Network security protection system and method for new power cyber-physical systems

By constructing a unified closed-loop network security protection system, the problems of insufficient fusion of multi-source heterogeneous data and incomplete closed-loop protection in the new power information physical system have been solved, realizing multi-scenario adaptation and rapid response, and improving the system's security protection capabilities.

CN122137670APending Publication Date: 2026-06-02STATE GRID ANHUI ELECTRIC POWER CO LTD ELECTRIC POWER SCI RES INST

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
STATE GRID ANHUI ELECTRIC POWER CO LTD ELECTRIC POWER SCI RES INST
Filing Date
2026-04-15
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Existing technologies lack the ability to unify and integrate multi-source heterogeneous data in new power cyber-physical systems, have incomplete closed-loop protection mechanisms, and lack the ability to provide unified protection and deployment across multiple scenarios, making it difficult to cope with cross-domain cascading failures and operational consequences caused by network attacks.

Method used

This paper provides a network security protection system and method for new power cyber-physical systems. Through data acquisition and management modules, scenario modeling and topology identification modules, security detection modules, fault simulation and propagation analysis modules, event response modules, and system recovery modules, a unified closed-loop collaborative protection architecture is constructed to achieve unified management of multi-source heterogeneous data, cross-layer coupled scenario modeling, and closed-loop protection.

Benefits of technology

It achieves unified integration of multiple protection functions, improves collaboration capabilities and event management efficiency, increases protection response speed, adapts to multi-scenario deployment, and enhances the security and stability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122137670A_ABST
    Figure CN122137670A_ABST
Patent Text Reader

Abstract

This application relates to a network security intelligent protection system and method for novel power cyber-physical systems, belonging to the field of power system network security technology. The system consists of a data acquisition and management module, a scenario modeling and topology identification module, a security detection module, a fault simulation and propagation analysis module, an event response module, a system recovery module, and a visualization module. Each module relies on unified data and a coupled scenario model for closed-loop collaboration. The method forms a closed-loop protection process through data standardization, cross-layer coupled scenario modeling, abnormal threat detection, fault simulation, strategy handling, recovery verification, and visualization. This invention achieves multi-source heterogeneous data fusion, network-physical cross-layer modeling, and a closed-loop security protection process, adapting to multiple scenarios such as dispatching master stations, substations / converter stations, and new energy power plants, thereby improving the network security protection, engineering implementation, and operational support capabilities of novel power cyber-physical systems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of power system network security technology, and in particular to a network security protection system and method for a new type of power cyber-physical system. Background Technology

[0002] With the advancement of new power system construction and the development of technologies such as the energy internet, wide-area measurement, and cloud-edge collaborative control, the power system is gradually evolving from a traditional operation mode dominated by the physical power grid to a new type of cyber-physical power system (CPPS) that deeply integrates information systems, communication networks, dispatch control systems, and the physical power grid. In this type of system, the dispatch master station, important substations / converter stations, and new energy power plants operate in close coupling with information flow, control flow, and energy flow. When the information side is attacked, communication links are blocked, or control logic is abnormal, the related risks can be transmitted to the physical side through measurement links, control links, and dispatch execution links, thereby affecting the safe and stable operation of the power system.

[0003] To address the aforementioned scenarios, existing cybersecurity protection technologies primarily include boundary isolation and communication protection solutions, anomaly detection and attack identification solutions, and situation assessment and collaborative defense solutions. These technologies enhance the security capabilities of new power systems in areas such as access control, protocol enhancement, anomaly identification, attack detection, risk characterization, and recovery assessment.

[0004] However, existing technologies still have the following shortcomings: First, existing methods mostly focus on boundary communication, intra-station messages, terminal access, or single-type attack detection, and have not yet integrated the physical side operation status, information side communication status, and control side execution status under a unified framework, lacking the ability to unify and integrate multi-source heterogeneous data. Second, existing methods typically lack a systematic characterization of the impact of decreased information-side observation capabilities, control-side functional degradation, and communication interruptions on the physical-side operational status and scheduling control capabilities. Third, most existing methods are limited to a single stage of protection, detection, or assessment, and lack unified closed-loop support for stages such as post-attack fault propagation analysis, response strategy generation, response execution verification, and recovery rollback, making it difficult to form a full-process collaborative mechanism of "detection - analysis - decision-making - response - recovery". Fourth, existing research usually focuses only on single scenarios such as dispatch master stations, important substations / converter stations or new energy power plants, and lacks a unified network security intelligent protection system architecture and layered deployment method that can adapt to multiple typical application scenarios at the same time. Fifth, existing technologies still do not adequately depict the systematic transmission of network attacks to the physical side via measurement links, control links, and business logic, and the subsequent induction of cross-domain cascading failures and operational consequences.

[0005] Therefore, there is an urgent need for a solution to the problems in existing technologies, such as insufficient integration of multi-source heterogeneous data and cross-domain states, incomplete closed-loop protection mechanisms, and insufficient unified protection and deployment capabilities across multiple scenarios. Summary of the Invention

[0006] Therefore, it is necessary to provide a network security protection system and method for new power cyber-physical systems to address the aforementioned technical problems.

[0007] In a first aspect, this application provides a network security protection system for a novel power cyber-physical system, comprising a data acquisition and management module, a scenario modeling and topology identification module, a security detection module, a fault simulation and propagation analysis module, an event response module, a system recovery module, and a visualization module, wherein: The data acquisition and management module uniformly accesses multi-source heterogeneous operational data and completes standardized processing, outputting standardized data objects; The scene modeling and topology identification module constructs a coupled scene model of the network layer and physical layer based on standardized data objects, and outputs topology data and key object data. The security detection module identifies system anomalies and threats based on a coupled scenario model and generates threat event objects; The fault simulation and propagation analysis module conducts fault consequence analysis and potential risk prediction simulation based on coupled scenario models and threat event objects; The incident response module generates protection and handling strategies based on threat event objects and simulation results; The system recovery module executes protection and handling strategies, completes system status verification, recovery, rollback and optimization, outputs execution results and feeds them back to the security detection module and the fault simulation and propagation analysis module; The visualization module uniformly presents the scene model, detection results, simulation results, response status, and recovery status; each module relies on a unified data foundation and a unified coupled scene model to form a closed-loop collaborative operation.

[0008] Optionally, in one embodiment of this application, the data acquisition and management module acquires multi-source heterogeneous operating data through mirror traffic interface, device interface, log interface, scenario configuration file interface and manual input interface, and performs protocol parsing, field extraction, time alignment, format conversion and object encapsulation on the acquired data to form standardized data objects.

[0009] Optionally, in one embodiment of this application, the scene modeling and topology identification module includes a scene topology management submodule and a scene topology editing and design submodule. The scene topology management submodule performs full lifecycle management of the scene model, and the scene topology editing and design submodule constructs network layer topology, physical layer topology and cross-layer connections to form a coupled scene model and object relationship structure.

[0010] Optionally, in one embodiment of this application, the threat event object generated by the security detection module includes event type, event time, attacker information, affected object information, risk level, scenario attribution information, and processing status.

[0011] Optionally, in one embodiment of this application, the fault simulation and propagation analysis module performs fault consequence analysis on detected threat events, conducts predictive simulation of potential risks by combining attack strategies, key link locations and system operating conditions, and outputs fault propagation paths, impact ranges, chain failure processes, key link analysis results and predictive risk data.

[0012] Optionally, in one embodiment of this application, the protection and handling strategy generated by the event response module includes handling suggestions and action requests.

[0013] Optionally, in one embodiment of this application, the system recovery module supports both automatic execution mode and manual confirmation execution mode.

[0014] Secondly, this application also provides a network security intelligent protection method for novel power cyber-physical systems, the method comprising: Unified access to multi-source heterogeneous runtime data and execution of protocol parsing, field extraction, time alignment, format conversion and object encapsulation to form standardized data objects; Construct a scenario model that couples the network layer and the physical layer based on standardized data objects; Based on the coupled scenario model, system anomalies and threats are identified and threat event objects containing specified fields are generated; Based on the coupled scenario model and threat event objects, conduct failure consequence analysis and potential risk prediction simulation, and generate protection and response strategies based on the simulation results; The system executes protection and handling strategies and completes system status verification, recovery, rollback and optimization. The execution results are fed back to the anomaly identification and fault simulation stages, and the scenario model, detection results, simulation results, handling status and recovery status are presented simultaneously to form a closed-loop protection.

[0015] Compared with existing technologies, the aforementioned network security protection system and method for new power cyber-physical systems have the following advantages: First, we will build a unified closed-loop intelligent network security protection system architecture, integrate multiple protection functions, and solve the problems of existing technologies being fragmented and lacking unified organization. Second, it enables unified management of multi-source heterogeneous data and unified modeling of cross-layer coupled scenarios, providing a consistent data and scenario foundation for the system and enhancing collaborative capabilities. Third, it enables unified organization, coordinated response, and closed-loop handling of security incidents, thereby improving incident management efficiency and protection response speed; Fourth, it is adaptable to deployment in multiple scenarios such as dispatch master stations, substations / converter stations, and new energy power plants, and has strong engineering implementation and scenario adaptation capabilities. Attached Figure Description

[0016] Figure 1 This is a schematic diagram of a network security protection system for a novel power cyber-physical system in one embodiment. Figure 2 This is a schematic diagram of module relationships and closed-loop collaboration in one embodiment; Figure 3 This is a flowchart illustrating a network security protection method for a novel power cyber-physical system in one embodiment. Figure 4 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0017] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0018] In one embodiment, such as Figure 1 As shown, a network security protection system for a new type of power information physical system is provided. Deployed at the core switch, aggregation switch, or their mirror traffic access points in the power grid communication network, it uniformly collects, organizes, and analyzes the operational status of the information side, control side, and physical side by accessing mirror traffic, network device status, physical device status, link status, service operation information, log alarm information, and scenario configuration data. Based on this, a network-physical layer coupled scenario model is constructed to complete scenario identification, anomaly detection, protection decision-making, policy execution, attack analysis, source tracing analysis, performance evaluation, and recovery rollback. The system includes a data acquisition and management module, a scenario modeling and topology identification module, a security detection module, a fault simulation and propagation analysis module, an event response module, a system recovery module, and a visualization module. Each module operates collaboratively in a closed loop based on a unified data foundation and a unified coupled scenario model.

[0019] In one embodiment, the data acquisition and management module forms the underlying data support foundation for the entire device. Its main function is to uniformly access, clean, organize, store, and distribute multi-source heterogeneous operational data. The data accessed by this module includes at least: switch mirrored traffic data, network and security device operating status data, physical device operating status data, link status data, log and alarm data, scenario configuration data, asset information data, and data manually entered by administrators. Specifically, this includes line parameters, power plant generation data, substation load data, converter station parameters, wind farm parameters, photovoltaic power station parameters, primary, secondary, and tertiary communication topologies, performance logs of key site network devices, link bandwidth throughput, packet loss rate statistics, and alarm logs, etc.

[0020] This module performs protocol parsing, field extraction, time alignment, format conversion, and object encapsulation on the raw data, outputting standardized data objects. These standardized data objects include at least node objects, link objects, event objects, scenario objects, log objects, and performance indicator objects. Node objects describe network and physical layer devices and their attributes; link objects describe intra-layer links and cross-layer relationships; event objects carry detection results and handling status; and scenario objects represent specific business scenarios or pre-defined template instances.

[0021] In a preferred embodiment, the data acquisition and management module receives data through mirror traffic interface, device interface, log interface, scenario configuration file interface and manual input interface, and maintains a unified data dictionary and basic field system to provide a consistent data entry point and data semantic foundation for subsequent modules.

[0022] In one embodiment, the scenario modeling and topology identification module serves as a fundamental support module for the intelligent protection device. It combines typical business scenario configurations, collected data, and coupling relationship models to uniformly organize and express information-side and physical-side objects and their relationships, constructing a network-physical layer coupled scenario model. This provides a unified scenario foundation for security detection, event response, fault simulation, and visualization. The scenario foundation of this module originates from typical business scenario analysis, cyber-physical topology research, and coupling model research.

[0023] The module's inputs include at least: node objects, link objects, scenario configuration objects, predefined scenario templates, automatically collected topology relationships, and manually entered design data. Its outputs include at least: network layer topology, physical layer topology, cross-layer connections between the network and physical layers, vulnerability node statistics, key node set, key link set, and topology event logs.

[0024] In a preferred embodiment, the scene modeling and topology identification module includes a scene topology management submodule and a scene topology editing and design submodule. The scene topology management submodule is used to manage the scene, and the scene topology editing and design submodule is used to construct network layer topology, physical layer topology or hybrid topology, and form the scene model and object relationship structure on which the system's subsequent detection and response depend.

[0025] In one embodiment, the security detection module is used to detect and identify abnormal traffic, intrusion behavior, device anomalies, abnormal links, and cross-layer abnormal connections during system operation based on the scenario model, and form threat event results.

[0026] The module's inputs include at least: coupled scenario model, real-time mirrored traffic, device status data, link status data, log and alarm data, attack type and impact analysis results, and identification results of critical nodes / critical links / vulnerabilities. Its outputs include at least: threat event objects, security score, number of threat events, abnormal traffic event results, intrusion behavior event results, device anomaly results, abnormal link results, and risk level distribution results. The requirements document explicitly lists fields such as security score, number of threat events, abnormal traffic, alarm events, device status, and abnormal links.

[0027] In a preferred embodiment, the security detection module abstracts different types of anomalies into threat event objects. Each threat event object includes at least the event type, event time, attacker information, affected object information, risk level, scenario attribution information, and processing status. For network attack events, it can output the source IP, target IP, attack type, risk level, and detection time; for device anomaly events, it can output the device name, device type, device status, and update time; for link anomaly events, it can output the source node, target node, link status, and detection time.

[0028] Furthermore, the module supports mapping detection results to both an event table and the coupled topology: the event fields are displayed in the table, and attacking nodes, faulty nodes, and abnormal connections are identified in the topology through node color, brightness, blinking mode, and link style changes. For example, network attacking nodes can be highlighted in red, physically faulty nodes can be highlighted in blue, and abnormal links or cross-layer abnormal connections can be distinguished by style changes.

[0029] In one embodiment, the fault simulation and propagation analysis module is used to deduce the propagation path, potential impact range, and cascading failure process of abnormal events based on the coupled scenario model, threat events, and system operating parameters.

[0030] The inputs to this module include at least: coupled scenario model, threat event objects, power grid and communication system parameters, equipment operating status, observability status, controllability status, and identification results of critical nodes and critical paths. Its outputs include at least: fault propagation path, scope of impact, potential cascading failure process, analysis results of critical links, load loss, fault impact indicators, and attack propagation timeline.

[0031] In a preferred embodiment, the fault simulation and propagation analysis module not only performs consequence analysis on currently detected events, but also predictively extrapolates potential risks by combining different attack strategies, key link locations, and system operating conditions. It also provides protection priority and handling intensity suggestions to the event response module, and provides recovery sequence and rollback basis to the system recovery module.

[0032] In one embodiment, the event response module is used to generate corresponding handling suggestions and protection strategies based on the threat event results output by the security detection module, combined with scenario attributes, asset objects, risk levels, key link information and defense strategy knowledge.

[0033] The module's inputs include at least: threat event objects, coupled scenario attributes, asset object information, key node and key link information, attack behavior impact assessment results, administrator-preset policies, and a policy knowledge base. Its outputs include at least: handling recommendations, protection policies, action requests, policy status, and event handling status. Both the requirements document and the prototype document support generating corresponding handling recommendations for each attack event, failure event, or contact anomaly record. These recommendations can be pre-configured by the administrator or automatically generated by the system.

[0034] In a preferred embodiment, the proposed actions include at least one or more of the following: blocking IP addresses, shutting down computers, encrypting links, optimizing traffic, limiting traffic, filtering content, adjusting access controls, manual confirmation, and issuing alerts. The module supports both static policy management and dynamic response decisions; static policy management is used to create, edit, copy, delete, enable, disable, and manage pending updates of policies, while dynamic response decisions are used to generate the optimal action for the current threat event.

[0035] In one embodiment, the system recovery module is used to perform corresponding recovery, rollback and optimization operations based on the handling actions generated by the event response module and the impact analysis results given by the fault simulation and propagation analysis module, and to verify the system state after execution.

[0036] The inputs to this module include at least: handling suggestions, action requests, failure propagation impact results, performance metric data, current service status, device status, and link status. Its outputs include at least: recovery strategy, rollback strategy, post-recovery status, execution result feedback, and performance impact feedback.

[0037] In a preferred embodiment, the system recovery module supports both automatic execution mode and manual confirmation execution mode. When a threat event meets preset automatic handling conditions, the module automatically executes relevant actions; when the event involves critical nodes, critical links, or critical business objects, it enters manual confirmation mode. Furthermore, when protective actions are detected to cause significant adverse changes in network latency, data packet loss rate, processing capacity, or business operation status, recovery, rollback, or secondary optimization actions are triggered, thereby achieving a closed loop of "handling—verification—recovery—optimization".

[0038] In one embodiment, the visualization module is used to present the scene model, detection results, response status, propagation analysis results, recovery status, and performance indicators to the administrator in a unified manner, and to provide an operation entry point.

[0039] The module's inputs include at least: scenario topology model, vulnerable node statistics, security detection results, event response status, fault propagation path, recovery results, and performance metrics. Its outputs include at least: coupled topology view, event alarm view, risk level statistics view, propagation replay view, policy status view, and performance monitoring view, and it supports administrators in performing scenario switching, policy confirmation, and recovery operations.

[0040] In one embodiment of this application, such as Figure 2 As shown, the data acquisition and management module serves as the underlying data foundation, responsible for the unified access and standardized processing of mirror traffic, device status, link status, log alarms, and scenario configuration data. It also provides basic objects and status data to the scenario modeling and topology identification module, security detection module, fault simulation and propagation analysis module, and visualization module.

[0041] The scenario modeling and topology identification module constructs a network layer-physical layer coupled scenario model based on the basic data, forming node relationships, link relationships, cross-layer relationships, vulnerable objects, and critical objects. This model is then provided to the security detection module and the fault simulation and propagation analysis module as a common scenario basis, while outputting a topology base map and statistical results to the visualization module.

[0042] Based on the coupled scenario model, the security detection module identifies abnormal traffic, intrusion behavior, device anomalies, abnormal links, and cross-layer abnormal connections, forming threat event objects. These threat event objects are then sent to the event response module, while the detection results are sent to the visualization module for display.

[0043] The fault simulation and propagation analysis module receives the scenario model, threat event objects, and system operating parameters. It analyzes the propagation path, impact range, and potential cascading failure consequences of abnormal events and sends the analysis results to the event response module and system recovery module. At the same time, it sends the propagation path and simulation results to the visualization module. This analysis process may include topology updates, power supply mapping updates, observability / controllability judgments, power flow calculations, line tripping judgments, and load loss statistics.

[0044] The event response module receives the threat event object and the propagation impact results, combines policy knowledge and scenario attributes to generate handling suggestions and protection strategies, and sends the strategy actions to the system recovery module for execution, while feeding back the strategy status to the visualization module.

[0045] The system recovery module executes corresponding actions based on the handling recommendations, verifies the execution results and business impact, and triggers recovery, rollback, or secondary optimization when necessary. Its execution and recovery results are sent back to the security detection module, fault simulation and propagation analysis module, and visualization module, thus forming a closed loop of system operation.

[0046] This creates a closed-loop collaborative mechanism encompassing data access, scenario modeling, anomaly detection, fault simulation, event response, system recovery, and result display. The key to this closed-loop mechanism lies not in a simple combination of page functions, but in integrating detection, analysis, decision-making, execution, and recovery into a single system architecture through a unified data foundation and scenario model, enabling each module to operate collaboratively around the goal of system-level security protection.

[0047] In one embodiment of this application, based on the above-described system, the present invention provides a network security intelligent protection method for novel power cyber-physical systems, such as... Figure 3 As shown, it includes the following steps: S1: Access switch mirror traffic, device status, link status, service operation information, log alarm information and scenario configuration data through the data acquisition and management module, and perform standardized processing.

[0048] S2: By combining scene modeling and topology identification modules with automatically collected data, manually designed data, or predefined scene templates, a network layer-physical layer coupled scene model is constructed.

[0049] S3: The security detection module detects abnormal traffic, intrusion behavior, device abnormalities, abnormal links, and cross-layer abnormal connections based on the scenario model, and generates threat event results.

[0050] S4: Analyze the propagation path, impact range, and potential cascading failure consequences of threat events through the fault simulation and propagation analysis module.

[0051] S5: The event response module generates corresponding protection recommendations and handling strategies based on the results of threat events and propagation analysis.

[0052] S6: Execute corresponding handling actions through the system recovery module, and verify the execution effect, business impact and performance indicators. Perform recovery, rollback or secondary optimization when necessary.

[0053] S7: The visualization module provides a unified display of scene topology, detection results, propagation path, response status, recovery status, and performance indicators, thus completing closed-loop protection of the system.

[0054] In a preferred embodiment, the system can detect no fewer than 5 types of network attack threats, with a detection accuracy of no less than 95%, a false alarm rate of no more than 5%, and a network security protection accuracy of no less than 99%; and supports demonstration applications in at least 1 dispatch master station and 2 plant stations.

[0055] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0056] In one embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 4As shown, the computer device includes a processor, memory, communication interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a network security intelligent protection method for a new type of power information physical system. The display screen can be an LCD screen or an e-ink screen. The input devices can be a touch layer covering the display screen, buttons, a trackball, or a touchpad on the computer device casing, or an external keyboard, touchpad, or mouse.

[0057] Those skilled in the art will understand that Figure 4 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0058] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.

[0059] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.

[0060] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0061] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A network security protection system for a new type of power cyber-physical system, characterized in that, It includes modules for data acquisition and management, scene modeling and topology identification, security detection, fault simulation and propagation analysis, event response, system recovery, and visualization. The data acquisition and management module uniformly accesses multi-source heterogeneous operational data and completes standardized processing, outputting standardized data objects; The scene modeling and topology identification module constructs a coupled scene model of the network layer and physical layer based on standardized data objects, and outputs topology data and key object data. The security detection module identifies system anomalies and threats based on a coupled scenario model and generates threat event objects; The fault simulation and propagation analysis module conducts fault consequence analysis and potential risk prediction simulation based on coupled scenario models and threat event objects; The incident response module generates protection and handling strategies based on threat event objects and simulation results; The system recovery module executes protection and handling strategies, completes system status verification, recovery, rollback and optimization, outputs execution results and feeds them back to the security detection module and the fault simulation and propagation analysis module; The visualization module uniformly presents the scene model, detection results, simulation results, response status, and recovery status; each module relies on a unified data foundation and a unified coupled scene model to form a closed-loop collaborative operation.

2. The network security protection system for novel power cyber-physical systems according to claim 1, characterized in that, The data acquisition and management module acquires multi-source heterogeneous operational data through mirror traffic interface, device interface, log interface, scenario configuration file interface and manual input interface. It performs protocol parsing, field extraction, time alignment, format conversion and object encapsulation on the acquired data to form standardized data objects.

3. The network security protection system for novel power cyber-physical systems according to claim 1, characterized in that, The scene modeling and topology identification module includes a scene topology management submodule and a scene topology editing and design submodule. The scene topology management submodule performs full lifecycle management of the scene model, while the scene topology editing and design submodule constructs network layer topology, physical layer topology, and cross-layer connections to form a coupled scene model and object relationship structure.

4. The network security protection system for novel power cyber-physical systems according to claim 1, characterized in that, The threat event object generated by the security detection module includes event type, event time, attacker information, affected object information, risk level, scenario attribution information, and processing status.

5. The network security protection system for novel power cyber-physical systems according to claim 1, characterized in that, The fault simulation and propagation analysis module performs fault consequence analysis on detected threat events, and conducts predictive simulations of potential risks by combining attack strategies, key link locations and system operating conditions, and outputs fault propagation paths, impact ranges, chain failure processes, key link analysis results and predictive risk data.

6. The network security protection system for novel power cyber-physical systems according to claim 1, characterized in that, The protection and handling strategy generated by the event response module includes handling suggestions and action requests.

7. The network security protection system for novel power cyber-physical systems according to claim 1, characterized in that, The system recovery module supports both automatic execution mode and manual confirmation execution mode.

8. A network security intelligent protection method for novel power cyber-physical systems, characterized in that, The method includes: Unified access to multi-source heterogeneous runtime data and execution of protocol parsing, field extraction, time alignment, format conversion and object encapsulation to form standardized data objects; Construct a scenario model that couples the network layer and the physical layer based on standardized data objects; Based on the coupled scenario model, system anomalies and threats are identified and threat event objects containing specified fields are generated; Based on the coupled scenario model and threat event objects, conduct failure consequence analysis and potential risk prediction simulation, and generate protection and response strategies based on the simulation results; The system executes protection and handling strategies and completes system status verification, recovery, rollback and optimization. The execution results are fed back to the anomaly identification and fault simulation stages, and the scenario model, detection results, simulation results, handling status and recovery status are presented simultaneously to form a closed-loop protection.