Substation data security monitoring system based on SCD modeling
By adopting a data security monitoring system based on SCD modeling in the substation and using bait cache nodes and diversion links for non-invasive security detection, the problems of high requirements for substation data security threats and equipment business continuity in smart grid systems are solved, and efficient and secure data monitoring and protection effects are achieved.
Patent Information
- Application Number
- PCT/CN2024/117899
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-21
- Filing Date
- 2024-09-10
- Publication Date
- 2025-06-26
AI Technical Summary
In smart grid systems, the data of the substation faces security threats, and the equipment has high requirements for business continuity and cannot withstand the decline in power quality and economic losses caused by shutdown monitoring. At the same time, it is necessary to monitor and prevent and control illegal intrusions without affecting the safety inspection of power equipment.
The substation data security monitoring system based on SCD modeling is adopted, which includes a monitoring center, data acquisition module, data storage module, SCD modeling module, bait cache module, service data transmission module, non-invasive security detection module and exception processing module. The SCD modeling module generates logical device layers, grid model layers and time data layers, builds an integrated business data model, and performs non-invasive security detection through bait cache nodes and diversion links.
It realizes that without affecting the normal operation of the substation, identify abnormal behaviors at the equipment layer and potential threats at the network layer, and take timely response measures to prevent illegal intrusions, improve data security monitoring efficiency, and avoid economic losses caused by power equipment shutdown monitoring.
Smart Images

Figure CN2024117899_26062025_PF_FP_ABST
Abstract
Description
A Substation Data Security Monitoring System Based on SCD Modeling Technical Field
[0001] The present invention relates to the technical field of data security monitoring, and in particular to a substation data security monitoring system based on SCD modeling. Background Art
[0002] As industrialization and informatization converge, traditionally isolated and separate communication protocols, devices, and systems are increasingly being connected. In smart grid systems, due to the large number of access terminals, complex environments, and widespread use of wireless communications, data faces a range of security threats, hindering the development of smart grids.
[0003] The SCD file contains information such as the substation topology, device types, communication parameters, and data models. It provides a unified description method that enables various devices to understand and interact with each other, thereby achieving more efficient and flexible system integration.
[0004] The comparative document CN114513342B "A method and system for security monitoring of communication data in smart substations" generates a security monitoring basis based on the entire station's SCD configuration file, security requirements and extracted information, monitors the data legitimacy of the smart substation communication network in real time according to the security policy, and captures, records, traces and issues alarms for illegal messages on the communication network in real time.
[0005] Comparative document CN110737722B, "System and Method for Synchronizing Substation Monitoring Backend Databases, SCDs, and RCDs," is used to issue and retrieve modification tokens, which can only exist once at a time, and to issue synchronization tokens. This system ensures accurate and reliable data synchronization through token settings. The system achieves 100% data synchronization accuracy and over 99% time savings. This significantly improves work efficiency and ensures reliable and secure power grid operation.
[0006] However, substation equipment has high requirements for business continuity and cannot withstand long-term equipment abnormality detection. It is necessary to avoid indirect economic losses caused by the decline in power quality due to shutdown monitoring of substation power equipment. At the same time, how to avoid affecting the safety detection of substation power equipment while monitoring and preventing illegal intrusions into the business data transmission process within the substation and improving the efficiency of substation data security monitoring is an urgent problem that we need to solve. We now provide a substation data security monitoring system based on SCD modeling.
[0007] Summary of the Invention
[0008] In view of this, an object of the present invention is to provide a substation data security monitoring system based on SCD modeling to overcome the above technical problems.
[0009] To achieve the above objectives, the present invention adopts the following technical solutions:
[0010] The present application provides a substation data security monitoring system based on SCD modeling, comprising a monitoring center, wherein the monitoring center is communicatively connected to a data acquisition module, a data storage module, an SCD modeling module, a decoy cache module, a service data transmission module, a non-intrusive security detection module, and an exception handling module;
[0011] The data acquisition module is used to collect business data of each device in the substation and send it to the database for storage, while recording the sending timestamp and receiving timestamp of the business data;
[0012] The data storage module is used to store historical business data of each device in the substation;
[0013] The SCD modeling module is used to generate the substation's logical device layer, grid model layer and time data layer based on the substation's entire SCD description file, and to build a business data integration model;
[0014] The decoy cache module is used to obtain a target logical device that meets the decoy cache node deployment standard in the logical device layer of the business data integration model, and obtain the data link path of the target logical device in the grid model layer of the business data integration model, set a decoy cache node on the data link path between the target logical device and the database, and build a diversion link between the decoy cache node and the non-intrusive security detection module; wherein, the decoy cache node includes a unidirectional read link and a unidirectional write link, the unidirectional write link is provided with a time verification unit, and the unidirectional read link is provided with a data synchronization unit, a read record unit, an automatic deletion unit and a real-time data unit;
[0015] The business data transmission module is used to transmit the business data in the business data integration model to the database through the bait cache node, and through the time verification unit set in the one-way write link, when the business data in the business data integration model is sent to the database through the one-way write link, the time verification unit obtains the sending timestamp of the business data based on the time data layer in the business data integration model, and sends the sending timestamp to the database, obtains the receiving timestamp of the existing business data in the database, compares the receiving timestamp with the sending timestamp sent to the database, and when the sending timestamp is greater than the receiving timestamp, the one-way write link allows the business data to be stored in the database, and at the same time, the business data and the sending timestamp of the business data are synchronously copied to the one-way read link, and sent to the non-intrusive The security detection module sends security detection information. When the sending timestamp is less than or equal to the receiving timestamp, the unidirectional write link marks the business data as abnormal delay data and refuses to store the abnormal delay data in the database. When the unidirectional write link receives the abnormal delay data three times in a row, network layer abnormality information of the corresponding logical device is generated and sent to the abnormal handling module. It is also used to store the business data synchronously copied from the unidirectional write link to the unidirectional read link through the data synchronization unit set in the unidirectional read link, record the read record of the business data in the data synchronization unit that has completed the access read operation through the read record unit, determine whether there is a read record of the business data in the read record unit through the automatic deletion unit, and when the read record of the business data exists in the read record unit, the automatic deletion unit deletes the business data stored in the data synchronization unit.
[0016] The non-invasive security detection module is used to determine the sending timestamp of the business data based on the received security detection information, and compare the sending timestamp of the business data stored in the real-time data unit with the sending timestamp of the business data determined by the security detection information for consistency. When the sending timestamp of the business data stored in the real-time data unit is consistent with the sending timestamp of the business data determined by the security detection information, the non-invasive security detection module reads the business data stored in the real-time data unit of the unidirectional read link through the diversion link. When there is no business data in the real-time data unit that is consistent with the sending timestamp of the business data determined by the security detection information, the non-invasive security detection module generates network layer exception information of the logical device corresponding to the business data and sends it to the exception handling module; it is also used to generate hardware layer processing information of the corresponding logical device based on the successfully read business data;
[0017] The exception handling module is provided with a hardware layer exception handling unit and a network layer exception handling unit. The hardware layer exception handling unit is used to execute corresponding hardware exception handling measures according to the hardware layer processing information of the received logical device; the network layer exception handling unit is used to execute corresponding software exception handling measures according to the network layer exception information of the received logical device.
[0018] Furthermore, in the above-mentioned system, the SCD modeling module is used to generate the logical device layer, grid model layer and time data layer of the substation based on the SCD description file of the entire substation, and the process of constructing the business data integrated model includes:
[0019] Obtaining, according to the SCD description file of the entire substation, the data exchange relationship between each device in the substation, the data exchange relationship between each device and other functional modules, the data type of each device, and the functional unit of each device;
[0020] Establishing a logical device layer of the substation according to the functional units of each device in the substation;
[0021] Establishing a grid model layer of the substation according to the data exchange relationship between the various devices in the substation and the data exchange relationship between the various devices and other functional modules;
[0022] Obtaining the business data and the sending timestamp and receiving timestamp of each logical device in the logical device layer, constructing a timestamp data list of the business data according to the sending timestamp and the receiving timestamp, and obtaining a time data layer;
[0023] The grid model layer and the time data layer are superimposed on the logical device layer to obtain the business data integration model.
[0024] Furthermore, in the above-mentioned system, establishing the logical device layer of the substation according to the functional units of each device in the substation includes:
[0025] Building digital spaces;
[0026] Acquire the physical entity of the substation equipment in the physical space during the operation of the substation;
[0027] Based on the SCD description file, each functional unit within the substation equipment is represented in the form of a logical node, and the physical entity of the substation equipment is represented in the form of a logical device composed of several logical nodes and mapped to the digital space to obtain a logical device layer.
[0028] Furthermore, the system described above, wherein the grid model layer of the substation is established according to the data exchange relationship between the various devices in the substation and the data exchange relationship between the various devices and other functional modules, includes:
[0029] According to the data exchange relationship between each device in the substation and the data exchange relationship between each device and other functional modules, a data link path of each logical device in the digital space is constructed to obtain a grid model layer.
[0030] Furthermore, in the above-mentioned system, the process of the decoy cache module obtaining the target logical device that meets the decoy cache node deployment standard in the logical device layer of the business data integration model includes:
[0031] Acquire security event data of each device in the substation according to the historical business data stored in the data storage module;
[0032] Selecting evaluation indicators based on the security event data of each device in the substation, setting indicator weights and safety importance levels of the evaluation indicators, and determining the membership matrix of each device in the substation to the safety importance level through fuzzy comprehensive evaluation;
[0033] Obtaining a safety importance level of each device in the substation according to the membership matrix and the indicator weight;
[0034] It is determined whether the logical device corresponding to each device in the substation is the target logical device according to the safety importance level of each device in the substation.
[0035] Furthermore, in the above system, the step of determining whether the logical device corresponding to each device in the substation is the target logical device according to the safety importance level of each device in the substation includes:
[0036] Set preset security importance levels;
[0037] The logical device corresponding to the device in the substation whose safety importance level is higher than the preset safety importance level is set as the target logical device.
[0038] Furthermore, in the above-mentioned system, the process of the non-intrusive security detection module generating hardware layer processing information of the logical device based on the successfully read business data includes:
[0039] Generate a device layer security monitoring rule configuration file based on the substation-wide SCD configuration file, and determine the standard parameter indicators of each logical device in the business data integration model according to the device layer security monitoring rule configuration file;
[0040] When the non-intrusive security detection module successfully reads the service data of the logical device in the decoy cache node, it obtains the operating parameter value of the logical device according to the service data and compares the operating parameter value with the standard parameter indicator;
[0041] When the operating parameter value does not meet the standard parameter index, the non-intrusive safety detection module generates hardware layer processing information of the logical device and sends it to the exception processing module.
[0042] Furthermore, in the above-mentioned system, the security event data includes attack data flow type, number of data attacks and frequency of data attacks.
[0043] Furthermore, in the above-mentioned system, the business data at least includes: transformer data, circuit breaker data, bus data, relay data and control system data.
[0044] Furthermore, in the system described above, the functional units include at least: a functional unit representing a switching device, a functional unit representing a measuring device, a functional unit representing a protection device, a functional unit representing a control device, a functional unit representing a monitoring device, and a functional unit representing a data transmission and communication device.
[0045] The beneficial effects of the present invention are:
[0046] The present invention provides an intrusive security monitoring module to perform non-intrusive security monitoring on the event logs and business data of the substation equipment. While avoiding the indirect economic losses caused by the decline in power quality caused by the shutdown monitoring of the power equipment at the equipment layer, the present invention takes corresponding countermeasures in a timely manner by identifying abnormal behaviors at the equipment layer, potential threats at the network layer, and signs of attacks at the network layer. The entire monitoring activity will not affect the normal operation of the substation system and achieve a protective effect. At the same time, based on the business data integration model, the display of business data is clearer and more intuitive. In addition, by setting up decoy cache nodes and diversion links, the business data read from the database by the non-intrusive security monitoring module is converted into read data. The business data in the bait cache node is obtained, which avoids the network congestion of the database caused by the non-invasive security monitoring modules of multiple devices in the substation accessing the database at the same time, thereby improving the efficiency of non-invasive security monitoring; at the same time, when illegal data invades and steals the business data inside the substation, the business data in the bait cache node is first accessed, and the business data in the bait cache node is automatically deleted after being accessed. When the non-invasive security monitoring module accesses the business data of the bait cache node without detecting it, it is determined that there is illegal intrusion data, and relevant alarm information is generated and sent to the exception handling module. The bait cache node further ensures the business data security of the substation while improving the efficiency of invasive security monitoring. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0048] FIG1 is a structural diagram of an embodiment of a substation data security monitoring system based on SCD modeling according to the present invention. DETAILED DESCRIPTION
[0049] To make the objectives, technical solutions, and advantages of the present invention more apparent, the technical solutions of the present invention will be described in detail below. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other implementations obtained by those of ordinary skill in the art without inventive effort are within the scope of protection of the present invention.
[0050] Figure 1 is a schematic diagram of the structure of an embodiment of a substation data security monitoring system based on SCD modeling according to the present invention. Referring to Figure 1 , this embodiment may include: a monitoring center 1, which is communicatively connected to a data acquisition module 2, a data storage module 3, an SCD modeling module 4, a decoy cache module 5, a service data storage module 6, a non-intrusive security detection module 7, and an exception handling module 8;
[0051] The data acquisition module 2 is used to collect the business data of each device in the substation and send it to the database for storage, while recording the sending and receiving timestamps of the business data;
[0052] The data storage module 3 is used to store the historical business data of each device in the substation;
[0053] The SCD modeling module 4 is used to generate the substation's logical device layer, grid model layer and time data layer based on the SCD description file of the entire substation, and to build a business data integration model;
[0054] The decoy cache module 5 is used to obtain a target logical device that meets the decoy cache node deployment standard in the logical device layer of the business data integration model, and obtain the data link path of the target logical device in the grid model layer of the business data integration model, set a decoy cache node on the data link path between the target logical device and the database, and build a diversion link between the decoy cache node and the non-intrusive security detection module; wherein the decoy cache node includes a unidirectional read link and a unidirectional write link, the unidirectional write link is provided with a time verification unit, and the unidirectional read link is provided with a data synchronization unit, a read record unit, an automatic deletion unit, and a real-time data unit;
[0055] The business data transmission module 6 is used to transmit the business data in the business data integration model to the database through the bait cache node, and through the time verification unit set in the one-way write link. When the business data in the business data integration model is sent to the database through the one-way write link, the time verification unit obtains the sending timestamp of the business data based on the time data layer in the business data integration model, and sends the sending timestamp to the database, obtains the receiving timestamp of the existing business data in the database, compares the receiving timestamp with the sending timestamp sent to the database, and when the sending timestamp is greater than the receiving timestamp, the one-way write link allows the business data to be stored in the database, and at the same time, the business data and the sending timestamp of the business data are synchronously copied to the one-way read link, and sent to the non-invasive security detection module 7. Send security detection information. When the sending timestamp is less than or equal to the receiving timestamp, the unidirectional write link marks the business data as abnormal delay data and refuses to store the abnormal delay data in the database. When the unidirectional write link receives abnormal delay data three times in a row, it generates network layer abnormal information of the corresponding logical device and sends it to the abnormal processing module 8; it is also used to store the business data synchronously copied from the unidirectional write link to the unidirectional read link through the data synchronization unit set in the unidirectional read link, record the read record of the business data in the data synchronization unit that has completed the access read operation through the read record unit, determine whether there is a read record of the business data in the read record unit through the automatic deletion unit, and when there is a read record of the business data in the read record unit, the automatic deletion unit deletes the business data stored in the data synchronization unit;
[0056] The non-intrusive security detection module 7 is used to determine the sending timestamp of the business data based on the received security detection information, and compare the sending timestamp of the business data stored in the real-time data unit with the sending timestamp of the business data determined by the security detection information for consistency. When the sending timestamp of the business data stored in the real-time data unit is consistent with the sending timestamp of the business data determined by the security detection information, the non-intrusive security detection module 7 reads the business data stored in the real-time data unit of the unidirectional read link through the shunt link. When there is no business data in the real-time data unit that is consistent with the sending timestamp of the business data determined by the security detection information, the non-intrusive security detection module 7 generates network layer exception information of the logical device corresponding to the business data and sends it to the exception processing module 8; it is also used to generate hardware layer processing information of the corresponding logical device based on the successfully read business data;
[0057] The exception handling module 8 is provided with a hardware layer exception handling unit and a network layer exception handling unit. The hardware layer exception handling unit is used to execute corresponding hardware exception handling measures according to the hardware layer processing information received from the logical device; the network layer exception handling unit is used to execute corresponding software exception handling measures according to the network layer exception information received from the logical device.
[0058] It can be understood that this embodiment performs non-invasive security monitoring on the event logs and business data of the substation equipment by setting an invasive security monitoring module. While avoiding the indirect economic losses caused by the decline in power quality caused by the shutdown monitoring of the power equipment at the equipment layer, by identifying the abnormal behavior of the equipment layer, the potential threats at the network layer and the signs of network layer attacks, corresponding countermeasures are taken in time. The entire monitoring activity will not affect the normal operation of the substation system and achieve a protective effect. At the same time, based on the business data integration model, the display of business data is clearer and more intuitive, and by setting bait cache nodes and diversion links, the business data read by the non-invasive security monitoring module in the database is converted into The system reads the business data in the bait cache node, avoiding the network congestion of the database caused by the non-invasive security monitoring modules of multiple devices in the substation accessing the database at the same time, thereby improving the efficiency of non-invasive security monitoring; at the same time, when illegal data invades and steals the business data inside the substation, it first accesses the business data in the bait cache node, and the business data in the bait cache node is automatically deleted after being accessed. When the non-invasive security monitoring module accesses the business data of the bait cache node without detecting it, it determines that there is illegal intrusion data, and generates relevant alarm information and sends it to the exception handling module 8. The bait cache node further ensures the business data security of the substation while improving the efficiency of invasive security monitoring.
[0059] It should be noted that business data includes: transformer data, specifically monitoring data such as transformer temperature, humidity, oil level, oil quality, current, voltage, and test data such as insulation resistance, ground resistance, and winding resistance;
[0060] Circuit breaker data, specifically: circuit breaker current, voltage, switch status, operation times and other monitoring data;
[0061] Busbar data, specifically: busbar current, voltage, temperature, humidity and other monitoring data, as well as busbar grounding resistance and other test data;
[0062] Relay data, specifically: monitoring data such as current, voltage, frequency, and phase of relay protection devices, as well as event data such as fault records and protection action records;
[0063] Control system data, specifically: control system operation commands, status information, alarm information, equipment configuration and other data.
[0064] The functional units in the device represented by the logical nodes include but are not limited to:
[0065] Used to represent the functional units of switching equipment such as circuit breakers, disconnectors, etc.; used to represent the functional units of measuring equipment such as current transformers, voltage transformers, etc.; used to represent the functional units of protection equipment such as differential protection, overvoltage protection, etc.; used to represent the functional units of control equipment such as automation control devices, remote control devices, etc.; used to represent the functional units of monitoring equipment such as status monitoring devices, fault recording devices, etc.; used to represent the functional units of data transmission and communication equipment such as communication interfaces, Ethernet switches, etc.
[0066] Preferably, the SCD modeling module 4 is used to generate the substation's logical device layer, grid model layer, and time data layer based on the substation's entire SCD description file, and to construct a business data integration model. The process includes:
[0067] According to the SCD description file of the entire substation, the data exchange relationship between each device in the substation, the data exchange relationship between each device and other functional modules, the data type of each device and the functional unit of each device are obtained;
[0068] Establish a logical device layer for the substation based on the functional units of each device in the substation;
[0069] Establish the substation grid model layer based on the data exchange relationship between each device in the substation and the data exchange relationship between each device and other functional modules;
[0070] Obtain the business data, sending timestamp, and receiving timestamp of each logical device in the logical device layer, build a timestamp data list of the business data based on the sending timestamp and receiving timestamp, and obtain the time data layer;
[0071] The grid model layer and the time data layer are superimposed on the logical device layer to obtain the business data integration model.
[0072] Preferably, a logical device layer of the substation is established according to the functional units of each device in the substation, including:
[0073] Building digital spaces;
[0074] Obtain the physical entity of substation equipment in the physical space during substation operation;
[0075] Based on the SCD description file, each functional unit in the substation equipment is represented in the form of a logical node, and the physical entity of the substation equipment is represented in the form of a logical device composed of several logical nodes and mapped to the digital space to obtain a logical device layer.
[0076] Preferably, the grid model layer of the substation is established according to the data exchange relationship between the various devices in the substation and the data exchange relationship between each device and other functional modules, including:
[0077] According to the data exchange relationship between each device in the substation and the data exchange relationship between each device and other functional modules, the data link path of each logical device in the digital space is constructed to obtain the grid model layer.
[0078] It should be noted that the functional units in the device represented by the logical node include but are not limited to:
[0079] Used to represent the functional units of switchgear such as circuit breakers and disconnectors; used to represent the functional units of measuring equipment such as current transformers and voltage transformers; used to represent the functional units of protection equipment such as differential protection and overvoltage protection; used to represent the functional units of control equipment such as automation control devices and remote control devices; used to represent the functional units of monitoring equipment such as status monitoring devices and fault recorders; used to represent the functional units of data transmission and communication equipment such as communication interfaces and Ethernet switches;
[0080] The data link path defines the sender and receiver of the data flow, the data transmission method and transmission rules. The data transmission method includes but is not limited to TCP / IP, UDP, etc. The data transmission rules include but are not limited to the GOOSE communication protocol based on the IEC61850 standard, the sampling value transmission based on the IEC61850-9-2LE and IEC61850-9-2HSR standards, the message transmission based on MQTT, the data interaction based on Web services, etc.
[0081] Preferably, the process of the decoy cache module 5 acquiring the target logical device that meets the decoy cache node deployment standard in the logical device layer of the business data integration model includes:
[0082] Obtain security event data of each device in the substation based on the historical business data stored in the data storage module 3;
[0083] Select evaluation indicators based on the safety event data of each device in the substation, set the indicator weights and safety importance levels of the evaluation indicators, and determine the membership matrix of each device in the substation to the safety importance level through fuzzy comprehensive evaluation;
[0084] Obtain the safety importance level of each device in the substation based on the membership matrix and indicator weight;
[0085] According to the safety importance level of each device in the substation, it is determined whether the logical device corresponding to each device in the substation is the target logical device.
[0086] Preferably, judging whether the logical device corresponding to each device in the substation is the target logical device according to the safety importance level of each device in the substation includes:
[0087] Set preset security importance levels;
[0088] The logical device corresponding to the device in the substation whose safety importance level is higher than the preset safety importance level is set as the target logical device.
[0089] Preferably, the security event data includes attack data flow type, number of data attacks and frequency of data attacks.
[0090] It can be understood that the data attack frequency changes in real time. First, the historical data attack frequency is generated based on the data attack timestamp and the number of data attacks of the attack data stream in the data storage module 3, and the time between the last data attack timestamp of the attack data stream and the current data attack time is obtained, and the data attack timestamp of the attack data stream is updated. The updated data attack frequency is generated based on the updated data attack timestamp and the number of data attacks.
[0091] Preferably, the process of the non-intrusive security detection module 7 generating hardware layer processing information of the logical device according to the successfully read business data includes:
[0092] Generate a device layer security monitoring rule configuration file based on the substation-wide SCD configuration file, and determine the standard parameter indicators of each logical device in the business data integration model according to the device layer security monitoring rule configuration file;
[0093] When the non-intrusive security detection module 7 successfully reads the service data of the logical device in the decoy cache node, it obtains the operating parameter value of the logical device according to the service data and compares the operating parameter value with the standard parameter index;
[0094] When the operating parameter value does not meet the standard parameter index, the non-intrusive safety detection module 7 generates hardware layer processing information of the logical device and sends it to the exception processing module 8 .
[0095] It can be understood that the same or similar parts of the above embodiments can be referenced to each other, and the contents not described in detail in some embodiments can refer to the same or similar contents in other embodiments.
[0096] It should be noted that, in the description of the present invention, the terms "first", "second", etc. are used for descriptive purposes only and should not be understood as indicating or implying relative importance. In addition, in the description of the present invention, unless otherwise specified, the meaning of "plurality" is at least two.
[0097] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, segment or portion of code comprising one or more executable instructions for implementing the steps of a specific logical function or process, and the scope of the preferred embodiments of the present invention includes alternative implementations in which functions may be performed out of the order shown or discussed, including performing functions in a substantially simultaneous manner or in the reverse order depending on the functions involved, which should be understood by those skilled in the art to which the embodiments of the present invention pertain.
[0098] It should be understood that various parts of the present invention can be implemented using hardware, software, firmware, or a combination thereof. In the above-described embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0099] Those skilled in the art will understand that all or part of the steps in the method of the above embodiment can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiment.
[0100] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing module, or each unit may exist physically separately, or two or more units may be integrated into a single module. The aforementioned integrated modules may be implemented in the form of hardware or in the form of software functional modules. If the integrated modules are implemented in the form of software functional modules and sold or used as independent products, they may also be stored in a computer-readable storage medium.
[0101] The storage medium mentioned above can be a read-only memory, a magnetic disk or an optical disk, etc.
[0102] Throughout this specification, reference to terms such as "one embodiment," "some embodiments," "examples," "specific examples," or "some examples" means that a specific feature, structure, material, or characteristic described in conjunction with that embodiment or example is included in at least one embodiment or example of the present invention. In this specification, schematic representations of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in any one or more embodiments or examples.
[0103] Although the embodiments of the present invention have been shown and described above, it will be understood that the above embodiments are illustrative and are not to be construed as limitations on the present invention. A person skilled in the art may change, modify, replace and modify the above embodiments within the scope of the present invention.
Claims
1. A substation data security monitoring system based on SCD modeling, including a monitoring center, characterized in that: The monitoring center is communicatively connected with a data acquisition module, a data storage module, an SCD modeling module, a decoy cache module, a business data transmission module, a non-intrusive security detection module and an exception handling module; The data acquisition module is used to collect the business data of each device in the substation and send it to the database for storage, while recording the sending timestamp and receiving timestamp of the business data; The data storage module is used to store the historical business data of each device in the substation; The SCD modeling module is used to generate the logical device layer, grid model layer and time data layer of the substation based on the SCD description file of the entire substation, and build a business data integration model; The decoy cache module is used to obtain the target logical device that meets the decoy cache node deployment standard in the logical device layer of the business data integration model, and obtain the data link path of the target logical device in the grid model layer of the business data integration model, set the decoy cache node on the data link path between the target logical device and the database, and build a diversion link between the decoy cache node and the non-intrusive security detection module; wherein the decoy cache node contains a unidirectional read link and a unidirectional write link, the unidirectional write link is provided with a time verification unit, and the unidirectional read link is provided with a data synchronization unit, a read record unit, an automatic deletion unit and a real-time data unit; The business data transmission module is used to transmit the business data in the business data integration model to the database through the decoy cache node, and through the time verification unit set in the unidirectional write link, when the business data in the business data integration model is sent to the database through the unidirectional write link, the time verification unit obtains the sending timestamp of the business data based on the time data layer in the business data integration model, sends the sending timestamp to the database, obtains the receiving timestamp of the business data already in the database, and compares the receiving timestamp with the sending timestamp sent to the database. When the sending timestamp is greater than the receiving timestamp, the unidirectional write link allows the business data to be stored in the database, and synchronously copies the business data and the sending timestamp of the business data to the unidirectional read link, and sends security detection information to the non-intrusive security detection module. When the sending timestamp is less than or equal to the receiving timestamp, the unidirectional write link marks the business data as abnormal delay data and refuses to store the abnormal delay data in the database. When the unidirectional write link receives the abnormal delay data three times in a row, it generates network layer abnormal information of the corresponding logical device and sends it to the abnormal handling module; it is also used to store the business data synchronously copied from the unidirectional write link to the unidirectional read link through the data synchronization unit set in the unidirectional read link, record the read record of the business data in the data synchronization unit being accessed and read through the read record unit, determine whether there is a read record of the business data in the read record unit through the automatic deletion unit, and when there is a read record of the business data in the read record unit, the automatic deletion unit deletes the business data stored in the data synchronization unit; The non-intrusive security detection module is used to determine the sending timestamp of the business data according to the received security detection information, and compare the sending timestamp of the business data stored in the real-time data unit with the sending timestamp of the business data determined by the security detection information for consistency. When the sending timestamp of the business data stored in the real-time data unit is consistent with the sending timestamp of the business data determined by the security detection information, the non-intrusive security detection module reads the business data stored in the real-time data unit of the unidirectional read link through the shunt link. When there is no business data in the real-time data unit that is consistent with the sending timestamp of the business data determined by the security detection information, the non-intrusive security detection module generates network layer exception information of the logical device corresponding to the business data and sends it to the exception handling module; it is also used to generate hardware layer processing information of the corresponding logical device according to the successfully read business data; The exception handling module is provided with a hardware layer exception handling unit and a network layer exception handling unit, and the hardware layer exception handling unit is used to handle the hardware layer of the received logical device according to the hardware layer processing The information executes corresponding hardware exception handling measures; the network layer exception handling unit is used to execute corresponding software exception handling measures according to the network layer exception information received from the logical device.
2. The system according to claim 1, characterized in that The SCD modeling module is used to generate the logical device layer, grid model layer and time data layer of the substation based on the SCD description file of the entire substation, and the process of building a business data integration model includes: According to the SCD description file of the entire substation, the data exchange relationship between each device in the substation, the data exchange relationship between each device and other functional modules, the data type of each device and the functional unit of each device are obtained; Establishing a logical device layer of the substation according to the functional units of each device in the substation; Establishing a grid model layer of the substation according to the data exchange relationship between the various devices in the substation and the data exchange relationship between the various devices and other functional modules; Obtaining the business data and the sending timestamp and receiving timestamp of each logical device in the logical device layer, constructing a timestamp data list of the business data according to the sending timestamp and the receiving timestamp, and obtaining a time data layer; The grid model layer and the time data layer are superimposed on the logic device layer to obtain the business data integration model.
3. The system according to claim 2, characterized in that The step of establishing a logical device layer of the substation according to the functional units of each device in the substation includes: Building digital spaces; Acquire the physical entity of the substation equipment in the physical space during the operation of the substation; Based on the SCD description file, each functional unit within the substation equipment is represented in the form of a logical node, and the physical entity of the substation equipment is represented in the form of a logical device composed of several logical nodes and mapped to the digital space to obtain a logical device layer.
4. The system according to claim 3, characterized in that The step of establishing the grid model layer of the substation according to the data exchange relationship between the various devices in the substation and the data exchange relationship between the various devices and other functional modules includes: According to the data exchange relationship between the various devices in the substation and the data exchange relationship between the various devices and other functional modules, the data link path of each logical device in the digital space is constructed to obtain the grid model layer.
5. The system according to claim 4, characterized in that The process of the decoy cache module acquiring the target logical device that meets the decoy cache node deployment standard in the logical device layer of the business data integration model includes: Acquire the security event data of each device in the substation according to the historical business data stored in the data storage module; Selecting evaluation indicators according to the safety event data of each device in the substation, setting the indicator weights and safety importance levels of the evaluation indicators, and judging the membership matrix of each device in the substation for the safety importance level through fuzzy comprehensive evaluation; Obtaining the safety importance level of each device in the substation according to the membership matrix and the indicator weight; It is determined whether the logical device corresponding to each device in the substation is the target logical device according to the safety importance level of each device in the substation.
6. The system according to claim 5, characterized in that The determining, according to the safety importance level of each device in the substation, whether the logical device corresponding to each device in the substation is the target logical device includes: Set preset security importance levels; The logical device corresponding to the device in the substation whose safety importance level is higher than the preset safety importance level is set as the target logical device.
7. The system according to claim 6, characterized in that The process in which the non-intrusive security detection module generates hardware layer processing information of the logical device based on the successfully read business data includes: Generate a device-layer security monitoring rule configuration file based on the substation-wide SCD configuration file, and determine the standard parameter indicators of each logical device in the business data integration model according to the device-layer security monitoring rule configuration file; When the non-intrusive security detection module successfully reads the business data of the logical device in the decoy cache node, it obtains the operating parameter value of the logical device according to the business data, and compares the operating parameter value with the standard parameter indicator; When the operating parameter value does not meet the standard parameter index, the non-intrusive safety detection module generates hardware layer processing information of the logical device and sends it to the exception processing module.
8. The system according to claim 7, characterized in that The security event data includes attack data flow type, data attack times and data attack frequency.
9. The system according to claim 8, characterized in that The business data at least includes: transformer data, circuit breaker data, bus data, relay data and control system data.
10. The system according to claim 9, characterized in that The functional units at least include: a functional unit representing a switch device, a functional unit representing a measuring device, a functional unit representing a protection device, a functional unit representing a control device, a functional unit representing a monitoring device, and a functional unit representing a data transmission and communication device.
Citation Information
Patent Citations
Intelligent substation network intrusion detection system and detection method based on deep learning
CN110086776A
Non-invasive intelligent substation vulnerability detection method
CN111131274A
Transformer substation global Internet of Things system based on smart rod and 5G and operation method thereof
CN112803594A
Substation data safety monitoring system based on SCD modeling
CN117527436A
Non-Intrusive Digital Agent for Behavioral Monitoring of Cybersecurity-Related Events in an Industrial Control System
US20170093885A1