Thermoelectric group industrial control security situation awareness system supporting global expansion
By employing a center-edge distributed architecture and multi-dimensional threat analysis, the coverage and scalability issues of the thermal power group's industrial control system were resolved, enabling comprehensive security situation awareness and rapid response, improving data security and operational efficiency, and meeting policy and regulatory requirements.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- QINGDAO THERMAL POWER GRP CO LTD
- Filing Date
- 2026-01-23
- Publication Date
- 2026-05-15
AI Technical Summary
The existing industrial control security situation awareness system for thermal power groups has limited coverage and poor scalability, making it difficult to adapt to the dynamic expansion needs of thermal power groups of different sizes. Furthermore, it lacks support for industrial control protocol parsing, has low versatility in threat detection scenarios, makes it difficult to guarantee data security and integrity, lacks hierarchical design in response mechanisms, and fails to meet policy and regulatory requirements.
The industrial control security situation awareness system, which adopts a center-edge distributed architecture, includes a distributed traffic detection probe cluster, a cross-network data interaction module, and a security response execution unit. It supports the parsing of multiple industrial control protocols and, combined with multi-dimensional threat analysis and situation assessment algorithms, achieves full-domain security situation awareness and rapid response.
It has achieved full coverage and elastic expansion of the industrial control network of the thermal power group, accurately identified industry-specific attack behaviors, ensured data transmission security, provided a rapid response mechanism, improved the accuracy of risk assessment and operation and maintenance decision support, and reduced deployment and operation and maintenance costs.
Smart Images

Figure CN122053601A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of industrial control security technology, specifically to a thermal power group industrial control security situation awareness system that supports full-domain expansion. Background Technology
[0002] As a key energy enterprise ensuring people's livelihood, the thermal power group's industrial control system covers the entire process of IoT sensing devices, including heat source boilers, heat exchange units, and individual household meters. Its network architecture encompasses the field equipment layer, control layer, and management layer, extending its business scope to core production areas, multiple branch production units, and cross-regional heating networks. The system's security and stability are directly related to heating reliability and the protection of people's livelihood. The thermal power industry is accelerating its digital transformation, with industrial control networks deeply integrating with the Internet of Things and cloud computing. However, it also faces the challenge of escalating cybersecurity threats. 72% of remote terminals have vulnerabilities in plaintext data transmission, and the contradiction between the iteration of new network attack technologies and the lag in traditional defense systems is prominent, posing a serious risk to the security of industrial control systems. Currently, existing technologies in the field of thermal power industrial control security situational awareness have many shortcomings and are insufficient to meet actual needs. Firstly, existing systems mostly adopt a centralized architecture, with data collection and analysis concentrated on a single platform, making it difficult to achieve full coverage of multiple branches and wide-area heating networks. Furthermore, their scalability is limited, requiring the reconstruction of the architecture for new nodes, resulting in long deployment cycles and high operation and maintenance costs, which cannot adapt to the dynamic expansion needs of thermal power groups of different sizes. Secondly, the existing system lacks sufficient support for parsing industrial control protocols such as Modbus, S7, and IEC61850, which are unique to the thermal power industry. The threat detection scenarios are highly generalized but lack customization, making it difficult to accurately identify industry-specific attack behaviors such as abnormal industrial control commands and illegal equipment start-up and shutdown. Furthermore, the cross-network transmission of multi-source data lacks reliable encryption and breakpoint resumption mechanisms, making it difficult to guarantee data security and integrity. The situation assessment algorithm is not adapted to the heating business scenario, resulting in low accuracy in risk prediction. Third, the existing system has not formed a closed loop of the entire process of data collection, transmission, analysis and response. The security response mechanism lacks hierarchical design, the response is delayed and not targeted enough. At the same time, it lacks efficient industrial control asset mapping and visualization functions, making it difficult for operation and maintenance personnel to intuitively grasp the status and security situation of assets across the entire domain. The decision support is weak, and production interruptions are easily caused by untimely handling, affecting the stability of heating supply.
[0003] Furthermore, policies and regulations such as the "Cybersecurity Law of the People's Republic of China" and the "Action Plan for Information Security of Industrial Control Systems," as well as the requirements for Level 3 Information Security Protection, all clearly stipulate requirements for the security monitoring, early warning, and risk prevention capabilities of industrial control systems. Therefore, developing an industrial control security situational awareness system that supports full-domain expansion, adapts to the characteristics of the thermal power industry, and possesses precise protection and rapid response capabilities has become an urgent need to address industry pain points, meet policy requirements, and ensure the safety of heating for people's livelihoods. Summary of the Invention
[0004] The purpose of this invention is to provide a power plant industrial control safety situation awareness system that supports full-domain expansion, in order to solve the problems of limited coverage and poor scalability of traditional centralized systems mentioned in the background art.
[0005] To achieve the above objectives, the present invention provides the following technical solution: The thermal power group's industrial control security situation awareness system, which supports full-domain expansion, includes: a central situation awareness platform, a distributed flow detection probe cluster, a cross-network data interaction module, and a security response execution unit; The distributed flow detection probe cluster adopts a center-edge elastic expansion architecture and is deployed in the core production area of the thermal power group and the production units of each branch company. It supports expansion to N branch company nodes as needed, where N is ≥12. Each probe collects mirrored flow from the industrial control network through bypass deployment. The industrial control network covers the field equipment layer, control layer, and management layer, and covers IoT sensing devices for the entire heating process, such as boilers, heat exchange units, and meters. The cross-network data interaction module adopts a dual-protocol redundant transmission mechanism of SYSLOG and KAFKA to realize encrypted transmission and breakpoint resumption of risk data, traffic metadata and alarm information between distributed probes and the central platform. The central situational awareness platform integrates a data fusion processing module, a multi-dimensional threat analysis module, an industrial control asset mapping module, and a security situation visualization module. It integrates deep analysis of industrial control protocols, multi-source threat intelligence correlation, asset vulnerability scanning, and attack behavior modeling technologies to achieve full-domain security situational awareness, risk warning, and attack tracing of thermal power industrial control networks. The security response execution unit works in conjunction with the central platform, supporting automatic blocking, honeypot redirection, and work order routing functions. The central platform achieves quantitative assessment of the overall security situation through the following core algorithms: ; in, This is a comprehensive evaluation value for the overall industrial control system security situation, ranging from 0 to 100. This is the asset importance weighting factor, with a value range of 0 to 25. This is the cumulative vulnerability risk value, ranging from 0 to 30. This represents the real-time attack threat strength, with a value ranging from 0 to 25. The business impact correlation is represented by a value ranging from 0 to 20. For normalized weight coefficients, satisfying Furthermore, it is dynamically adapted and adjusted based on the thermal power heating business scenario.
[0006] Preferably, the distributed flow detection probe cluster supports deep application layer analysis of various industrial control protocols such as Modbus, S7, OPCUA, IEC61850, DNP3, EtherNet / IP, CIP and IEC104. It adopts a self-developed DPI deep packet detection engine combined with full flow capture technology to achieve fine-grained auditing at the level of control commands, control points and command values, with data acquisition time accuracy ≤5ms.
[0007] Preferably, the multi-dimensional threat analysis module has a built-in customized scenario-based analysis engine for the thermal power industry, which presets at least eight threat scenarios, including abnormal computing power occupancy threat detection, Webshell attack chain tracing, weak password brute-force identification, industrial control abnormal command detection, cross-network access violation monitoring, ransomware identification, plaintext password leakage warning and illegal equipment start-up and shutdown monitoring. It achieves intelligent aggregation of multi-source alarms and attack path reconstruction through causal correlation algorithms.
[0008] As a preferred option, the cumulative vulnerability risk value in the core algorithm The following industrial control system vulnerability risk quantification algorithm is used for calculation: ; in, This represents the total number of vulnerabilities detected. The CVSS 3.1 base score for the k-th vulnerability ranges from 0 to 10. This represents the difficulty coefficient for exploiting the vulnerability, with a value ranging from 0.1 to 1.0. The business criticality of the vulnerability-related assets is determined by a value ranging from 0.5 to 1.5, with 1.2 to 1.5 for core business assets and 0.5 to 1.0 for non-core business assets. As a vulnerability disclosure time decay factor, , This is the attenuation coefficient, with a value ranging from 0.02 to 0.05. This represents the number of days since the vulnerability was disclosed.
[0009] Preferably, the central situational awareness platform integrates a multi-source threat intelligence fusion module, employing an intelligence credibility-weighted fusion algorithm to achieve unified processing of commercial intelligence, open-source intelligence, and self-produced intelligence. The algorithm expression is as follows: in, The confidence level of the merged threat intelligence, with a value ranging from 0 to 1. For the number of intelligence sources, Let be the initial confidence level of the i-th intelligence source. This is the credibility coefficient of the intelligence source, with a value ranging from 0.3 to 1.0. For intelligence time freshness factor, , This is the attenuation coefficient, with a value ranging from 0.01 to 0.03. For the current time, For the time of intelligence release, The value ranges from 0.6 to 1.0, representing the matching degree between intelligence and thermal power industrial control scenarios.
[0010] Preferably, the distributed traffic detection probe cluster supports dynamic load balancing scheduling, and achieves full-domain coverage expansion through the following distributed probe collaborative scheduling algorithm: in, This represents the scheduling priority of the j-th probe, with a value ranging from 0 to 1. The current processing bandwidth of the j-th probe. This represents the maximum processing bandwidth of the probe. Let j represent the number of assets covered by the j-th probe. The total number of assets in the entire domain. This represents the real-time risk level of the area covered by the j-th probe, with a value ranging from 0 to 10. The highest risk level in the entire region. This is the load weighting coefficient, with a value ranging from 0.4 to 0.6. This is the risk weighting coefficient, with a value ranging from 0.2 to 0.3. The dispatch center determines the weighting based on... Dynamically allocate detection tasks and support hot-swappable expansion of probe nodes.
[0011] Preferably, the industrial control asset mapping module adopts an asset discovery mechanism that combines active detection and passive identification. It automatically establishes an asset ledger through an asset fingerprint feature matching algorithm. The algorithm extracts device protocol fingerprints, port features, firmware versions, and configuration parameters to construct an asset fingerprint database. It supports batch identification and status monitoring of more than 321,000 residential individual meters, more than 2,583 heat exchange units, and more than 78 boilers, and automatically draws an industrial control network topology map with risk status markers.
[0012] Preferably, the security situation visualization module uses the following situation prediction algorithm to predict security risk trends for the next 24 hours: ; in, For the future The predicted situation after a certain time, This represents the current situation value. The historical data sampling interval ranges from 15 minutes to 60 minutes. This represents the number of historical sampling points, ranging from 10 to 20. This is a trend correction coefficient, with a value ranging from 0.8 to 1.2. For the current heating load, For the rated heating load, This is the heating load influence coefficient, with a value ranging from 0.1 to 0.3. Adjust dynamically based on real-time weather data.
[0013] Preferably, the cross-network data interaction module is equipped with a dual encryption mechanism: the transport layer uses the TLS 1.3 protocol for encryption, and the data payload uses the AES-256-GCM algorithm for encryption. It supports 180-day retention and traceability query of log data, which includes network device logs, security device logs, database audit logs, and industrial control protocol interaction logs.
[0014] Preferably, the security response execution unit supports situation assessment values. A three-level response mechanism: when When an alarm is triggered and logs are saved, it will be displayed. When this happens, the firewall will dynamically update the IP whitelist and block suspicious traffic; when When the honeypot is activated, the core server is isolated and the work order is automatically routed to the emergency response team, with a response delay of ≤30s. The core server includes the production scheduling server, the database server and the trade settlement server.
[0015] Compared with the prior art, the beneficial effects of the present invention are: (1) This invention adopts a center-edge distributed architecture and a dynamic load balancing scheduling algorithm to achieve full coverage and elastic expansion of the industrial control network of thermal power groups. The distributed flow detection probe cluster supports hot-swapping and can be expanded to multiple branch nodes as needed without adjusting the existing system architecture. It effectively adapts to the different deployment scale requirements of thermal power groups from small to large, solving the pain points of limited coverage and poor scalability of traditional centralized systems, and reducing the cost of large-scale deployment and operation and maintenance.
[0016] (2) This invention, through a multi-dimensional threat analysis module and a customized scenario-based analysis engine, combined with a multi-source threat intelligence fusion algorithm, achieves accurate identification and attack path reconstruction of attack behaviors specific to the thermal power industry. Simultaneously, core algorithms such as comprehensive security situation quantitative assessment and vulnerability risk accumulation calculation are fully adapted to thermal power business scenarios, improving the accuracy of risk assessment and prediction. The dual encryption and breakpoint resumption mechanism of the cross-network data interaction module ensures the security and integrity of multi-source data transmission, providing reliable data support for precise protection.
[0017] (3) This invention constructs a closed-loop management mechanism covering the entire process of data acquisition, transmission, analysis, and response. Based on a three-level response mechanism using situation assessment values, it enables graded risk management with a response delay of ≤30s. This allows for rapid blocking of attacks, isolation of core equipment, and dispatching of emergency resources, minimizing the impact of security incidents on heating production. The integrated asset mapping and situation visualization modules enhance the clarity of industrial control asset management and the intuitiveness of the security situation, providing efficient support for maintenance personnel's decision-making and ensuring the continuous and stable operation of thermal power production. Attached Figure Description
[0018] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are explained in detail together with the embodiments of the invention, but do not constitute a limitation thereof.
[0019] Figure 1 This is a system composition block diagram of the present invention; Figure 2 This is a comparison chart of the asset coverage of the three sets of embodiments of the present invention, including the number of boilers, the number of heat exchange units, and the number of individual meters for residential households; Figure 3 This is a comparison diagram of the system configuration of three sets of embodiments of the present invention, including the number of probes, the number of servers, and the number of firewalls; Figure 4 This is a comparative diagram of the implementation effects of three sets of embodiments of the present invention, including response time and recovery of economic losses. Detailed Implementation
[0020] The technical solutions of the present invention will be clearly and completely described below with reference to the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.
[0021] like Figure 1 As shown, the thermal power group industrial control security situation awareness system supporting full-domain expansion described in this invention adopts a center-edge distributed architecture. The core includes four major components: a central situation awareness platform, a distributed traffic detection probe cluster, a cross-network data interaction module, and a security response execution unit. Each component is linked through standardized interfaces to achieve closed-loop management of the entire process of data collection, transmission, analysis, and response. At the same time, it supports the expansion of nodes as needed to adapt to the industrial control security protection needs of thermal power groups of different sizes.
[0022] The system deployment follows the principles of layered deployment and full coverage: the central situational awareness platform is deployed in the core computer room of the thermal power group headquarters, and a dual-machine hot standby mode is adopted to ensure high availability; the distributed flow detection probe cluster is deployed in a bypass mode at the network exit of each production area, including the core production area of the group headquarters, the production units of each branch company, and cross-regional heating pipeline nodes; the cross-network data interaction module is deployed at the network boundary between the central platform and the edge probes to realize secure data transmission between networks with different security levels; the security response execution unit is linked with the firewalls, industrial firewalls, honeypot devices, etc. of each production area and is deployed at the isolation boundary between the industrial control network and the office network.
[0023] Detailed implementation of each core module of this invention: (a) Distributed traffic detection probe cluster This module adopts an embedded hardware architecture. The single probe hardware configuration is as follows: Intel Core i7-12700H CPU, 32GB DDR5 memory, 1TB SSD storage, and four 10GE SFP+ optical ports for network interfaces, supporting full-traffic mirroring acquisition. The probe incorporates a self-developed DPI deep packet inspection engine, which, through a pre-built industrial control protocol feature library, enables deep application-layer analysis of more than 10 industrial control protocols, including Modbus, S7, OPC UA, IEC 61850, DNP3, EtherNet / IP, CIP, and IEC 104.
[0024] The probe workflow is as follows: 1) Collect the full traffic of the industrial control network in the area through bypass mirroring, with the collection time accuracy controlled within ≤5ms; 2) The DPI engine performs protocol parsing on the traffic, extracting key information such as control commands, control points, command values, and device addresses; 3) Perform preliminary filtering and formatting on the parsed traffic data to identify abnormal traffic characteristics (such as illegal control commands, abnormal port access, protocol field tampering, etc.). 4) Upload raw traffic metadata, abnormal feature data, and alarm information to the central situational awareness platform through the cross-network data interaction module.
[0025] To achieve full-domain expansion, the probe cluster supports dynamic load balancing scheduling. The scheduling center collects parameters such as the processing bandwidth, number of covered assets, and risk level of the covered area for each probe in real time, and calculates the scheduling priority of each probe through a distributed probe collaborative scheduling algorithm. Dynamically allocate probe tasks. When a new branch office node is added, only the corresponding number of probe devices need to be added. They can be connected to the cluster in a plug-and-play manner, and the scheduling center will automatically identify and allocate tasks without requiring large-scale adjustments to the existing system architecture.
[0026] (ii) Cross-network data interaction module This module employs a dual-protocol redundant transmission mechanism using SYSLOG and KAFKA. The SYSLOG protocol is used to transmit data with lower real-time requirements, such as alarm logs, while the KAFKA protocol is used to transmit large volumes of high-real-time data, such as traffic metadata. To ensure data transmission security, the module uses a dual encryption mechanism: the transport layer uses TLS 1.3 for link encryption, and certificate authentication is used to verify the identity between the central platform and the probes; the data payload is encrypted using the AES-256-GCM algorithm, and the key is updated regularly by the key management center every 7 days.
[0027] Meanwhile, the module supports breakpoint resume functionality: the probe employs a local caching mechanism, temporarily storing data on a local SSD when the network is interrupted, with a cache capacity supporting 72 hours of full data storage; after the network recovers, the module automatically verifies the missing data during the interruption and incrementally transmits the missing data to the central platform, ensuring data integrity. Furthermore, the module supports 180-day log data retention, including network device logs, security device logs, database audit logs, and industrial control protocol interaction logs, facilitating subsequent security tracing and analysis.
[0028] (III) Central Situation Awareness Platform This platform is the core analysis unit of the system. It adopts a microservice architecture and integrates four sub-modules: a data fusion and processing module, a multi-dimensional threat analysis module, an industrial control asset mapping module, and a security situation visualization module. Each sub-module interacts with data through a message queue.
[0029] 1. Data Fusion Processing Module: This module receives multi-source data (traffic metadata, anomaly characteristic data, alarm information, etc.) uploaded from various probes. After data cleaning, deduplication, and standardization, it achieves data fusion through a multi-source data association algorithm. Specifically, it first synchronizes the data in time (based on the central platform time, with an error correction of ≤1ms), and then performs association matching based on key fields such as device address, protocol type, and timestamp to generate a unified security data view.
[0030] 2. Multi-dimensional Threat Analysis Module: This module includes a built-in customized scenario-based analysis engine for the thermal power industry, pre-setting eight threat scenarios: abnormal computing power usage threat detection, Webshell attack chain tracing, weak password brute-force identification, abnormal industrial control command detection, cross-network access violation monitoring, ransomware identification, plaintext password leakage warning, and illegal device start / stop monitoring. It intelligently aggregates multi-source alarms using a causal correlation algorithm. Specifically, it extracts features such as the attack source IP, attack target, attack time, and attack type from each alarm, calculates feature similarity, aggregates alarms with a similarity ≥85% into a single attack event, and reconstructs the attack path. Simultaneously, the module integrates a multi-source threat intelligence fusion module, employing a confidence-weighted fusion algorithm to process commercial intelligence (such as Qi An Xin threat intelligence), open-source intelligence (such as the CVE vulnerability database), and self-produced intelligence (such as attack features collected by the system), outputting the confidence level of the fused threat intelligence. This provides support for threat analysis.
[0031] 3. Industrial Control Asset Mapping Module: This module employs a hybrid asset discovery mechanism combining active detection and passive identification. Active detection acquires device response information by sending customized industrial control protocol probe packets. Passive identification extracts device protocol fingerprints, port features, firmware versions, and configuration parameters by analyzing traffic data collected by probes. Combining the results of active detection and passive identification, an asset fingerprint database is constructed using an asset fingerprint feature matching algorithm. This automatically establishes an asset ledger, enabling batch identification and status monitoring of equipment such as residential meters, heat exchangers, and boilers. Simultaneously, the module automatically draws an industrial control network topology map with risk status markers. The topology map is updated in real-time, with an update frequency of 5 minutes per iteration.
[0032] 4. Security Situation Visualization Module: Adopts a B / S architecture and supports web-based visualization. Displayed content includes: Overall Security Situation Evaluation Value. This includes information on risk level distribution in different regions, asset distribution and risk status, attack statistics, and security trend prediction. The system uses situational prediction algorithms to forecast security risk trends for the next 24 hours, providing decision support for operations and maintenance personnel.
[0033] Platform core algorithm implementation: (1) Global security situation quantitative assessment algorithm: ; Among them, dynamic adaptation based on thermal power heating business scenarios , , , During the calculation, the asset importance weighting factor is first obtained through the asset mapping module. Obtain the cumulative vulnerability risk value through vulnerability scanning. The threat analysis module obtains the real-time attack threat intensity. Obtain the degree of business impact correlation through business correlation analysis The final calculation yielded (Value range: 0 to 100).
[0034] (2) Algorithm for calculating the cumulative value of vulnerability risk: For each vulnerability detected, query its CVSS 3.1 baseline score. Assign a value based on the difficulty of exploiting the vulnerability. (Easy to utilize: 0.8–1.0; Medium utilization: 0.4–0.7; Difficult to utilize: 0.1–0.3), assign values based on the criticality of the asset's business. Core business assets are valued at 1.2 to 1.5, and non-core business assets at 0.5 to 1.0, calculated based on the vulnerability disclosure time. ,in Finally, the sum is obtained .
[0035] (iv) Safety Response Execution Unit This unit collaborates with the central situational awareness platform, based on the comprehensive security situation assessment value across the entire domain. Implement a three-level response mechanism: 1. Level 1 Response ( The system automatically triggers alarm notifications (web pop-up window + SMS notification to maintenance personnel) and retains relevant log data. Maintenance personnel only need to pay attention to alarm information and do not need to perform blocking operations. 2. Level II Response ( The central platform sends control commands to the firewall, dynamically updates the IP whitelist, blocks the source IP of suspicious traffic, and records the blocking logs. Operation and maintenance personnel need to promptly verify attack events. 3. Level 3 response ( The system automatically activates the honeypot redirection function to direct attack traffic to the industrial honeypot; it also links with the industrial firewall to isolate core servers (production scheduling server, database server, and trade settlement server); it automatically generates emergency work orders and transfers them to the emergency response team, with a response delay of ≤30s, and the emergency team must complete the incident handling within 1 hour.
[0036] III. System Workflow 1. Data Acquisition: The distributed traffic detection probe cluster bypasses and collects the full traffic of the industrial control network in each production area, performs protocol parsing and preliminary filtering, and extracts key data; 2. Data transmission: The cross-network data interaction module adopts a dual-protocol encrypted transmission mechanism to securely transmit the data collected by the probe to the central situational awareness platform, and supports breakpoint resume; 3. Data Processing and Analysis: The central platform integrates and processes the received data, identifies attack events through a multi-dimensional threat analysis module, establishes an asset ledger through an industrial control asset mapping module, and calculates a comprehensive security posture evaluation value across the entire domain using core algorithms. ; 4. Security Response: The security response execution unit, based on... The value is used to execute the corresponding three-level response mechanism to achieve operations such as alarm prompts, traffic blocking, honeypot diversion, and core server isolation; 5. Visualization and Traceability: The security posture visualization module displays the overall security posture, and the retained log data supports subsequent security traceability analysis.
[0037] The following three examples of deployment in thermal power groups of different sizes further illustrate the implementation effect of the present invention. Each embodiment adopts the system architecture and implementation scheme described in the above specific embodiments, and only adjusts the relevant parameters according to the deployment scale.
[0038] Example 1: Deployment of a small-scale thermal power group (12 branch nodes) 1. Deployment scale: This thermal power group is a small local enterprise with 12 branch nodes, covering 2 core production areas and 12 branch production units. The assets covered include 15 boilers, 1,200 heat exchange units, and 150,000 individual household meters.
[0039] 2. System Configuration: (1) Distributed traffic detection probe cluster: 16 probes are deployed (2 in the core production area and 1 in each branch office), with a maximum processing bandwidth of 16 probes. Scheduling algorithm parameters , ; (2) Cross-network data interaction module: It is deployed on a single independent server, supports SYSLOG / KAFKA dual protocol transmission, and the encryption key is updated every 7 days; (3) Central Situation Awareness Platform: Deployed 2 servers (dual-machine hot standby), CPU is Intel Xeon Gold 6330, memory is 64GB, storage is 10TB, algorithm parameters , , , , , ; (4) Security Response Execution Unit: Links 15 firewalls and 2 industrial honeypot devices.
[0040] 3. Implementation Results: The system ran stably for 30 days without any downtime. Data acquisition time accuracy was ≤4ms, vulnerability identification accuracy was ≥92%, and the false alarm rate for attack events was ≤3%. When a branch office experienced a weak password brute-force attack, the system calculated... The system triggered a Level 2 response, blocking the suspicious IP address within 5 seconds, without affecting production operations.
[0041] Example 2: Deployment of a medium-sized cross-regional thermal power group (20 branch nodes) 1. Deployment Scale: This thermal power group is a cross-regional enterprise with business covering 3 provinces, 20 branch company nodes, covering 5 core production areas, 20 branch company production units and 30 cross-regional heating network nodes. The assets covered include 35 boilers, 2,583 heat exchange units and 321,000 residential individual meters.
[0042] 2. System Configuration: (1) Distributed flow detection probe cluster: 30 probes are deployed (3 in the core production area, 1 in each branch company, and 0.5 in each heating pipeline node, for a total of 15 probes), with a maximum processing bandwidth of probes. Scheduling algorithm parameters , ; (2) Cross-network data interaction module: Deploy 2 servers (load balancing), support dual protocol redundant transmission, and local cache capacity supports 72 hours of full data storage; (3) Central Situation Awareness Platform: Deployed 4 servers (2 primary and 2 backup), CPU is Intel Xeon Gold 6430, memory is 128GB, storage is 50TB, algorithm parameters , , , , , Situation prediction algorithm sampling interval , ; (4) Security Response Execution Unit: Links 30 firewalls, 5 industrial honeypot devices, and 3 work order flow systems.
[0043] 3. Implementation Results: The system supports full coverage of 20 branch office nodes. Expansion requires no adjustments to the existing architecture, and new probes are plug-and-play. After 60 days of operation, the data transmission success rate is ≥99.9%, the breakpoint recovery time is ≤10 seconds, and the security situation prediction accuracy is ≥88%. When a cross-regional heating network node experiences an industrial control anomaly command attack, the system calculates... The system triggered a Level 3 response, completing honeypot redirection and core server isolation within 20 seconds. After the work order was transferred to the emergency response team, the incident was handled within 40 minutes, ensuring the continuous operation of the heating business.
[0044] Example 3: Deployment of a large-scale, comprehensive thermal power group (30 branch company nodes) 1. Deployment Scale: This thermal power group is a nationwide enterprise with business covering 10 provinces, 30 branch company nodes, covering 8 core production areas, 30 branch company production units and 80 cross-regional heating network nodes. The assets covered include 78 boilers, 5,000 heat exchange units and 800,000 individual household meters.
[0045] 2. System Configuration: (1) Distributed flow detection probe cluster: 56 probes are deployed (5 in the core production area, 1 in each branch company, and 0.5 in each heating pipeline node, for a total of 40 probes), with a maximum processing bandwidth of probes. Scheduling algorithm parameters , ; (2) Cross-network data interaction module: 4 servers are deployed (cluster deployment), supporting multi-site active-active deployment. Encryption adopts the national cryptographic SM4 algorithm (compatible with AES-256-GCM), and the key update cycle is 5 days; (3) Central Situation Awareness Platform: Deployed with 8 servers (4 primary and 4 backup), adopting a distributed cluster architecture, with Intel Xeon Platinum 8480C CPU, 256GB memory, 200TB storage, and algorithm parameters. , , , , , Situation prediction algorithm sampling interval , ; (4) Security Response Execution Unit: Links 60 firewalls, 10 industrial honeypot devices, 5 work order circulation systems and 1 emergency command platform.
[0046] 3. Implementation Results: The system supports full-domain expansion to 30 branch office nodes, with a single platform processing an average of 10TB of traffic data per day and a data processing latency of ≤200ms. After 90 days of operation, system availability is ≥99.99%, threat intelligence fusion confidence level is ≥0.92, and attack attribution accuracy is ≥95%. When a ransomware attack occurs in a core production area, the system calculates... The system triggered a Level 3 response, completing the isolation of the core server and the redirection of traffic to the honeypot within 15 seconds. The emergency command platform coordinated emergency teams from multiple regions through the work order system to handle the situation, and completed virus removal and system recovery within 30 minutes. This prevented large-scale production interruption and saved approximately 5 million yuan in economic losses.
[0047] The thermal power group industrial control safety situation awareness system supported by this invention has the following advantages: This invention employs a center-edge distributed architecture and a dynamic load balancing scheduling algorithm to achieve full coverage and elastic expansion of the industrial control network of a thermal power group. The distributed flow detection probe cluster supports hot-swapping and plug-and-play functionality, and can be expanded to multiple branch office nodes as needed without adjusting the existing system architecture. It effectively adapts to the different deployment scale requirements of thermal power groups ranging from small to large, solving the pain points of limited coverage and poor scalability of traditional centralized systems, and reducing the cost of large-scale deployment and operation and maintenance.
[0048] This invention, through a multi-dimensional threat analysis module and a customized scenario-based analysis engine, combined with a multi-source threat intelligence fusion algorithm, achieves accurate identification and attack path reconstruction of attack behaviors specific to the thermal power industry. Simultaneously, core algorithms such as comprehensive security posture quantitative assessment and vulnerability risk accumulation calculation are fully adapted to thermal power business scenarios, improving the accuracy of risk assessment and prediction. The dual encryption and breakpoint resumption mechanism of the cross-network data interaction module ensures the security and integrity of multi-source data transmission, providing reliable data support for precise protection.
[0049] This invention constructs a closed-loop management mechanism covering the entire process of data acquisition, transmission, analysis, and response. Based on a three-level response mechanism using situation assessment values, it enables tiered risk management with a response latency of ≤30 seconds. This allows for rapid attack blocking, isolation of core equipment, and dispatch of emergency resources, minimizing the impact of security incidents on heating production. The integrated asset mapping and situation visualization modules enhance the clarity of industrial control asset management and the intuitiveness of the security situation, providing efficient support for maintenance personnel's decision-making and ensuring the continuous and stable operation of thermal power production.
[0050] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely preferred examples and are not intended to limit the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of the present invention is defined by the appended claims and their equivalents.
Claims
1. A power plant industrial control safety situation awareness system supporting full-domain expansion, characterized in that: include: Central situational awareness platform, distributed traffic detection probe cluster, cross-network data interaction module, and security response execution unit; The distributed flow detection probe cluster adopts a center-edge elastic expansion architecture and is deployed in the core production area of the thermal power group and the production units of each branch company. It supports expansion to N branch company nodes as needed, where N is ≥12. Each probe collects mirrored flow from the industrial control network through bypass deployment. The industrial control network covers the field equipment layer, control layer, and management layer, and covers IoT sensing devices for the entire heating process, including boilers, heat exchange units, and metering instruments. The cross-network data interaction module adopts a dual-protocol redundant transmission mechanism of SYSLOG and KAFKA to realize encrypted transmission and breakpoint resumption of risk data, traffic metadata and alarm information between distributed probes and the central platform. The central situational awareness platform integrates a data fusion processing module, a multi-dimensional threat analysis module, an industrial control asset mapping module, and a security situation visualization module. It integrates deep analysis of industrial control protocols, multi-source threat intelligence correlation, asset vulnerability scanning, and attack behavior modeling technologies to achieve full-domain security situational awareness, risk warning, and attack tracing of thermal power industrial control networks. The security response execution unit works in conjunction with the central platform, supporting automatic blocking, honeypot redirection, and work order routing functions. The central platform achieves quantitative assessment of the overall security situation through the following core algorithms: ; in, This is a comprehensive evaluation value for the overall industrial control system security situation, ranging from 0 to 100. This is the asset importance weighting factor, with a value range of 0 to 25. This is the cumulative vulnerability risk value, ranging from 0 to 30. This represents the real-time attack threat strength, with a value ranging from 0 to 25. The business impact correlation is represented by a value ranging from 0 to 20. For normalized weight coefficients, satisfying Furthermore, it is dynamically adapted and adjusted based on the thermal power heating business scenario.
2. The thermal power group industrial control safety situation awareness system supporting full-domain expansion as described in claim 1, characterized in that, The distributed flow detection probe cluster supports deep application layer analysis of various industrial control protocols such as Modbus, S7, OPCUA, IEC61850, DNP3, EtherNet / IP, CIP and IEC104. It adopts a self-developed DPI deep packet detection engine combined with full flow capture technology to achieve fine-grained auditing at the level of control commands, control points and command values, with data acquisition time accuracy ≤5ms.
3. The thermal power group industrial control safety situation awareness system supporting full-domain expansion as described in claim 1, characterized in that, The multi-dimensional threat analysis module has a built-in customized scenario-based analysis engine for the thermal power industry. It has at least eight preset threat scenarios, including abnormal computing power occupancy threat detection, Webshell attack chain tracing, weak password brute-force identification, industrial control abnormal command detection, cross-network access violation monitoring, ransomware identification, plaintext password leakage warning, and illegal device start-up and shutdown monitoring. It achieves intelligent aggregation of multi-source alarms and attack path reconstruction through causal correlation algorithms.
4. The thermal power group industrial control safety situation awareness system supporting full-domain expansion as described in claim 1, characterized in that, The core algorithm contains a cumulative vulnerability risk value. The following industrial control system vulnerability risk quantification algorithm is used for calculation: ; in, This represents the total number of vulnerabilities detected. The CVSS 3.1 base score for the k-th vulnerability ranges from 0 to 10. This represents the difficulty coefficient for exploiting the vulnerability, with a value ranging from 0.1 to 1.
0. The business criticality of the vulnerability-related assets is determined by a value ranging from 0.5 to 1.5, with 1.2 to 1.5 for core business assets and 0.5 to 1.0 for non-core business assets. As a vulnerability disclosure time decay factor, , This is the attenuation coefficient, with a value ranging from 0.02 to 0.
05. This represents the number of days since the vulnerability was disclosed.
5. The thermal power group industrial control safety situation awareness system supporting full-domain expansion as described in claim 1, characterized in that, The central situational awareness platform integrates a multi-source threat intelligence fusion module, employing an intelligence credibility-weighted fusion algorithm to achieve unified processing of commercial intelligence, open-source intelligence, and self-produced intelligence. The algorithm expression is as follows: in, The confidence level of the merged threat intelligence, with a value ranging from 0 to 1. For the number of intelligence sources, Let be the initial confidence level of the i-th intelligence source. This is the credibility coefficient of the intelligence source, with a value ranging from 0.3 to 1.
0. For intelligence time freshness factor, , This is the attenuation coefficient, with a value ranging from 0.01 to 0.
03. For the current time, For the time of intelligence release, The value ranges from 0.6 to 1.0, representing the matching degree between intelligence and thermal power industrial control scenarios.
6. The thermal power group industrial control safety situation awareness system supporting full-domain expansion as described in claim 1, characterized in that, The distributed traffic detection probe cluster supports dynamic load balancing scheduling, and achieves full-domain coverage expansion through the following distributed probe collaborative scheduling algorithm: in, This represents the scheduling priority of the j-th probe, with a value ranging from 0 to 1. The current processing bandwidth of the j-th probe. This represents the maximum processing bandwidth of the probe. Let j represent the number of assets covered by the j-th probe. The total number of assets in the entire domain. This represents the real-time risk level of the area covered by the j-th probe, with a value ranging from 0 to 10. The highest risk level in the entire region. This is the load weighting coefficient, with a value ranging from 0.4 to 0.
6. This is the risk weighting coefficient, with a value ranging from 0.2 to 0.
3. The dispatch center determines the weighting based on... Dynamically allocate detection tasks and support hot-swappable expansion of probe nodes.
7. The thermal power group industrial control safety situation awareness system supporting full-domain expansion as described in claim 1, characterized in that, The industrial control asset mapping module adopts an asset discovery mechanism that combines active detection and passive identification. It automatically establishes an asset ledger through an asset fingerprint feature matching algorithm. The algorithm extracts device protocol fingerprints, port features, firmware versions, and configuration parameters to build an asset fingerprint database. It supports batch identification and status monitoring of more than 321,000 residential individual meters, more than 2,583 heat exchange units, and more than 78 boilers, and automatically draws an industrial control network topology map with risk status markers.
8. The thermal power group industrial control safety situation awareness system supporting full-domain expansion as described in claim 1, characterized in that, The security situation visualization module uses the following situation prediction algorithm to predict security risk trends for the next 24 hours: ; in, For the future The predicted situation after the time limit, This represents the current situation value. The historical data sampling interval ranges from 15 minutes to 60 minutes. This represents the number of historical sampling points, ranging from 10 to 20. This is a trend correction coefficient, with a value ranging from 0.8 to 1.
2. For the current heating load, For the rated heating load, This is the heating load influence coefficient, with a value ranging from 0.1 to 0.
3. Adjust dynamically based on real-time weather data.
9. The thermal power group industrial control safety situation awareness system supporting full-domain expansion as described in claim 1, characterized in that, The cross-network data interaction module is equipped with a dual encryption mechanism. The transport layer uses the TLS1.3 protocol for encryption, and the data payload uses the AES-256-GCM algorithm for encryption. It supports 180-day retention and traceability query of log data, which includes network device logs, security device logs, database audit logs, and industrial control protocol interaction logs.
10. The thermal power group industrial control safety situation awareness system supporting full-domain expansion according to claim 1, characterized in that, The security response execution unit supports situation assessment values. A three-level response mechanism: when When an alarm is triggered and logs are saved, it will be displayed. When this happens, the firewall will dynamically update the IP whitelist and block suspicious traffic; when When the honeypot is activated, the core server is isolated and the work order is automatically routed to the emergency response team, with a response delay of ≤30s. The core server includes the production scheduling server, the database server and the trade settlement server.