Huang Xiuli, Shi Congcong, Z. Xiaojian, Fei Jiaxuan, Zhang Rui, Fan Jie
{"title":"Design of Anomaly Monitoring Framework for Source-Grid-Load Friendly Coordination System","authors":"Huang Xiuli, Shi Congcong, Z. Xiaojian, Fei Jiaxuan, Zhang Rui, Fan Jie","doi":"10.1109/ICSGEA.2018.00032","DOIUrl":null,"url":null,"abstract":"At present, the Source-Grid-Load Friendly Coordination System is relatively weak in dealing with professional organized complex attack. To deal with the security problem, this paper designs anomaly monitoring framework of Source-Grid-Load Friendly Coordination System which includes the network communication anomaly monitoring and the Source-Grid-Load interactive terminal anomaly monitoring. For the network communication anomaly monitoring, a method based on rule-matching is used to identify anomaly events of the sensitive business operation, detecting business command exceptions by analyzing the business command features of the system. For the Source-Grid-Load interactive terminal anomaly monitoring, a method based on the security policy is used to monitor the anomaly status of the terminal by matching malicious behavior in real time.","PeriodicalId":445324,"journal":{"name":"2018 International Conference on Smart Grid and Electrical Automation (ICSGEA)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 International Conference on Smart Grid and Electrical Automation (ICSGEA)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICSGEA.2018.00032","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2
Abstract
At present, the Source-Grid-Load Friendly Coordination System is relatively weak in dealing with professional organized complex attack. To deal with the security problem, this paper designs anomaly monitoring framework of Source-Grid-Load Friendly Coordination System which includes the network communication anomaly monitoring and the Source-Grid-Load interactive terminal anomaly monitoring. For the network communication anomaly monitoring, a method based on rule-matching is used to identify anomaly events of the sensitive business operation, detecting business command exceptions by analyzing the business command features of the system. For the Source-Grid-Load interactive terminal anomaly monitoring, a method based on the security policy is used to monitor the anomaly status of the terminal by matching malicious behavior in real time.