Safety protection method, device and equipment
By performing multi-dimensional anomaly and risk detection on the operational behavior and function call data of the power system, and combining it with dynamic protection action response, the problem of poor power system security protection in existing technologies has been solved, and effective protection against complex network attacks has been achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GUANGZHOU ELECTRIC POWER COMM NETWORK LTD
- Filing Date
- 2025-12-16
- Publication Date
- 2026-04-17
AI Technical Summary
When facing complex network attacks, existing technologies for power system security protection mainly remain at the network boundary layer, making it difficult to effectively identify and block attacks at the application layer, and lacking timeliness and adaptability in the face of dynamic attacks.
By acquiring operational behavior data and function call data of the power system, multi-dimensional anomaly detection is performed. Combined with threat datasets, risk detection is conducted, and dynamic protective actions are taken to improve the effectiveness of security protection.
It effectively improves the security protection of the power system in the face of complex network attacks, and enhances its adaptability and timeliness to dynamic attack behaviors.
Smart Images

Figure CN121887449A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security technology, and in particular to a security protection method, device, and equipment. Background Technology
[0002] With the increasing sophistication and targeting of cyberattacks, especially the growing number of advanced persistent threats (APTs) targeting critical infrastructure, identifying and blocking dynamic internal / external attacks on power systems has become a key focus for relevant personnel.
[0003] Currently, most related technologies adopt a "peripheral protection" model, relying on network boundary devices such as firewalls, intrusion detection systems (IDS), and security isolation gateways to implement network access control and traffic filtering for power systems, thereby achieving security protection for the power system. However, this security protection method mainly stays at the network boundary layer outside the power system, and its security protection effect is unsatisfactory in the face of increasingly complex network attacks.
[0004] Therefore, the problems with the relevant technologies still need to be solved and optimized. Summary of the Invention
[0005] The purpose of this invention is to at least partially solve one of the technical problems existing in the related art.
[0006] Therefore, one objective of this invention is to provide a security protection method, apparatus, and device, wherein the method can effectively improve the security protection effect of power systems when facing complex network attacks.
[0007] To achieve the above-mentioned technical objectives, the technical solutions adopted in the embodiments of this application include: In a first aspect, embodiments of this application provide a security protection method, including: Acquire a threat dataset, a security behavior model, and a security function statistical model of the power system, as well as operational behavior data and function call data of the power system at the current sampling time point; the function call data includes a call chain sequence and several first call functions, the call chain sequence being used to indicate the call order of the first call functions; Based on the security behavior model and the security function statistical model, multi-dimensional anomaly detection is performed on the runtime behavior data and the function call data to obtain anomaly detection data. Based on the anomaly detection data and the threat dataset, risk detection processing is performed on the runtime behavior data and the function call data to obtain risk detection data; The risk detection data is dynamically responded to to obtain the target protection action, and the power system is protected based on the target protection action.
[0008] In addition, the method according to the above embodiments of this application may also have the following additional technical features: Furthermore, in one embodiment of this application, obtaining a security behavior model includes: Obtain the historical behavior matrix of the power system; The historical behavior matrix is filtered to obtain a behavior sample set, which is a set of baseline behaviors of the power system under no-attack conditions, and each baseline behavior corresponds to a matrix element in the historical behavior matrix. The safety behavior model is obtained by constructing a model from the set of behavioral samples.
[0009] Furthermore, in one embodiment of this application, obtaining the security function statistical model includes: Obtain the function call sequence of the power system at historical sampling time points; Perform function analysis on each historical function in the function call sequence to obtain a function security state vector corresponding to each historical function; Based on all the security state vectors of the functions, the statistical model of the security function is constructed.
[0010] Furthermore, in one embodiment of this application, the step of performing multi-dimensional anomaly detection on the runtime behavior data and the function call data based on the security behavior model and the security function statistical model to obtain anomaly detection data includes: Get the function detection threshold; The operational behavior data is input into the safety behavior model for behavior deviation analysis to obtain behavior deviation data; Each first calling function in the function call data is input into the security function statistical model for call deviation analysis to obtain first call deviation data corresponding to each first calling function; Based on the function detection threshold, function threshold detection is performed on all the first call deviation data to obtain a number of second call deviation data. The anomaly detection data is obtained by performing weighted fusion detection on the behavioral deviation data and all the second call deviation data.
[0011] Furthermore, in one embodiment of this application, the step of performing risk detection processing on the runtime behavior data and the function call data based on the anomaly detection data and the threat dataset to obtain risk detection data includes: Obtain the anomaly detection threshold and invoke the directed graph; Based on the directed call graph, the call sequence of the function call data is analyzed to obtain several second call functions, which are used to characterize the first call functions with abnormal call order. Based on the anomaly detection threshold, anomaly threshold detection is performed on the anomaly detection data to obtain the threshold detection result; If the threshold detection result indicates that the anomaly detection data is greater than the anomaly detection threshold, then based on the threat dataset and the anomaly detection data, a multidimensional risk analysis is performed on the operational behavior data, all second call functions, and third call functions to obtain the risk detection data; the third call function is the first call function corresponding to the second call deviation data.
[0012] Furthermore, in one embodiment of this application, the step of performing multi-dimensional risk analysis on the runtime behavior data, all second and third calling functions, based on the threat dataset and the anomaly detection data, to obtain the risk detection data includes: Based on the threat dataset, several threat intelligence samples are obtained, including sample behavior feature vectors, threat function feature sets, and threat level labels; Based on the sample behavior feature vector of each threat intelligence sample, feature similarity analysis is performed on the operational behavior data to obtain the behavioral feature similarity corresponding to each threat intelligence sample; Based on the threat function feature set of each threat intelligence sample, perform function similarity analysis on all the second and / or third calling functions to obtain the function set similarity to each threat intelligence sample; Based on the similarity of each behavioral feature, the similarity of the corresponding function set is fused to obtain several fused similarities; Based on the anomaly detection data and all the fusion similarities, risk analogy detection is performed on the threat dataset to obtain the risk detection data.
[0013] Furthermore, in this embodiment of the application, the step of dynamically responding to the risk detection data to obtain the target protection action includes: Obtain the dynamic protection table of the power system at the current sampling time point. The dynamic protection table includes several protection classification functions and the level protection actions of the protection classification functions. Based on the risk detection data, the target classification function is obtained by matching the level of each protection classification function in the dynamic protection table. Based on the target classification function, all the protection actions of the specified levels are screened to obtain the target protection actions.
[0014] Furthermore, in this embodiment of the application, the method further includes: Acquire several neighbor detection data of the power system, and the classification threshold of each protection classification function; the neighbor detection data is used to characterize the risk detection data at adjacent time points; the adjacent time points are used to characterize the sampling time points that are adjacent to the current sampling time point on the time axis; Based on the risk detection data and all the neighbor detection data, the threshold of each protection classification function is updated to obtain several updated protection classification functions.
[0015] Secondly, embodiments of this application provide a safety protection device, including: The first processing unit is used to acquire a threat dataset, a security behavior model, and a security function statistical model of the power system, as well as the operating behavior data and function call data of the power system at the current sampling time point; the function call data includes a call chain sequence and several first call functions, and the call chain sequence is used to indicate the calling order of the first call functions; The second processing unit is used to perform multi-dimensional anomaly detection on the running behavior data and the function call data according to the security behavior model and the security function statistical model to obtain anomaly detection data; The third processing unit is used to perform risk detection processing on the runtime behavior data and the function call data based on the anomaly detection data and the threat dataset to obtain risk detection data; The fourth processing unit is used to dynamically respond to the risk detection data, obtain the target protection action, and perform security protection on the power system based on the target protection action.
[0016] Thirdly, embodiments of this application also provide an electronic device, including: At least one processor; At least one memory for storing at least one program; When the at least one program is executed by the at least one processor, the at least one processor performs the method described above.
[0017] Fourthly, embodiments of this application also provide a computer-readable storage medium storing a processor-executable program, which, when executed by the processor, is used to implement the above-described method.
[0018] Fifthly, embodiments of this application also provide a computer program product, which includes a computer program stored in a computer-readable storage medium. A processor of an electronic device reads the computer program from the computer-readable storage medium and executes the computer program, causing the electronic device to perform the method described above.
[0019] The advantages and beneficial effects of this application will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of this application: This application discloses a security protection method, apparatus, and device. The method acquires a threat dataset, a security behavior model, and a security function statistical model of a power system, as well as operational behavior data and function call data of the power system at the current sampling time. The function call data includes a call chain sequence and several first call functions, with the call chain sequence indicating the call order of the first call functions. Based on the security behavior model and the security function statistical model, multi-dimensional anomaly detection is performed on the operational behavior data and the function call data to obtain anomaly detection data. Based on the anomaly detection data and the threat dataset, risk detection processing is performed on the operational behavior data and the function call data to obtain risk detection data. Dynamic protection action responses are performed on the risk detection data to obtain target protection actions, and security protection is provided to the power system based on the target protection actions. This method, by acquiring operational behavior data and function call data of the power system application layer, performing multi-dimensional anomaly detection on the operational behavior data and function call data, and combining this with subsequent risk detection and dynamic protection action responses, can effectively improve the security protection effect of the power system when facing complex network attacks. Attached Figure Description
[0020] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the following description is provided with accompanying drawings of the relevant technical solutions in the embodiments of this application or the prior art. It should be understood that the accompanying drawings described below are only for the purpose of clearly illustrating some embodiments of the technical solutions in this application. For those skilled in the art, other drawings can be obtained based on these drawings without any creative effort.
[0021] Figure 1 A schematic flowchart illustrating a security protection method provided in an embodiment of this application; Figure 2 A schematic diagram of the frame of a safety protection device provided in an embodiment of this application; Figure 3 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0022] The embodiments of this application are described in detail below. Examples of these embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain this application, and should not be construed as limiting this application. The step numbers in the following embodiments are set only for ease of explanation, and there is no limitation on the order between the steps. The execution order of each step in the embodiments can be adaptively adjusted according to the understanding of those skilled in the art.
[0023] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.
[0024] Currently, most related technologies adopt a "peripheral protection" model, relying on network boundary devices such as firewalls, intrusion detection systems (IDS), and security isolation gateways to implement network access control and traffic filtering for power systems, thereby achieving security protection. However, this security protection method mainly stays at the network boundary layer outside the power system. It can only identify and block known threats at the network communication layer. As network attacks become increasingly complex, this method is difficult to effectively protect against attacks at the application layer of the power system (such as attackers injecting malicious commands through normal communication channels and remotely executing malicious commands by exploiting power system vulnerabilities), resulting in unsatisfactory security protection.
[0025] Furthermore, some related technologies achieve security protection through threat detection in power systems. However, since this method relies heavily on log analysis or offline rule matching, it is difficult to respond in a timely manner to dynamic attacks, resulting in poor timeliness and adaptability of security protection.
[0026] It should be noted that the aforementioned related technologies are only used to assist in understanding the technical solutions of this application and do not mean that they belong to the publicly disclosed prior art.
[0027] In view of this, embodiments of this application provide a security protection method, apparatus, and device. The method acquires operational behavior data and function call data of the power system application layer, performs multi-dimensional anomaly detection on the operational behavior data and function call data, and combines it with subsequent risk detection and dynamic protection action response. This can effectively improve the security protection effect of the power system when facing complex network attacks (such as attacks on the power system application layer).
[0028] Furthermore, this method performs risk monitoring on runtime behavior data and function call data based on anomaly detection data and threat datasets. Specifically, it detects risk categories in the threat dataset by using anomaly detection data and all fused similarities. This improves the adaptability of threat detection to dynamic attack behaviors, effectively enhancing the timeliness and effectiveness of security protection. Additionally, this method uses a protection grading function with dynamically updated grading thresholds to respond to risk detection data with protective actions, further improving adaptability to dynamic attack behaviors and enhancing the timeliness and effectiveness of security protection.
[0029] Reference Figure 1 In this application embodiment, a security protection method includes: Step 110: Obtain the threat dataset, security behavior model, and security function statistical model of the power system, as well as the operating behavior data and function call data of the power system at the current sampling time point; the function call data includes a call chain sequence and several first call functions, the call chain sequence being used to indicate the calling order of the first call functions; In this embodiment, the threat dataset can be a collection of the latest threat intelligence samples of the power system; the security behavior model can be a normal behavior model of the power system under no-attack conditions; and the security function statistical model can be a statistical model of the normal function parameter distribution of the power system during the safe operation phase.
[0030] It is understandable that operational behavior data can be core behavioral indicators of the power system at the current sampling time point. This operational behavior data includes function call counts, system call counts, network output packet counts, memory write operation counts, and total file write bytes, etc. Among them, the function call count is used to represent the total number of times the key functions of the power system (including communication, control, and database access functions) are called per unit time; the system call count is used to represent the total number of times the power system kernel layer is called within the sampling period; the network output packet count is used to represent the number of TCP / UDP packets sent out by the power system from the application layer; the memory write operation count is used to represent the number of memory write operations performed by user-mode programs in the power system within the current period; and the total file write bytes is used to represent the total number of bytes written to logs or configuration files by the power system monitoring program within the current sampling period / sampling time point.
[0031] The function call data can be a set of call function sequences recorded by the power system in the order of call time at the current sampling time point, and the call chain sequence and the first call function can be determined by combining the call function sequence.
[0032] It is worth mentioning that runtime behavior data and function call data can be obtained in real time by deploying the RASP (Runtime Application Self-Protection) module in the power system master control server and embedding it into the application execution environment of the power system.
[0033] In some embodiments, obtaining a security behavior model includes: Obtain the historical behavior matrix of the power system; The historical behavior matrix is filtered to obtain a behavior sample set, which is a set of baseline behaviors of the power system under no-attack conditions, and each baseline behavior corresponds to a matrix element in the historical behavior matrix. The safety behavior model is obtained by constructing a model from the set of behavioral samples.
[0034] In this embodiment of the application, the behavior matrix of the power system over several consecutive sampling periods prior to the current sampling time point can be obtained, denoted as the historical behavior matrix, which can be represented as:
[0035] in, For historical behavior matrix; and These are the feature vector forms of the running behavior data in the first sampling period, the second sampling period, and the Nth sampling period, respectively.
[0036] Understandably, behavior filtering involves filtering all matrix elements in the historical behavior matrix. Each matrix element corresponds to a feature vector of the operational behavior data within a sampling period (referred to as baseline behavior), thereby obtaining several matrix elements under attack-free states. The behavior sample set is then determined based on the matrix elements under all attack-free states. Model construction can begin by calculating the expected vector and covariance matrix of this behavior sample set, and then determining the security behavior model based on the calculated expected vector and covariance matrix.
[0037] For example, this security behavior model can be represented as:
[0038] in, A functional representation of the safety behavior model; Let be the expected vector of the behavioral sample set; Let be the covariance matrix of the behavioral sample set; Let i be the baseline behavior in the behavior sample set; It is the transpose symbol; A functional representation of the behavioral sample set; Let M be the Mth baseline behavior in the behavior sample set, where M ≤ N.
[0039] In some embodiments, obtaining the security function statistical model includes: Obtain the function call sequence of the power system at historical sampling time points; Perform function analysis on each historical function in the function call sequence to obtain a function security state vector corresponding to each historical function; Based on all the security state vectors of the functions, the statistical model of the security function is constructed.
[0040] In this embodiment of the application, the function call sequence of the power system at historical sampling time points can be collected through the RASP module. This function call sequence can be represented as:
[0041] in, For the power system at the sampling time point The following is a sequence of function calls; , and These are the identifiers for the first function call, the second function call, and the Lth function call, respectively.
[0042] Understandably, function analysis can be achieved by monitoring data such as the length of input parameters, the number of bytes of output data, and the return delay of each called function in the power system using RASP functions, and constructing a function safety state vector based on this data. For example, for any historical called function, its function safety state vector can be represented as:
[0043] in, This is the function safety state vector for the i-th function call (i.e., the i-th historical function call) in the function call sequence; The length of the input parameters for the i-th function call; This represents the number of bytes output during the i-th function call. The return delay for the i-th function call.
[0044] It is worth mentioning that after obtaining the safety state vectors of all functions, the expected vector and covariance matrix of the safety state vectors of all functions can be calculated, and the statistical model of the safety function can be determined based on the calculated expected vector and covariance matrix. The functional representation of the statistical model of the safety function is similar to the functional representation of the aforementioned safety behavior model, and can be easily deduced by analogy.
[0045] Step 120: Based on the security behavior model and the security function statistical model, perform multi-dimensional anomaly detection on the runtime behavior data and the function call data to obtain anomaly detection data; In this embodiment, multidimensional anomaly detection can be performed from the behavioral dimension and the function call dimension, through a security behavior model and a security function statistical model, thereby obtaining anomaly detection data.
[0046] In some embodiments, the step of performing multidimensional anomaly detection on the runtime behavior data and the function call data based on the security behavior model and the security function statistical model to obtain anomaly detection data includes: Get the function detection threshold; The operational behavior data is input into the safety behavior model for behavior deviation analysis to obtain behavior deviation data; Each first calling function in the function call data is input into the security function statistical model for call deviation analysis to obtain first call deviation data corresponding to each first calling function; Based on the function detection threshold, function threshold detection is performed on all the first call deviation data to obtain a number of second call deviation data. The anomaly detection data is obtained by performing weighted fusion detection on the behavioral deviation data and all the second call deviation data.
[0047] In this embodiment, the specific value of the function detection threshold can be set according to the actual situation. Behavioral deviation analysis can involve inputting operational behavior data into a safety behavior model, and using the Mahalanobis distance metric to calculate the degree of difference between the current operational behavior data and normal behavior, thereby obtaining behavioral deviation data. Specifically, if the current sampling time point is... The behavioral deviation data can be represented as:
[0048] in, This is behavioral deviation data; Sampling time point The feature vector form of the running behavior data.
[0049] Understandably, the content of call deviation analysis is similar to that of the aforementioned behavior deviation analysis, and can be easily deduced by analogy. Specifically, for any first calling function in the function call data, the function safety state vector of the first calling function can be input into the safety function statistical model. The safety function statistical model uses Mahalanobis distance to calculate the degree of difference between the current running behavior data and the normal behavior, thereby obtaining the first call deviation data of the first calling function.
[0050] Function threshold detection can compare the magnitude of the function detection threshold with each first call deviation data, and determine the first call deviation data that is greater than the function detection threshold as the second call deviation data. The specific value of the function detection threshold can be set according to the actual situation.
[0051] It is worth mentioning that weighted fusion detection can fuse behavioral deviation data and all second-level call deviation data based on preset weight coefficients to achieve the fusion of deviation information in the behavioral dimension and the function call dimension, thereby obtaining anomaly detection data. This anomaly detection data can be represented as follows:
[0052] in, This is data for anomaly detection; The weighting coefficients are [0, 1]. This represents the total number of deviation data in the second call; The first call deviation data, i.e. the second call deviation data, is used to characterize the first call deviation data that is greater than the function detection threshold; This is an indicator function that takes the value 1 when the condition in the indicator function is true, and takes the value 0 otherwise. This is behavioral deviation data; The maximum safety deviation threshold can be preset or determined based on the expected vector and covariance matrix of the safety behavior model, combined with the three sigma (3σ) principle.
[0053] Step 130: Based on the anomaly detection data and the threat dataset, perform risk detection processing on the runtime behavior data and the function call data to obtain risk detection data; In this embodiment of the application, risk detection data can be obtained by analyzing the risks present in runtime behavior data and function call data based on anomaly detection data and threat datasets.
[0054] In some embodiments, the step of performing risk detection processing on the runtime behavior data and the function call data based on the anomaly detection data and the threat dataset to obtain risk detection data includes: Obtain the anomaly detection threshold and invoke the directed graph; Based on the directed call graph, the call sequence of the function call data is analyzed to obtain several second call functions, which are used to characterize the first call functions with abnormal call order. Based on the anomaly detection threshold, anomaly threshold detection is performed on the anomaly detection data to obtain the threshold detection result; In this embodiment, the anomaly detection threshold is similar to the aforementioned function detection threshold and can be easily deduced. The directed graph being invoked can be a directed graph established by the power system under its initial safe operating state. , where the set of nodes This represents the set of functions that the power system is allowed to call, and the set of edges. This indicates the allowed function call relationships in the power system, specifically, that the power system allows calls between the i-th and j-th calling functions.
[0055] It is understandable that for any adjacent call pair in the call chain sequence... Call sequence analysis can be performed to determine whether an adjacent call pair belongs to a directed call graph. If it does not, it indicates that the call order of the two first call functions in the adjacent call pair is abnormal. In this case, each first call function in the adjacent call pair can be identified as the second call function. The same logic applies to the remaining adjacent call pairs in the call chain sequence. Anomaly threshold detection can be performed by comparing the magnitudes of two anomaly detection thresholds to obtain the threshold detection result.
[0056] If the threshold detection result indicates that the anomaly detection data is greater than the anomaly detection threshold, then based on the threat dataset and the anomaly detection data, a multidimensional risk analysis is performed on the operational behavior data, all second call functions, and third call functions to obtain the risk detection data; the third call function is the first call function corresponding to the second call deviation data.
[0057] Further, the risk detection data is obtained by performing multi-dimensional risk analysis on the runtime behavior data, all second and third calling functions, based on the threat dataset and the anomaly detection data, including: Based on the threat dataset, several threat intelligence samples are obtained, including sample behavior feature vectors, threat function feature sets, and threat level labels; Based on the sample behavior feature vector of each threat intelligence sample, feature similarity analysis is performed on the operational behavior data to obtain the behavioral feature similarity corresponding to each threat intelligence sample; Based on the threat function feature set of each threat intelligence sample, perform function similarity analysis on all the second and / or third calling functions to obtain the function set similarity to each threat intelligence sample; Based on the similarity of each behavioral feature, the similarity of the corresponding function set is fused to obtain several fused similarities; Based on the anomaly detection data and all the fusion similarities, risk analogy detection is performed on the threat dataset to obtain the risk detection data.
[0058] In this embodiment of the application, if the threshold detection result is that the abnormal detection data is greater than the abnormal detection threshold, several threat intelligence samples can be obtained based on the threat dataset. The sample behavior feature vector of the threat intelligence sample is similar to the aforementioned baseline behavior. The threat function feature set can be the set of call functions that are abnormal in the threat intelligence sample. The threat level label is used to identify the threat level of the corresponding threat intelligence sample.
[0059] It is understandable that, for any threat intelligence sample's sample behavior feature vector, feature similarity analysis can be expressed as:
[0060] in, The similarity to the behavioral features corresponding to the i-th threat intelligence sample; It is the Euclidean norm. This is a behavioral feature scale parameter, and its specific value can be preset. Let be the sample behavior feature vector of the i-th threat intelligence sample.
[0061] Function similarity analysis can begin by constructing an anomalous function set from all second and / or third calling functions. Specifically, in a first implementation, all second calling functions can be identified as the anomalous function set; or, in a second implementation, all third calling functions can be identified as the anomalous function set; or, in a third implementation, duplicate functions in all second and third calling functions can be removed, and the deduplicated calling functions can be identified as the anomalous function set. Next, the function set similarity between this anomalous function set and each threat function feature set is calculated. For example, for any threat function feature set, its corresponding function set similarity can be expressed as:
[0062] in, The similarity of the function set corresponding to the i-th threat intelligence sample; A set of exception functions; Let be the set of threat function features for the i-th threat intelligence sample.
[0063] It should be noted that for any threat intelligence sample, the behavioral feature similarity and function set similarity of the threat intelligence sample can be weighted and fused to obtain the fused similarity of the threat intelligence sample. This fused similarity can be expressed as:
[0064] in, The fusion similarity with the i-th threat intelligence sample; and These represent the fusion weights of behavioral features and functional features, respectively. The specific value can be set according to the actual situation.
[0065] Risk category analysis can begin by selecting the highest fusion similarity from all fusion similarities, denoted as the target similarity. Next, based on the target similarity, corresponding threat intelligence samples are selected from the threat dataset, denoted as target intelligence samples. Then, risk detection data is determined based on the threat level label and fusion similarity of the target intelligence sample, as well as anomaly detection data. For example, in this embodiment, taking a total of 5 threat levels as an example, the risk detection data can be represented as:
[0066] in, For risk monitoring data; Threat level labels for target intelligence samples; The fusion similarity with the target intelligence sample; And satisfy .
[0067] Step 140: Response the risk detection data to perform dynamic protection actions, obtain the target protection actions, and perform security protection on the power system based on the target protection actions.
[0068] In this embodiment of the application, the dynamic protection action response can be based on risk detection data, determining the dynamic protection action corresponding to the risk monitoring data at the current sampling time point, denoted as the target protection action, and causing the power system to execute the target protection action to achieve the safety protection of the power system.
[0069] In some embodiments, the step of dynamically responding to the risk detection data to obtain the target protection action includes: Obtain the dynamic protection table of the power system at the current sampling time point. The dynamic protection table includes several protection classification functions and the level protection actions of the protection classification functions. Based on the risk detection data, the target classification function is obtained by matching the level of each protection classification function in the dynamic protection table. Based on the target classification function, all the protection actions of the specified levels are screened to obtain the target protection actions.
[0070] In this embodiment of the application, taking a total of 5 threat levels as an example, the protection classification function of the dynamic protection table can be expressed as:
[0071] in, This is the overall representation of the protection classification function; These are the classification thresholds for various protection classification functions in the power system, and their specific initial values can be set according to actual conditions.
[0072] It is understood that graded protection actions may include several of the first, second, or third actions executed in the power system application layer response, and the specific values of these actions are greater than or equal to 0; among them, the first action... To block the execution of the current exception function; second action To freeze the relevant session threads and generate a security snapshot; and the third action To record the complete call stack and memory image. Specifically, when When, do not perform any action; when When (i.e., the protection classification function of the third threat level) is invoked, the first action is executed. ; When (i.e., the protection classification function of the fourth threat level) is invoked, the first action is executed. Second action ; When (i.e., the protection classification function of the fifth threat level) is invoked, the first action is executed. Second action and the third action .
[0073] Understandably, level matching can involve substituting risk detection data into each protection level function in a dynamic protection characterization to determine the successfully matched level function, for example, in... Upon establishment, the protection classification function of the third threat protection level can be determined as the target classification function, and the first action will be executed. This was identified as a target protection action.
[0074] In some embodiments, the method further includes: Acquire several neighbor detection data of the power system, and the classification threshold of each protection classification function; the neighbor detection data is used to characterize the risk detection data at adjacent time points; the adjacent time points are used to characterize the sampling time points that are adjacent to the current sampling time point on the time axis; Based on the risk detection data and all the neighbor detection data, the threshold of each protection classification function is updated to obtain several updated protection classification functions.
[0075] In this embodiment, after determining the target protection action at the current sampling time point and executing it on the power system, risk detection data from several sampling time points prior to and adjacent to the current sampling time point can be recorded as adjacent detection data. Based on all adjacent detection data and the risk detection data at the current sampling time point, the classification threshold of each protection classification function is updated, and the updated classification threshold is used to replace the original classification threshold in each protection classification function, thereby obtaining several updated protection classification functions. These updated protection classification functions are used as the protection classification functions for the next sampling time point.
[0076] For example, for any given grading threshold, the updated grading threshold can be expressed as:
[0077] in, The updated grading threshold, i.e., the sampling time point. The grading threshold of the protection grading function used; The grading threshold before the update, i.e., the sampling time point. The grading threshold of the protection grading function used can specifically be... , , or At the sampling time point The following grading thresholds; The learning rate parameter can be a constant. This is the average value of all recent detection data.
[0078] Reference Figure 2 The safety protection device proposed in this application includes... The first processing unit 101 is used to acquire a threat dataset, a security behavior model, and a security function statistical model of the power system, as well as the operating behavior data and function call data of the power system at the current sampling time point; the function call data includes a call chain sequence and several first call functions, and the call chain sequence is used to indicate the calling order of the first call functions; The second processing unit 102 is used to perform multi-dimensional anomaly detection on the running behavior data and the function call data according to the security behavior model and the security function statistical model to obtain anomaly detection data; The third processing unit 103 is used to perform risk detection processing on the runtime behavior data and the function call data based on the anomaly detection data and the threat dataset to obtain risk detection data; The fourth processing unit 104 is used to perform dynamic protection action response on the risk detection data, obtain the target protection action, and perform security protection on the power system according to the target protection action.
[0079] It is understood that the content of the above method embodiments is applicable to the present device embodiments. The specific functions implemented by the present device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0080] Reference Figure 3 This application also provides an electronic device, including: At least one processor 201; At least one memory 202 is used to store at least one program; When the at least one program is executed by the at least one processor 201, the at least one processor 201 implements the method embodiment described above.
[0081] Similarly, it can be understood that the content of the above method embodiments is applicable to this device embodiment. The specific functions implemented by this device embodiment are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0082] This application also provides a computer-readable storage medium storing a program executable by a processor 201, which, when executed by the processor 201, is used to implement the above-described method embodiments.
[0083] Similarly, the content of the above method embodiments is applicable to the present computer-readable storage medium embodiments. The specific functions implemented by the present computer-readable storage medium embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0084] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps in the above-described method embodiments.
[0085] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods.
[0086] In some alternative embodiments, the functions / operations mentioned in the block diagrams may not occur in the order shown in the operation diagrams. For example, depending on the functions / operations involved, two consecutively shown blocks may actually be executed substantially simultaneously, or the blocks may sometimes be executed in reverse order. Furthermore, the embodiments presented and described in the flowcharts of this application are provided by way of example to provide a more comprehensive understanding of the technology. The disclosed methods are not limited to the operations and logic flows presented herein. Alternative embodiments are contemplated in which the order of various operations is changed and sub-operations described as part of a larger operation are executed independently.
[0087] Furthermore, although this application is described in the context of functional modules, it should be understood that, unless otherwise stated to the contrary, one or more of the functions and / or features may be integrated into a single physical device and / or software module, or one or more functions and / or features may be implemented in a separate physical device or software module. It is also understood that a detailed discussion of the actual implementation of each module is unnecessary for understanding this application. Rather, given the properties, functions, and internal relationships of the various functional modules in the apparatus disclosed herein, the actual implementation of the module will be understood within the scope of conventional technology for an engineer. Therefore, those skilled in the art can implement the application set forth in the claims using ordinary techniques without excessive experimentation. It is also understood that the specific concepts disclosed are merely illustrative and not intended to limit the scope of this application, which is determined by the full scope of the appended claims and their equivalents.
[0088] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods in the embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0089] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-including system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device.
[0090] More specific examples (a non-exhaustive list) of computer-readable media include: electrical connections (electronic devices) having one or more wires, portable computer disk drives (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which programs can be printed, because programs can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.
[0091] It should be understood that various parts of this application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.
[0092] In the foregoing description of this specification, the references to terms such as "one embodiment," "another embodiment," or "some embodiments," etc., indicate that a specific feature, structure, material, or characteristic described in connection with an embodiment or example is included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.
[0093] Although embodiments of this application have been shown and described, those skilled in the art will understand that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of this application, the scope of which is defined by the claims and their equivalents.
[0094] The above is a detailed description of the preferred embodiments of this application, but this application is not limited to the embodiments. Those skilled in the art can make various equivalent modifications or substitutions without departing from the spirit of this application, and these equivalent modifications or substitutions are all included within the scope defined by the claims of this application.
Claims
1. A security protection method, characterized in that, include: Acquire the threat dataset, security behavior model, and security function statistical model of the power system, as well as the operational behavior data and function call data of the power system at the current sampling time point; The function call data includes a call chain sequence and several first call functions, wherein the call chain sequence is used to indicate the calling order of the first call functions; Based on the security behavior model and the security function statistical model, multi-dimensional anomaly detection is performed on the runtime behavior data and the function call data to obtain anomaly detection data. Based on the anomaly detection data and the threat dataset, risk detection processing is performed on the runtime behavior data and the function call data to obtain risk detection data; The risk detection data is dynamically responded to to obtain the target protection action, and the power system is protected based on the target protection action.
2. The method according to claim 1, characterized in that, Obtain a security behavior model, including: Obtain the historical behavior matrix of the power system; The historical behavior matrix is filtered to obtain a behavior sample set, which is a set of baseline behaviors of the power system under no-attack conditions, and each baseline behavior corresponds to a matrix element in the historical behavior matrix. The safety behavior model is obtained by constructing a model from the set of behavioral samples.
3. The method according to claim 1, characterized in that, Obtain the statistical model of the security function, including: Obtain the function call sequence of the power system at historical sampling time points; Perform function analysis on each historical function in the function call sequence to obtain a function security state vector corresponding to each historical function; Based on all the security state vectors of the functions, the statistical model of the security function is constructed.
4. The method according to claim 1, characterized in that, The step involves performing multi-dimensional anomaly detection on the runtime behavior data and the function call data based on the security behavior model and the security function statistical model to obtain anomaly detection data, including: Get the function detection threshold; The operational behavior data is input into the safety behavior model for behavior deviation analysis to obtain behavior deviation data; Each first calling function in the function call data is input into the security function statistical model for call deviation analysis to obtain first call deviation data corresponding to each first calling function; Based on the function detection threshold, function threshold detection is performed on all the first call deviation data to obtain a number of second call deviation data. The anomaly detection data is obtained by performing weighted fusion detection on the behavioral deviation data and all the second call deviation data.
5. The method according to claim 4, characterized in that, The step of performing risk detection processing on the runtime behavior data and the function call data based on the anomaly detection data and the threat dataset to obtain risk detection data includes: Obtain the anomaly detection threshold and invoke the directed graph; Based on the directed call graph, the call sequence of the function call data is analyzed to obtain several second call functions, which are used to characterize the first call functions with abnormal call order. Based on the anomaly detection threshold, anomaly threshold detection is performed on the anomaly detection data to obtain the threshold detection result; If the threshold detection result indicates that the anomaly detection data is greater than the anomaly detection threshold, then based on the threat dataset and the anomaly detection data, a multidimensional risk analysis is performed on the operational behavior data, all second call functions, and third call functions to obtain the risk detection data; the third call function is the first call function corresponding to the second call deviation data.
6. The method according to claim 5, characterized in that, The step involves performing multi-dimensional risk analysis on the runtime behavior data, all second and third call functions, based on the threat dataset and the anomaly detection data, to obtain the risk detection data, including: Based on the threat dataset, several threat intelligence samples are obtained, including sample behavior feature vectors, threat function feature sets, and threat level labels; Based on the sample behavior feature vector of each threat intelligence sample, feature similarity analysis is performed on the operational behavior data to obtain the behavioral feature similarity corresponding to each threat intelligence sample; Based on the threat function feature set of each threat intelligence sample, perform function similarity analysis on all the second and / or third calling functions to obtain the function set similarity to each threat intelligence sample; Based on the similarity of each behavioral feature, the similarity of the corresponding function set is fused to obtain several fused similarities; Based on the anomaly detection data and all the fusion similarities, risk analogy detection is performed on the threat dataset to obtain the risk detection data.
7. The method according to any one of claims 1-6, characterized in that, The dynamic protection action response to the risk detection data, to obtain the target protection action, includes: Obtain the dynamic protection table of the power system at the current sampling time point. The dynamic protection table includes several protection classification functions and the level protection actions of the protection classification functions. Based on the risk detection data, the target classification function is obtained by matching the level of each protection classification function in the dynamic protection table. Based on the target classification function, all the protection actions of the specified levels are screened to obtain the target protection actions.
8. The method according to claim 7, characterized in that, The method further includes: Acquire several neighbor detection data of the power system, and the classification threshold of each protection classification function; the neighbor detection data is used to characterize the risk detection data at adjacent time points; the adjacent time points are used to characterize the sampling time points that are adjacent to the current sampling time point on the time axis; Based on the risk detection data and all the neighbor detection data, the threshold of each protection classification function is updated to obtain several updated protection classification functions.
9. A safety protection device, characterized in that, include: The first processing unit is used to acquire the threat dataset, security behavior model, and security function statistical model of the power system, as well as the operating behavior data and function call data of the power system at the current sampling time point; The function call data includes a call chain sequence and several first call functions, wherein the call chain sequence is used to indicate the calling order of the first call functions; The second processing unit is used to perform multi-dimensional anomaly detection on the running behavior data and the function call data according to the security behavior model and the security function statistical model to obtain anomaly detection data; The third processing unit is used to perform risk detection processing on the runtime behavior data and the function call data based on the anomaly detection data and the threat dataset to obtain risk detection data; The fourth processing unit is used to dynamically respond to the risk detection data, obtain the target protection action, and perform security protection on the power system based on the target protection action.
10. An electronic device, characterized in that, include: At least one processor; At least one memory for storing at least one program; When the at least one program is executed by the at least one processor, the at least one processor performs the method as described in any one of claims 1-8.