As the application of Power Internet of Things in the distribution network, Power Distribution Internet of Things is a new type of power network produced by the deep integration of traditional power industry and Internet of Things technology. The threat tracing method of security events in Power Distribution Internet of things is much significant to the security of Power Distribution Internet of things, it can help to quickly locate the source of security events and send back the threats of security events in distribution network. This research focuses on the construction of network security knowledge graph for the threat tracing of power distribution iot security events, which is the basic work of the threat tracing method.
Passwords play an important role in power system security protection. But the existence of weak passwords poses a great threat to the security of the power system. However, the current password management methods of power industrial control systems have loopholes in which some weak passwords are not detected. This paper reference the design method of the PCFG algorithm and proposes a weak password scanning scheme. Hot words and personal information are introduced into the construction of a weak password dictionary for the first time, and the weak password dictionary is expanded based on machine learning technology. Passwords are stored as ciphertext in the power system. According to this characteristic, this scheme calculates the hash value of the weak password dictionary and compares that stored in the target system. This scheme can scan weak password ciphertext and is more suitable for the power system.
Power monitoring system, as the key to ensure the normal operation of power, is facing huge security threats. The existing protection measures for power monitoring systems mostly start from the aspect of early warning, instead of actual penetration testing of the power monitoring system. To solve this problem, a path analysis method of power monitoring system based on attack graph is proposed to simulate the security test of power monitoring system. In the aspect of route selection, this project quantifies the attack benefits and attack costs to obtain the attack efficiency on each path, and then applies the ant colony algorithm with high efficiency to select the attack path.
The construction of the power Internet of Things has led various terminals to access the corporate network on a large scale. The internal and external business interaction and data exchange are more extensive. The current security protection system is based on border isolation protection. This is difficult to meet the needs of the power Internet of Things connection and open shared services. This paper studies the application scheme of the "zero trust" typical business scenario of the power Internet of Things with "Continuous Identity Authentication and Dynamic Access Control" as the core, and designs the power internet security protection architecture based on zero trust.
With the development of cloud computing, artificial intelligence, big data and other technologies, network systems are facing more and more security risks and threats. The traditional security architecture based on border protection cannot meet the increasing security protection requirements. The zero-trust security architecture which has the characteristics of continuous identity authentication and minimized authority allocation can adapt to the security protection requirements of most current network systems. Based on the zero-trust security architecture, a dynamic access control and authorization system is proposed. User portraits and user trust are generated according to user behavior. Real-time hierarchical control in different scenarios is used in the system to achieve dynamic and fine-grained access control and authorization.