A network security resource scheduling method and device suitable for a power system
By acquiring real-time voltage and current variation characteristics from multi-source heterogeneous data streams of the power system, processing the feature data using a time series analysis model, and combining it with a task priority model, the problem of network security protection task delay in traditional power systems is solved, and reasonable task scheduling is achieved, ensuring the stable operation of the power system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING UNIV OF TECH
- Filing Date
- 2026-05-23
- Publication Date
- 2026-07-31
AI Technical Summary
In traditional power systems, network security protection tasks are delayed due to insufficient resources, leading to the spread of security incidents. Existing resource scheduling logic fails to effectively balance efficiency and security.
By acquiring real-time variation characteristics of voltage and current from multi-source heterogeneous data streams of the power system, a time series analysis model is used to process the characteristic data, identify abnormal events, and combine it with a task priority model to determine the priority of network security protection and data processing tasks, thereby achieving reasonable resource scheduling.
It enables the rational scheduling of network security and data processing tasks in the power system, balancing efficiency and security, and ensuring the stable operation of the power system.
Smart Images

Figure CN122496282A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of new power system technology, and in particular to a network security resource scheduling method and apparatus applicable to power systems. Background Technology
[0002] The new power system is a next-generation power system upgraded from the traditional power system to adapt to the global energy transition and the "dual carbon" (carbon peaking and carbon neutrality) goals. It is based on a high proportion of renewable energy, supported by a high proportion of power electronic equipment, and integrates digital technology and new business models to achieve clean, intelligent, and flexible operation of the entire power supply chain from production to transmission, distribution, consumption, and storage.
[0003] Currently, traditional resource scheduling often fails to treat data processing tasks (such as metering and statistics) and network security protection tasks equally, relying on a single logic of "efficiency first." However, in power systems, delays in security protection (such as attack detection and anomaly blocking) can directly lead to the spread of security incidents. For example, if data processing tasks occupy high-performance nodes while network security protection tasks are delayed due to insufficient resources, the critical window for attack blocking may be missed. This can also be described as a lag in security protection caused by ambiguous task priorities. Therefore, to ensure the stable operation of power systems, a network security resource scheduling method suitable for power systems is urgently needed, which is a technical problem that needs to be solved. Summary of the Invention
[0004] This application provides a network security resource scheduling method and apparatus applicable to power systems. Its main purpose is to solve the security risks caused by the single task execution logic of "efficiency first". This application focuses on network security resource scheduling of power systems. Through the closed-loop logic of "data acquisition - trend analysis - priority judgment - resource allocation", it realizes the reasonable scheduling of network security tasks and data processing tasks based on the real-time status of the power system, taking into account both the efficiency and security of task execution in the power system, and ensuring the stable operation of the power system.
[0005] To achieve the above objectives, this application mainly provides the following technical solutions:
[0006] The first aspect of this application provides a network security resource scheduling method applicable to power systems, which is used for data processing tasks and network security protection tasks. The method includes:
[0007] Real-time variation characteristics of voltage and current are obtained from multi-source heterogeneous data streams of the power system to generate a feature dataset, which includes at least amplitude and frequency.
[0008] The feature dataset is processed using a time series analysis model to obtain trend index data for voltage and current, which includes at least the amplitude change rate and frequency offset.
[0009] Based on the trend indicator data, it is determined whether an abnormal event has occurred in the power system, and the corresponding response measures for the abnormal event are network security protection tasks.
[0010] If so, then based on the trend indicator data and combined with the pre-built task priority model, the priorities corresponding to the network security protection task and the data processing task are determined, and a task priority ranking is generated. The task priority model defines key dimensions corresponding to the assessment of the urgency of the task, including at least: system risk correlation, time sensitivity, and severity of consequences.
[0011] According to the task priority, the network security protection task and the data processing task are scheduled to different service nodes for task processing.
[0012] A second aspect of this application provides a network security resource scheduling device suitable for power systems, applied to data processing tasks and network security protection tasks. The device includes:
[0013] The acquisition unit is used to acquire real-time variation characteristics of voltage and current from multi-source heterogeneous data streams of the power system and generate a feature dataset, wherein the feature dataset includes at least amplitude and frequency.
[0014] The processing unit is used to process the feature dataset using a time series analysis model to obtain trend index data of voltage and current, wherein the trend index data includes at least the amplitude change rate and frequency offset.
[0015] The judgment unit is used to determine whether an abnormal event has occurred in the power system based on the trend indicator data, and the corresponding response measures for the abnormal event are network security protection tasks.
[0016] The determining unit is used to determine the priority of the network security protection task and the data processing task based on the trend indicator data and the pre-built task priority model when an abnormal event is determined to occur in the power system, and to generate a task priority ranking. The task priority model defines key dimensions for evaluating the urgency of the task, including at least: system risk correlation, time sensitivity, and severity of consequences.
[0017] The scheduling unit is used to sort the network security protection task and the data processing task according to the task priority and schedule them to different service nodes for task processing.
[0018] A third aspect of this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the network security resource scheduling method for power systems as described above.
[0019] A fourth aspect of this application provides an electronic device, the device including at least one processor, and at least one memory and bus connected to the processor;
[0020] The processor and the memory communicate with each other via the bus.
[0021] The processor is used to call program instructions in the memory to execute the network security resource scheduling method applicable to power systems as described above.
[0022] By employing the above-described technical solution, the technical solution provided in this application has at least the following advantages:
[0023] This application provides a network security resource scheduling method and apparatus applicable to power systems. This application obtains real-time variation characteristics of voltage and current from multi-source heterogeneous data streams of the power system, resulting in a feature dataset including at least amplitude and frequency. A time series analysis model is used to process the feature dataset to obtain trend index data for voltage and current. Then, based on the trend index data, the application further determines whether an abnormal event has occurred in the power system by quantifying whether the trend conforms to the physical laws of the power system. If so, corresponding network security protection tasks requiring countermeasures are assigned. Finally, this application embodiment prioritizes network security protection tasks and data processing tasks based on the trend index data and a pre-built task priority model, enabling task scheduling operations based on task priority to ensure that high-priority tasks are executed efficiently.
[0024] Compared to existing technologies, this application addresses the security risks caused by a single "efficiency-first" task execution logic. It focuses on network security resource scheduling in power systems and achieves reasonable scheduling of network security tasks and data processing tasks based on the power system through a closed-loop logic of "data acquisition - trend analysis - priority judgment - resource allocation". This balances the efficiency and security of task execution in the power system and ensures the stable operation of the power system.
[0025] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description
[0026] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the scope of this application. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings:
[0027] Figure 1 A flowchart of a network security resource scheduling method applicable to power systems is provided as an embodiment of this application;
[0028] Figure 2 A block diagram illustrating the composition of a network security resource scheduling device suitable for power systems, provided in this application embodiment;
[0029] Figure 3 This is a block diagram of another network security resource scheduling device for power systems provided in an embodiment of this application. Detailed Implementation
[0030] Exemplary embodiments of the present application will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present application are shown in the drawings, it should be understood that the present application may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this application will be thorough and complete, and will fully convey the scope of the present application to those skilled in the art.
[0031] The core objective of a power system is "stable power supply." During daily operation, a significant amount of resources is allocated to data processing tasks (such as real-time metering, load forecasting, and equipment status monitoring), which directly impact power supply efficiency and economy. Meanwhile, network security tasks (such as attack detection, anomaly blocking, and data encryption) are often considered "auxiliary work" and are easily squeezed out when resources are scarce. For example, when a high-performance computing node receives both "load forecasting data processing" and "abnormal traffic detection" tasks simultaneously, traditional scheduling models may prioritize allocating resources to the former because "load forecasting has a more direct impact on power supply scheduling," leading to delays in security tasks.
[0032] The inventors discovered that the inherent contradiction between "safety and efficiency" in the current power system is that safety tasks are easily "marginalized." This implicit logic of "efficiency first" can lead to a lag in security protection. For example, if security tasks cannot be started in time due to insufficient resources when an attack occurs, the "golden window" for blocking the attack may be missed.
[0033] To this end, the inventors, through research, found that if the single logic of "efficiency first" is broken, when security tasks compete with other tasks for resources, the resource acquisition of security tasks can be forcibly guaranteed through clear priority definitions, thereby fundamentally avoiding the risk of "security giving way to efficiency".
[0034] Based on the above considerations, this application provides a network security resource scheduling method suitable for power systems, applied to data processing tasks and network security tasks. In this application embodiment, data processing tasks refer to those directly related to power supply efficiency and economy, while network security protection tasks refer to tasks taken to respond to abnormal events, such as... Figure 1 As shown, the following specific steps are provided in this embodiment of the invention:
[0035] 101. Obtain real-time variation characteristics of voltage and current from multi-source heterogeneous data streams of the power system, and generate a feature dataset, which includes at least amplitude and frequency.
[0036] In this embodiment of the application, the core electrical characteristics (amplitude and frequency) of voltage and current are extracted from the "multi-source heterogeneous data stream" of the power system (such as data from different sources and formats, such as substation sensors, communication networks, and monitoring equipment) to generate a feature dataset.
[0037] This step provides "raw material data" for subsequent analysis and focuses on the most critical electrical quantities (voltage and current) in the power system to ensure that the data is strongly correlated with the system's operating status.
[0038] 102. Use a time series analysis model to process the feature dataset to obtain trend index data of voltage and current. The trend index data should include at least the amplitude change rate and frequency offset.
[0039] The time series analysis model includes, but is not limited to, models suitable for processing time series data, such as ARIMA and LSTM.
[0040] This step involves using a time series analysis model to calculate trend indicators (amplitude change rate, frequency offset), transforming instantaneous, discrete characteristic data into "trend information" (such as whether the voltage amplitude is rising rapidly or whether the frequency is deviating from the rated value), providing a basis for judging whether the system is abnormal (or under attack).
[0041] 103. Based on trend indicator data, determine whether an abnormal event has occurred in the power system, and the corresponding response measures for the abnormal event are network security protection tasks.
[0042] In power systems, abnormal states (such as equipment failures) or network attacks (such as fake data injection and malicious manipulation) are often manifested through trend changes in the amplitude and frequency of voltage and current. This step provides a quantitative basis for judging whether the system is abnormal or under attack (this step is collectively referred to as "abnormal events") by capturing these "unnatural trend characteristics". The following explanation uses "abnormal increase in voltage amplitude" as an example.
[0043] Scenario Example 1: Abnormally high voltage amplitude (possibly due to malicious manipulation or equipment failure).
[0044] Normal state: In a power system, the voltage amplitude is usually stable within ±5% of the rated value (e.g., the normal voltage of a 10kV line is 9.5-10.5kV), and the amplitude change rate is slow (e.g., the change rate due to load fluctuations is ≤0.5% / second).
[0045] Abnormal / Attack Scenario: If an attacker manipulates reactive power compensation equipment through network intrusion (such as maliciously switching capacitors), it may cause the voltage amplitude to rise rapidly.
[0046] This step involves trend analysis using trend indicator data, and includes the following examples:
[0047] The feature dataset (e.g., 101) will collect real-time data on voltage amplitude: for example, 10kV in the first second, 10.3kV in the second second, 10.7kV in the third second, and 11.2kV in the fourth second (12% exceeding the rated value of 10kV).
[0048] Time series analysis models (such as LSTM) calculate the rate of change of amplitude: the rate of change in the first 1-2 seconds is 3% / second ((10.3-10) / 10÷1=3%), the rate of change in the second-3 seconds is 3.9% / second, and the rate of change in the third-4 seconds is 4.7% / second, showing an "accelerated upward" trend.
[0049] Trend indicator conclusion: The rate of change of amplitude has been continuously exceeding the normal threshold (0.5% / second) and is showing an increasing trend, which is an "unnatural rapid rise".
[0050] Judgment basis: This trend does not conform to the smooth characteristics of normal load fluctuations, and is more likely to be caused by malicious manipulation (attack) or equipment failure (such as abnormal voltage rise of transformer). The trend indicator provides quantitative evidence for this judgment (the rate of change exceeds the threshold and accelerates).
[0051] Additionally, as in scenario example 2, a rapid frequency shift (possibly due to a load attack or malicious interference with the generator) is judged based on the following: This trend is more likely a system imbalance caused by a network attack (such as maliciously sending load commands or interfering with generator control signals) rather than a natural load change, and network security protection tasks (such as attack tracing and command verification) need to be triggered.
[0052] This step actually involves quantifying whether the trend conforms to the physical laws of the power system (such as whether the rate of change exceeds the threshold, whether the deviation is within a reasonable range, and whether the trend is continuous and smooth), providing a "calculable and comparable" basis for subsequent anomaly judgment, thereby determining whether an abnormal event has occurred in the power system.
[0053] For example, if the trend indicator is within the normal threshold (slow rate of change, small deviation), it is more likely to be a natural fluctuation, and resources should be prioritized for data processing tasks (such as load forecasting).
[0054] If the trend indicator exceeds the threshold (rapid change, large deviation, unnatural jump), it indicates that there may be an anomaly or attack. The priority of network security protection tasks should be increased through the task priority model of S103, and the system security should be ensured through resource scheduling (S104-S105).
[0055] This transformation from "instantaneous characteristics" to "trend indicators" essentially converts "discrete data" into "interpretable deviations in physical laws," enabling cybersecurity protection to respond more accurately to real threats.
[0056] 104. If an abnormal event is determined to have occurred in the power system, the priorities of network security protection tasks and data processing tasks are determined based on trend indicator data and a pre-built task priority model, and a task priority ranking is generated.
[0057] In the embodiments of this application, data processing tasks refer to tasks that are directly related to power supply efficiency and economy, and are tasks that support system operation but are not related to real-time safety, such as historical data archiving (e.g., long-term storage of voltage and current curves), non-real-time data analysis (e.g., load forecasting, offline assessment of equipment health), log statistics (e.g., periodic summarization of communication traffic), etc.
[0058] However, network security protection tasks refer to the tasks taken to respond to abnormal events, which are directly related to the security of the power system. Examples include: real-time attack detection (such as detecting intrusions and malicious code injections targeting SCADA systems); vulnerability emergency repair (such as deploying patches for communication protocol vulnerabilities); data encryption and integrity verification (such as preventing telemetry data from being tampered with), etc.
[0059] In this step, the task priority model is an assessment framework that defines the urgency of tasks. It is a set of predefined rules or algorithms used to evaluate the urgency of "network security protection tasks" and "data processing tasks" and output a priority ranking. Its core function is to transform the "real-time status trend of the power system" into "task execution priority," ensuring that resources are allocated to more critical tasks.
[0060] For example, the model needs to define key dimensions for assessing the urgency of the task (which are strongly correlated with the characteristics of the power system), including at least the following:
[0061] (1) System risk correlation: Whether the failure of the task will directly lead to system risk (e.g., the failure of attack detection may cause a power outage, which has a high priority; the failure of data archiving only affects subsequent analysis, which has a low priority); (2) Time sensitivity: Whether the task has a strict execution time limit (e.g., the attack detection when the frequency is abnormal requires a millisecond-level response, which has a high priority; the historical data processing can be delayed, which has a low priority); (3) Severity of consequences: The consequences of the task not being executed in time (e.g., the failure of the protection task may cause equipment damage and a large-scale power outage; the failure of the data processing task may only affect the statistical accuracy).
[0062] This step involves model processing, which outputs a priority ranking of tasks, clearly defining the priority of "network security protection tasks" and "data processing tasks" (e.g., "protection tasks > processing tasks" or "processing tasks > protection tasks").
[0063] However, it's important to clarify that, for example, if 103 refers to "trend indicator data to determine whether an abnormal event has occurred in the power system," since trend indicator data includes at least the current trend and the future trend, determining whether an abnormal event has occurred in the power system can include current events or predicted future events. Therefore, if 103 identifies one or more abnormal events, then based on such abnormal events, there can be one or more cybersecurity protection tasks requiring corresponding measures. Thus, the task priority ranking obtained in 104 can include "multiple cybersecurity protection tasks and multiple data processing tasks," not just "one cybersecurity protection task and one data processing task." Furthermore, even if there are multiple cybersecurity protection tasks and multiple data processing tasks, the generated task priority ranking may not necessarily place all "cybersecurity protection tasks" before all "data processing tasks," or vice versa. Instead, there may be a mix of these two types of tasks in terms of priority. The specific reason for the priority ranking is determined based on the evaluation results obtained from the model processing.
[0064] 105. Prioritize tasks and schedule network security protection tasks and data processing tasks to different service nodes for execution.
[0065] In this step, the "real-time status trend of the power system" is transformed into "task execution priority" according to the task priority, so as to ensure that resources are tilted towards more critical tasks. According to this embodiment, high-priority tasks can be scheduled to service nodes with high computing power or lower load according to this priority, so as to ensure that high-priority tasks are executed efficiently.
[0066] In addition to the service nodes required for data processing and network security tasks, this application embodiment can also use a "priority queue + greedy algorithm" to extract available resources from the remaining resources of high-performance nodes and allocate them to "real-time change detection tasks" (such as continuous monitoring of voltage / current anomalies) to generate a final resource allocation scheme. The purpose is to quickly utilize the remaining resources to meet the real-time monitoring needs while ensuring high-priority tasks, and to avoid resource idleness.
[0067] The present application provides a network security resource scheduling method applicable to power systems. This method obtains real-time voltage and current variation characteristics from multi-source heterogeneous data streams of the power system, resulting in a feature dataset including at least amplitude and frequency. A time series analysis model is used to process the feature dataset to obtain voltage and current trend index data. Then, based on the trend index data, the method quantifies whether the trend conforms to the physical laws of the power system to further determine whether an abnormal event has occurred in the power system. If so, corresponding network security protection tasks requiring countermeasures are assigned. Finally, based on the trend index data and using a pre-built task priority model, the network security protection tasks and data processing tasks are prioritized to ensure efficient execution of high-priority tasks.
[0068] Compared to existing technologies, this application addresses the security risks caused by a single task execution logic prioritizing efficiency. This application focuses on network security resource scheduling in power systems. Through a closed-loop logic of "data acquisition - trend analysis - priority judgment - resource allocation," it achieves reasonable scheduling of network security tasks and data processing tasks based on the real-time status of the power system, balancing the efficiency and security of task execution in the power system and ensuring the stable operation of the power system.
[0069] In some modified embodiments, the above 104 "Based on trend indicator data and combined with a pre-built task priority model, determine the priorities of network security protection tasks and data processing tasks, and generate a task priority ranking" can be further explained in detail as follows: such as A1-A6;
[0070] A1. Determine the multiple indicator dimensions included in the trend indicator data.
[0071] The trend indicator data should include at least the following dimensions: voltage / current amplitude change rate and frequency offset.
[0072] A2. Assign different weights to multiple indicator dimensions.
[0073] The weighting rules for trend indicators, such as the weight ratios set for "trend indicators" (amplitude change rate, frequency offset), are used to quantify the degree of influence of different trend indicators on "task priority". Their core function is to clarify "which power system state changes are more dangerous", thereby guiding the judgment of the task priority model.
[0074] The purpose of prioritizing weight allocation in this application embodiment is to make task priorities change with system state (such as automatically increasing security protection priority when frequency shifts rapidly), avoiding rigid scheduling caused by fixed priorities.
[0075] For example, the weight allocation provided in this application embodiment is based on the "degree of influence of trend indicators on power system security," and the weights need to be aligned with the core characteristics of the power system, such as:
[0076] Frequency offset: Power systems have extremely high requirements for frequency stability (e.g., the rated frequency of my country's power grid is 50Hz, and the allowable deviation is usually ≤±0.2Hz). Large frequency offsets may cause generators to lose synchronism, equipment overload, or even system collapse. Therefore, the weight of frequency offset is usually high.
[0077] Amplitude change rate: Rapid changes in voltage amplitude (such as sudden rises or falls) may cause damage to equipment insulation or abnormal load, but there is usually a certain buffer time (such as through voltage regulator adjustment), so the weight may be lower than the frequency offset (the specific settings need to be combined with system parameters).
[0078] After assigning weights, the weights provided in this application embodiment are typically expressed as numerical weights (e.g., frequency offset weight 0.7, amplitude change rate weight 0.3) or threshold rules (e.g., "when the frequency offset > 0.5Hz, the weight automatically increases to 0.9"). For example, if the frequency offset is 0.6Hz (far exceeding the threshold), the weight is set to 0.8; if the amplitude change rate is 0.2% / s (relatively flat), the weight is set to 0.2.
[0079] This avoids misjudgments caused by treating all trend indicators equally. For example, when the voltage amplitude change rate is small (low weight) but the frequency offset is large (high weight), the system will determine that "the current state is more dangerous" and thus tend to increase the priority of network security protection tasks.
[0080] A3. Determine the comprehensive risk index corresponding to the trend data based on the different weights corresponding to different indicator dimensions. For example, the comprehensive risk index = (frequency offset × weight 1) + (amplitude change rate × weight 2).
[0081] A4. Input the comprehensive risk index corresponding to the trend data into the task priority model for evaluation and processing to obtain the first score value corresponding to the network security protection task.
[0082] It should be noted that in this step, an anomaly has already been identified based on trend indicator data, and the response to the anomaly is a network security protection task. Since the purpose of scoring in this step is to evaluate the "urgency," the score output by the model is indirectly equivalent to the score of the network security protection task required for the "anomaly," that is, it measures the "urgency" of the need for network security protection tasks.
[0083] In the embodiments of this application, the "task priority model" and the "weight allocation rules" do not exist independently, but work together through the logic of "weighted trend indicators → task urgency score → priority ranking".
[0084] In this step, the task priority model is an assessment framework that defines the urgency of tasks. It is a set of predefined rules or algorithms used to evaluate the urgency of "network security protection tasks" and "data processing tasks" and output a priority ranking. Its core function is to transform the "real-time status trend of the power system" into "task execution priority," ensuring that resources are allocated to more critical tasks.
[0085] For example, the model needs to define key dimensions for assessing the urgency of the task (which are strongly related to the characteristics of the power system) including at least the following: (1) system risk correlation, (2) time sensitivity, and (3) severity of consequences (as explained in 104, which will not be repeated here).
[0086] A5. Obtain the second score value corresponding to the data processing task obtained by the task priority model's evaluation of the data processing task.
[0087] It should be noted that, in addition to the “abnormal events” determined by trend indicator data as in 103, there are also some data processing tasks during the normal operation of the power system. The embodiments of this application can use the same “task priority model” to score the data processing tasks, and the evaluation dimensions required in the model processing are the same as those for the processing of network security protection tasks.
[0088] Furthermore, in this step, A4 and A5 can be executed in parallel, meaning that within a very small time error range, in order to ensure that the model outputs scores for network security protection tasks and data processing tasks under the same power system operating conditions, the model outputs scores for network security protection tasks and data processing tasks.
[0089] A6. By comparing the first score and the second score, sort them from high to low to obtain the priorities of network security protection tasks and data processing tasks, and generate task priority sorting.
[0090] For example, the data processing execution logic provided in the "task priority model" in this step includes the following:
[0091] Input the "Comprehensive Risk Index" into the "Task Priority Model". The model combines its own predefined evaluation dimensions (system risk correlation, time sensitivity, and severity of consequences) to give an "urgency score" to the two types of tasks.
[0092] If the overall risk index is high (e.g., large frequency offset) → the model determines that "the network security protection task is highly correlated with system risk and is highly time-sensitive" → security task score (90 points) > data processing task score (40 points); if the overall risk index is low (e.g., amplitude and frequency are stable) → the model determines that "the data processing task can be executed normally, and the security task is not urgent" → data processing task score (60 points) > security task score (30 points).
[0093] In this embodiment of the application, the task priority ranking is obtained by sorting the network security protection task and data processing task according to the score output of the model from high to low.
[0094] In this embodiment, the collaboration between the "task priority model" and the "weight allocation rule" constructs a precise mapping between "power system state → task priority," serving as the "decision center" of the entire resource scheduling scheme. Its core value lies in: by quantifying the real-time risks of the power system, it shifts resource scheduling from "experience-driven" to "data-driven," ensuring that the allocation of network security resources is highly matched with the actual security needs of the system.
[0095] In some modified embodiments, this application embodiment also monitors the magnitude of numerical change on each indicator dimension. If the magnitude of numerical change reaches a preset threshold, the different weights assigned to multiple indicator dimensions are updated. Furthermore, a time period can be set for "monitoring" to provide a dynamic weight adjustment mechanism.
[0096] In this application embodiment, the most critical safety indicators of the power system (such as frequency stability) are given higher priority through weight allocation rules to ensure that "the most dangerous state triggers the most urgent protection task". Moreover, "dynamic weight" is used instead of "static weight". For example, the trend indicators change in real time with the system state (such as the frequency offset increasing from 0.1Hz to 0.6Hz), and the weight allocation rules are changed, so that the task priority model can dynamically adjust the score, avoiding the rigid scheduling caused by "fixed priority" (such as not occupying too many resources when the system is stable, and quickly tilting resources when abnormal).
[0097] In some modified embodiments, for the above 105 "Scheduling network security protection tasks and data processing tasks to different service nodes for task processing according to task priority", two parallel schemes are further provided, and the specific explanations are as follows:
[0098] One scheduling scheme is as follows: determine the load status information and computing power of each service node in the power system; based on the load status information and computing power of each service node, comprehensively evaluate and rank each service node to obtain a queue of usable service nodes, and sort the usable service nodes in the queue according to the evaluation value from high to low; establish a correspondence between each task and service node based on the task priority and the queue of usable service nodes; and schedule different tasks to the corresponding service nodes for task processing according to the correspondence.
[0099] The embodiments of this application can quantify "computing power" in the form of a score, such as defining a "computing power score" (e.g., 1-10 points) for each service node. For example, high-performance nodes (CPU≥3GHz, memory≥16GB) get 8-10 points; ordinary nodes (CPU 2-3GHz, memory 8-16GB) get 4-7 points; and edge nodes (CPU≤2GHz, memory≤8GB) get 1-3 points.
[0100] Furthermore, the "load status" can be quantified in the form of a score, such as calculating a "load score" (e.g., 1-10 points) based on the node's current CPU utilization, memory utilization, and bandwidth utilization. The lower the load, the higher the score (e.g., 8-10 points for load rate ≤30%, 4-7 points for 30%-70%, and 1-3 points for ≥70%).
[0101] Therefore, the weights of "load status" and "computing power" are combined and assigned to the two dimensions (which can be dynamically adjusted). For example, the comprehensive score of a service node = computing power score × α + load status score × (1-α), where α is the weight coefficient (0<α<1). If the system focuses more on task processing efficiency, α can be set to 0.6-0.7; if it focuses more on avoiding node overload, α can be set to 0.3-0.4.
[0102] Accordingly, this application embodiment comprehensively evaluates service nodes based on the dimensions of "high computing power" and "service node load status". For example, service nodes are sorted from high to low according to the comprehensive score to form the final "queue of usable service nodes". In the queue of usable service nodes, they are sorted from high to low according to the evaluation value.
[0103] Based on task priority and the available service node queue, a correspondence is established between each task and the service node. That is, high-priority, high-computation tasks need to be matched with nodes with high comprehensive scores (i.e., "strong computing power + low current load") to ensure that the tasks are completed in a short time. Based on this correspondence, different tasks are scheduled to the corresponding service nodes for task processing.
[0104] Another scheduling scheme is as follows: sort tasks by priority and execute the operation of scheduling and assigning each task to a service node one by one; during the process of scheduling and assigning each task to a service node one by one, a greedy algorithm is used to evaluate the remaining service nodes to select the optimal target service node each time a task is scheduled to the corresponding service node, so as to schedule the next task to the target service node for task processing, until the last task in the task priority sorting is scheduled.
[0105] In this scheduling scheme, instead of first constructing a "queue of available service nodes" as in the previous scheme, it dynamically sorts tasks by priority. After scheduling a high-priority task, it evaluates the optimal target service node from the remaining service nodes to execute the next priority task. Since each service node may have existing tasks being executed, the load status and remaining computing power of those unassigned service nodes change over time (even within a very short timeframe) as tasks are scheduled to different service nodes according to priority. Therefore, in this scheme, after each task is scheduled, a greedy algorithm is used to re-optimize (i.e., evaluate the optimal target service node from the remaining service nodes) to take on the next task, realizing the dynamic scheduling of tasks, achieving on-demand allocation of resources, and improving overall utilization.
[0106] The embodiments of this application, which combine "prioritizing critical tasks", "improving scheduling efficiency with a greedy algorithm", and "dynamically adapting to node states", can not only meet the requirements of real-time performance and security for critical scenarios such as power systems, but also optimize resource utilization through simple and efficient logic, avoiding the computational burden caused by complex algorithms, and have strong practicality and feasibility.
[0107] Furthermore, as a response to the above Figure 1 The implementation of the method shown in this application provides a network security resource scheduling device suitable for power systems. This device embodiment corresponds to the aforementioned method embodiment. For ease of reading, this device embodiment will not repeat the details of the aforementioned method embodiment, but it should be understood that the device in this embodiment can implement all the contents of the aforementioned method embodiment. This device is used to achieve reasonable scheduling of network security tasks and data processing tasks based on the real-time status of the power system, specifically as follows... Figure 2 As shown, the device includes:
[0108] The acquisition unit 21 is used to acquire real-time variation characteristics of voltage and current from the multi-source heterogeneous data stream of the power system and generate a feature dataset, wherein the feature dataset includes at least amplitude and frequency.
[0109] Processing unit 22 is used to process the feature dataset using a time series analysis model to obtain trend index data of voltage and current, wherein the trend index data includes at least the amplitude change rate and frequency offset.
[0110] The judgment unit 23 is used to determine whether an abnormal event has occurred in the power system based on the trend indicator data, and the corresponding response measures for the abnormal event are network security protection tasks.
[0111] The determining unit 24 is used to determine the priority of the network security protection task and the data processing task based on the trend indicator data and the pre-built task priority model when an abnormal event is determined to occur in the power system, and to generate a task priority ranking. The task priority model defines key dimensions corresponding to the assessment of the urgency of the task, including at least: system risk correlation, time sensitivity and consequence severity.
[0112] The scheduling unit 25 is used to sort the network security protection task and the data processing task according to the task priority and schedule them to different service nodes for task processing.
[0113] Furthermore, such as Figure 3 As shown, the determining unit package 24 includes:
[0114] The first determining module 241 is used to determine multiple indicator dimensions contained in the trend indicator data;
[0115] The allocation module 242 is used to allocate different weights to the multiple indicator dimensions;
[0116] The second determining module 243 is used to determine the comprehensive risk index corresponding to the trend data based on the different weights corresponding to different indicator dimensions.
[0117] Processing module 244 is used to input the comprehensive risk index corresponding to the trend data into the task priority model for evaluation and processing, and obtain the first score value corresponding to the network security protection task.
[0118] The processing module 244 is further configured to obtain the second score value corresponding to the data processing task obtained by the evaluation processing performed by the task priority model on the data processing task.
[0119] The generation module 245 is used to compare the first score value and the second score value, sort them from high to low, and obtain the priority of the network security protection task and the data processing task, so as to generate the task priority sort.
[0120] Furthermore, such as Figure 3 As shown, the determining unit 24 further includes:
[0121] Monitoring module 246 is used to monitor the magnitude of numerical change in each of the indicator dimensions;
[0122] The update module 247 is used to update the different weights assigned to the multiple indicator dimensions if the magnitude of the change in the value reaches a preset threshold.
[0123] Furthermore, in some modified embodiments, the scheduling unit 25 is specifically used for:
[0124] Determine the load status information and computing capabilities of each service node in the power system;
[0125] Based on the load status information and computing power of each service node, the service nodes are comprehensively evaluated and sorted to obtain a queue of usable service nodes. The usable service nodes are then sorted from high to low according to their evaluation value.
[0126] Based on the task priority sorting and the available service node queue, establish the correspondence between each task and the service node;
[0127] Based on the aforementioned correspondence, different tasks are scheduled to the corresponding service nodes for task processing.
[0128] Furthermore, in some modified embodiments, the scheduling unit 25 is also specifically used for:
[0129] According to the task priority sorting, the operation of scheduling and assigning each task to a service node is executed one by one; during the process of scheduling and assigning each task to a service node one by one, when scheduling a task to the corresponding service node, a greedy algorithm is used to evaluate the remaining service nodes to select the optimal target service node, so as to schedule the next task to the target service node for task processing, until the last task in the task priority sorting is scheduled.
[0130] As described above, the network security resource scheduling device for power systems includes a processor and a memory. The aforementioned acquisition unit, processing unit, judgment unit, determination unit, and scheduling unit are all stored as program units in the memory, and the processor executes the aforementioned program units stored in the memory to achieve the corresponding functions.
[0131] The processor contains a kernel, which retrieves the corresponding program units from memory. One or more kernels can be configured, and by adjusting kernel parameters, the security risks caused by a single "efficiency-first" task execution logic are addressed. This application focuses on network security resource scheduling in power systems. Through a closed-loop logic of "data acquisition - trend analysis - priority judgment - resource allocation," it achieves reasonable scheduling of network security tasks and data processing tasks based on the real-time status of the power system, balancing the efficiency and security of task execution in the power system and ensuring its stable operation.
[0132] This application provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the network security resource scheduling method for power systems as described above.
[0133] This application provides an electronic device, which includes at least one processor, at least one memory and a bus connected to the processor; wherein the processor and the memory communicate with each other through the bus; the processor is used to call program instructions in the memory to execute the network security resource scheduling method for power systems as described above.
[0134] This application also provides a computer program product that, when executed on a data processing device, is adapted to perform the initialization steps of a network security resource scheduling method applicable to a power system.
[0135] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0136] In a typical configuration, the device includes one or more processors (CPUs), memory, and a bus. The device may also include input / output interfaces, network interfaces, etc.
[0137] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and memory includes at least one memory chip. Memory is an example of computer-readable media.
[0138] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0139] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0140] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0141] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A cyber-security resource scheduling method for power systems, characterized in that, The method, applicable to data processing tasks and network security protection tasks, includes: Real-time variation characteristics of voltage and current are obtained from multi-source heterogeneous data streams of the power system to generate a feature dataset, which includes at least amplitude and frequency. The feature dataset is processed using a time series analysis model to obtain trend index data for voltage and current, which includes at least the amplitude change rate and frequency offset. Based on the trend indicator data, it is determined whether an abnormal event has occurred in the power system, and the corresponding response measures for the abnormal event are network security protection tasks. If so, then based on the trend indicator data and combined with the pre-built task priority model, the priorities corresponding to the network security protection task and the data processing task are determined, and a task priority ranking is generated. The task priority model defines key dimensions corresponding to the assessment of the urgency of the task, including at least: system risk correlation, time sensitivity, and severity of consequences. According to the task priority, the network security protection task and the data processing task are scheduled to different service nodes for task processing.
2. The method of claim 1, wherein, The step of determining the priorities of the network security protection task and the data processing task based on the trend indicator data and in conjunction with a pre-built task priority model, and generating a task priority ranking, includes: Determine the multiple indicator dimensions contained in the trend indicator data; Different weights are assigned to the aforementioned multiple indicator dimensions; The comprehensive risk index corresponding to the trend data is determined based on the different weights corresponding to different indicator dimensions. The comprehensive risk index corresponding to the trend data is input into the task priority model for evaluation and processing to obtain the first score value corresponding to the network security protection task. The second score value corresponding to the data processing task is obtained by the evaluation processing of the data processing task by the task priority model. By comparing the first score and the second score, and sorting them from high to low, the priorities corresponding to the network security protection task and the data processing task are obtained, thereby generating a task priority ranking.
3. The method according to claim 2, characterized in that, The method further includes: Monitor the magnitude of numerical changes across each of the aforementioned indicator dimensions; If the magnitude of the numerical change reaches a preset threshold, then the different weights assigned to the multiple indicator dimensions are updated.
4. The method according to any one of claims 1 to 3, characterized in that, According to the task priority, the network security protection task and the data processing task are scheduled to different service nodes for execution, including: Determine the load status information and computing capabilities of each service node in the power system; Based on the load status information and computing power of each service node, the service nodes are comprehensively evaluated and sorted to obtain a queue of usable service nodes. The usable service nodes are then sorted from high to low according to their evaluation value. Based on the task priority sorting and the available service node queue, establish the correspondence between each task and the service node; Based on the aforementioned correspondence, different tasks are scheduled to the corresponding service nodes for task processing.
5. The method according to any one of claims 1 to 3, characterized in that, The step of scheduling the network security protection task and the data processing task to different service nodes for execution according to the task priority includes: According to the task priority, each task is scheduled and assigned to a service node one by one. During the process of scheduling and assigning each task to a service node, a greedy algorithm is used to evaluate the remaining service nodes each time a task is scheduled to the corresponding service node to select the optimal target service node, so as to schedule the next task to the target service node for task processing, until the last task in the task priority ranking is scheduled.
6. A network security resource scheduling device suitable for power systems, characterized in that, The device is used for data processing tasks and network security protection tasks, and includes: The acquisition unit is used to acquire real-time variation characteristics of voltage and current from multi-source heterogeneous data streams of the power system and generate a feature dataset, wherein the feature dataset includes at least amplitude and frequency. The processing unit is used to process the feature dataset using a time series analysis model to obtain trend index data of voltage and current, wherein the trend index data includes at least the amplitude change rate and frequency offset. The judgment unit is used to determine whether an abnormal event has occurred in the power system based on the trend indicator data, and the corresponding response measures for the abnormal event are network security protection tasks. The determining unit is used to determine the priority of the network security protection task and the data processing task based on the trend indicator data and the pre-built task priority model when an abnormal event is determined to occur in the power system, and to generate a task priority ranking. The task priority model defines key dimensions for evaluating the urgency of the task, including at least: system risk correlation, time sensitivity, and severity of consequences. The scheduling unit is used to sort the network security protection task and the data processing task according to the task priority and schedule them to different service nodes for task processing.
7. The apparatus according to claim 6, characterized in that, The determining unit includes: The first determining module is used to determine multiple indicator dimensions contained in the trend indicator data; The allocation module is used to assign different weights to the multiple indicator dimensions; The second determining module is used to determine the comprehensive risk index corresponding to the trend data based on the different weights corresponding to different indicator dimensions. The processing module is used to input the comprehensive risk index corresponding to the trend data into the task priority model for evaluation and processing, and obtain the first score value corresponding to the network security protection task. The processing module is also used to obtain the second score value corresponding to the data processing task obtained by the evaluation processing of the data processing task by the task priority model. The generation module is used to compare the first score value and the second score value, sort them from high to low, and obtain the priorities corresponding to the network security protection task and the data processing task, so as to generate the task priority sorting.
8. The apparatus according to claim 7, characterized in that, The determining unit further includes: The monitoring module is used to monitor the magnitude of numerical changes in each of the aforementioned indicator dimensions; An update module is used to update the different weights assigned to the multiple indicator dimensions if the magnitude of the change in the value reaches a preset threshold.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the network security resource scheduling method for power systems as described in any one of claims 1-5.
10. An electronic device, characterized in that, The device includes at least one processor, and at least one memory and bus connected to the processor; The processor and the memory communicate with each other via the bus. The processor is used to invoke program instructions in the memory to execute the network security resource scheduling method for power systems as described in any one of claims 1-5.