Power generation enterprise-oriented industrial control system vulnerability grading and response system and method

By constructing a multi-dimensional vulnerability scoring model and digital twin verification based on power generation scenarios, the shortcomings of existing vulnerability management methods in power generation enterprise industrial control systems are addressed. This enables accurate, scenario-based assessment and targeted management of vulnerabilities in power generation enterprise industrial control systems, thereby improving security protection capabilities and production stability.

CN121966918APending Publication Date: 2026-05-01HUANENG POWER INT INC +1
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HUANENG POWER INT INC
Filing Date
2025-12-08
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Existing vulnerability management methods in power generation companies' industrial control systems do not fully consider business characteristics, lack quantitative assessment of the impact on power production, rely insufficiently on foreign vulnerability databases, lack dynamic risk prediction capabilities, and are difficult to deal with targeted advanced persistent threats.

Method used

We construct a knowledge graph that integrates multiple vulnerability databases, establish a multi-dimensional vulnerability scoring model (EICSVS) for power generation scenarios, achieve attack path prediction and hierarchical collaborative response through vulnerability exploitation networks, generate hierarchical response strategies that match the operating characteristics of power generation systems, and ensure the continuity of power production through digital twin verification.

Benefits of technology

It enables accurate, scenario-based assessment and targeted management of vulnerabilities in the industrial control systems of power generation enterprises, improves security protection capabilities, and ensures the stability of power generation and emergency response capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121966918A_ABST
    Figure CN121966918A_ABST
Patent Text Reader

Abstract

The invention provides a power generation enterprise-oriented industrial control system vulnerability grading and responding system and method, and the system comprises a knowledge graph construction module which is used for integrating power generation industry multi-source vulnerability data to construct an exclusive knowledge graph; the dynamic vulnerability evaluation module is used for carrying out dynamic risk evaluation by adopting a multi-dimensional scoring model based on the power generation network topology and service flow characteristics; and the collaborative response processing module is used for generating a hierarchical response strategy and verifying the hierarchical response strategy through a digital twin environment. According to the method, accurate and scene risk assessment of the vulnerabilities of the power generation industrial control system is realized, an emergency disposal scheme matched with the power generation operation characteristics is provided, the pertinence and reliability of the network security protection capability of a power generation enterprise are effectively improved, and safe and stable operation of a power production system is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial control system network security technology, specifically to a vulnerability classification and response system and method for industrial control systems in power generation enterprises. Background Technology

[0002] With the rapid development of the Industrial Internet, power generation companies' industrial control systems are moving from closed and isolated systems to interconnected systems, facing increasingly severe cybersecurity threats. Industrial control system vulnerabilities serve as a primary entry point for attackers, making their effective management a crucial aspect of ensuring safe power production. Currently, the internationally accepted approach is to use the Common Vulnerability Scoring System (CVSS) to rate vulnerabilities and develop corresponding remediation priority strategies based on these ratings. This technology has become a fundamental technical means in the field of industrial cybersecurity.

[0003] However, existing vulnerability management methods have significant limitations in power generation scenarios: First, the general CVSS scoring system does not fully consider the business characteristics of power generation industrial control systems, such as the extremely high requirements for equipment real-time performance and system availability, and lacks quantitative assessment of the impact on power production operations and environmental specificity; second, existing methods rely excessively on foreign vulnerability databases (such as CVE / NVD), lack compatibility with domestically disclosed vulnerability information (such as CNVD, CNNVD), and lack vulnerability data specific to equipment and systems in my country's power generation industry; finally, traditional solutions are mostly static assessments, lacking the ability to dynamically predict risks based on attack chains, making it difficult to cope with targeted advanced persistent threats to power systems.

[0004] To overcome the aforementioned shortcomings, this invention proposes a vulnerability classification and response system and method for industrial control systems in power generation enterprises. By constructing a knowledge graph integrating multiple vulnerability databases (including domestic vulnerability databases such as CNVD), a multi-dimensional vulnerability scoring model (ElectricityIndustrialControlSystemVulnerabilityScore, EICSVS) is established for power generation scenarios. Furthermore, attack path prediction and graded collaborative response are achieved based on a vulnerability exploitation network, forming an intelligent vulnerability governance solution suitable for the power generation industry, effectively improving the security protection capabilities of power generation infrastructure. Summary of the Invention

[0005] The present invention aims to at least solve one of the technical problems existing in the prior art, and provides a vulnerability classification and response system and method for industrial control systems of power generation enterprises.

[0006] In a first aspect, embodiments of the present invention provide a vulnerability classification and response system for industrial control systems of power generation enterprises, the system comprising: The knowledge graph construction module is used to integrate multi-source vulnerability data unique to the power generation industry and construct an industrial control vulnerability knowledge graph that includes power generation equipment knowledge ontology and business logic. The vulnerability dynamic assessment module is used to calculate the scenario-based vulnerability risk level that has a real impact on power production based on the topology of the power generation network and the characteristics of the business flow. The collaborative response and handling module is used to generate tiered response strategies based on the operating characteristics of the power generation system and to ensure the continuity of power production through digital twin verification.

[0007] In conjunction with the first aspect, the knowledge graph construction module includes: The data acquisition unit is configured to focus on collecting vulnerability data specific to the power generation industry, including vulnerability information of key power generation equipment such as DCS systems, SCADA systems, and relay protection devices, with particular attention to power industry-related vulnerabilities in CNVD. The knowledge graph generation unit is configured to use a domain-adaptive BERT model to process the description text of power generation equipment, identify the association between power generation-specific equipment such as generator sets, substations, and excitation systems and vulnerabilities, and construct a knowledge graph that enhances the business logic of power generation. The vulnerability exploitation chain reasoning unit is configured to analyze the propagation path of vulnerabilities in the power generation production environment based on the network architecture and business flow of the power generation system, and establish a vulnerability exploitation chain model for the power generation process.

[0008] In conjunction with the first aspect, the vulnerability dynamic assessment module includes: The asset detection and matching unit is configured to identify key business assets in the power generation network, including real-time monitoring systems, automatic generation control (AGC) systems, power metering systems, etc., and assess the importance level of the equipment in the power generation business. The multi-dimensional scoring unit is configured to use the EICSVS scoring model based on power generation scenarios, focusing on evaluating the impact of vulnerabilities on key indicators such as power generation continuity, grid stability, and power supply reliability, while taking into account the special constraints of the power generation environment. The risk rating unit is configured to dynamically adjust the risk level determination threshold based on the operating status of the power generation system and the grid load, ensuring that the risk assessment results meet the actual needs of power generation.

[0009] The collaborative response and handling module specifically includes: The strategy generation unit is configured to formulate different levels of response strategies to meet the real-time requirements of the power generation system, with a focus on ensuring the continuous and stable operation of the core power generation business. The response execution unit is configured to combine the operation and management system of the power generation system to design a human-machine collaborative response process, ensuring that network security measures are consistent with power safety production regulations; The simulation verification unit is configured to simulate the vulnerability exploitation process in the digital twin environment of the power generation system, test the impact of response measures on the power generation process, and verify that the security measures will not cause grid fluctuations or power outages.

[0010] Secondly, embodiments of the present invention provide a method for vulnerability classification and response in industrial control systems for power generation enterprises, the method comprising: Construct an industrial control vulnerability knowledge graph that integrates the characteristics of power generation equipment and business logic, and extract the unique vulnerability relationships of the power generation system through a domain-adaptive pre-trained language model; Dynamic risk assessment is conducted based on power generation network topology and business flow, and a multi-dimensional scoring model based on power generation scenarios is used to quantify the impact of vulnerabilities on power production. Generate a graded response strategy that matches the operating characteristics of the power generation system, and verify the impact of the response measures on the stability of the power generation process through a digital twin environment.

[0011] In conjunction with the second aspect, the construction of an industrial control system vulnerability knowledge graph that integrates the characteristics of power generation equipment and business logic, and the extraction of unique vulnerability relationships in the power generation system through a domain-adaptive pre-trained language model, includes: Collect vulnerability data specific to the power generation industry, focusing on collecting vulnerability information related to key power generation equipment such as DCS systems, SCADA systems, and relay protection devices, especially vulnerability data related to the power industry in CNVD; The domain-adaptive BERT model is used to process the description text of power generation equipment, identify the association between power generation-specific equipment such as generator sets, substations, and excitation systems and vulnerabilities, and build a power generation equipment ontology library; Based on the network architecture and business flow of the power generation system, we analyze the propagation path of vulnerabilities in the power generation production environment and establish a vulnerability exploitation chain model for the power generation process.

[0012] In conjunction with the second aspect, the dynamic risk assessment based on power generation network topology and business flow, and the use of a multi-dimensional scoring model tailored to power generation scenarios to quantify the impact of vulnerabilities on power production, includes: Identify key business assets in the power generation network, including real-time monitoring systems, automatic generation control (AGC) systems, and power metering systems, and assess the importance level of the equipment in the power generation business; The EICSVS scoring model, which is based on power generation scenarios, is adopted to focus on evaluating the impact of vulnerabilities on key indicators such as power generation continuity, grid stability, and power supply reliability, while taking into account the special constraints of the power generation environment. The risk level threshold is dynamically adjusted based on the operating status of the power generation system and the grid load to ensure that the risk assessment results meet the actual needs of power generation.

[0013] In conjunction with the second aspect, the generation of a graded response strategy that matches the operating characteristics of the power generation system, and the verification of the impact of the response measures on the stability of the power generation process through a digital twin environment, includes: To meet the real-time requirements of the power generation system, different levels of response strategies are formulated to ensure the continuous and stable operation of the core power generation business and avoid unnecessary shutdowns for maintenance. In conjunction with the operation and management system of the power generation system, design a human-machine collaborative response process to ensure that network security measures are consistent with power safety production regulations; Simulate the vulnerability exploitation process in a digital twin environment of the power generation system, test the impact of response measures on the power generation process, and verify that the security measures will not cause grid fluctuations or power outages.

[0014] Thirdly, embodiments of the present invention provide an electronic device, comprising: One or more processors; A storage unit is used to store one or more programs, which, when executed by one or more processors, enable the one or more processors to implement any of the above-mentioned methods for classifying and responding to vulnerabilities in industrial control systems for power generation enterprises.

[0015] Fourthly, embodiments of the present invention provide a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, can implement any of the above-mentioned methods for classifying and responding to vulnerabilities in industrial control systems for power generation enterprises.

[0016] Compared with existing technologies, this invention provides a vulnerability classification and response system and method for industrial control systems (ICS) in power generation enterprises. By constructing an ICS vulnerability knowledge graph module that integrates power generation equipment characteristics and business logic, it achieves deep fusion and intelligent correlation analysis of multi-source heterogeneous security data, characterizing the unique risk profile of the power generation system. Through a dynamic risk assessment module based on power generation network topology and business flow, it introduces a power generation-scenario-based EICSVS multidimensional scoring model and dynamic threshold classification mechanism, achieving quantitative, accurate, and scenario-based assessment of vulnerability risks, overcoming the drawbacks of general assessment models being disconnected from actual power generation production. Finally, by generating a classified response strategy that matches the operating characteristics of the power generation system and verifying it in a digital twin environment, it ensures the technical effectiveness of each security measure, forming a closed-loop management system. This method ultimately achieves the core objective of deeply integrating network security risk management into the power generation production business process, improving the targeting, accuracy, and reliability of vulnerability management in power generation enterprises' ICS, and providing assurance for the stable operation and emergency response of power plants. Attached Figure Description

[0017] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0018] Figure 1 A schematic diagram of the overall architecture of a vulnerability classification and response system for industrial control systems of power generation enterprises provided in an embodiment of the present invention; Figure 2 The main flowchart of the vulnerability classification and response method for industrial control systems of power generation enterprises provided in the embodiments of the present invention; Figure 3 A detailed flowchart of the vulnerability classification and response method for industrial control systems of power generation enterprises provided in this embodiment of the invention; Figure 4 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present invention. Detailed Implementation

[0019] To enable those skilled in the art to better understand the technical solutions of the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the described embodiments of the present invention without creative effort are within the scope of protection of the present invention.

[0020] Unless otherwise specifically stated, the technical or scientific terms used in the embodiments of this invention should be understood in their ordinary meaning as understood by one of ordinary skill in the art to which this invention pertains. The terms "comprising" or "including," as used in the embodiments of this invention, do not limit the shapes, numbers, steps, actions, operations, components, elements, and / or groups thereof mentioned, nor do they exclude the appearance or addition of one or more other different shapes, numbers, steps, actions, operations, components, elements, and / or groups thereof, or the inclusion of these.

[0021] Unless otherwise specifically stated, the relative arrangement, numerical expressions, and values ​​of the components and steps described in these embodiments do not limit the scope of the invention. It should also be understood that, for ease of description, the dimensions of the various parts shown in the drawings are not drawn to actual scale, and techniques, methods, and apparatus known to those skilled in the art may not be discussed in detail; however, where appropriate, the illustrated techniques, methods, and apparatus should be considered part of the specification. In all the examples shown and discussed herein, any other specific example may have different values. It should be noted that similar symbols and letters in the following figures denote similar items; therefore, once an item is defined in one figure, it need not be further discussed in subsequent figures.

[0022] In the description of the embodiments of the present invention, the terms "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of the present invention. In the embodiments of the present invention, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in a suitable manner in any one or more embodiments or examples. Furthermore, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in the embodiments of the present invention, as well as the features of different embodiments or examples.

[0023] Hereinafter, exemplary embodiments according to the present invention will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of the present invention, and not all embodiments of the present invention. It should be understood that the present invention is not limited to the exemplary embodiments described herein.

[0024] like Figure 1 The diagram shown is a structural schematic of a vulnerability classification and response system for industrial control systems in power generation enterprises, according to an embodiment of the present invention. The system includes: The knowledge graph construction module 110 is used to integrate multi-source vulnerability data unique to the power generation industry and construct an industrial control vulnerability knowledge graph that includes power generation equipment knowledge ontology and business logic. The vulnerability dynamic assessment module 120 is used to calculate the scenario-based vulnerability risk level that has a real impact on power production based on the topology of the power generation network and the characteristics of the business flow. The collaborative response and handling module 130 is used to generate graded response strategies based on the operating characteristics of the power generation system and to ensure the continuity of power production through digital twin verification.

[0025] The specific implementation of the knowledge graph construction module 110 is as follows: The data acquisition unit adopts a multi-source heterogeneous data acquisition architecture, directly connecting to domestic vulnerability databases such as CNVD and CNNVD via API interfaces to obtain power industry-specific vulnerability data. Simultaneously, a distributed web crawler is deployed to collect security announcements and vulnerability reports from power generation equipment manufacturers. For internal enterprise data, an asset information collection agent has been developed and deployed in different security zones within the power generation company to collect model, version, and configuration information of critical equipment such as DCS systems, SCADA systems, and relay protection devices. During data acquisition, special attention is paid to vulnerability types specific to the power generation industry, such as industrial control protocol vulnerabilities (IEC-60870-5-104, IEC-61850, etc.), control logic vulnerabilities, and vulnerabilities related to power generation processes.

[0026] The knowledge graph generation unit employs an ontology-based knowledge modeling approach, first defining the schema layer of the power generation industry knowledge graph. The core entities defined include: vulnerability entities (containing attributes such as CVE-ID, CNVD-ID, vulnerability type, and scope of impact), equipment entities (containing attributes such as equipment type, manufacturer, model, and firmware version), attack technology entities (based on an extension of the ATT&CK for ICS framework), and business system entities (including power generation, transmission, and substation business systems). Entity relationships include: impact relationships (vulnerabilities affect equipment), exploitation relationships (attack techniques exploit vulnerabilities), and composition relationships (equipment constitutes business systems).

[0027] An improved BERT-WWM model is employed for unstructured text processing. First, during the pre-training phase, texts from the power generation industry, including technical documents, equipment manuals, and safety reports, are used to further train the model, enabling it to better understand power generation terminology. In the fine-tuning phase, a bidirectional attention mechanism is used to enhance entity relationship recognition, particularly when processing long text descriptions of power generation equipment. Positional encoding and a domain dictionary are introduced to improve entity recognition accuracy. The entities and relationships output by the model are manually verified before being stored in the Neo4j graph database.

[0028] The vulnerability exploitation chain inference unit, based on a constructed knowledge graph, developed a vulnerability exploitation chain analysis algorithm for a power generation scenario. The algorithm first extracts the network topology and business process diagram of the power generation system, then embeds nodes using a graph neural network to calculate the reachability probability between vulnerable nodes. Specifically, for the hierarchical structure of the power generation system (management network, monitoring network, control network), the algorithm analyzes the possibility of vulnerability exploitation across network boundaries and generates attack paths targeting the power generation business process.

[0029] The specific implementation of the vulnerability dynamic assessment module 120 is as follows: The asset detection and matching unit employs a combined approach of active scanning and passive traffic analysis. Active scanning utilizes optimized industrial control equipment identification probes, supporting fingerprint recognition for industrial control protocols such as Modbus, DNP3, and IEC-104. Passive traffic analysis captures network traffic via mirroring and uses deep learning algorithms to automatically identify critical business traffic in the power generation system (such as AGC control commands and PMU data). The identified equipment information is then matched against a knowledge graph using a hybrid matching algorithm based on edit distance and semantic similarity to calculate the matching confidence level.

[0030] A multi-dimensional scoring unit implements an EICSVS scoring model tailored to power generation scenarios. The model comprises four dimensions: Inherent Exploitability (E), calculated based on factors such as PoC / EXP existence and attack complexity; Business Impact (I), focusing on assessing the impact of vulnerabilities on power generation operations, including the degree of impact on power generation, grid stability, and power supply reliability, incorporating power generation business expert knowledge and establishing a criticality scoring system for equipment; Scenario Accessibility (A), analyzing the exploitability of vulnerabilities in specific environments based on power generation network topology and access control policies; and Environment Specificity (S), considering the special requirements of the power generation environment, such as real-time performance, reliability, and electromagnetic compatibility. The scoring formula is: EICSVS = E × (0.4I + 0.3A + 0.3S), and the weight parameters can be adjusted according to the power generation type (thermal power, hydropower, new energy).

[0031] The risk rating unit employs a dynamic threshold algorithm, adjusting the risk rating threshold based on the actual operating status of the power generation system. The algorithm inputs include information such as grid load conditions, generator operating status, and maintenance plans. A machine learning model dynamically calculates the most suitable risk rating threshold for the current operating state. For example, during peak grid load periods, the risk rating threshold is automatically increased to avoid unnecessary maintenance operations that could impact power supply reliability.

[0032] The collaborative response and handling module 130 is implemented as follows: The strategy generation unit employs a combination of case-based reasoning and a rule engine. First, a power generation industry emergency response case library is established, containing historical examples of typical power generation safety incidents. The rule engine, based on power generation safety production regulations, defines handling rules for different risk levels. When a vulnerability is discovered, the system first performs case matching to find similar historical case handling solutions, then adjusts them according to the current environmental characteristics to generate a specific response strategy, including technical operation steps, responsible personnel, and time requirements.

[0033] The response execution unit is integrated with the security devices of power generation enterprises through a standardized interface (such as REST API). It supports linkage with devices such as firewalls, IDS, and security audit systems to implement automated response measure execution. Considering the characteristics of the power generation industry, a human-machine collaboration mechanism is specially designed. All automatically executed operations need to be confirmed by the on-duty personnel to ensure compliance with the regulations on power production safety management. The system also provides complete operation logs and audit tracking functions.

[0034] Based on the digital twin platform of the power generation system, the simulation verification unit constructs a simulation test environment consistent with the real production environment. The digital twin platform contains real DCS logic, control algorithms, and process models. Before implementing important response measures, they are first tested in the digital twin environment to evaluate the impact of the security measures on the power generation process, including the impact on unit stability, grid fluctuations, and power supply reliability. Only after passing the test can the corresponding response measures be executed in the production environment.

[0035] As Figure 2 , Figure 3 shown, it is a schematic flowchart of a method for classifying and responding to industrial control system vulnerabilities for power generation enterprises according to an embodiment of the present invention, including: S201: Construct an industrial control vulnerability knowledge graph that integrates power generation equipment characteristics and business logic, and extract the unique vulnerability association relationships of the power generation system through a domain-adapted pre-trained language model; S202: Conduct dynamic risk assessment based on the power generation network topology and business flow, and use a multi-dimensional scoring model for power generation scenarios to quantify the impact degree of vulnerabilities on power production; S203: Generate a hierarchical response strategy that matches the operating characteristics of the power generation system, and verify the impact of the response measures on the stability of the power generation process through the digital twin environment.

[0036] Furthermore, the construction of the industrial control vulnerability knowledge graph that integrates power generation equipment characteristics and business logic, and the extraction of the unique vulnerability association relationships of the power generation system through a domain-adapted pre-trained language model include: Specifically, through multi-source data collection technology, systematically obtain data from international common vulnerability databases (CVE), domestic vulnerability databases (CNVD, CNNVD), security announcements of equipment manufacturers, and enterprise internal asset management systems. The collection process focuses particularly on vulnerability information related to assets unique to the power generation industry, such as distributed control systems (DCS), supervisory control and data acquisition systems (SCADA), relay protection devices, industrial control protocols (such as IEC 60870-5-104, IEC 61850), etc.

[0037] Specifically, an ontology-based knowledge modeling approach is used to construct the schema layer of the knowledge graph. The core entities defined include: vulnerabilities, devices, attack techniques, and incidents. The relationships between entities include: "vulnerability_affects_devices", "attack technique_exploits_vulnerability", and "device_belongs to_business system", thus formally expressing professional knowledge in the power generation field.

[0038] Specifically, domain-adaptive natural language processing (NLP) models (such as BERT models that are pre-trained on power generation industry texts) are used to automatically extract entities and relationships from unstructured texts (such as vulnerability descriptions and equipment manuals), complete the knowledge graph, and use graph computing algorithms to infer and generate potential vulnerability exploitation chains (AttackPaths) for power generation business processes.

[0039] Furthermore, the dynamic risk assessment based on power generation network topology and business flow, employing a multi-dimensional scoring model tailored to power generation scenarios to quantify the impact of vulnerabilities on power production, includes: Specifically, asset detection and business context awareness: This involves identifying live assets in the current network environment through proactive scanning (using probes sensitive to industrial control protocols) and passive traffic analysis. Crucially, the system not only identifies device type and version but also automatically determines the device's criticality level in the power generation process by interfacing with the enterprise asset management system or network topology map. For example, a server used for AGC (Automatic Generation Control) has a far greater business criticality than a server used for historical data recording.

[0040] Specifically, a multi-dimensional dynamic scoring model for power generation scenarios, EICSVS, is proposed. Its calculation formula is: EICSVS = E × (ω1 × I + ω2 × A + ω3 × S). Here, E (Inherent Availability) is based on the Exploitability score of CVSS v3.1 with fine-tuning. The weights ω1, ω2, and ω3 of the three dimensions I, A, and S satisfy ω1 + ω2 + ω3 = 1, with default values ​​of 0.4, 0.3, and 0.3. These can be adjusted according to different power generation types (such as thermal power, hydropower, wind power, etc.). For example, for hydropower plants with extremely high stability requirements, a higher weight can be assigned to business impact (I). Table 1 below details the evaluation dimensions of the EICSVS model and the considerations specific to the power generation industry.

[0041] Table 1: Detailed Explanation of the Dimensions of the EICSVS Scoring Model

[0042] Furthermore, the generation of a graded response strategy that matches the operating characteristics of the power generation system, and the verification of the impact of the response measures on the stability of the power generation process through a digital twin environment, includes: Specifically, the graded response strategy generation strategy is based on the EICSVS score and risk level classification, generating a graded response strategy that strictly matches the operating characteristics of the power generation system. The strategy generation engine employs a combination of rule-based reasoning and case-based reasoning. First, the system has a built-in predefined response rule library, with rule templates shown in Table 2 below: Table 2: Examples of Hierarchical Response Strategy Rules

[0043] Specifically, the system uses a case reasoning engine to perform similarity matching with a historical case database. This database stores a large number of security incident handling records specific to the power generation industry. Each case includes fields such as vulnerability characteristics, environmental context, measures taken, and the effects of the handling. By calculating the multi-dimensional feature similarity between the current vulnerability scenario and historical cases, the system retrieves the most relevant historical cases and uses their handling solutions as important references for the current response strategy, thereby generating more accurate and practical handling suggestions.

[0044] Specifically, digital twin verification and simulation testing is conducted: To minimize the potential impact of response measures on the real production system, all major operations (such as patch installation for Level 3 and above risks, significant changes to firewall rules, and modifications to core logic) must pass verification testing in a digital twin environment before execution. Verification testing includes three steps: environment construction, test execution, and impact assessment.

[0045] Environment Construction: The digital twin environment is constructed by synchronizing the control logic, configuration information, network topology, and historical operating data of the real production system, forming a high-fidelity simulation test platform. This environment is physically isolated from the production environment, but can simulate the real power generation process and control behavior.

[0046] Test execution: Deploy and activate planned response measures (such as patches to be installed and access control lists (ACLs) to be adjusted) in the digital twin environment. Then, run a series of predefined test cases that simulate normal power generation operations as well as various possible edge cases.

[0047] Impact Assessment: Monitor key performance indicators (KPIs) of the digital twin system after implementing response measures, including but not limited to: control system stability (CPU / memory utilization, control cycle jitter, communication latency); process continuity (interruption of the simulated power generation process, whether critical parameters (such as pressure, temperature, flow rate, and speed) exceed limits); and functional compatibility (whether all control functions, alarm functions, and human-machine interface function normally). The test results generate a detailed assessment report, clearly indicating whether the response measure has been validated, or what potential risks and compatibility issues exist.

[0048] Specifically, collaborative handling and closed-loop management are implemented. Validated response strategies are automatically generated into standardized handling work orders, which are then pushed to the enterprise's Security Operations Management (SOC) platform, Management Information System (MIS), or dispatching ticketing system via system integration interfaces (such as RESTful APIs). The work order clearly defines the handling steps, operation window, responsible person, and acceptance criteria. The entire handling process follows power safety production regulations, emphasizing human-machine collaboration. For high-risk operations, the system mandates secondary confirmation from operators before executing critical steps. The entire handling process is recorded and tracked in real time, forming a complete closed loop from strategy generation, simulation testing, work order execution to effect feedback. After handling is completed, the system reviews and evaluates the effectiveness of the strategy, extracts experience and knowledge to optimize future response strategy and case libraries, achieving self-learning and continuous improvement of the system.

[0049] This invention provides a vulnerability classification and response method for industrial control systems (ICS) in power generation enterprises. By constructing an ICS vulnerability knowledge graph module that integrates power generation equipment characteristics and business logic, it achieves deep fusion and intelligent correlation analysis of multi-source heterogeneous security data, characterizing the unique risk profile of the power generation system. Through a dynamic risk assessment module based on power generation network topology and business flow, it introduces a power generation-scenario-based EICSVS multidimensional scoring model and dynamic threshold classification mechanism, achieving quantitative, accurate, and scenario-based assessment of vulnerability risks, overcoming the drawbacks of general assessment models being disconnected from actual power generation production. Finally, by generating a classified response strategy that matches the operating characteristics of the power generation system and verifying it in a digital twin environment, it ensures the technical effectiveness of each security measure, forming a closed-loop management system. This method ultimately achieves the core objective of deeply integrating network security risk management into the power generation production business process, improving the targeting, accuracy, and reliability of ICS vulnerability management in power generation enterprises, and providing assurance for the stable operation and emergency response of power plants.

[0050] Electronic device 400 can be a desktop computer, laptop, handheld computer, cloud server, or other electronic device. Electronic device 400 may include, but is not limited to, processor 401 and memory 402. Those skilled in the art will understand that... Figure 4This is merely an example of electronic device 400 and does not constitute a limitation on electronic device 400. It may include more or fewer components than shown, or combine certain components, or different components. For example, electronic device may also include input / output devices, network access devices, buses, etc.

[0051] Processor 401 can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor.

[0052] The memory 402 can be an internal storage unit of the electronic device 400, such as a hard disk or RAM of the electronic device 400. The memory 402 can also be an external storage device of the electronic device 400, such as a plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, or Flash Card equipped on the electronic device 400. Furthermore, the memory 402 can include both internal and external storage units of the electronic device 400. The memory 402 is used to store the computer program 403 and other programs and data required by the electronic device. The memory 402 can also be used to temporarily store data that has been output or will be output.

[0053] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this invention. The specific working process of the units and modules in the above system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0054] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0055] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments of the invention herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of the invention.

[0056] In the embodiments provided by this invention, it should be understood that the disclosed devices / electronic devices and methods can be implemented in other ways. For example, the device / electronic device embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. Multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0057] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0058] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0059] If integrated modules / units are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program may include computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. Computer-readable media may include: any entity or device capable of carrying computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in a computer-readable medium may be appropriately added to or subtracted according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media may not include electrical carrier signals and telecommunication signals.

[0060] It is understood that the above embodiments are merely exemplary implementations used to illustrate the principles of the present invention, and the present invention is not limited thereto. For those skilled in the art, various modifications and improvements can be made without departing from the spirit and essence of the present invention, and these modifications and improvements are also considered to be within the scope of protection of the present invention.

Claims

1. A vulnerability classification and response system for industrial control systems in power generation enterprises, characterized in that, The system includes: The knowledge graph construction module is used to integrate multi-source vulnerability data unique to the power generation industry and construct an industrial control vulnerability knowledge graph that includes power generation equipment knowledge ontology and business logic. The vulnerability dynamic assessment module is used to calculate the scenario-based vulnerability risk level that has a real impact on power production based on the topology of the power generation network and the characteristics of the business flow. The collaborative response and handling module is used to generate tiered response strategies based on the operating characteristics of the power generation system and to ensure the continuity of power production through digital twin verification.

2. The vulnerability classification and response system for industrial control systems of power generation enterprises according to claim 1, characterized in that, The knowledge graph construction module includes: The data acquisition unit is configured to collect power generation industry-specific vulnerability data from multiple data sources, including CVE, CNVD, and CNNVD. The graph generation unit is configured to process unstructured text using a domain-adaptive pre-trained language model to extract entities and relationships specific to the power generation system. The exploit chain reasoning unit is configured to generate potential attack paths for the power generation system based on entity associations in the knowledge graph.

3. The vulnerability classification and response system for industrial control systems of power generation enterprises according to claim 1, characterized in that, The vulnerability dynamic assessment module includes: The asset detection and matching unit is configured to identify key business assets in the power generation network and assess their importance level; The multi-dimensional scoring unit is configured to use the EICSVS model for power generation industrial control vulnerability scoring, and to conduct quantitative evaluation from four dimensions: inherent exploitability, business impact, scenario accessibility and environment specificity. The risk rating unit is configured to dynamically adjust the risk level determination threshold based on the operating status of the power generation system.

4. The vulnerability classification and response system for industrial control systems of power generation enterprises according to any one of claims 1 to 3, characterized in that, The collaborative response and handling module includes: The strategy generation unit is configured to generate differentiated response strategies based on risk levels; The response execution unit is configured to integrate with security devices through a standardized interface to execute response measures. The simulation verification unit is configured to test the impact of response measures on the power generation process in a digital twin environment.

5. A vulnerability classification and response method for industrial control systems in power generation enterprises, characterized in that, The method includes: Construct an industrial control vulnerability knowledge graph that integrates the characteristics of power generation equipment and business logic, and extract the unique vulnerability relationships of the power generation system through a domain-adaptive pre-trained language model; Dynamic risk assessment is conducted based on power generation network topology and business flow, and a multi-dimensional scoring model based on power generation scenarios is used to quantify the impact of vulnerabilities on power production. Generate a graded response strategy that matches the operating characteristics of the power generation system, and verify the impact of the response measures on the stability of the power generation process through a digital twin environment.

6. The vulnerability classification and response method for industrial control systems of power generation enterprises according to claim 5, characterized in that, The construction of an industrial control system vulnerability knowledge graph that integrates the characteristics of power generation equipment and business logic extracts the unique vulnerability relationships of the power generation system through a domain-adaptive pre-trained language model, including: Vulnerability data was collected from CVE, CNVD, and CNNVD vulnerability databases, as well as security announcements from power equipment manufacturers, using a combination of API interfaces and web crawlers. The BERT-WWM model, which has been pre-trained on text from the power generation field, is used to extract entity relations from unstructured text. The model employs a bidirectional attention mechanism to enhance the ability to identify entity relations in the power generation field. Based on graph neural network algorithms, node embedding and relation reasoning are performed to generate vulnerability exploitation chain models for power generation control systems, protection devices, and monitoring systems. The models specifically analyze industrial control protocol vulnerabilities and inter-device dependencies.

7. The vulnerability classification and response method for industrial control systems of power generation enterprises according to claim 5, characterized in that, The dynamic risk assessment based on power generation network topology and business flow, employing a multi-dimensional scoring model tailored to power generation scenarios, quantifies the impact of vulnerabilities on power production, including: The industrial control equipment in the power generation network is identified by combining active scanning with passive traffic analysis, and the device fingerprinting technology based on machine learning is used to match the device nodes in the knowledge graph. The power generation industrial control vulnerability scoring model EICSVS is used for calculation, and the calculation formula is EICSVS = E × (ω1 × I + ω2 × A + ω3 × S); where E is based on the Exploitability score of CVSS v3.1 and finely tuned; E is inherent exploitability, I is business impact, A is scenario accessibility, and S is environment specificity; the weights ω1, ω2, ω3 of the three dimensions I, A, and S satisfy ω1 + ω2 + ω3 = 1, and their default values ​​are 0.4, 0.3, and 0.3, respectively. Based on the operating status of the power generation system and the grid load, a dynamic threshold algorithm is used to adjust the risk level classification threshold.

8. The method for vulnerability classification and response in industrial control systems for power generation enterprises according to any one of claims 5 to 7, characterized in that, The generation of a graded response strategy that matches the operating characteristics of the power generation system, and the verification of the impact of the response measures on the stability of the power generation process through a digital twin environment, includes: Based on the vulnerability risk level and the operating characteristics of the power generation system, a response strategy is generated by combining case reasoning with a rule engine. By integrating with security devices through standardized interfaces, it supports the automatic or human-machine collaborative execution of response measures; The exploitation process was simulated using a digital twin environment of the power generation system. The impact of the response measures on the power generation process was tested, and it was verified that the security measures would not cause grid fluctuations or power outages.

9. An electronic device, characterized in that, include: One or more processors; A storage unit for storing one or more programs, which, when executed by one or more processors, enable the one or more processors to implement the vulnerability classification and response method for industrial control systems of power generation enterprises according to any one of claims 5 to 8.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it can implement the vulnerability classification and response method for industrial control systems of power generation enterprises according to any one of claims 5 to 8.

Citation Information

Patent Citations

  • A packaging system

    IE61850B1