中国电力 ›› 2024, Vol. 57 ›› Issue (3): 135-143, 151.DOI: 10.11930/j.issn.1004-9649.202302015

• 电网 • 上一篇    下一篇

继电保护远程运维系统报文合规检测及入侵阻断技术应用

余江1(), 高宏慧1(), 史泽兵1(), 蒋纬纬2, 武芳瑛2, 詹庆才2(), 张蕊2   

  1. 1. 中国南方电网电力调度控制中心,广东 广州 510530
    2. 北京四方继保自动化股份有限公司,北京 100085
  • 收稿日期:2023-02-06 接受日期:2024-01-12 出版日期:2024-03-28 发布日期:2024-03-26
  • 作者简介:余江(1975—),女,博士,正高级工程师,从事电力系统继电保护运行与管理,E-mail:yujiang@csg.cn
    高宏慧(1979—),女,硕士,高级工程师,从事电力系统继电保护运行与管理,E-mail:gaohh@csg.cn
    史泽兵(1979—),男,硕士,正高级工程师,从事电力系统继电保护和运行控制研究, E-mail:shizb@csg.cn
    詹庆才(1982—),男,通信作者,硕士,正高级工程师,从事电力自动化软件开发与项目管理,E-mail:zhanqingcai@sf-auto.com
  • 基金资助:
    中国南方电网有限责任公司科技项目(继电保护远程运维本质安全关键技术研究,ZDKJXM20200049)。

Application of Message Compliance Detection and Intrusion Blocking Technology in Remote Operation and Maintenance System of Relay Protection

Jiang YU1(), Honghui GAO1(), Zebing SHI1(), Weiwei JIANG2, Fangying WU2, Qingcai ZHAN2(), Rui ZHANG2   

  1. 1. Dispatching Center of China Southern Grid, Guangzhou 510530, China
    2. Beijing Sifang Automation Co., Ltd., Beijing 100085, China
  • Received:2023-02-06 Accepted:2024-01-12 Online:2024-03-28 Published:2024-03-26
  • Supported by:
    This work is supported by Science and Technology Projects of CSG (Research on Key Technology in Intrinsic Safety of Relay Protection Remote Operation and Maintenance, No.ZDKJXM20200049)

摘要:

继电保护远程运维中数据传输各环节存在网络入侵风险,现有安全措施未有效处理业务层风险,且存在风险阻断不及时等问题。为此,提出一种报文合规检测方法及入侵阻断技术,分析报文的对象、格式、业务逻辑和行为模式,建立报文合规规则库及不合规报文阻断策略,设计开发不合规报文阻断模块及“一键阻断”紧急控制模块。通过模拟仿真环境测试,结果表明,上述技术对不同类型异常报文进行的阻断效果与预期一致,可有效阻断非法入侵攻击,从而提高继电保护远程运维的安全性和稳定性。

关键词: 继电保护, 远程运维, 网络安全, 入侵检测, 紧急控制

Abstract:

In the remote operation and maintenance of relay protection, there are network intrusion risks at every stage of data transmission. Existing security measures have not effectively addressed business layer risks, and some issues such as delayed risk response still exist. Therefore, a message compliance detection method and intrusion blocking technology have been proposed. By analyzing the objects, formats, business logic, and behavioral patterns of messages, a library of message compliance rules and a strategy for blocking non-compliant messages are established. Finally, modules for blocking non-compliant messages and an "emergency blocking" control module are designed and developed. The simulation testing results indicate that the proposed technology consistently blocks abnormal messages of different types as expected. This technology can effectively prevent the illegal intrusion attacks, thereby enhancing the security and stability of the remote operation and maintenance for relay protection.

Key words: relay protection, remote operation and maintenance, network security, intrusion detection, emergency control