may be an initial intrusion using a macro virus, and the next step may be persistence." The large language model will generate a specific, executable investigation instruction, which is essentially an "intelligence optimization strategy." For the above hypothesis, the investigation instruction might specifically be: "Request targeted monitoring of the PowerShell process with PID=5678, and only report new intelligence on all write operations related to registry startup items or scheduled tasks within the next 5 minutes." By generating and outputting processing instructions corresponding to the initial security intelligence packet of the target through a large language model, the goal of accurately processing the initial security intelligence packet of the target is achieved, ensuring the rationality of the generated processing instructions.
[0062] Leveraging the macroscopic analytical capabilities of cloud-based large models, the distribution network endpoint agents are guided to dynamically optimize their generated initial security intelligence packages, transforming the investigation from a one-off static snapshot into a dynamic process of continuous iteration and gradual refinement.
[0063] Step 2031: In response to determining that the processing instruction is an investigation instruction, the investigation instruction is encrypted and sent to the distribution network endpoint.
[0064] In this step, when the processing instruction is an investigation instruction, it indicates that an investigation of the target's initial security intelligence package is required. The investigation instruction is encrypted using a cloud private key and securely sent to the distribution network endpoint via an authenticated downlink data stream, ensuring the reliability of the investigation instruction transmission.
[0065] Step 2041: In response to determining that a new initial security intelligence packet corresponding to the investigation instruction sent by the distribution network endpoint is received within a predetermined time, the target initial security intelligence packet and the new initial security intelligence packet are used as the target initial security intelligence packet in the next round of the second investigation operation, and the next round of the second investigation operation is carried out.
[0066] In this step, if a new initial security intelligence packet corresponding to an investigation instruction sent by the distribution network endpoint is received within the predetermined time, it indicates that the distribution network endpoint has supplemented the target initial security intelligence packet with data. The investigation needs to continue using a large language model based on the existing data corresponding to the target initial security intelligence packet and the supplemented data. The target initial security intelligence packet and the new initial security intelligence packet are then used as the target initial security intelligence packets for the next round of the second investigation operation. Through dynamic data fusion, the goal of accurately supplementing the target initial security intelligence packet can be achieved, ensuring the richness of the target initial security intelligence packet.
[0067] Step 2042: In response to determining that a closed-ended answer corresponding to the investigation instruction sent by the distribution network endpoint is received within the predetermined time, the target initial security intelligence packet and the closed-ended answer are used as the target initial security intelligence packet in the next round of the second investigation operation, and the next round of the second investigation operation is performed.
[0068] In this step, if a closed-ended answer is received from the distribution network endpoint within a predetermined time, it indicates that the distribution network endpoint has provided a closed-ended response to the cloud's question. The target initial security intelligence package and the closed-ended answer are then used as the target initial security intelligence package for the next round of the second investigation operation. The closed-ended answer ensures an accurate understanding of the target initial security intelligence package, guaranteeing its richness.
[0069] Step 2032: In response to determining that the processing instruction is an end-of-investigation instruction, exit at least one round of the second investigation operation.
[0070] In this step, if the processing instruction is a "Terminate Investigation" instruction, it indicates that there is no need to investigate the initial security intelligence package of the target, and the second investigation operation is exited after at least one round. Exiting at least one round of the second investigation operation promptly when processing the "Terminate Investigation" instruction aligns with the security closed-loop management logic and avoids continuous resource consumption.
[0071] Through a two-way trusted protocol, the cloud-based large language model can securely issue certified supplementary investigation commands to distribution network endpoints. The distribution network endpoints then generate more targeted intelligence as a response on demand, upgrading static analysis to a dynamic "analysis-re-analysis" closed-loop investigation model, significantly improving the efficiency and accuracy of analyzing complex attacks.
[0072] Through the above scheme, in response to the determination that an initial security intelligence packet sent by the distribution network endpoint has been received, the initial security intelligence packet is taken as the target initial security intelligence packet. Multiple rounds of second investigation operations are performed based on the target initial security intelligence packet. Each round of second investigation operations is executed as follows: The target initial security intelligence packet undergoes security verification. In response to the determination that the target initial security intelligence packet passes the security verification, the target initial security intelligence packet is input into a pre-trained large language model. The large language model generates and outputs a processing instruction corresponding to the target initial security intelligence packet, achieving accurate processing of the target initial security intelligence packet and ensuring the rationality of the generated processing instruction. In response to the determination that the processing instruction is an investigation instruction, the investigation instruction is encrypted and sent to the distribution network endpoint, ensuring the reliability of the investigation instruction transmission. In response to the determination that a new initial security intelligence packet corresponding to the investigation instruction sent by the distribution network endpoint is received within a predetermined time, the target initial security intelligence packet and the new initial security intelligence packet are taken as the target initial security intelligence packets for the next round of second investigation operations. This achieves the purpose of accurately supplementing the target initial security intelligence packet, ensuring the richness of the target initial security intelligence packet. In response to determining that a closed-ended answer corresponding to an investigation instruction sent by the distribution network endpoint is received within the predetermined time, the target initial security intelligence package and the closed-ended answer are used as the target initial security intelligence package in the next round of the second investigation operation. This ensures accurate understanding of the target initial security intelligence package and guarantees its richness. In response to determining that the processing instruction is a termination instruction, at least one round of the second investigation operation is exited to avoid continuous resource consumption.
[0073] In another embodiment provided in this application, the method for determining semantic security intelligence packets for power distribution networks provided in this application was tested, and several test results were obtained. Test result 1: Solving the data source trust problem. In the test, a log tampering attack (deleting critical process creation logs) was introduced. The results show that, due to the digital signature and hardware proof contained in its semantic security intelligence packets, the cloud can immediately identify tampering during data transmission or the untrusted state of the data source, thereby refusing to analyze contaminated data. Test result 2: Bridging the representation gap and improving detection accuracy. The attack chain detection accuracy of the three systems was compared in the case of no data tampering, and the results are as follows: Figure 4 As shown. By Figure 4 As can be seen, Baseline A is the baseline system A, Baseline B is the baseline system B, and Proposed Method represents the system that processes the security intelligence packets determined by the method of this application. The detection accuracy of the method of this application reached 96%. Baseline system A, because it reports raw logs, has difficulty in effectively inferring causal relationships between events from its cloud-based LLM, resulting in the lowest accuracy. Although baseline system B has structured the data, its simple JSON format does not reflect the causal links between events. In contrast, the system of this application significantly improves intelligence richness through the TCHE method, enabling the LLM to perform inference based on higher information gain. This result verifies the rationality of the proposed indicator design and also shows that high intelligence richness directly translates into higher detection accuracy. Test effect 3: Realizing dynamic feedback investigation and improving analysis efficiency. In complex lateral movement tests, the cloud-based LLM only has medium confidence after the initial analysis. This intelligence richness system allows the cloud-based large language model to request supplementary intelligence "all network connections of target process PID=1234 in the next 5 minutes" from the distribution network endpoint through a trusted channel. After the distribution network endpoints responded, LLM, combined with new, hardware-certified evidence, successfully raised the confidence level to high confidence and confirmed the attack. Neither of the two baseline systems possessed this closed-loop investigation capability and was unable to complete the task.
[0074] In summary, the experimental results demonstrate that this application effectively addresses the shortcomings of existing technologies in terms of data reliability, analytical accuracy, and survey interactivity, ensuring the comprehensiveness of the security intelligence package.
[0075] In another embodiment provided in this application, the scenario is summarized as follows: Taking a typical power distribution network operation and maintenance management device as an example, an attacker uses spear-phishing emails to induce maintenance personnel to open a document containing malicious macros on their engineering station connected to the internal system of the power distribution network. This document triggers the Word process (winword.exe) to execute embedded PowerShell commands, thereby generating a powershell.exe process on the engineering station and attempting to establish a connection with a remote command and control (C2) server. Once a foothold is established, the attacker may use this location to further penetrate lower-level intelligent terminal devices (such as FTUs) through LotL commands (such as sc creating services) or by modifying the registry, or to achieve persistence on the engineering station, preparing for subsequent attacks.
[0076] like Figure 5 As shown, Figure 5 This is a detailed flowchart illustrating the method for determining semantic security information packets for power distribution networks according to an embodiment of this application. Figure 5 It illustrates the entire process from step one to step seven, specifically: Step 1: Data Acquisition and Secure Input.
[0077] Continuously collect data from events, such as process creation, network connection, file / registry writes, etc.
[0078] Events are sent to the trusted endpoint interaction agent on the distribution network endpoint side via a controlled channel. Data acquisition itself can occur at the distribution network endpoint, but it must be verified for integrity and accepted by the trusted endpoint interaction agent in the distribution network endpoint before entering the trusted link.
[0079] For example, events include: process creation: {ParentImage: "C:\winword.exe", ParentPID:1234, ChildImage:"C:\powershell.exe", ChildPID:5678, Cmd:"..."}; network connection: {Image:"C:\powershell.exe", PID:5678, DstIP:"123.45.67.89", DstPort:443}.
[0080] Step 2: Event encoding and intelligence generation within the endpoint trusted interaction agent.
[0081] The trusted interaction agent at the endpoint performs actions on received events within a trusted environment at the distribution network endpoint, according to the method for determining semantic security intelligence packets for distribution networks provided in this application. 1. Event-level atomic encoding (representing events using domain prefixes and characterization); 2. Construct causal links based on the tracking process ID / parent process ID, handle, file identifier, etc., and perform intelligence-level aggregation; 3. Generate structured security intelligence events S and calculate global characteristics, such as the external link count of ProcA.
[0082] For example, a security intelligence event is a TCHE intelligence: [GLOBAL: Proc_winword_NetCount=1 ...]PROC:Img_winword_hash PID_1234 <spawns>PROC:Img_powershell_hash PID_5678 PPID_1234<FOLLOWED_BY> NET:PID_5678 DstIP_123.45.67.89 DstPort_443.
[0083] Steps 1 and 2 are the process of generating security intelligence events from events to be verified, such as... Figure 6 As shown, events awaiting security verification are generated into security intelligence events after atomic-level encoding and intelligence-level structured aggregation. The codes obtained through event-level atomic encoding contain a domain prefix, which is used to store the data source and allows for the extraction of key data from the event through feature encoding and hashing. All encoded event codes are then subjected to intelligence-level structured aggregation, linking all encoded events causally and extracting global and local features from all encoded events. Finally, multi-layered standardized intelligence text is generated.
[0084] Step 3: Local risk assessment.
[0085] A local lightweight model deployed within a trusted environment performs real-time evaluation of TCHE intelligence and calculates the conditional probability P(H). _1 |S), and based on the hierarchical decision function D(P(H) _1 |S))(threshold is θ _"low" and θ _"high" (where the threshold is configurable), output one of the discrete processing actions: `ArchiveLocally` / `EscalateToCloud` / `EscalateAndMitigate`, and generate a structured preliminary judgment, such as `{risk: "high", reason: "process_spawn_and_c2"}`.
[0086] Step 4: Semantic security intelligence encapsulation and hardware notarization.
[0087] If the decision mapping is "report" or "report and mitigate", the encapsulation unit in the trusted environment will construct a semantic initial security intelligence package, which includes: TCHE intelligence text S; local assessment results and confidence (metadata); runtime metrics and timestamps; and hardware proof report / signature (the intelligence digest is signed by a private key derived from the Physically Unclonable Function (PUF) + Hardware Trust Root (RoT)).
[0088] The Hardware Root of Trust (PUF+RoT) is responsible for the signature and challenge-response, proving that the signing private key is protected by the RoT and that the signature is fresh (preventing replay). The entire encapsulation process is completed in collaboration with the hardware within a trusted environment to ensure the authenticity and integrity of the reported content.
[0089] Step 5: Report to the cloud for verification (device → cloud).
[0090] The semantic initial security intelligence packet is reported to the cloud through an encrypted channel; the cloud first verifies the hardware proof report and signature (based on the device public key / certificate chain) to confirm that the source of the initial security intelligence packet and the operating metrics of the trusted environment have not been tampered with.
[0091] The cloud performs more complex LLM analysis on the initial security intelligence package, such as attack chain inference and IOC correlation, and draws preliminary conclusions and confidence levels.
[0092] Step 6: Issue the certified survey command via the cloud.
[0093] If the cloud-based analysis evidence is insufficient to confirm critical actions such as persistence, the cloud sends a signed supplementary collection command to the trusted interaction agent of that endpoint through an established trusted channel. For example, it might request supplementary intelligence on all network connections, registry writes, and scheduled task operations of `PID=5678` within the next 5 minutes. This downlink command is verified for signature and integrity within a trusted environment; only commands that pass verification are executed or trigger controlled data collection.
[0094] Step 7: Collect additional samples, re-encode, and report as needed at the end.
[0095] Within a trusted environment, the endpoint agent performs more granular monitoring of the target process according to instructions. After capturing new evidence such as "writing to registry startup items", it re-executes TCHE encoding to generate supplementary intelligence, and then encapsulates and hardware-certifies it in step 4 before reporting it to the cloud.
[0096] The cloud receives and verifies supplementary evidence, correlates it with the initial intelligence, and completes the reconstruction of the attack chain. Initial access (malicious document) → Execution (PowerShell) → Command and control (C2 connection) → Persistence (registry modification).
[0097] Based on a high-confidence evidence chain, the cloud can issue further responses (such as issuing isolation instructions or automated handling strategies), or hand them over to security operations personnel for offline handling.
[0098] It should be noted that the method in this embodiment can be executed by a single device, such as a computer or server. The method can also be applied in a distributed scenario, where multiple devices cooperate to complete the task. In such a distributed scenario, one of these devices may execute only one or more steps of the method in this embodiment, and the multiple devices will interact with each other to complete the method described.
[0099] It should be noted that the above description describes some embodiments of this application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in a different order than that shown in the above embodiments and still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0100] Based on the same inventive concept, corresponding to any of the above embodiments, this application also provides a device for determining semantic security information packets for power distribution networks.
[0101] refer to Figure 7 The device for determining semantic security intelligence packets for power distribution networks is applied to a power distribution network endpoint, which is communicatively connected to the cloud. The device includes: In response to receiving an event requiring security verification, multiple rounds of verification operations are performed based on the event. Each round of verification operations is executed as follows: The first generation module 10 is configured to encode the event to obtain multiple event codes, and generate a security intelligence event based on the multiple event codes.
[0102] The first sending module 20 is configured to determine the risk level corresponding to the security intelligence event through a pre-trained lightweight model, and in response to determining that the risk level is greater than a first predetermined value, encapsulate and encrypt the security intelligence event to obtain an initial security intelligence packet, and send the initial security intelligence packet to the cloud.
[0103] The investigation module 30 is configured to respond to receiving an investigation instruction for the initial security intelligence packet from the cloud within a predetermined time, and to perform multiple rounds of first investigation operations based on the investigation instruction to obtain investigation results.
[0104] The verification module 401 is configured to, in response to the detection of a new event in the survey results, use the new event as an event in the next round of verification operations and perform the next round of verification operations.
[0105] The verification module 402 is further configured to, in response to the absence of the new event in the investigation results, or in response to the determination that no investigation instruction sent by the cloud has been received within the predetermined time, identify the initial security intelligence packet in all rounds of verification operations as the security intelligence packet corresponding to the event, and exit at least one round of verification operations.
[0106] The aforementioned device, in response to receiving an event to be verified for security, performs multiple rounds of verification operations based on the event. Each round of verification operations is as follows: the event is encoded to obtain multiple event codes, and a security intelligence event is generated based on the multiple event codes. This links scattered, single-coded events into an intelligence chain with contextual logic, reducing information silos and achieving accurate integration of all encoded events. A pre-trained lightweight model determines the risk level corresponding to the security intelligence event, achieving accurate determination of the risk level. In response to determining that the risk level is greater than a first predetermined value, the security intelligence event is encapsulated and encrypted to obtain an initial security intelligence packet. The initial security intelligence packet is sent to the cloud, effectively preventing tampering of the security intelligence event and ensuring the security of security intelligence event transmission. In response to receiving an investigation instruction from the cloud regarding the initial security intelligence packet within a predetermined time, multiple rounds of first investigation operations are performed based on the investigation instruction to obtain investigation results, which helps to enhance the richness of threat intelligence. In response to the detection of a new event in the investigation results, the new event is used as the event in the next round of verification operations, enabling dynamic expansion of the event. In response to the detection of no new event in the investigation results, or in response to the determination that no investigation instruction sent from the cloud has been received within the predetermined time, the initial security intelligence package in all rounds of verification operations is identified as the security intelligence package corresponding to the event, and at least one round of verification operations is exited, ensuring the comprehensiveness and accuracy of the security intelligence package.
[0107] In some embodiments, the survey module 30 is further configured to perform the following in each round of the first survey operation: perform security verification on the survey instruction; in response to determining that the survey instruction passes the security verification, and in response to determining that the survey instruction is a closed-ended query instruction, determine the closed-ended answer corresponding to the closed-ended query instruction based on the closed-ended query instruction, encrypt the closed-ended answer and send it to the cloud; in response to determining that a feedback survey instruction for receiving the closed-ended answer is received within the predetermined time, use the feedback survey instruction as the survey instruction in the next round of the first survey operation and execute the next round of the first survey operation; in response to determining that no feedback survey instruction for receiving the closed-ended answer is received within the predetermined time, use all determined closed-ended answers as the survey result and exit at least one round of the first survey operation; in response to determining that the survey instruction passes the security verification, and in response to determining that the survey instruction is an event supplement instruction, determine the new event corresponding to the event supplement instruction based on the event supplement instruction, use the new event as the survey result and exit at least one round of the first survey operation.
[0108] In some embodiments, the first generation module 10 is further configured to divide the event in a predetermined order to obtain a sequence containing multiple sub-events; for each sub-event in the sequence, obtain the data source of the sub-event; and determine the key data of the sub-event using a predetermined algorithm. Based on the data source and key data corresponding to the sub-event, atomically encode the event to obtain the event code corresponding to the sub-event.
[0109] In some embodiments, the first generation module 10 is further configured to perform causal connection on the plurality of event codes in a predetermined order to obtain an aggregated event; determine the importance of each event code and the risk value of the aggregated event based on the plurality of event codes; for each event code, in response to determining that the importance of the event code is greater than a second predetermined value, determine the event code as a target event code; and generate the security intelligence event based on the importance of each target event code, the risk value, the aggregated event, and each target event code.
[0110] In some embodiments, the first generation module 10 is further configured to, for each event code, determine a sensitivity score corresponding to the event code based on the event code and predefined highly sensitive operation events; calculate the usage rate of the event code based on the event codes corresponding to historical events and the event code, and determine a rarity score corresponding to the event code based on the usage rate; determine at least one adjacent event code corresponding to the event code based on the event code and the sequence, and determine an association score corresponding to the event code based on the event code and all adjacent event codes; calculate the importance of the event code based on the sensitivity score, rarity score, and association score corresponding to the event code; determine a sub-risk value corresponding to the event code using a predetermined function; and determine the risk value corresponding to the aggregated event based on all sub-risk values.
[0111] In some embodiments, the first sending module 20 is further configured to obtain a proof report corresponding to the distribution network endpoint and an identification information corresponding to the security intelligence event; encapsulate the proof report, the security intelligence event, and the identification information to obtain an encapsulated packet; and encrypt the encapsulated packet to obtain the initial security intelligence packet.
[0112] In some embodiments, a second sending module is further included, which is configured to generate and send warning information based on the security intelligence packet corresponding to the event after determining the initial security intelligence packet in all rounds of verification operations as the security intelligence packet corresponding to the event.
[0113] For ease of description, the above devices are described in terms of function, divided into various modules. Of course, in implementing this application, the functions of each module can be implemented in one or more software and / or hardware.
[0114] Based on the same inventive concept, and corresponding to any of the above embodiments, this application also provides a device for upgrading the USB firmware of a vehicle.
[0115] refer to Figure 8 The device for determining semantic security intelligence packets for power distribution networks is applied to a remote server in the cloud, wherein the cloud is communicatively connected to the power distribution network endpoints. The device includes: The receiving module 50 is configured to, in response to determining that an initial security intelligence packet has been received from the distribution network endpoint, use the initial security intelligence packet as a target initial security intelligence packet.
[0116] Based on the initial security intelligence package of the target, multiple rounds of second investigation operations are performed, and each round of second investigation operations is executed as follows: The second generation module 60 is configured to perform security verification on the target initial security intelligence packet. In response to determining that the target initial security intelligence packet passes the security verification, the target initial security intelligence packet is input into a pre-trained large language model, and the large language model generates and outputs the processing instructions corresponding to the target initial security intelligence packet.
[0117] The first determining module 701 is configured to, in response to determining that the processing instruction is an investigation instruction, encrypt and send the investigation instruction to the distribution network endpoint; The second determining module 801 is configured to, in response to determining that a new initial security intelligence packet corresponding to an investigation instruction sent by the distribution network endpoint is received within a predetermined time, use the target initial security intelligence packet and the new initial security intelligence packet as the target initial security intelligence packet in the next round of the second investigation operation, and perform the next round of the second investigation operation. The second determining module 802 is further configured to, in response to determining the closed-ended answer corresponding to the investigation instruction sent by the distribution network endpoint within the predetermined time, use the target initial security intelligence packet and the closed-ended answer as the target initial security intelligence packet in the next round of the second investigation operation, and perform the next round of the second investigation operation; The first determining module 702 is further configured to exit at least one round of the second investigation operation in response to determining that the processing instruction is an end investigation instruction.
[0118] Using the aforementioned apparatus, in response to determining that an initial security intelligence packet sent by the distribution network endpoint has been received, the initial security intelligence packet is designated as the target initial security intelligence packet. Multiple rounds of second investigation operations are performed based on the target initial security intelligence packet. Each round of the second investigation operation is executed as follows: The target initial security intelligence packet undergoes security verification. In response to determining that the target initial security intelligence packet passes the security verification, the target initial security intelligence packet is input into a pre-trained large language model. The large language model generates and outputs a processing instruction corresponding to the target initial security intelligence packet, achieving accurate processing of the target initial security intelligence packet and ensuring the rationality of the generated processing instruction. In response to determining that the processing instruction is an investigation instruction, the investigation instruction is encrypted and sent to the distribution network endpoint, ensuring the reliability of the investigation instruction transmission. In response to determining that a new initial security intelligence packet corresponding to the investigation instruction sent by the distribution network endpoint is received within a predetermined time, the target initial security intelligence packet and the new initial security intelligence packet are designated as the target initial security intelligence packets for the next round of the second investigation operation. This allows for accurate supplementation of the target initial security intelligence packet, ensuring its richness. In response to determining that a closed-ended answer corresponding to an investigation instruction sent by the distribution network endpoint is received within the predetermined time, the target initial security intelligence package and the closed-ended answer are used as the target initial security intelligence package in the next round of the second investigation operation. This ensures accurate understanding of the target initial security intelligence package and guarantees its richness. In response to determining that the processing instruction is a termination instruction, at least one round of the second investigation operation is exited to avoid continuous resource consumption.
[0119] The apparatus of the above embodiments is used to implement the corresponding method for determining semantic security information packets for power distribution networks in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0120] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, this application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the method for determining semantic security information packages for power distribution networks as described in any of the above embodiments.
[0121] Figure 9 This embodiment illustrates a more specific hardware structure of an electronic device. The device may include a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, memory 1020, input / output interface 1030, and communication interface 1040 are interconnected internally via the bus 1050.
[0122] The processor 1010 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.
[0123] The memory 1020 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 1020 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program code is stored in the memory 1020 and is called and executed by the processor 1010.
[0124] The input / output interface 1030 is used to connect input / output modules to realize information input and output. The input / output modules can be configured as components in the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Input devices may include keyboards, mice, touch screens, microphones, various sensors, etc., and output devices may include displays, speakers, vibrators, indicator lights, etc.
[0125] The communication interface 1040 is used to connect a communication module (not shown in the figure) to enable communication between this device and other devices. The communication module can communicate via wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).
[0126] Bus 1050 includes a pathway for transmitting information between various components of the device, such as processor 1010, memory 1020, input / output interface 1030, and communication interface 1040.
[0127] It should be noted that although the above-described device only shows the processor 1010, memory 1020, input / output interface 1030, communication interface 1040, and bus 1050, in specific implementations, the device may also include other components necessary for normal operation. Furthermore, those skilled in the art will understand that the above-described device may only include the components necessary for implementing the embodiments of this specification, and not necessarily all the components shown in the figures.
[0128] The electronic devices described above are used to implement the corresponding semantic security information package determination method for power distribution networks in any of the foregoing embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0129] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, this application also provides a non-transitory computer-readable storage medium storing computer instructions for causing the computer to execute the method for determining semantic security information packets for power distribution networks as described in any of the above embodiments.
[0130] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transfer medium that can be used to store information accessible by a computing device.
[0131] The computer instructions stored in the storage medium of the above embodiments are used to cause the computer to execute the method for determining semantic security information packets for power distribution networks as described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0132] Based on the same concept, corresponding to the methods of any of the above embodiments, this application also provides a computer program product, including computer program instructions, which, when run on a computer, cause the computer to execute the method for determining semantic security information packages for power distribution networks as described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0133] It should be noted that the embodiments of this application can also be further described in the following ways: It is understood that before using the technical solutions of the various embodiments in this disclosure, users will be informed of the type, scope of use, and usage scenarios of the personal information involved in an appropriate manner, and user authorization will be obtained.
[0134] For example, upon receiving a user's active request, a prompt message is sent to the user to explicitly inform them that the requested operation will require the acquisition and use of the user's personal information. This allows the user to independently choose, based on the prompt message, whether to provide personal information to the software or hardware such as electronic devices, applications, servers, or storage media performing the operations of this disclosed technical solution.
[0135] As an optional but not limited implementation, in response to a user's active request, sending a prompt message to the user can be done via a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide personal information to the electronic device.
[0136] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.
[0137] Those skilled in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of this application is limited to these examples; under the concept of this application, the technical features of the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations of different aspects of the embodiments of this application as described above, which are not provided in detail for the sake of brevity.
[0138] Additionally, to simplify the description and discussion, and to avoid obscuring the embodiments of this application, the well-known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided drawings. Furthermore, the apparatus may be shown in block diagram form to avoid obscuring the embodiments of this application, and this also takes into account the fact that the details of the implementation of these block diagram apparatuses are highly dependent on the platform on which the embodiments of this application will be implemented (i.e., these details should be fully understood by those skilled in the art). While specific details (e.g., circuits) have been set forth to describe exemplary embodiments of this application, it will be apparent to those skilled in the art that the embodiments of this application can be implemented without these specific details or with variations thereof. Therefore, these descriptions should be considered illustrative rather than restrictive.
[0139] Although this application has been described in conjunction with specific embodiments thereof, many substitutions, modifications, and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may be used with the embodiments discussed.
[0140] The embodiments of this application are intended to cover all such substitutions, modifications, and variations that fall within the broad scope of this application. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the embodiments of this application should be included within the protection scope of this application.< / spawns> < / spawns> < / spawns> < / spawns>
Claims
1. A method for determining a semanticized security intelligence package for a power distribution network, characterized in that, Applied to a distribution network endpoint, wherein the distribution network endpoint is communicatively connected to a cloud, the method includes: In response to receiving an event requiring security verification, multiple rounds of verification operations are performed based on the event. Each round of verification operations is executed as follows: The event is encoded to obtain multiple event codes, and a security intelligence event is generated based on the multiple event codes; The risk level corresponding to the security intelligence event is determined by a pre-trained lightweight model. In response to determining that the risk level is greater than a first predetermined value, the security intelligence event is encapsulated and encrypted to obtain an initial security intelligence package, and the initial security intelligence package is sent to the cloud. In response to the determination that an investigation instruction for the initial security intelligence package is received from the cloud within a predetermined time, multiple rounds of first investigation operations are performed based on the investigation instruction to obtain investigation results; In response to the detection of a new event in the survey results, the new event is used as the event in the next round of verification operations, and the next round of verification operations is performed. In response to the detection that the new event does not exist in the investigation results, or in response to the determination that no investigation instruction sent by the cloud is received within the predetermined time, the initial security intelligence packet in all rounds of verification operations is identified as the security intelligence packet corresponding to the event, and at least one round of verification operations is exited.
2. The method according to claim 1, characterized in that, The process of performing multiple rounds of the first investigation based on the investigation instruction to obtain investigation results includes: The first round of the investigation is conducted as follows: The investigation order is subject to security verification. In response to determining that the survey instruction passes the security verification, and in response to determining that the survey instruction is a closed-ended query instruction, based on the closed-ended query instruction, a closed-ended answer corresponding to the closed-ended query instruction is determined, and the closed-ended answer is encrypted and sent to the cloud; in response to determining that a feedback survey instruction with the closed-ended answer is received within the predetermined time, the feedback survey instruction is used as the survey instruction in the next round of the first survey operation, and the next round of the first survey operation is executed; in response to determining that no feedback survey instruction with the closed-ended answer is received within the predetermined time, all determined closed-ended answers are used as the survey result, and at least one round of the first survey operation is exited. In response to determining that the investigation instruction has passed the security verification, and in response to determining that the investigation instruction is an event supplement instruction, based on the event supplement instruction, a new event corresponding to the event supplement instruction is determined, the new event is taken as the investigation result, and at least one round of the first investigation operation is exited.
3. The method according to claim 1, characterized in that, The event is encoded to obtain multiple event codes, including: The events are divided in a predetermined order to obtain a sequence containing multiple sub-events; For each sub-event in the sequence, the data source of the sub-event is obtained, and key data of the sub-event is determined using a predetermined algorithm. Based on the data source and key data corresponding to the sub-event, the event is atomically encoded to obtain the event code corresponding to the sub-event.
4. The method according to claim 3, characterized in that, The generation of security intelligence events based on the multiple event codes includes: The multiple event codes are connected causally in a predetermined order to obtain an aggregate event; Based on the multiple event codes, determine the importance of each event code and the risk value of the aggregated event; For each event code, in response to determining that the importance of the event code is greater than a second predetermined value, the event code is determined as a target event code; The security intelligence event is generated based on the importance corresponding to each target event code, the risk value, the aggregated event, and each target event code.
5. The method according to claim 4, characterized in that, The step of determining the importance of each event code and the risk value of the aggregated event based on the multiple event codes includes: For each event code, a sensitivity score is determined based on the event code and predefined high-sensitivity operation events. Based on the event codes corresponding to historical events and the event codes, the usage rate of the event codes is calculated, and based on the usage rate, the rarity score corresponding to the event codes is determined; Based on the event code and the sequence, at least one adjacent event code corresponding to the event code is determined, and based on the event code and all adjacent event codes, the association score corresponding to the event code is determined; Based on the sensitivity score, rarity score, and association score corresponding to the event code, the importance of the event code is calculated. The sub-risk value corresponding to the event code is determined using a predetermined function; Based on all sub-risk values, the risk value corresponding to the aggregated event is determined.
6. The method according to claim 1, characterized in that, The process of encapsulating and encrypting the security intelligence event to obtain an initial security intelligence packet includes: Obtain the proof report corresponding to the distribution network endpoint and the identification information corresponding to the security intelligence event; The proof report, the security intelligence event, and the identification information are encapsulated to obtain an encapsulated package; The package is encrypted to obtain the initial security intelligence package.
7. The method according to claim 1, characterized in that, After identifying the initial security intelligence packet from all rounds of verification operations as the security intelligence packet corresponding to the event, the method includes: Based on the security intelligence package corresponding to the event, an early warning message is generated and sent.
8. A method for determining semantic security information packets for power distribution networks, characterized in that, The method is applied in the cloud, where the cloud is communicatively connected to the endpoints of the power distribution network, and includes: In response to determining that an initial security intelligence packet has been received from the distribution network endpoint, the initial security intelligence packet is taken as the target initial security intelligence packet; Based on the initial security intelligence package of the target, multiple rounds of second investigation operations are performed, and each round of second investigation operations is executed as follows: The initial security intelligence packet of the target is subjected to security verification. In response to determining that the initial security intelligence packet of the target passes the security verification, the initial security intelligence packet of the target is input into a pre-trained large language model, and the large language model generates and outputs the processing instructions corresponding to the initial security intelligence packet of the target. In response to determining that the processing instruction is an investigation instruction, the investigation instruction is encrypted and sent to the distribution network endpoint; In response to determining that a new initial security intelligence packet corresponding to an investigation instruction sent by the distribution network endpoint is received within a predetermined time, the target initial security intelligence packet and the new initial security intelligence packet are used as the target initial security intelligence packet in the next round of the second investigation operation, and the next round of the second investigation operation is carried out. In response to determining that a closed-ended answer corresponding to an investigation instruction sent by the distribution network endpoint is received within the predetermined time, the target initial security intelligence packet and the closed-ended answer are used as the target initial security intelligence packet in the next round of the second investigation operation, and the next round of the second investigation operation is carried out. In response to determining that the processing instruction is an investigation termination instruction, exit at least one round of the second investigation operation.
9. A device for determining semantic security information packets for power distribution networks, characterized in that, The device is applied to a distribution network endpoint, which is communicatively connected to a cloud, and includes: In response to receiving an event requiring security verification, multiple rounds of verification operations are performed based on the event. Each round of verification operations is executed as follows: The first generation module is configured to encode the event to obtain multiple event codes, and generate a security intelligence event based on the multiple event codes; The first sending module is configured to determine the risk level corresponding to the security intelligence event through a pre-trained lightweight model, and in response to determining that the risk level is greater than a first predetermined value, encapsulate and encrypt the security intelligence event to obtain an initial security intelligence packet, and send the initial security intelligence packet to the cloud. The investigation module is configured to respond to receiving an investigation instruction for the initial security intelligence packet from the cloud within a predetermined time, and to perform multiple rounds of first investigation operations based on the investigation instruction to obtain investigation results; The verification module is configured to, in response to the detection of a new event in the survey results, treat the new event as an event in the next round of verification operations and perform the next round of verification operations. The verification module is further configured to, in response to the absence of the new event in the investigation results, or in response to the determination that no investigation instruction sent by the cloud has been received within the predetermined time, identify the initial security intelligence packet in all rounds of verification operations as the security intelligence packet corresponding to the event, and exit at least one round of verification operations.
10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the program, it implements the method as described in any one of claims 1 to 7.