Dynamic IP Defense for New Energy Control Stations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

New energy centralized control station networks face significant network security challenges, including hacker attacks and malicious software infections, which can lead to system paralysis and safety risks. Traditional static defense methods are inadequate in addressing internal threats and changing network environments, and the use of fixed IP addresses makes these systems vulnerable to targeted attacks.

Innovation Solution

A dynamic defense system and method for new energy centralized control station networks based on dynamic IP addresses. This system involves acquiring network parameters, constructing an IP address mapping table, monitoring network traffic, evaluating defense states, and dynamically adjusting IP addresses and firewall rules to resist malicious reconnaissance and attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional static defense means (firewall, IDS) are used, then external attacks can be prevented to a certain extent, but adaptability to internal threats and changing network environments is poor

Engineering Contradiction:
Improvedefense effectivenessVSAvoidadaptability to internal threats and changing network environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic IP address allocation and dynamic firewall rules that automatically adjust based on network traffic analysis. The system transitions from static defense configurations to dynamic ones where IP addresses and firewall rules can change in real-time according to detected threats and network conditions, thereby improving adaptability while maintaining reliability

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system dynamically changes network parameters including IP addresses, port assignments, and firewall rule sets based on analyzed network traffic patterns and threat detection results. This parameter dynamicization allows the defense system to adapt to evolving threats while maintaining effective protection

Inventive Principle:
Principle #35Parameter changes

2Ease of manufacture

If a fixed IP address is adopted, then network configuration is simple, but it is easier for attackers to find targets and carry out targeted attacks

Engineering Contradiction:
Improvenetwork configuration simplicityVSAvoidvulnerability to targeted attacks
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic IP address allocation where the centralized control station's IP address changes periodically or based on security conditions. This dynamic IP mechanism maintains configuration simplicity through automated management while significantly reducing vulnerability to targeted attacks by making the target location unpredictable

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary anti-action by proactively changing IP addresses before attackers can identify and target the system. The dynamic IP mechanism preemptively counteracts potential targeted attacks by ensuring the target address is not static or predictable

Inventive Principle:
Principle #9Preliminary anti-action

3Object-affected harmful factors

If dynamic IP adjustment is implemented, then malicious network reconnaissance can be resisted, but system complexity increases

Engineering Contradiction:
Improveresistance to malicious network reconnaissanceVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system implements self-service through automated IP address management and dynamic firewall rule generation. The centralized control station automatically performs IP allocation, traffic analysis, threat detection, and rule updates without requiring manual intervention, thereby resisting malicious reconnaissance while managing system complexity through automation

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses feedback mechanisms where network traffic is continuously monitored and analyzed, and the results feed back into automatic IP address and firewall rule adjustments. This closed-loop feedback system enables effective resistance to reconnaissance attacks while managing complexity through automated decision-making based on observed network conditions

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12289333B2Dynamic defense system and method of new energy centralized control station network based on dynamic IP
Publication Date: 2025.04.29 ELECTRIC POWER RES INST STATE GRID JIANGXI ELECTRIC POWER CO
  • US12289333B2 patent drawing
  • US12289333B2 patent drawing
  • US12289333B2 patent drawing

AI summary

A method of a new energy centralized control station network based on dynamic IP can determine the occurrence frequency and the occurrence interval of the abnormal traffic, further analyze and determine the defense state of a new energy centralized control station based on this, and execute the corresponding dynamic optimization solution according to different defense states, so that the IP address and the firewall of the new energy centralized control station can be dynamically adjusted to ensure the security performance of the new energy centralized control station, reduce the risk of external intrusion, effectively resist malicious network reconnaissance such as scanning attacks and ensure the stable operation of a new energy power generation system.