Power industry control threat response method based on industry protocol analysis and multi-source fusion

By collecting and synchronizing multi-source heterogeneous data in the power industrial control system, constructing a cross-layer consistent association structure, and analyzing and dynamically updating the model in real time, the problem of insufficient adaptability to new attacks and insufficient multi-source data fusion in existing technologies is solved. This achieves efficient threat identification and location, and improves the security and response efficiency of the power industrial control system.

CN122420409APending Publication Date: 2026-07-17GUANGZHOU ELECTRIC POWER COMM NETWORK LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
GUANGZHOU ELECTRIC POWER COMM NETWORK LTD
Filing Date
2026-04-09
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

The existing security protection system of power industrial control system has limited adaptability to new or cross-protocol attack methods, and the integration degree of multi-source data fusion and collaborative analysis is low, resulting in low accuracy in identifying complex threats and potential attack chains. In addition, it is prone to performance bottlenecks or high false alarm rates in large-scale power industrial control scenarios.

Method used

By collecting multi-source heterogeneous data from the network layer, host layer, and physical layer, performing time synchronization and preprocessing, constructing a cross-layer consistent association structure, analyzing data consistency in real time, and combining distributed collaborative analysis, dynamically updating the normal behavior model, and identifying and locating threat propagation paths.

Benefits of technology

It enables accurate identification of complex threats, improves the accuracy and interpretability of threat location, reduces network bandwidth consumption and the computing pressure on the central platform, and enhances the system's deployment flexibility and response efficiency in large-scale power environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122420409A_ABST
    Figure CN122420409A_ABST
Patent Text Reader

Abstract

本发明提供基于工控协议解析与多源融合的电力工控威胁应对方法,该方法包括:采集电力工控网络层、主机层及物理层的多源异构数据,经预处理与时间同步得到时间对齐的数据集;提取业务流程场景下的网络通信行为特征,构建对应的正常行为模型;基于设备标识、业务对象标识及场景标识,构建跨网络层、主机层与物理层的一致性关联结构;通过时间窗口分析跨层数据一致性,检测失配事件;分析失配事件在各层的关联表现,定位威胁传播路径并生成威胁评估结果;根据运行环境差异,在数据源侧执行行为匹配与失配筛查,将异常信息上传至分析平台进行分布式协同分析。该方法能够提升威胁检测的全面性与准确性,有效识别隐蔽攻击,增强威胁定位的精确度。
Need to check novelty before this filing date? Find Prior Art