Diao Yang, Chen Hui, Liu Wei, Rasool Abdur
Shaoguan Power Supply Bureau, Guangdong Power Grid Co., Ltd., Shaoguan, Guangdong, China.
School of Artificial Intelligence, Shenzhen Polytechnic University, Shenzhen, GuangDong, China.
PeerJ Comput Sci. 2024 Nov 22;10:e2512. doi: 10.7717/peerj-cs.2512. eCollection 2024.
A substation is integral to the functioning of a power grid, enabling the efficient and safe transmission and distribution of electrical energy to meet the demands of consumers. The digital transformation of critical infrastructures, particularly in the electric power sector, such as the emergence of intelligent substations, is a double-edged sword. While it brings about efficiency improvements and consumer-centric advancements, it raises concerns about the heightened vulnerability to cyberattacks. This article proposes a new static-dynamic strategy for host security detection by implementing a system prototype and evaluating its detection accuracy. To reduce the subjectivity in manually selecting features, we combine classified protection for cybersecurity-related standards and construct the requirement generation algorithm to construct a network security detection standard library for the substation host. Based on this, we develop strategy generation algorithm to match the list of host detection projects to obtain the security detection strategy of the target host. Moreover, we output and analyze the detection logs to obtain a security detection report. The prototype is efficient and effective through practical use, and it serves as a practical tool in substation host security detection. The experiments suggest that the mechanism proposed in our study can operate at a high speed and demonstrates satisfactory performance in terms of detection.
变电站对于电网的运行不可或缺,它能实现电能的高效、安全传输与分配,以满足用户需求。关键基础设施的数字化转型,尤其是电力部门,比如智能变电站的出现,是一把双刃剑。虽然它带来了效率提升和以用户为中心的进步,但也引发了对网络攻击脆弱性增加的担忧。本文通过实现一个系统原型并评估其检测准确性,提出了一种新的主机安全检测静态 - 动态策略。为减少手动选择特征时的主观性,我们结合对网络安全相关标准的分类保护,构建需求生成算法,为变电站主机构建网络安全检测标准库。在此基础上,我们开发策略生成算法,使其与主机检测项目列表相匹配,以获取目标主机的安全检测策略。此外,我们输出并分析检测日志以获得安全检测报告。通过实际应用,该原型高效且有效,它是变电站主机安全检测的实用工具。实验表明,我们研究中提出的机制能够高速运行,并且在检测方面表现出令人满意的性能。