The invention provides a
network security threat evaluation method for a substation
monitoring system. The method comprises the steps of firstly, reading a UML graph which describes a
monitoring system application scene, and identifying primary
network security threats and
attack objects of the substation
monitoring system; then analyzing and combining the
network security threats, outputting a monitoring
system security
threat model, and refining the model into an
attack tree; and finally, carrying out formalized description on the
attack processes and attack behaviors of the specific network security threats, and outputting the attack processes and attack behaviors in an Object-Z format. Correspondingly, the invention also provides a matched network security
threat evaluation system for the substation monitoring
system. According to the method provided by the invention, the network security threats of the monitoring
system can be described qualitatively, and the network security threats are visual and clear; and the threat attack behaviors are described by use of a formalized mathematical language, and therefore, corresponding defensive measures can be provided.