Single-node security capability portrait driven multi-source alarm linkage handling method and system
Patent Information
- Application Number
- CN202611044223.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-14
- Publication Date
- 2026-09-22
AI Technical Summary
[0005]本发明的目的在于提供一种单节点安全能力画像驱动的多源告警联动处置方法及系统,旨在解决现有技术存在的“多源告警难以归一关联、节点能力差异导致策略不落地或扰动业务、缺乏合规控制项覆盖与最小开销策略选择机制、处置缺少回执校验与效果验证、以及缺乏可用于合规审计的覆盖证明与证据包存证”等问题
本发明通过对控制区各接入节点建立单节点安全能力画像,并将合规控制项集合映射为节点可覆盖控制项集合;对来自多类安全设备与系统的告警进行采集与归一化,形成统一事件模型并关联到目标节点,在此基础上计算事件等级或风险评分;在满足预设合规约束的前提下,结合节点能力约束与性能预算约束,从策略库自动选择预估开销最小的合规策略组合,生成联动处置动作集合并执行;动作执行后获取回执并进行一致性校验与效果验证,形成合规覆盖证明与证据包,对证据包进行摘要存证并输出审计记录,从而实现“告警—研判—策略选择—联动处置—验证—存证”的闭环处置与合规证明。
Smart Images

Figure CN122802239A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security and security management technology for industrial control systems, and in particular to a method and system for multi-source alarm linkage handling driven by a single-node security capability profile. Background Technology
[0002] As a core area for critical business operations, the DCS control area of thermal power plants involves key functions such as control commands, measurement point sampling, status monitoring, and operation and maintenance management. Its cybersecurity capabilities not only need to meet real-time and availability requirements but also comply with the requirements of critical information infrastructure and security assessment. In actual projects, the control area often deploys multiple types of security devices and systems simultaneously, such as boundary protection, host auditing, industrial probes, cryptographic devices, asset management, and security management platforms. These devices generate a large amount of heterogeneous alarms and event data. The operation and maintenance side needs to normalize, analyze, and classify alarms, and take coordinated measures such as rate limiting, blocking, isolation, enhanced authentication, and audit enhancement to control risks and ensure production continuity.
[0003] However, existing control area security management and joint response solutions typically have the following shortcomings: First, the inconsistent formats and semantics of multi-source alarm data make it difficult to form a unified event model and interpretable correlation analysis results, leading to false alarms, missed alarms, or insufficient timeliness of response; Second, the complex types and significant differences in capabilities of control area equipment, with different nodes having varying degrees of support for national cryptographic algorithms, certificate authentication, log retention, transmission protection, and performance overhead, means that existing solutions lack capability profile modeling for individual nodes and the expression of "what can / cannot do," easily resulting in policy deployment failures or causing business disruptions; Third, existing joint response solutions... The first problem is that the proactive handling often relies on human experience or fixed plans, lacking a mechanism for automatically selecting and optimizing strategy combinations with minimum overhead under compliance constraints. This makes it difficult to meet compliance control coverage while also considering real-time budget. The second problem is that the handling process lacks execution receipt verification and effect verification loops, which poses the risk of "issuing but not taking effect, or executing but not achieving the desired effect," easily leading to repeated handling or risk spread. The third problem is that there is a lack of "compliance coverage proof" and traceable evidence packages for compliance inspections, making it impossible to clearly prove which control items the strategy combination adopted at a specific event level covers, how gaps are compensated, and whether the handling chain is closed-loop and effective.
[0004] Therefore, there is an urgent need for a safety management method for the DCS control area of thermal power plants, which integrates the single-node safety capability profile and compliance control item mapping into the multi-source alarm linkage and handling framework, selects the minimum feasible compliance strategy combination under compliance constraints and performance budget constraints, and forms a verifiable, auditable, and traceable chain of evidence for handling. Summary of the Invention
[0005] The purpose of this invention is to provide a multi-source alarm linkage handling method and system driven by a single-node security capability profile, aiming to solve the problems existing in the prior art such as "difficulty in unifying and associating multi-source alarms, differences in node capabilities leading to policy failure or disruption to business, lack of compliance control item coverage and minimum overhead strategy selection mechanism, lack of feedback verification and effect verification in handling, and lack of coverage proof and evidence package storage that can be used for compliance auditing".
[0006] In a first aspect, the present invention provides a multi-source alarm linkage handling method driven by a single-node security capability profile, the method comprising: Collect asset information and security capability information of each access node in the DCS control area of thermal power plants to establish a security capability profile of a single node and generate a set of control items that can be covered for each node. Collect multi-source alarm data and normalize it into a unified event model. Associate the unified event model with the target node identifier. Calculate the event level or risk score based on the event type, severity and association information of the unified event model. Based on the event level or risk score, compliance constraints are determined, and based on the security capability profile of the target node and the set of coverable control items, the strategy combination that satisfies the compliance constraints and has the lowest estimated cost is selected, and a set of coordinated handling actions is generated. The set of coordinated actions is executed, and compliance coverage proof is constructed and evidence package is formed based on the execution receipt and the selected strategy combination. The compliance coverage proof and evidence package are then stored and audited.
[0007] In some embodiments, the step of collecting asset information and security capability information of each access node within the thermal power plant DCS control area to establish a single node security capability profile includes: The capability information of the collection node includes national cryptographic algorithm capability, identity authentication capability, transmission protection capability, log and audit capability, performance budget, and firmware or software trustworthiness. The collected capability information is aggregated into a single-node security capability profile, and a set of control items that the node can cover is generated based on the node's security capability profile. The control items include at least one or more of the following: identity authentication, access control, transmission protection, security audit, intrusion prevention, or security management. When a version change, capability change, frequent anomalies, or policy change is detected, the security capability profile is updated.
[0008] In some embodiments, the step of calculating the event level or risk score based on the event type, severity, and correlation information of the unified event model includes: Collect alarm data from at least one type of device, including network security devices, host auditing devices, cryptographic devices, perimeter protection devices, industrial security probes, or asset management systems. The collected alarm data is uniformly converted into a unified event model that includes event type, timestamp, source identifier, target node, severity, confidence level, scope of impact, and evidence summary. Based on at least one association rule among IP address, MAC address, port, certificate identifier, asset ledger mapping, or session identifier, the unified event model is associated with the target node identifier. Based on a preset set of thresholds, the event level is calculated using the severity, confidence, and scope of impact in a unified event model. The event level is at least divided into four levels: general, concern, serious, and emergency. The risk score is calculated by combining alarm severity, alarm confidence, degree of homogeneous clustering, node credibility, and the hit status of sensitive objects or sensitive operations.
[0009] In some embodiments, the step of selecting a strategy combination that satisfies the compliance constraints and has the lowest estimated overhead based on the security capability profile of the target node and the set of coverable control items includes: The compliance constraints that need to be met are determined based on the event level or risk score, and the compliance constraints specify a lower bound on the number or type of controls that must be covered at that level. Select all candidate strategy combinations from the strategy library that cover the set of control items and satisfy the compliance constraints; Calculate the estimated cost for each candidate strategy combination. The estimated cost includes at least one or more of the following: latency increment, CPU usage increment, interaction number increment, and log increment, and is constrained by the upper bound of the latency budget in the node performance budget. Select the candidate strategy combination with the lowest estimated cost as the minimum feasible compliance strategy combination, and generate a set of coordinated action actions based on the selected strategy combination.
[0010] In some embodiments, the step of generating a set of coordinated action actions includes: Based on the selected strategy combination, corresponding linkage actions are mapped from the preset action library. The actions include at least one or more of the following: rate limiting, read-only, blocking or isolation, strong authentication upgrade, log level upgrade, policy distribution, work order triggering, and recovery rollback. Actions that can be executed by a node are directly included in the action set; actions that cannot be executed by a node are either replaced by equivalent alternatives or executed by calling external nodes. When an event reaches a severe or urgent level, or when a risk score exceeds a high-risk threshold, the action set includes at least one or more of the following: isolation, enhanced authentication, tightened access control, or enhanced transport protection. Recovery conditions and cooldown times are set for the isolation or tightening policy.
[0011] In some embodiments, the step of constructing compliance coverage proof and forming an evidence package based on the combination of execution receipt and selected strategy includes: Compare the current required compliance constraints with the actual set of control items covered by the selected strategy combination to generate a compliance coverage certificate. The compliance coverage certificate includes at least the target node identifier, event level, required coverage set, actual coverage set, difference set, and description of alternative control items. The original alarm summary, the normalized unified event model, related evidence, security capability profile snapshot, strategy selection process summary, execution receipt, verification result and audit signature summary are packaged together to form an evidence package, and the generated summary of the evidence package is signed or written to a trusted storage medium.
[0012] In some embodiments, the step of storing and auditing the compliance coverage proof and evidence package includes: Summarize and store the compliance coverage evidence and evidence package to generate an immutable storage record; Output audit logs, which include at least node identifier, timestamp, event type, severity, confidence level, event level or risk score, security capability profile identifier, strategy combination identifier, action set identifier, compliance coverage proof identifier, evidence package hash value, and handling result.
[0013] Secondly, this invention provides a multi-source alarm linkage and handling system driven by a single-node security capability profile, the system comprising: The capability information acquisition module is used to collect asset information and security capability information of each access node in the DCS control area of thermal power plants, so as to establish a single node security capability profile and generate a set of control items that can be covered for each node. The association module is used to collect multi-source alarm data and normalize it into a unified event model, associate the unified event model with the target node identifier, and calculate the event level or risk score based on the event type, severity and association information of the unified event model. The strategy filtering module is used to determine compliance constraints based on the event level or risk score, and select the strategy combination that satisfies the compliance constraints and has the lowest estimated cost based on the security capability profile of the target node and the set of coverable control items, and generate a set of coordinated handling actions. The evidence storage module is used to execute the set of coordinated actions, construct compliance coverage proof and form an evidence package based on the execution receipt and the selected strategy combination, and store and audit the compliance coverage proof and evidence package.
[0014] Thirdly, the present invention provides a storage medium that stores one or more programs, which, when executed by a processor, implement the above-described single-node security capability profile-driven multi-source alarm linkage handling method.
[0015] Fourthly, the present invention provides an electronic device, the electronic device comprising a memory and a processor, wherein: The memory is used to store computer programs; When the processor executes the computer program stored in the memory, it implements the above-mentioned single-node security capability profile-driven multi-source alarm linkage handling method.
[0016] Compared with the prior art, the present invention has the following advantages: This invention establishes a single-node security capability profile for each access node in the control area and maps the set of compliance control items to a set of control items that the node can cover. Alarms from various security devices and systems are collected and normalized to form a unified event model, which is then associated with the target node. Based on this model, the event level or risk score is calculated. Under the premise of meeting preset compliance constraints, and combined with node capability constraints and performance budget constraints, the invention automatically selects the compliance policy combination with the lowest estimated cost from the policy library, generates a set of coordinated action actions, and executes them. After the actions are executed, receipts are obtained and consistency and effectiveness are verified to form a compliance coverage certificate and evidence package. The evidence package is then summarized and stored, and audit records are output, thereby achieving a closed-loop process of "alarm—analysis—policy selection—coordinated action—verification—storage," and compliance proof. Attached Figure Description
[0017] Figure 1 This is a flowchart of a multi-source alarm linkage handling method driven by a single-node security capability profile in one embodiment of the present invention; Figure 2 This is a schematic diagram of a multi-source alarm linkage and handling system driven by a single-node security capability profile, according to an embodiment of the present invention.
[0018] The following detailed description, in conjunction with the accompanying drawings, will further illustrate the present invention. Detailed Implementation
[0019] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention. Unless otherwise defined, the technical or scientific terms used herein should have the ordinary meaning understood by those skilled in the art. The terms "comprising" and similar expressions used herein mean that the element or object preceding the word covers the element or object listed after the word and its equivalents, but does not exclude other elements or objects.
[0020] Example 1 like Figure 1 As shown, an embodiment of the present invention proposes a multi-source alarm linkage handling method driven by a single-node security capability profile. The method includes steps S101 to S104, wherein: Step S101: Collect asset information and security capability information of each access node in the DCS control area of the thermal power plant to establish a security capability profile of a single node and generate a set of control items that can be covered for each node. It should be noted that within the DCS control area of a thermal power plant, there are significant differences in hardware configuration, operating system, security software, and cryptographic support capabilities among different nodes. If the same security policy is uniformly distributed to all nodes, some nodes may fail to execute the policy due to insufficient capabilities, or this could cause business disruptions. Therefore, this step first collects asset information (such as device type, operating system version, IP address, etc.) and security capability information (whether it supports national cryptographic algorithms, whether it has identity authentication capabilities, whether it supports log retention, performance overhead budget, etc.) from each access node within the control area. Through a combination of offline asset inventory and online detection, the system aggregates this information into a single-node security capability profile for each node. Based on this, according to preset control item coverage judgment rules (e.g., when a node supports strong identity authentication capabilities, it is determined that it can cover identity authentication control items; when a node supports national cryptographic encryption or tag verification, it is determined that it can cover transmission protection control items), a set of control items that each node can actually cover is generated. This set is a crucial constraint for subsequent policy selection, ensuring that each action in the selected policy combination is executable on the target node.
[0021] Furthermore, within the DCS control area of thermal power plants, the security capabilities of different nodes vary significantly. For example, some nodes support the national cryptographic algorithms SM2 / SM3 / SM4, while others only support ordinary hashing and encryption. Some nodes have complete log retention and reporting capabilities, while others, limited by storage capacity, can only record critical events. Therefore, it is necessary to collect six types of core capability information: national cryptographic algorithm capability (indicating the node's support for SM2 / SM3 / SM4), identity authentication capability (indicating support for certificates, passwords, fingerprints, or tokens), transmission protection capability (indicating whether secure tunnels, tag verification, or encryption suites are supported), logging and auditing capability (indicating log level, retention period, and reporting capability), performance budget (indicating latency budget and the upper bound of acceptable overhead), and firmware or software trustworthiness (indicating signature verification, version trustworthiness, and historical anomaly rate). The system aggregates the collected information into a single-node security capability profile for each node and generates a set of control items that can actually be covered based on preset control item coverage rules. For example, if the identity authentication capability meets the strong authentication threshold, it is determined that the identity authentication control item can be covered; if the transmission protection capability supports national cryptographic encryption, it is determined that the transmission protection control item can be covered. Considering that the hardware and software configuration of nodes may change over time (such as version upgrades, addition of security modules, frequent anomalies, etc.), this embodiment also specifies the conditions for updating the profile: when a version change, capability change, frequent anomalies, or policy change is detected, the system re-executes the data collection and profile generation process to ensure that the capability profile always remains consistent with the actual state of the node, thereby providing accurate constraints for subsequent policy selection.
[0022] Step S102: Collect multi-source alarm data and normalize it into a unified event model, associate the unified event model with the target node identifier, and calculate the event level or risk score based on the event type, severity and association information of the unified event model; It should be noted that thermal power plant DCS control areas typically deploy various security devices and systems, including boundary protection devices, host auditing systems, cryptographic devices, industrial security probes, and asset management systems. The alarm data generated by these systems varies in format and semantics, making it difficult to directly use for coordinated response decisions. Therefore, the first step is to collect raw alarm data from these devices and convert it into a standardized event model that includes event type, timestamp, source identifier, target node, severity, confidence level, impact scope, and evidence summary. Then, based on association rules such as IP address, MAC address, port, certificate identifier, asset ledger mapping, or session identifier, each normalized event is associated with a specific target node identifier, clarifying which node the event affects. On this basis, the event level (general, attention, severe, and urgent) is calculated according to a preset threshold set. Simultaneously, a risk score is calculated by integrating alarm severity, confidence level, homogeneous clustering degree, node credibility, and sensitive object hit rate, and a contribution decomposition is output for audit traceability. The calculated event level or risk score will serve as a direct basis for subsequent strategy selection.
[0023] Step S103: Determine compliance constraints based on the event level or risk score, and select the strategy combination that satisfies the compliance constraints and has the lowest estimated cost based on the security capability profile of the target node and the set of coverable control items, and generate a set of coordinated handling actions. It should be noted that this constraint specifies a lower bound on the number or types of controls that must be covered under this risk level (e.g., emergency events must simultaneously cover four controls: authentication, access control, transmission protection, and security auditing). Then, the system reads the generated target node security capability profile and the set of coverable controls, and filters out candidate policy combinations from the policy library that actually cover all control items and satisfy the above compliance constraints. For each candidate policy combination, the system calculates its estimated overhead, including latency increment, CPU usage increment, interaction count increment, and log increment, and is constrained by the upper bound of the latency budget in the node performance budget. Finally, the policy combination with the lowest estimated overhead is selected as the minimum feasible compliance policy combination, and a specific set of coordinated actions is generated based on this policy combination (such as rate limiting, read-only, blocking and isolation, strong authentication upgrade, log level improvement, policy distribution, and work order triggering). For actions that the node cannot execute, the system automatically selects equivalent alternative actions or calls external nodes to execute them on its behalf.
[0024] Furthermore, in some embodiments, to generate a set of coordinated action actions, corresponding coordinated action actions need to be mapped from a preset action library based on the selected strategy combination. Supported action types include at least rate limiting (limiting the rate of specific traffic), read-only (downgrading write operation permissions to read-only), blocking or isolation (cutting off communication connections or isolating nodes), strong authentication upgrade (upgrading from password authentication to certificate or two-factor authentication), log level improvement (increasing log recording granularity), policy distribution (synchronizing policies to other devices), work order triggering (dispatching work orders to the operation and maintenance system), and recovery rollback (rolling back to the previous state in case of failure). Since the capability profiles of target nodes differ, not all actions can be executed on any node. Therefore, the system needs to determine the executability of each action based on the node's security capability profile: for actions that the node can execute, they are directly included in the action set; for actions that the node cannot execute, the system selects a functionally equivalent alternative action from the action library (e.g., using enhanced log auditing as compensation when strong authentication upgrade cannot be executed), or calls external nodes (such as the security management platform or adjacent nodes) to execute the action on its behalf. Furthermore, when an event reaches a severe or urgent level, or a risk score exceeds a high-risk threshold, it indicates a serious threat, and the action set must include at least one or more of the following strong measures: isolation, enhanced authentication, tightened access control, or enhanced transport protection. This is to prevent frequent policy fluctuations.
[0025] Step S104: Execute the set of coordinated actions, construct a compliance coverage certificate and form an evidence package based on the execution receipt and the selected strategy combination, and store and audit the compliance coverage certificate and evidence package.
[0026] In this step, the system executes the generated set of coordinated action actions, collects execution receipts for each action, and verifies the consistency between the issued policy and the actual effective policy on the node based on the policy summary. If they are inconsistent, a retry or escalation action is triggered. Then, the system compares the compliance constraints required for the current event level with the actual set of control items covered by the selected policy combination to generate a compliance coverage certificate. This certificate includes at least the target node identifier, event level, required coverage set, actual coverage set, difference set, and a description of alternative control items. If a discrepancy exists, the system escalates the event or triggers external compensation actions. Simultaneously, the system packages the original alarm summary, normalized event model, related evidence, security capability profile snapshot, policy selection process summary, execution receipt, verification result, and audit signature summary into an evidence package. The system then signs the generated summary of the evidence package or writes it to a trusted storage medium to prevent tampering. Finally, the system outputs an audit record containing the node identifier, timestamp, event type, severity, confidence level, event level or risk score, various identifiers, and handling result for operational traceability and compliance checks.
[0027] Furthermore, in some embodiments, after a security incident is handled, it is not only necessary to confirm that the handling actions have been performed, but also to demonstrate to auditors or compliance agencies that: at a specific incident level, what handling measures the system took, which compliance controls these measures covered, whether there were any coverage gaps, and how to compensate for them. This embodiment first requires the system to compare each control with the set of controls actually covered by the selected strategy combination, based on the compliance constraints required for the current incident level, to generate a compliance coverage certificate. This certificate contains at least five core elements: target node identifier (clearly indicating which node the certificate targets), incident level (clearly indicating the risk level of the incident), required coverage set (a list of controls required by compliance standards), actual coverage set (a list of controls actually covered by the selected strategy combination), difference set (controls that are required to be covered but not actually covered, i.e., coverage gaps), and alternative control item description (for controls that cannot be directly covered, what alternative measures were used to compensate). If there is a non-empty difference set, the system will escalate the incident or trigger external compensation actions to fill the gaps. Meanwhile, to ensure the legal traceability of the entire handling process, this embodiment requires the system to package the following information into an evidence package: original alarm summary (original evidence at the time of event triggering), normalized unified event model (standardized event record), associated evidence (basis for associating events with nodes), security capability profile snapshot (capability status of nodes at the time of handling), strategy selection process summary (decision basis for choosing this strategy combination), execution receipt (execution results of each action), verification results (effect verification conclusions), and audit signature summary (signature used for integrity verification). Finally, a summary is generated for the evidence package and signed or written to a trusted storage medium (such as blockchain or hardware security module) to ensure that the content of the evidence package cannot be tampered with after storage.
[0028] Furthermore, after completing the construction of the compliance coverage proof and the generation of the evidence package, this information needs to be persistently stored in an immutable form for subsequent compliance checks, security audits, and incident tracing. This embodiment first requires digest storage of the compliance coverage proof and evidence package, that is, generating a unique content digest using a hash algorithm, signing the digest, and writing it into a trusted storage medium (such as a blockchain storage platform, hardware security module, or tamper-proof log server). This storage mechanism ensures that any modification to the original data will result in a digest mismatch, thus being detectable. Simultaneously, to facilitate quick retrieval and review of handling records by operations personnel and audit systems, this embodiment requires the system to output structured audit records. The audit log should include at least the following fields: Node Identifier (the node where the event occurred), Timestamp (the time of the event occurrence and handling), Event Type (e.g., intrusion detection alarm, abnormal behavior, etc.), Severity (the severity level of the alarm), Confidence Level (the credibility of the alarm), Event Level or Risk Score (the quantified risk value calculated in step S102), Security Capability Profile Identifier (a snapshot of the node's capabilities at that time), Policy Combination Identifier (the minimum feasible compliance policy combination selected), Action Set Identifier (the actual coordinated handling actions executed), Compliance Coverage Proof Identifier (the generated compliance coverage proof), Evidence Package Hash Value (a hash value used to verify the integrity of the evidence package), and Handling Result (whether the handling was successful, whether there are any coverage gaps, etc.). Through these fields, auditors can fully reconstruct the entire process of triggering, analyzing, deciding, handling, and storing evidence for each security event, meeting all evidence requirements for security assessment and compliance audits.
[0029] In summary, this invention transforms coordinated response from "unified platform distribution" to "executable strategy selection under capability constraints" by establishing a single-node security capability profile and generating a set of control items that can be covered by the node, significantly reducing the risks of strategy non-implementation and business disruption. By normalizing and modeling multi-source alarms and associating them with target nodes, and combining event levels or risk scores to achieve interpretable analysis, it provides a unified input for coordinated response. Under the premise of meeting compliance constraints, this invention automatically selects the compliance strategy combination with the lowest estimated overhead, achieving a configurable trade-off between compliance coverage and performance budget, improving response efficiency and real-time controllability. This invention incorporates action execution receipts, consistency verification, and effect verification into a closed loop, avoiding the hidden risks of "distribution not taking effect" or "ineffective response," and supports escalation of response or transfer to manual processes in case of failure. Furthermore, this invention generates compliance coverage proof and evidence packages, and performs summary storage of the evidence packages, forming a traceable and verifiable audit evidence chain that can directly support confidentiality assessment / key basis checks and post-event traceability, thereby comprehensively improving the automation level, reliability, compliance verifiability, and operational efficiency of multi-source alarm coordinated response in thermal power DCS control areas.
[0030] Example 2 like Figure 2 As shown, an embodiment of the present invention proposes a multi-source alarm linkage handling system driven by a single-node security capability profile, characterized in that the system includes: The capability information acquisition module 10 is used to collect asset information and security capability information of each access node in the DCS control area of the thermal power plant, so as to establish a single node security capability profile and generate a set of control items that can be covered for each node. The association module 20 is used to collect multi-source alarm data and normalize it into a unified event model, associate the unified event model with the target node identifier, and calculate the event level or risk score based on the event type, severity and association information of the unified event model. The strategy filtering module 30 is used to determine compliance constraints based on the event level or risk score, and select the strategy combination that satisfies the compliance constraints and has the lowest estimated cost based on the security capability profile of the target node and the set of coverable control items, and generate a set of coordinated handling actions. The evidence storage module 40 is used to execute the set of linked handling actions, construct a compliance coverage certificate and form an evidence package based on the execution receipt and the selected strategy combination, and store and audit the compliance coverage certificate and evidence package.
[0031] Example 3 An embodiment of the present invention also proposes a storage medium on which one or more programs are stored, which, when executed by a processor, implement the above-described single-node security capability profile-driven multi-source alarm linkage handling method.
[0032] Example 4 An embodiment of the present invention also proposes an electronic device, including a memory and a processor, wherein the memory is used to store computer programs, and the processor is used to execute the computer programs stored in the memory to realize the above-mentioned single-node security capability profile-driven multi-source alarm linkage handling method.
[0033] Those skilled in the art will understand that the logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can mean any means that can contain stored, communicated, propagated, or transmitted programs for use by, or in conjunction with, an instruction execution system, apparatus, or device.
[0034] More specific examples of computer-readable media (a non-exhaustive list) include: electrical connections (electronic devices) having one or more wires, portable computer disk drives (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.
[0035] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.
[0036] While embodiments of the present invention have been described in detail above, it will be apparent to those skilled in the art that various modifications and variations can be made to these embodiments. However, it should be understood that such modifications and variations fall within the scope and spirit of the invention as described in the embodiments. Furthermore, the present invention described herein may have other embodiments and can be implemented or carried out in various ways.
Claims
1. A method for multi-source alarm linkage handling driven by a single-node security capability profile, characterized in that, The method includes: Collect asset information and security capability information of each access node in the DCS control area of thermal power plants to establish a security capability profile of a single node and generate a set of control items that can be covered for each node. Collect multi-source alarm data and normalize it into a unified event model. Associate the unified event model with the target node identifier. Calculate the event level or risk score based on the event type, severity and association information of the unified event model. Based on the event level or risk score, compliance constraints are determined, and based on the security capability profile of the target node and the set of coverable control items, the strategy combination that satisfies the compliance constraints and has the lowest estimated cost is selected, and a set of coordinated handling actions is generated. The set of coordinated actions is executed, and compliance coverage proof is constructed and evidence package is formed based on the execution receipt and the selected strategy combination. The compliance coverage proof and evidence package are then stored and audited.
2. The multi-source alarm linkage handling method driven by a single-node security capability profile according to claim 1, characterized in that, The steps for collecting asset information and security capability information of each access node within the DCS control area of the thermal power plant to establish a single node security capability profile include: The capability information of the collection node includes national cryptographic algorithm capability, identity authentication capability, transmission protection capability, log and audit capability, performance budget, and firmware or software trustworthiness. The collected capability information is aggregated into a single-node security capability profile, and a set of control items that the node can cover is generated based on the node's security capability profile. The control items include at least one or more of the following: identity authentication, access control, transmission protection, security audit, intrusion prevention, or security management. When a version change, capability change, frequent anomalies, or policy change is detected, the security capability profile is updated.
3. The multi-source alarm linkage handling method driven by a single-node security capability profile according to claim 1, characterized in that, The steps for calculating the event level or risk score based on event type, severity, and correlation information according to the unified event model include: Collect alarm data from at least one type of device, including network security devices, host auditing devices, cryptographic devices, perimeter protection devices, industrial security probes, or asset management systems. The collected alarm data is uniformly converted into a unified event model that includes event type, timestamp, source identifier, target node, severity, confidence level, scope of impact, and evidence summary. Based on at least one association rule among IP address, MAC address, port, certificate identifier, asset ledger mapping, or session identifier, the unified event model is associated with the target node identifier. Based on a preset set of thresholds, the event level is calculated using the severity, confidence, and scope of impact in a unified event model. The event level is at least divided into four levels: general, concern, serious, and emergency. The risk score is calculated by combining alarm severity, alarm confidence, degree of homogeneous clustering, node credibility, and the hit status of sensitive objects or sensitive operations.
4. The multi-source alarm linkage handling method driven by a single-node security capability profile according to claim 1, characterized in that, The step of selecting the strategy combination that satisfies the compliance constraints and has the lowest estimated overhead based on the security capability profile of the target node and the set of coverable control items includes: The compliance constraints that need to be met are determined based on the event level or risk score, and the compliance constraints specify a lower bound on the number or type of controls that must be covered at that level. Select all candidate strategy combinations from the strategy library that cover the set of control items and satisfy the compliance constraints; Calculate the estimated cost for each candidate strategy combination. The estimated cost includes at least one or more of the following: latency increment, CPU usage increment, interaction number increment, and log increment, and is constrained by the upper bound of the latency budget in the node performance budget. Select the candidate strategy combination with the lowest estimated cost as the minimum feasible compliance strategy combination, and generate a set of coordinated action actions based on the selected strategy combination.
5. The multi-source alarm linkage handling method driven by a single-node security capability profile according to claim 1, characterized in that, The steps for generating the set of coordinated action actions include: Based on the selected strategy combination, corresponding linkage actions are mapped from the preset action library. The actions include at least one or more of the following: rate limiting, read-only, blocking or isolation, strong authentication upgrade, log level upgrade, policy distribution, work order triggering, and recovery rollback. Actions that can be executed by a node are directly included in the action set; actions that cannot be executed by a node are either replaced by equivalent alternatives or executed by calling external nodes. When an event reaches a severe or urgent level, or when a risk score exceeds a high-risk threshold, the action set includes at least one or more of the following: isolation, enhanced authentication, tightened access control, or enhanced transport protection. Recovery conditions and cooldown times are set for the isolation or tightening policy.
6. The multi-source alarm linkage handling method driven by a single-node security capability profile according to claim 1, characterized in that, The steps of constructing compliance coverage proof and forming an evidence package based on the combination of execution receipts and selected strategies include: Compare the current required compliance constraints with the actual set of control items covered by the selected strategy combination to generate a compliance coverage certificate. The compliance coverage certificate includes at least the target node identifier, event level, required coverage set, actual coverage set, difference set, and description of alternative control items. The original alarm summary, the normalized unified event model, related evidence, security capability profile snapshot, strategy selection process summary, execution receipt, verification result and audit signature summary are packaged together to form an evidence package, and the generated summary of the evidence package is signed or written to a trusted storage medium.
7. The multi-source alarm linkage handling method driven by a single-node security capability profile according to claim 1, characterized in that, The steps for storing and auditing the compliance coverage proof and evidence package include: Summarize and store the compliance coverage evidence and evidence package to generate an immutable storage record; Output audit logs, which include at least node identifier, timestamp, event type, severity, confidence level, event level or risk score, security capability profile identifier, strategy combination identifier, action set identifier, compliance coverage proof identifier, evidence package hash value, and handling result.
8. A multi-source alarm linkage and handling system driven by a single-node security capability profile, characterized in that, The system includes: The capability information acquisition module is used to collect asset information and security capability information of each access node in the DCS control area of thermal power plants, so as to establish a single node security capability profile and generate a set of control items that can be covered for each node. The association module is used to collect multi-source alarm data and normalize it into a unified event model, associate the unified event model with the target node identifier, and calculate the event level or risk score based on the event type, severity and association information of the unified event model. The strategy filtering module is used to determine compliance constraints based on the event level or risk score, and select the strategy combination that satisfies the compliance constraints and has the lowest estimated cost based on the security capability profile of the target node and the set of coverable control items, and generate a set of coordinated handling actions. The evidence storage module is used to execute the set of coordinated actions, construct compliance coverage proof and form an evidence package based on the execution receipt and the selected strategy combination, and store and audit the compliance coverage proof and evidence package.
9. An electronic device, characterized in that, The electronic device includes a memory and a processor, wherein: The memory is used to store computer programs; When the processor executes the computer program stored in the memory, it implements the single-node security capability profile-driven multi-source alarm linkage handling method as described in any one of claims 1-7.
10. A storage medium, characterized in that, The storage medium stores one or more programs, which, when executed by a processor, implement the single-node security capability profile-driven multi-source alarm linkage handling method as described in any one of claims 1-7.