WO2014173173A1 - 智能电网安全督查自动化系统 - Google Patents
智能电网安全督查自动化系统 Download PDFInfo
- Publication number
- WO2014173173A1 WO2014173173A1 PCT/CN2014/000255 CN2014000255W WO2014173173A1 WO 2014173173 A1 WO2014173173 A1 WO 2014173173A1 CN 2014000255 W CN2014000255 W CN 2014000255W WO 2014173173 A1 WO2014173173 A1 WO 2014173173A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- supervision
- smart grid
- inspection
- security
- task
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q10/00—Administration; Management
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q50/00—Information and communication technology [ICT] specially adapted for implementation of business processes of specific business sectors, e.g. utilities or tourism
- G06Q50/06—Energy or water supply
Definitions
- the invention relates to the field of smart grid security monitoring technology, in particular to a smart grid security supervision automation system.
- security configuration is also an aspect that can be exploited by hackers and requires security hardening.
- the smart grid Compared with the general grid, the smart grid has wider openness and system complexity, and can interact with the outside world, which means it is more vulnerable to external intrusion.
- new equipment and new technologies in the fields of wireless communication continue to emerge, and are gradually applied to the construction of power communication networks, making smart grids have complex access environments, flexible and diverse access methods, and a large number of intelligent access.
- Features such as terminals, which will increase the security risks of smart grids.
- it is necessary to strengthen and implement the safety requirements of the State Grid Corporation for smart grid equipment from all stages of equipment life testing, project acceptance and operation and maintenance, and to establish safety inspectors meeting relevant safety requirements. Library.
- the object of the present invention is to develop an automated system for the safety supervision of smart grid equipment in the power industry.
- the smart grid security supervision and automation system of the invention comprises:
- Smart Grid Supervisor Used to store inspection templates for different types of smart grid equipment
- Supervisor Template Editor Used to edit the default supervision template in the inspection library to generate a new inspection template for a certain type of smart grid equipment
- Supervise task editor Define and issue inspection tasks, explicitly use a default or edit generated inspection template to perform security inspection on a range of smart grid devices;
- Supervise task actuators The included inspection template is interpreted and implemented for safety supervision;
- the security supervision task generated by the security supervision task editor for a smart grid device is sent to the security supervision task interpretation actuator installed on the smart grid device, and the smart grid device security supervisor is The execution result of the inspection task is submitted to the safety supervision result analyzer for analysis of the inspection result; the inspection result display: The safety supervision result report of the selected smart grid equipment is generated based on the result of the inspection result analyzer.
- the scalable smart grid inspection library is configured to store an inspection template for different types of smart grid devices, and the supervision template is composed of one or more security inspection items. Involving account passwords, rights assignment, security auditing, remote access control, kernel security, file system security, performance security, etc., for each security supervision item, the method of automatic supervision, the judgment result judgment standard and the supervision item are also defined. Information such as weight points, data sources and standards for the supervision template are from the national grid company's safety requirements and standards for various smart grid equipment.
- the supervision template in the smart grid inspection library can be supervised by the template boundary controller and supervisor.
- the supervising task executor completes the smart grid equipment safety supervision work, according to the smart grid
- the security supervision automation protocol encapsulates the inspection result information in an XML file, and sends it to the inspection task result display module through the SSL encryption communication interface, and the inspection task display module monitors the task result.
- the smart grid security inspection automation system of the invention has the advantages of: quickly and accurately defining a security supervision template for various known smart grid devices, and an inspection template for a new smart grid device to be introduced in the future
- Customizing the security supervision template according to this standard protocol greatly improves the security inspector scope of the smart grid equipment and the flexibility of the new smart grid equipment security supervision template formulation, and quickly delivers the security supervision task to the designated smart grid.
- Figure 1 is a schematic diagram of the structure of the smart grid security supervision library.
- Figure 2 is a schematic diagram of the data flow of the safety supervision automation system.
- Figure 3 is a schematic diagram of the smart grid security supervision automation protocol.
- the smart grid inspection library is used to store inspection templates for different types of smart grid equipment.
- the supervision template includes the system's predefined default supervision template. Different inspection templates are based on the national grid for the smart grid. Relevant safety requirements, including one or more safety oversight items.
- the custom security supervision template for a certain type of smart grid equipment generated by editing and modifying with the predefined default supervision template is also stored in the smart grid security supervision database.
- the predefined default safety oversight templates in the Smart Grid Safety Oversight Library are based on the National Grid's relevant safety specifications for a certain type of Smart Grid equipment.
- the inspection template editor is used to edit the default supervision template of the smart grid security supervision library, select the default supervision template predefined for a smart grid device in the smart grid security inspection library, and the default supervision
- the inspection items in the template are edited to generate a custom security inspection template for the smart grid equipment of this type, and the custom security supervision template is stored in the smart grid security inspection library.
- the safety supervision task interpretation actuator is deployed on the smart grid device, receiving the security supervision task in the XML file format issued by the inspection task editor, and interpreting the security supervision task in the XML format and Execution, supervision task interpretation of the actuator is mainly through reading the smart grid device configuration file, or executing system instructions on the smart grid device to complete the security supervision task.
- the inspection result analyzer based on the above-mentioned safety supervision task interpretation actuator, generates a corresponding safety level for a smart grid equipment safety inspection result, and gives a safety repair suggestion.
- the results of the inspection show that the safety supervision results report of the selected smart grid equipment is generated based on the results of the above-mentioned safety supervision result analyzer.
- the security supervision automation system uses SSL to ensure the integrity, confidentiality and consistency of the communication data.
- the communication interface needs to be responsible for the initialization of the communication port, the initialization of the SSL process, and various abnormalities in the communication process.
- Figure 2 shows the security inspection automation system data flow
- the Security Oversight Template Editor invokes a predefined default security audit template from the Smart Grid Security Supervisory Library to modify and generate a custom security audit template for a certain type of smart grid device.
- Customized security supervision template The most task information is imported into the supervision task editor. At the same time, the inspection task end time is defined in the supervision task editor, the target smart grid equipment information is supervised, and the inspection task passes the score information. . 3 The audit task editor assembles the above information into an XML file according to the smart grid security supervision automation protocol disclosed in the present invention, and sends it to the communication interface.
- the communication interface and the target smart grid device establish an SSL secure channel and send the XML task file to the target smart grid device.
- the audit task explained by the target smart grid explains that the executor performs security audits according to the security audit tasks defined in the task XML file.
- the smart grid device communication interface sends the security supervision result information to the security supervision automation system through the SSL secure channel.
- the communication interface submits the safety supervision result information to the supervision result analyzer, generates a corresponding safety level according to the safety supervision result of the smart grid device, and gives a safety repair suggestion.
- the safety supervision report generator generates a safety supervision result report of the selected smart grid device based on the result of the above-mentioned safety supervision result analyzer.
- FIG. 3 shows a schematic diagram of a smart grid security supervision automation protocol disclosed in the present invention: a smart grid security supervision library realized by this standard protocol can realize fast and accurate definition for various known smart grid devices.
- the security supervision template, the supervision template for the new smart grid equipment that needs to be introduced in the future can also be customized according to this standard protocol.
- the security supervision task can be quickly delivered to the designated smart grid equipment to collect distributed smart grid equipment configuration information through a structured data format.
- the overall structure consists of four parts: version information, smart grid equipment type, safety supervision project, safety supervision method, and the following:
- the version information identifier is used to describe the version information of the security supervision template, including: version ID, revision number.
- the smart grid device type contains the standard naming information of the smart grid device hardware and software. This information can be used to determine the security supervision method and corresponding security solutions, including: device type, manufacturer, device model, software version, for different types of intelligence.
- Grid equipment can be associated with one or more security oversight items.
- Security supervision item 0 involving account password, authority allocation, security audit, remote access control, kernel security, file system security, performance security, etc., including: security supervision project number, security supervision project name, security standard value, security Supervise project weights, descriptions, and security fixes.
- security inspection method For a safety inspection project, one or more safety inspection methods may be required to complete the relationship between these safety inspection methods.
- the safety supervision method is a set of instructions for conducting safety supervision, for example, setting the password complexity of the smart grid equipment, including: safety supervision item number, implementation method, supervision information acquisition path, and judgment standard.
- Description and safety fix information includes descriptions of safety oversight items, mapping of national grid related safety regulations, and corresponding safety fixes.
- the association between the safety inspection method and the safety inspection item is based on the safety supervision item number.
- the implementation method in the security supervision method may be a method of reading system configuration information or a method of executing related system instructions.
- the supervisor information acquisition path contains the path information of the system configuration information file to be read, or the path information of a certain system instruction.
- the judgment standard in the safety supervision method is to compare the obtained inspection result information with the safety standard value in the safety supervision item, and the comparison method may be equal to, greater than, less than or included.
Landscapes
- Business, Economics & Management (AREA)
- Engineering & Computer Science (AREA)
- Economics (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Marketing (AREA)
- Health & Medical Sciences (AREA)
- Theoretical Computer Science (AREA)
- Strategic Management (AREA)
- Tourism & Hospitality (AREA)
- Human Resources & Organizations (AREA)
- General Business, Economics & Management (AREA)
- Entrepreneurship & Innovation (AREA)
- Quality & Reliability (AREA)
- Operations Research (AREA)
- Public Health (AREA)
- Water Supply & Treatment (AREA)
- General Health & Medical Sciences (AREA)
- Primary Health Care (AREA)
- Storage Device Security (AREA)
- Testing And Monitoring For Control Systems (AREA)
Abstract
一种智能电网安全督査自动化系统,包括:智能电网督查库,督查模板编辑器,督査任务编辑器,督查任务执行器,督査结果分析器,通讯接口,督查结果展示。其优点是:能实现快速、准确的定义针对各种已知智能电网设备的安全督査模板,对于未来需要引入的新智能电网设备的督査模板也可以按照此标准协议进行安全督查模板的定制,大大提高了智能电网设备的安全督察范围和新智能电网设备安全督查模板制定的灵活性,快速的将安全督査任务下发到指定的智能电网设备,以实现通过结构化的数据格式收集分散的智能电网设备配置信息。
Description
智能电网安全督查自动化系统
技术领域
本发明涉及智能电网安全监测技术领域, 具体地说是一种智能电网安全督査 自动化系统。
背景技术
智能电网齊及后, 随着业务的发展, 安全问题会越来越被重视, 除了这些设 备自身的漏洞外, 安全配置也是会被黑客利用的一个方面, 需要进行安全加固。
智能电网和一般电网相比, 具有更广阔的开放性和系统复杂性, 可以实现和 外界的互动, 也就意味着更容易受到外来侵扰。 同时, 无线通信等领域的新设备、 新技术不断涌现, 并逐步广泛应用到电力通信网络的建设中, 使得智能电网具有 复杂的接入环境、 灵活多样的接入方式、 数量庞大的智能接入终端等特征, 这将 加大智能电网的安全风险。 例如, W前许多正在部署的、 用以支持智能电网项 的技术——智能电表、 传感器等, 都会加大电网受攻击的风险。 为保证智能电网 系统的安全, 必须从设备入网测试、 工程验收和运行维护等设备全生命周期各个 阶段加强和落实国家电网公司对智能电网设备相关安全要求, 同时需要设立满足 相关安全要求的安全督察库。
安全督查库中需要制定各种智能电网设备安全检查点、 操作指南和操作标 准。安全督査库的制定为智能电网设备标准化的安全操作提供了框架和标准。 也 为运维人员提供了检査默认风险的标杆, 但是面对智能电网系统中种类繁杂、 数 量众多的设备和软件, 如何快速、 有效的检查设备, 乂如何集中收集督査的结果, 以及制作督查报告, 并且最终识别那些与督查库规范不符合的项 t!, 以达到整改 合规的要求, 这些都是运维人员面临的新的难题。
目前国内还没有能够支持各种智能电网设备的通用安全督查工具, 无法有效 对其系统脆弱性进行检杳, 也无法 [^动化的实现电网公司相关安全规范的合规性 检査, 导致智能电网设备容易遭受口令破解、 非法连接、 非法植入恶意软件等攻 击, 可能引发电力系统中一些功能的丧失, 以及敏感数据的非法篡改。
发明内容
本发明的目的研究一种针对电力行业智能电网设备进行安全督査的自动化系 统。
本发明智能电网安全督査自动化系统, 包括:
智能电网督库: 用于存放针对不同类型智能电网设备的督査模板;
督查模板编辑器: 用于对督査库中的默认督査模板进行编辑, 以生成针对某 一类智能电网设备新的督查模板;
督查任务编辑器: 定义并下发督查任务, 明确使用某一默认或编辑生成的督 査模板, 对某一范围的智能电网设备进行安全督査工作; 督查任务执行器: 对任务中所包含的督査模板进行解释执行, 以进行安全督 査工作;
督杳结果分析器: 基于督査任务解释执行器对某一智能电网设备安全督查结 果来生成相应的安全级别, 并给出安全修复建议;
通讯接口: 将安全督査任务编辑器所生成的针对某一智能电网设备的安全督 查任务下发给该智能电网设备上安装的安全督査任务解释执行器, 并将该智能电 网设备安全督査任务的执行结果提交给安全督杳结果分析器进行督査结果分析; 督査结果展示: 基于督査结果分析器的结果来生成所选智能电网设备的安全 督查结果报告。
信息进行归并和统一呈现。 所述的可扩展的智能电网督查库, 用于存放针对 不同类型智能电网设备的督査模板,督査模板是由一个或多个安全督查项目组成,
涉及账号口令、 权限分配、 安全审计、 远程访问控制、 内核安全、 文件系统安全、 性能安全等,针对每个安全督杳项 还定义了自动化督査的方法、督査结果判断标 准和督查项权重分值等信息,督査模板的数据来源和制定标准来自国家电网公司 对各种智能电网设备的安全要求和标准,智能电网督査库中的督查模板可被督査 模板边界器和督査任务编辑器调用; 督査模板编辑器, 调用智能电网督査库中的 默认督查模板, 并对其进行编辑, 以生成针对某一类智能电网设备新的督査模板, 或是在原有督查模板的基础上针对新增加的智能电网设备定义督査模板; 督查任 务编辑器, 针对某一类智能电网设备, 调用智能电网督查库中的默认督査模板和 自定义督査模板, 定义安全督査任务, 在安全督査任务中还包括任务执行时间以 及考核分数等信息; 督査任务定义工作完成后, 系统将按照本发明中公布的智能 电网安全督査自动化协议, 将督査任务相关信息以 XML文件的形式, 通过 SSL加 密通讯接口下发给安装在智能电网设备上的任务解释执行器, 由督査任务执行器 对) (ML任务文件进行解析, 并对包含其中的督査模板进行解释执行。 督查任务执 行器在完成智能电网设备安全督査工作后, 按照智能电网安全督查自动化协议, 将督査结果信息封装在 XML文件中, 通过 SSL加密通讯接口发送给督查任务结果 展示模块, 由督査任务展示模块对督査任务结果
本发明智能电网安全督査自动化系统, 其优点是: 能实现快速、 准确的定义 针对各种已知智能电网设备的安全督査模板, 对于未来需要引入的新智能电网设 备的督査模板也可以按照此标准协议进行安全督査模板的定制, 大大提高了智能 电网设备的安全督察范围和新智能电网设备安全督查模板制定的灵活性, 快速的 将安全督査任务下发到指定的智能电网设备, 以实现通过结构化的数据格式收集 分散的智能电网设备配置信息。
附图说明
图 1为智能电网安全督查库结构示意图。
图 2为安全督査自动化系统数据流示意图。
图 3为智能电网安全督查自动化协议示意图。
具体实施方式
如图 1所示, 智能电网督查库, 用于存放针对不同类型智能电网设备的督查 模板, 督杳模板包括系统预定义的默认督査模板, 不同的督査模板按照国家电网 针对智能电网相关安全要求, 包括一个或多个安全督査项目。 同时利用预定义的 默认督査模板进行编辑和修改后生成的针对某一类智能电网设备的自定义安全督 査模板也存放在智能电网安全督杳库中。 智能电网安全督查库中的预定义默认安 全督杳模板以国家电网针对某一类型智能电网设备的相关安全规范为基础进行制 定。 每个预定义安全督査模板中包含一个或多个针对某-一类型智能电网设备的安 全督查项目, 包括账号口令类安全督查项目、 权限控制类安全督查项目、 安全审 计类安全督査项目、远程访问控制类安全督査项 1=1、 文件系统类安全督查项目等。
督査模板编辑器, 用于对智能电网安全督查库屮的默认督査模板进行编辑, 选择智能电网安全督查库中针对某一智能电网设备预定义的默认督査模板, 对默 认督査模板中的督査项目进行编辑, 以生成针对该类智能电网设备的自定义安全 督査模板, 自定义安全督査模板存放在智能电网安全督査库中。
督査任务编辑器, 从智能电网安全督查库中选择针对某一个或多个智能电网 设备的预定义默认安全督査模板或自定义安全督査模板, 对所选定的一个或多个 智能电网设备, 定义并下发安全督査任务。 定义督査任务时需要确定督查任务执 行结束时间以及督査结果通过分值。 在完成安全督査任务的定义后, 安全督査任 务编辑器会按照安全督査任务定义时所选择的安全督査模板信总、 目标督査智能 电网设备信息、 安全督査任务结束时间、 安全督査任务通过分值等信息, 依据本 发明中公布的一种智能电网安全督查自动化协议, 将上述信息组装成 XML文件格
式的任务文件。
督查任务解释执行器, 安全督査任务解释执行器部署在智能电网设备上, 接 收督査任务编辑器下发的 XML文件格式的安全督查任务, 对 XML格式的安全督查 任务进行解释并执行, 督査任务解释执行器主要是通过读取智能电网设备配置文 件, 或是在该智能电网设备上执行系统指令等方式来完成安全督査任务。
督查结果分析器, 基于上述安全督查任务解释执行器对某一智能电网设备安 全督查结果来生成相应的安全级别, 并给出安全修复建议。
督査结果展示, 基于上述安全督査结果分析器的结果来生成所选智能电网设 备的安全督査结果报告。
通讯接口, 用于将安全督查任务编辑器所生成的针对某一智能电网设备的安 全督查任务下发给该智能电网设备上安装的安全督查任务解释执行器, 并将该智 能电网设备安全督查任务的执行结果提交给安全督查结果分析器进行督查结果分 析。 本发明中安全督査自动化系统使用 SSL的方式确保通讯数据的完整性、 保密 性和一致性, 通讯接口需要负责通讯端口的初始化、 SSL 过程的初始化、 以及处 理通信过程中的各种异常。
图 2示出安全督査自动化系统数据流:
①安全督査模板编辑器从智能电网安全督査库中调用预定义的默认安全督査 模板, 修改并生成针对某一类智能电网设备的自定义安全督査模板。
②自定义的安全督査模板最为任务信息导入到督査任务编辑器, 同时在督査 任务编辑器中定义好督査任务结束时间、 督査目标智能电网设备信息以及督査任 务通过分值信息。
③督查任务编辑器将以上信息按照本发明中公布的智能电网安全督査自动化 协议, 组装成 XML文件后, 发送给通讯接口。
④通讯接口和目标智能电网设备建立 SSL安全通道, 并将 XML任务文件发送 给目标智能电网设备。
⑤目标智能电网上部署的督査任务解释执行器按照任务 XML文件中定义的安 全督査任务进行安全督査。
⑥督查任务解释执行器将安全督査结果信息返回给智能电网设备上的通讯接
Pl。
⑦智能电网设备通讯接口将安全督査结果信息通过 SSL安全通道发送给安全 督査自动化系统。
⑧通讯接口将安全督査结果信息提交给督査结果分析器, 根据该智能电网设 备安全督査结果来生成相应的安全级别, 并给出安全修复建议。
⑨安全督查报告生成器根据上述安全督査结果分析器的结果来生成所选智能 电网设备的安全督查结果报告。
图 3示出了本发明中公开了一种智能电网安全督査自动化协议示意图: 通过以此标准协议实现的智能电网安全督査库, 能实现快速、 准确的定义针 对各种已知智能电网设备的安全督査模板, 对于未来需要引入的新智能电网设备 的督査模板也可以按照此标准协议进行安全督査模板的定制。 同时以此标准协议 为基础, 能快速的将安全督査任务下发到指定的智能电网设备, 以实现通过结构 化的数据格式收集分散的智能电网设备配置信息。 其总体结构包括四部分组成: 版本信息、 智能电网设备类型、 安全督査项目、 安全督査方法, 其屮:
版本信息标识用来描述安全督查模板的版本信息, 包括: 版本 ID、 修订号。 智能电网设备类型包含智能电网设备硬件、 软件的标准命名信息, 通过该信 息可以确定安全督査方法和相应的安全解决方案, 包括: 设备类型、 厂家、 设备 型号、 软件版本, 针对不同类型的智能电网设备可以关联一个或多个安全督査项 目。
安全督查项 0, 涉及账号口令、 权限分配、 安全审计、 远程访问控制、 内核 安全、 文件系统安全、 性能安全等, 包括: 安全督査项目编号、 安全督査项目名 称、 安全标准值、 安全督查项目权重、 描述及安全修复信息。 针对 个安全督査 项目, 可能需要一种或是多种安全督查方法来完成, 这些安全督査方法之间可以 使与的关系也可以是或的关系。
安全督査方法是一套用于进行安全督査的指令, 例如对智能电网设备的口令 复杂度的设置, 包括: 安全督查项目编号、 实现方法、 督査信息获取路径、 判断 标准。
描述及安全修复信息包括对安全督査项目的描述信息、 国家电网相关安全规 范的映射以及相应的安全修复方案。 安全督査方法和安全督查项 之间的关联是 依据安全督查项目编号实现的。 安全督査方法中的实现方法可以是通过读取系统 配置信息的方法或是通过执行相关系统指令的方法。 督査信息获取路径中包含有 需要读取的系统配置信息文件的路径信息, 或是执行某个系统指令的路径信息。 安全督査方法中的判断标准是将获取到的督査结果信息与安全督查项目中的安全 标准值进行比对, 比对方式可以是等于、 大于、 小于或是包含等。
Claims
1.一种智能电网安全督査自动化系统, 其特征在于: 包括: 智能电网督库 , 督査模板编辑器,督査任务编辑器,督査任务执行器,通讯接口,督査结果展示; 所 述的可扩展的智能电网督査库,用于存放针对不同类型智能电网设备的督査模板, 督査模板是由一个或多个安全督査项目组成, 涉及账号口令、 权限分配、 安全审 计、 远程访问控制、 内核安全、 文件系统安全、 性能安全等; 针对每个安全督査 项目还定义了自动化督査的方法、 督查结果判断标准和督査项权重分值等信息, 督査模板的数据来源和制定标准来自国家电网公司对各种智能电网设备的安全要 求和标准,智能电网督査库中的督查模板可被督査模板边界器和督査任务编辑器 调用; 督査模板编辑器, 调用智能电网督査库中的默认督査模板, 并对其进行编 辑, 以生成针对某一类智能电网设备新的督査模板, 或是在原有督査模板的基础 上针对新增加的智能电网设备定义督査模板; 督査任务编辑器, 针对某- -类智能 电网设备, 调用智能电网督查库中的默认督査模板和自定义督査模板, 定义安全 督査任务, 在安全督查任务中还包括任务执行时间以及考核分数等信息; 督査任 务定义工作完成后, 系统将按照本发明中公布的智能电网安全督査自动化协议, 将督査任务相关信息以 XML文件的形式, 通过 SSL加密通讯接口下发给安装在智 能电网设备上的任务解释执行器, 由督查任务执行器对 XML任务文件进行解析, 并对包含其中的督査模板进行解释执行; 督查任务执行器在完成智能电网设备安 全督査工作后, 按照智能电网安全督査自动化协议, 将督查结果信息封装在 XML 文件中, 通过 SSL加密通讯接口发送给督查任务结果展示模块, 由督査任务展示 模块对督査任务结果信息进行归并和统一呈现。
2.如权利要求 1智能电网安全督査自动化系统, 其特征在于: 所述畋智能电 网督査库: 用于存放针对不同类型智能电网设备的督査模板。
3.如权利要求 1智能电网安全督査 动化系统, 其特征在于: 督查模板编辑 器: 用于对督査库中的默认督查模板进行编辑, 以生成针对某一类智能电网设备 新的督査模板。
4.如权利要求 1智能电网安全督査自动化系统, 其特征在于: 督查任务编辑 器: 定义并下发督查任务, 明确使用某一默认或编辑生成的督査模板, 对某一范 围的智能电网设备进行安全督査工作。
5.如权利要求 1智能电网安全督査自动化系统, 其特征在于: 督查任务执行 器: 对任务中所包含的督查模板进行解释执行, 以进行安全督査工作。
6.如权利要求 1智能电网安全督査自动化系统, 其特征在于: 督査结果分析 器: 基于督査任务解释执行器对某一智能电网设备安全督查结果来生成相应的安 全级别, 并给出安全修复建议。
7.如权利要求 1智能电网安全督査自动化系统, 其特征在于: 通讯接口: 将 安全督查任务编辑器所生成的针对某一智能电网设备的安全督査任务下发给该智 能电网设备上安装的安全督查任务解释执行器, 并将该智能电网设备安全督査任 务的执行结果提交给安全督査结果分析器进行督査结果分析。
8.如权利要求 1智能电网安全督査自动化系统,其特征在于:督査结果展示: 基于督査结果分析器的结果来生成所选智能电网设备的安全督査结果报告。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN2013101144401.X | 2013-04-24 | ||
| CN201310144401XA CN103268569A (zh) | 2013-04-24 | 2013-04-24 | 智能电网安全督查自动化系统 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2014173173A1 true WO2014173173A1 (zh) | 2014-10-30 |
Family
ID=49012196
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2014/000255 Ceased WO2014173173A1 (zh) | 2013-04-24 | 2014-03-12 | 智能电网安全督查自动化系统 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN103268569A (zh) |
| WO (1) | WO2014173173A1 (zh) |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN110533338A (zh) * | 2019-09-03 | 2019-12-03 | 杭州安恒信息技术股份有限公司 | 公安系统网络安全现场监督检查方法以及装置 |
| CN110763929A (zh) * | 2019-08-08 | 2020-02-07 | 浙江大学 | 一种换流站设备智能监测预警系统及方法 |
Families Citing this family (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103268569A (zh) * | 2013-04-24 | 2013-08-28 | 湖北省电力公司信息通信分公司 | 智能电网安全督查自动化系统 |
| CN103905270A (zh) * | 2014-03-11 | 2014-07-02 | 国网湖北省电力公司信息通信公司 | 智能电网andriod系统安全基线自动化检查系统及检查方法 |
| CN104281918A (zh) * | 2014-09-26 | 2015-01-14 | 国家电网公司 | 输变电状态监测系统pda设备安全自评估系统及方法 |
| CN105306471A (zh) * | 2015-11-03 | 2016-02-03 | 国家电网公司 | 智能电网安全域边界设备访问控制策略管控系统及方法 |
| CN106228308A (zh) * | 2016-07-28 | 2016-12-14 | 国网江苏省电力公司扬州供电公司 | 一种用于督察电网工作的管控系统及管控方法 |
| CN107358359A (zh) * | 2017-07-14 | 2017-11-17 | 安徽荣旭信息科技有限公司 | 一种电厂安全性评估系统 |
| CN108805431A (zh) * | 2018-05-30 | 2018-11-13 | 国网江苏省电力有限公司南通供电分公司 | 一种用于电网增强现实现场作业的工作任务智能推送的设计方法 |
| CN111611204B (zh) * | 2020-04-30 | 2024-03-01 | 中国舰船研究设计中心 | 一种分布式任务进度数据采集与分析方法 |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20100110933A1 (en) * | 2008-10-30 | 2010-05-06 | Hewlett-Packard Development Company, L.P. | Change Management of Model of Service |
| CN101795018A (zh) * | 2009-12-31 | 2010-08-04 | 华北电力大学 | 基于可视化的电网智能调度技术支持系统 |
| CN103049826A (zh) * | 2013-01-06 | 2013-04-17 | 中国南方电网有限责任公司超高压输电公司检修试验中心 | 电网运行维护自动化系统 |
| CN103268569A (zh) * | 2013-04-24 | 2013-08-28 | 湖北省电力公司信息通信分公司 | 智能电网安全督查自动化系统 |
Family Cites Families (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US8631161B2 (en) * | 2008-09-30 | 2014-01-14 | Andrei B. Lavrov | Computer program product, system and method for field management and mobile inspection |
| CN102457414B (zh) * | 2011-12-23 | 2014-01-01 | 广东电网公司电力科学研究院 | 用于等保测评中的网络安全自动测评方法及其系统 |
| CN102624557A (zh) * | 2012-03-09 | 2012-08-01 | 浪潮通信信息系统有限公司 | 一种客户侧设备配置自动核查、配置及备份的方法 |
-
2013
- 2013-04-24 CN CN201310144401XA patent/CN103268569A/zh active Pending
-
2014
- 2014-03-12 WO PCT/CN2014/000255 patent/WO2014173173A1/zh not_active Ceased
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20100110933A1 (en) * | 2008-10-30 | 2010-05-06 | Hewlett-Packard Development Company, L.P. | Change Management of Model of Service |
| CN101795018A (zh) * | 2009-12-31 | 2010-08-04 | 华北电力大学 | 基于可视化的电网智能调度技术支持系统 |
| CN103049826A (zh) * | 2013-01-06 | 2013-04-17 | 中国南方电网有限责任公司超高压输电公司检修试验中心 | 电网运行维护自动化系统 |
| CN103268569A (zh) * | 2013-04-24 | 2013-08-28 | 湖北省电力公司信息通信分公司 | 智能电网安全督查自动化系统 |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN110763929A (zh) * | 2019-08-08 | 2020-02-07 | 浙江大学 | 一种换流站设备智能监测预警系统及方法 |
| CN110533338A (zh) * | 2019-09-03 | 2019-12-03 | 杭州安恒信息技术股份有限公司 | 公安系统网络安全现场监督检查方法以及装置 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN103268569A (zh) | 2013-08-28 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2014173173A1 (zh) | 智能电网安全督查自动化系统 | |
| CN103905270A (zh) | 智能电网andriod系统安全基线自动化检查系统及检查方法 | |
| Langer et al. | From old to new: Assessing cybersecurity risks for an evolving smart grid | |
| CN105320854B (zh) | 通过签名平衡防止自动化组件受到程序篡改 | |
| Thomas et al. | Learning from vulnerabilities-categorising, understanding and detecting weaknesses in industrial control systems | |
| Bicaku et al. | Security standard compliance verification in system of systems | |
| CN103718119B (zh) | 自动对设备创建可执行安全功能的方法和装置 | |
| Bugeja et al. | IoTSM: an end-to-end security model for IoT ecosystems | |
| CN106054822A (zh) | 规划和工程设计方法,软件工具和模拟工具 | |
| CN104281918A (zh) | 输变电状态监测系统pda设备安全自评估系统及方法 | |
| CN108595953A (zh) | 对手机应用进行风险评估的方法 | |
| CN118119942A (zh) | 用于识别网络物理系统操纵的计算机实现的方法和监督装置以及计算机实现的工具和网络物理系统 | |
| Dietz et al. | Employing digital twins for security-by-design system testing | |
| CN107608291A (zh) | 一种智能变电站应用功能联动规则验证方法及系统 | |
| Eshghie et al. | Highguard: Cross-chain business logic monitoring of smart contracts | |
| Kosmowski et al. | INTEGRATED FUNCIONAL SAFETY AND CYBERSECURITY. ANALYSIS METHOD FOR SMART MANUFACTURING SYSTEMS | |
| CN106920022B (zh) | 卷烟工业控制系统的安全脆弱性评估方法、系统及设备 | |
| Weippl et al. | Security in cyber-physical production systems: A roadmap to improving IT-security in the production system lifecycle | |
| US12019756B1 (en) | Automated cyber evaluation system | |
| Ozkan et al. | Evidence-based threat modeling for ics | |
| CN116541191A (zh) | 技术装置操作过程中的操作事件的分析方法 | |
| Alla et al. | Host-based Intrusion Detection for Industrial Control Systems | |
| Awad | Automated volatile memory forensics for programmable logic controllers | |
| Liao | Smart contract vulnerability detection based on dynamic and static combination | |
| Buczkowski et al. | Optimal Security Hardening over a Probabilistic Attack Graph: A Case Study of an Industrial Control System using CySecTool |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 14788732 Country of ref document: EP Kind code of ref document: A1 |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 14788732 Country of ref document: EP Kind code of ref document: A1 |