Power plant cyber-security data automatic extraction method
Patent Information
- Application Number
- CN202610609011.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-06
- Publication Date
- 2026-09-22
AI Technical Summary
然而,这种方法在复杂的发电厂网络环境中暴露出明显的局限性:静态规则难以适应动态演进的网络威胁,全量数据采集模式与OT环境资源约束存在根本性矛盾,以及现有的方法通常缺乏对数据价值与资源消耗的精细化衡量与闭环反馈
(1)通过将威胁处置指令转化为具体的数据采集规则,并基于数据价值密度、资源消耗率和业务等级三个维度进行动态调整,解决了传统静态规则采集模式下数据价值低、资源浪费严重的问题。
Smart Images

Figure CN122802524A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of cybersecurity technology for industrial control systems, and in particular to an automated method for extracting cybersecurity data from power plants. Background Technology
[0002] As a core component of the nation's critical information infrastructure, the cybersecurity of power plants is of paramount importance. With the rapid development of smart grids and the Industrial Internet, the network structure of power plants is becoming increasingly complex, forming a heterogeneous environment encompassing management information zones and production control zones. The industrial control systems within the production control zone are directly related to the stability and security of power production; a cyberattack could lead to unplanned unit shutdowns, equipment damage, or even larger-scale grid accidents. To achieve timely detection, response, and evidence collection of cyber threats, automated extraction and analysis of multi-source security data from power plant networks is necessary. These data sources are diverse, including firewall and intrusion detection system logs from IT networks, as well as industrial protocol communication traffic and industrial control equipment operation logs from OT networks.
[0003] Currently, common automated data extraction methods mainly rely on predefined, static collection rules. These rules are typically configured based on fixed asset lists and event types. However, this approach reveals significant limitations in complex power plant network environments: static rules struggle to adapt to dynamically evolving network threats, the full-data collection model fundamentally contradicts the resource constraints of OT environments, and existing methods often lack refined measurement and closed-loop feedback regarding data value and resource consumption. Summary of the Invention
[0004] Based on the above-mentioned situation of the prior art, the purpose of this embodiment of the invention is to provide an automated method for extracting network security data from power plants, which can adapt to the threat situation and system status, and achieve precise resource allocation and maximize data value in the data extraction process.
[0005] To achieve the above objectives, according to one aspect of the present invention, an automated method for extracting network security data from power plants is provided, comprising the steps of: Receive threat handling instructions sent by the upper-layer security platform, wherein the threat handling instructions include target assets and target behaviors; Based on the threat handling instructions, identify target data collection points related to the target assets and target behaviors; The threat handling instructions are converted into executable data collection rules, which include the data collection frequency and preliminary processing methods. The executable data acquisition rules are sent to the target data acquisition points so that the target data acquisition points can perform adaptive data acquisition according to the executable data acquisition rules; Based on the data uploaded by the target data collection points, calculate the data value density and resource consumption rate of each target data collection point; The data collection rules are dynamically adjusted based on the data value density and resource consumption rate of each target data collection point, as well as the business level of the target asset.
[0006] Furthermore, the threat handling instructions are converted into executable data collection rules, including: Based on the target asset attributes in the threat handling instructions, set the initial collection frequency and preliminary processing method.
[0007] Furthermore, the business classification of the target assets includes critical, important, and general levels; The preliminary processing methods include lossless mode, key field mode, and summary mode; the lossless mode means recording the original data or performing lossless compression on the original data; the key field mode means extracting and storing key fields in the original data; and the summary mode means performing high-granular aggregation on the original data.
[0008] Furthermore, based on the target asset attributes in the threat handling instructions, the initial collection frequency and preliminary processing method are set, including: Based on the type of the target asset, the initial acquisition frequency is set to the corresponding standard base frequency; Based on the business level of the target asset, set the initial preliminary processing method. If the business level is critical or important, set the initial preliminary processing method to critical field mode; if the business level is general, set the initial preliminary processing method to summary mode.
[0009] Furthermore, the data value density is calculated according to the following formula: in, Indicates data value density. This indicates the number of data entries that triggered subsequent security alerts. This indicates the total number of data entries output by the data collection point.
[0010] Furthermore, the resource consumption rate is calculated according to the following formula: in, Indicates the resource consumption rate. This indicates the CPU consumption rate of the data acquisition process; This indicates the bandwidth consumption rate of the data acquisition point; This indicates the storage consumption rate of the data collection points; , and This indicates the weight of the corresponding item.
[0011] Furthermore, based on the data value density and resource consumption rate of each target data collection point, as well as the business level of the target asset, the data collection rules are dynamically adjusted, including: Adjust the data collection frequency in the data collection rules according to the adjustment factor; Adjust the data processing method in the data collection rules according to the values of data value density and resource consumption rate.
[0012] Furthermore, the data collection frequency in the data collection rules is adjusted according to the adjustment factor, including: when At that time, double the current sampling frequency; when At the same time, maintain the current sampling frequency; when When this happens, the current sampling frequency will be reduced to a low-frequency sampling mode; in, Indicates the adjustment factor. Indicates a high adjustment threshold. Adjusting the threshold in the representation, This indicates a low adjustment threshold.
[0013] Furthermore, the adjustment factor is calculated according to the following formula: in, Indicates the adjustment factor. Indicates data value density. Indicates the business level. Indicates resource consumption rate; when the business level is critical. When the business level is important When the business level is general. .
[0014] Furthermore, based on the values of data value density and resource consumption rate, the data processing methods in the data collection rules are adjusted, including: when and At that time, the initial processing method will be adjusted to non-destructive mode; when ,or and At that time, the initial processing method was adjusted to the key field mode; when and At that time, the current preliminary handling method will remain unchanged; In other cases, the initial processing method will be adjusted to summary mode; in, Indicates the high-density threshold. Indicates the medium density threshold. Indicates the low density threshold; This indicates the high consumption rate threshold. This indicates the low consumption rate threshold.
[0015] In summary, this invention provides an automated method for extracting network security data from power plants, comprising the following steps: receiving a threat handling instruction sent by an upper-layer security platform, the threat handling instruction indicating target assets and target behaviors; identifying target data collection points related to the target assets and target behaviors based on the threat handling instruction; converting the threat handling instruction into executable data collection rules, the data collection rules including data collection frequency and preliminary processing methods; distributing the executable data collection rules to the target data collection points so that the target data collection points perform adaptive data collection according to the executable data collection rules; calculating the data value density and resource consumption rate of each target data collection point based on the data uploaded by the target data collection points; and dynamically adjusting the data collection rules according to the data value density and resource consumption rate of each target data collection point and the business level of the target assets. The technical solution of this invention has the following beneficial technical effects: (1) By converting threat handling instructions into specific data collection rules and dynamically adjusting them based on three dimensions—data value density, resource consumption rate, and business level—the problem of low data value and serious resource waste under the traditional static rule collection model is solved.
[0016] (2) By quantifying the balance between data value density and resource consumption rate, and combining the business level weight of power plant assets, an adjustment factor calculation model was established, which enabled adaptive adjustment of collection frequency and processing granularity under the premise of monitoring the quality of key assets. Attached Figure Description
[0017] Figure 1 This is a flowchart of the automated extraction method for network security data from power plants provided in an embodiment of the present invention. Detailed Implementation
[0018] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to specific embodiments and the accompanying drawings. It should be understood that these descriptions are merely exemplary and not intended to limit the scope of the invention. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concept of the invention.
[0019] It should be noted that, unless otherwise defined, the technical or scientific terms used in one or more embodiments of the present invention should have the ordinary meaning understood by one of ordinary skill in the art to which this invention pertains. The terms "first," "second," and similar terms used in one or more embodiments of the present invention do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Terms such as "comprising" or "including" mean that the element or object preceding the word encompasses the element or object listed following the word and its equivalents, without excluding other elements or objects. Terms such as "connected" or "linked" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect.
[0020] The technical solution of the present invention will be described in detail below with reference to the accompanying drawings. An embodiment of the present invention provides an automated method for extracting network security data from power plants. This method is based on a data acquisition and management platform installed within the power plant network and can be deployed in the power plant's management information area. Figure 1 The flowchart of the automated extraction method for power plant network security data according to an embodiment of the present invention is shown below. Figure 1 As shown, the method includes the following steps: S202. Receive threat handling instructions from the upper-layer security platform. These instructions include target assets and target behaviors. Target assets refer to physical entities located in the power plant network that require security data collection. These include network devices (e.g., switches, routers), security devices (e.g., firewalls), computing devices (e.g., servers, workstations), and industrial control equipment (e.g., programmable logic controllers (PLCs), remote terminal units (RTUs)). They are described using identification information, including asset type, asset ID, IP address, and MAC address. Target behaviors refer to network activities or system state change sequences related to the target assets that pose potential security risks. These include protocol type, function code, packet size / frequency, specific event ID, error type, unauthorized operations, and abnormal instruction sequences.
[0021] S204. Based on threat handling instructions, identify target data collection points related to target assets and target behaviors. In this embodiment of the invention, all data collection points in the power plant network are equipped with data collection controllers. The data collection controllers can receive data collection rules and control the data collection points to collect data according to the data collection rules. Data collection points include three categories: network traffic probes, log collection interfaces, and operation audit collection points. Data collection rules include data collection frequency and preliminary processing methods. Preliminary processing methods include lossless mode, key field mode, and summary mode. In lossless mode, the original data is recorded or the original data is losslessly compressed. In key field mode, key fields are extracted and stored from the original data. In summary mode, the original data is aggregated at a high granularity. For example, within a preset time window, N operations on the same target from the same source can be aggregated into one data entry. Asset context mappings can be pre-established. These mappings include the inherent attributes and core attributes of assets, as well as the mapping relationships between them. Inherent attributes include asset type, business level, asset ID, IP address, and MAC address. Core attributes include network communication attributes, system log attributes, and operation control attributes. Each core attribute is mapped to a corresponding data collection point; for example, network communication attributes have network traffic probes, system log attributes have log collection interfaces, and operation control attributes have operation audit collection points. Business levels are categorized into three levels based on the asset's importance within the power plant's business system: critical, important, and general. Critical level refers to equipment directly involved in core process control such as power generation, transmission, and primary energy conversion, such as PLCs and RTUs. Important level refers to equipment that does not directly perform process control but provides real-time monitoring, operation interfaces, data services, or area protection for critical level equipment, such as monitoring equipment and historical databases. General level refers to equipment located in the power plant's network environment whose operating status does not directly affect the control and monitoring of the power production process, such as environmental monitoring sensors and office area network equipment.
[0022] Based on threat handling instructions and pre-defined asset context mappings, target data collection points related to target assets and target behaviors can be identified through the following steps: S2041. Extract the identification information of the target asset and the target behavior from the threat handling instructions.
[0023] S2042. Locate the target asset in the asset context mapping using the target asset's identification information. Match the target asset in the asset context mapping using the asset ID, IP address, and MAC address.
[0024] S2043. Based on the location of the target asset and target behavior, find the core attribute corresponding to the target asset in the asset context mapping, and then find the corresponding target data collection point in the core attribute. The asset context mapping also maps the target behavior to the corresponding core attribute, where protocol type, function code, and packet size / frequency correspond to network traffic, specific event ID and error type correspond to system logs, and unauthorized operations and abnormal instruction sequences correspond to operational behaviors.
[0025] S206. Convert the above threat handling instructions into executable data collection rules. Based on the target asset attributes, set the initial collection frequency and preliminary processing method. The initial collection frequency can be set as a standard base frequency based on the target asset type and historical power plant data. The initial preliminary processing method can be set according to the target asset's business level. If the business level is critical or important, set the preliminary processing method to critical field mode; if the business level is general, set the preliminary processing method to summary mode.
[0026] S208. The executable data acquisition rules are distributed to the target data acquisition points so that the target data acquisition points can perform adaptive data acquisition according to the executable data acquisition rules. During the adaptive data acquisition process, the target data acquisition points acquire and process data according to the acquisition frequency and preliminary processing method in the executable data acquisition rules, and then upload the acquired data.
[0027] S210. Based on the data uploaded by the target data collection points, calculate the data value density and resource consumption rate of each data collection point. Data value density measures the proportion of effective information in a unit of data output that can directly serve security analysis, threat detection, or forensic investigation. Resource consumption rate quantifies the load impact on the network environment caused by the data collection process and the data collection points during execution. Data value density can be calculated using the following formula: in, Indicates data value density. This indicates the number of data entries that triggered subsequent security alerts. This indicates the total number of data entries output by the data collection point.
[0028] Resource consumption rate can be calculated using the following formula: in, Indicates the resource consumption rate. The CPU consumption rate of the data acquisition process can be obtained by dividing the CPU utilization rate of the data acquisition process by the upper limit of the total available CPU utilization. The bandwidth consumption rate of a data collection point can be obtained by dividing the network bandwidth used by the data collection point by the total available bandwidth of the network links. The storage consumption rate of the data acquisition point can be obtained by dividing the instantaneous storage space occupied by the data at the data acquisition point by the total storage space allocated to the data acquisition system. , and This indicates the weight of the corresponding item, which can be set according to actual needs.
[0029] S212. Dynamically adjust the data collection rules based on the data value density and resource consumption rate of each target data collection point, as well as the business level of the target asset. Calculate the adjustment factor based on the data value density and resource consumption rate of each target data collection point, and the business level of the target asset. in, Indicates the adjustment factor. Indicates data value density. Indicates the business level. Indicates resource consumption rate; when the business level is critical. When the business level is important When the business level is general.
[0030] Based on the data value density and resource consumption rate of each target data collection point, as well as the business level of the target asset, the data collection rules can be dynamically adjusted according to the following steps: S2121. Adjust the data acquisition frequency in the data acquisition rules according to the adjustment factor. The acquisition frequency can be adjusted based on the comparison results between the adjustment factor and each adjustment threshold: when At this time, the current sampling frequency is doubled, so that a more continuous data sequence can be collected; when At the same time, maintain the current sampling frequency; when At this time, the current collection frequency will be halved to balance resource consumption; when When this happens, the current sampling frequency will be reduced to a low-frequency sampling mode, for example, to 1 / 10 of the current sampling frequency.
[0031] in, , , These represent the high adjustment threshold, medium adjustment threshold, and low adjustment threshold, respectively.
[0032] S2122. Adjust the data processing method in the data collection rules based on the values of data value density and resource consumption rate. This adjustment can be made by comparing data value density with high-density, medium-density, and low-density thresholds, and by comparing resource consumption rate with high-consumption and low-consumption rate thresholds. when and When the data value density is high and the resource consumption rate is low, the initial processing method is adjusted to lossless mode, so that all the details of the collected data are preserved. when ,or and When the initial processing method is adjusted to the key field mode, data collection is carried out in an efficient and information-sufficient manner under clearly defined medium-to-high value or high-load conditions. when and At that time, the current preliminary handling method will remain unchanged; In other cases, the initial processing method will be adjusted to summary mode.
[0033] in, , and These are the high-density threshold, medium-density threshold, and low-density threshold, with typical values of [value missing]. , , ; and These are the high consumption rate threshold and the low consumption rate threshold, with typical values of [values to be filled in]. , .
[0034] In summary, this invention relates to an automated data extraction method for cybersecurity in power plants, comprising the following steps: receiving a threat handling instruction sent by an upper-layer security platform, the threat handling instruction indicating target assets and target behaviors; identifying target data collection points related to the target assets and target behaviors based on the threat handling instruction; converting the threat handling instruction into executable data collection rules, the data collection rules including data collection frequency and preliminary processing methods; distributing the executable data collection rules to the target data collection points so that the target data collection points perform adaptive data collection according to the executable data collection rules; calculating the data value density and resource consumption rate of each target data collection point based on the data uploaded by the target data collection points; and dynamically adjusting the data collection rules according to the data value density and resource consumption rate of each target data collection point and the business level of the target assets. The technical solution of this invention solves the problems of low data value and serious resource waste in the traditional static rule collection mode by transforming threat handling instructions into specific data collection rules and dynamically adjusting them based on three dimensions: data value density, resource consumption rate, and business level. By quantitatively evaluating the balance between data value density and resource consumption rate and combining the business level weight of power plant assets, an adjustment factor calculation model is established, which enables adaptive adjustment of collection frequency and processing granularity under the premise of monitoring the quality of key assets.
[0035] It should be understood that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of the invention (including the claims) is limited to these examples. Within the framework of this invention, technical features of the above embodiments or different embodiments can also be combined, steps can be implemented in any order, and many other variations exist regarding different aspects of one or more embodiments of the invention as described above; for the sake of brevity, they are not provided in the details. The specific embodiments described above are merely illustrative or explanatory of the principles of the invention and do not constitute a limitation thereof. Therefore, any modifications, equivalent substitutions, improvements, etc., made without departing from the spirit and scope of the invention should be included within the protection scope of the invention. Furthermore, the appended claims are intended to cover all variations and modifications falling within the scope and boundaries of the appended claims, or equivalent forms of such scope and boundaries.
Claims
1. A method for automatically extracting network security data from power plants, characterized in that, Including the following steps: Receive threat handling instructions sent by the upper-layer security platform, wherein the threat handling instructions include target assets and target behaviors; Based on the threat handling instructions, identify target data collection points related to the target assets and target behaviors; The threat handling instructions are converted into executable data collection rules, which include the data collection frequency and preliminary processing methods. The executable data acquisition rules are sent to the target data acquisition points so that the target data acquisition points can perform adaptive data acquisition according to the executable data acquisition rules; Based on the data uploaded by the target data collection points, calculate the data value density and resource consumption rate of each target data collection point; The data collection rules are dynamically adjusted based on the data value density and resource consumption rate of each target data collection point, as well as the business level of the target asset.
2. The method according to claim 1, characterized in that, Converting the threat handling instructions into executable data collection rules includes: Based on the target asset attributes in the threat handling instructions, set the initial collection frequency and preliminary processing method.
3. The method according to claim 2, characterized in that, The target assets are classified into three business levels: critical, important, and general. The preliminary processing methods include lossless mode, key field mode, and summary mode; the lossless mode means recording the original data or performing lossless compression on the original data; the key field mode means extracting and storing key fields in the original data; and the summary mode means performing high-granular aggregation on the original data.
4. The method according to claim 3, characterized in that, Based on the target asset attributes in the threat handling instructions, set the initial collection frequency and preliminary processing method, including: Based on the type of the target asset, the initial acquisition frequency is set to the corresponding standard base frequency; Based on the business level of the target asset, set the initial preliminary processing method. If the business level is critical or important, set the initial preliminary processing method to critical field mode; if the business level is general, set the initial preliminary processing method to summary mode.
5. The method according to claim 4, characterized in that, The data value density is calculated according to the following formula: in, Indicates data value density. This indicates the number of data entries that triggered subsequent security alerts. This indicates the total number of data entries output by the data collection point.
6. The method according to claim 4, characterized in that, The resource consumption rate is calculated according to the following formula: in, Indicates resource consumption rate. This indicates the CPU consumption rate of the data acquisition process; This indicates the bandwidth consumption rate of the data acquisition point; This indicates the storage consumption rate of the data collection points; , and This indicates the weight of the corresponding item.
7. The method according to claim 5 or 6, characterized in that, Based on the data value density and resource consumption rate of each target data collection point, as well as the business level of the target asset, the data collection rules are dynamically adjusted, including: Adjust the data collection frequency in the data collection rules according to the adjustment factor; Adjust the data processing method in the data collection rules according to the values of data value density and resource consumption rate.
8. The method according to claim 7, characterized in that, Adjust the data collection frequency in the data collection rules according to the adjustment factor, including: when At that time, double the current sampling frequency; when At the same time, maintain the current sampling frequency; when When this happens, the current sampling frequency will be reduced to a low-frequency sampling mode; in, Indicates the adjustment factor. Indicates a high adjustment threshold. Adjusting the threshold in the representation, This indicates a low adjustment threshold.
9. The method according to claim 8, characterized in that, The adjustment factor is calculated according to the following formula: in, Indicates the adjustment factor. Indicates data value density. Indicates the business level. Indicates resource consumption rate; when the business level is critical. When the business level is important When the business level is general. .
10. The method according to claim 9, characterized in that, Based on the values of data value density and resource consumption rate, adjust the data processing methods in the data collection rules, including: when and At that time, the initial processing method will be adjusted to non-destructive mode; when ,or and At that time, the initial processing method was adjusted to the key field mode; when and At that time, the current preliminary handling method will remain unchanged; In other cases, the initial processing method will be adjusted to summary mode; in, Indicates the high-density threshold. Indicates the medium density threshold. Indicates the low density threshold; This indicates the high consumption rate threshold. This indicates the low consumption rate threshold.