스마트그리드 기기의 침해사고 탐지 장치 및 방법

24-03-2017 дата публикации
Номер:
KR0101719698B1
Контакты:
Номер заявки: 00-16-102008040
Дата заявки: 22-01-2016

[1]

The invention concerns a method and a device for detecting accident a breach of grid, grid using input port system of sharing, security breach accident to gap-fill or, generated security breach accident generated security breach accident judges whether existing techniques are disclosed.

[2]

Smart grid (Smart Grid) provide the means by which power generation, safety footboard, extending to the step of selling integrated intelligent grid grid information technology curved means other. Consumer smart grid power supplier for exchanging information in both directions, and displays the real-time power usage, to supply the usage amount is formed on the, energy optimizing the efficiency substrate.

[3]

Smart grid open and bidirectional communication environment can be based on various security accident, for major infrastructure can be cyber attack causes serious damage. For example, the amount of generated last year 2010 [su[su] chin [su[su] net (Stuxnet), pressure, temperature and valve was such as SCADA system failures. Also, electric wiring operation of another person or raise electricity [lyo[lyo], remote electrical smart grid security threats can be adjusted easily a dehydroxylated, smart grid applied to cyber attack increased interest etc. of a hacker.

[4]

Smart grid as well as to reduce the exchange of information and user based on user data communication services by is fixed to the body. The peer-to-peer security threats existing IT environment with new security threat smart grid can be generated from the surface. The smart grid consumer personal information and power usage information is transmitted in both directions by the consumer privacy is personal information and power usage information outlet can be substituted. Also, power usage information can be force with up modulation charging full and bypassing attached.

[5]

It is consumer registration key smart grid system connected to other smart phone or via the Internet to security threats while to a rotation force has been, in order to mimic the possibility of a fabrics of various kinds of smart security threat.

[6]

Smart grid security attack control right of money or power supply, can be malicious use, added security in daily life and before having smart grid environment when divided by problem, various social infrastructure can be attack an enlarged, an enormous increase in doing greatest damage are expected.

[7]

The, offers a smart grid having a fluidic oscillator arranged to detect accident, correspond to reflection from a detected security breach accident required disclosed.

[8]

10 - 1547998 Korean Patent registration first call, 27 August 2015 public (name: vulnerability analysis apparatus for providing information method)

[9]

The aim of the invention is suspected judges whether the smart grid of security breach accident, various security threats to secure smart grid environment on the anterior segment are disclosed.

[10]

Also, the aim of the invention is generated security breach accident judges whether generated security breach accident is mounted to, and then it is generated security breach accident to rapid and accurate are disclosed.

[11]

In order to achieve the purposes of the smart grid delivers the event detection device, a plurality of smart grid devices from each non-volatile memory dump Image system and application log data change information system including a receiving unit, the received plurality of the system if there is a change information, file system log data input port information including at least one input port and the smart grid device according trend information generating analysis unit, and the first smart grid device 1 has resistant corresponding trend information except the smart grid device 1 1 2 has resistant corresponding smart grid devices drive the progression, the determining determines whether the smart grid having a fluidic oscillator 1 accident offers having a predetermined wavelength.

[12]

The, a judgment part, all of the other smart grid device input port and the input port information received from each of the file system log data obtained one event, time-wise the 2 can be trend information.

[13]

The, a judgment part, molding unit, one unit, the number of main units and wall units set in the trend information 1 2 the trend information can be compared.

[14]

The, a judgment part, adjusted to correspond to the kind of the comparison set file system log data using the at least one input port and input port information 1 2 compares the trend information can be trend information.

[15]

The, a judgment part, the plurality of smart grid devices trend information using the input from the classification algorithms is moved along, the smart grid device information corresponding to a number of best the progression determines the security breach accident can be.

[16]

The, a judgment part, the security breach accident is to determine the smart grid device for storing the information corresponding to the progress of the accident by comparing the trend information corresponding to security breach accident, calculating the similarity can be.

[17]

The, the analyzing unit is, the non-volatile memory dump analyzing the images is generated searches the files, including modifying at least one of time and access time using time information, the file system can be input port information.

[18]

The, the analyzing unit is, the system and application log data analysis using searches the time information, the log data can be input port information.

[19]

The, the analyzing unit is, the non-volatile memory dump storing processes, the creation of the file, modifying, and deleting at least one of access time and event occurs or analyzing the contents of the event, the system and application log data to, the event occurs can be time and analyzing the contents of the event.

[20]

The, the plurality of smart grid tools are, identification information, the risky information, model name at least one can be equal to each other.

[21]

Also, breach of event detection device smart grid device performed by a smart grid device a breach of event detection the method includes smart grid devices from each non-volatile memory dump Image system and application log data receiving system including change information, the received plurality of the system if there is a change information, file system log data trend information including at least one input port and input port information generating device according the smart grid, smart grid device valve 1 1 1 1 has resistant corresponding trend information except the smart grid device smart grid devices to drive the first output corresponding to the progress of 2, 1 of the accident that determines whether the security of smart grid comprising the following steps.

[22]

According to the invention, judges whether the smart grid of security breach accident suspected, various security threats can be build secure smart grid environment.

[23]

Also, whether generated security breach accident is mounted to transform the generated security breach accident, generated security breach accident can be quickly correspond exactly.

[24]

Figure 1 shows a one embodiment of the invention smart grid device schematic represents a breach of event detection for comparing the surface environment are disclosed. Figure 2 shows a breach of event detection components of a smart grid device also one embodiment of the invention indicating block are disclosed. Figure 3 shows a one embodiment of the invention smart grid device a breach of event detection presents a flow operation are disclosed. Figure 4 shows a S330 in security breach accident to explain the order of Figure 3 also determine whether the process are disclosed. Figure 5 shows a one embodiment of the invention smart grid device a breach of accident detector for analyzing non-volatile memory dump Image representing the result of example are disclosed. Figure 6 shows a one embodiment of the invention smart grid device a breach of accident detector system and application log data representing the result of analysis of the example are disclosed.

[25]

The present invention the attached HTML page through detailed as follows. Wherein, repeated description, the subject matter of the present invention can be unnecessarily haze known function, and description to operate dispensed to each other. Embodiments of the present invention per industry with average knowledge to account for the entire surface to which are disclosed. Thus, the shape and size of the elements in the drawing for and apparatus or the like can be described more specifically.

[26]

Below, preferred embodiments according to the present invention attached HTML page through detailed as follows.

[27]

[28]

Figure 1 shows a one embodiment of the invention smart grid device schematic represents a breach of event detection for comparing the surface environment are disclosed.

[29]

As shown in fig. 1, smart grid device a breach of event detection device (200) is applied environment smart grid device 1 (100 _ 1), smart grid device 2 (100 _ 2), ... N smart grid device (100 _N) (also referred to as "a plurality of smart grid devices" below.) is the lungs. And a plurality of smart grid device (100) are smart grid device a breach of event detection device (200) on a wired or wireless connected thereto.

[30]

A plurality of smart grid device (100) are non-volatile memory dump Image, system and application system comprising change information generated by the log data of each smart grid delivers the event detection device (200) components in the. The non-volatile memory dump Image system and application log data generated by smart grid device (100) is determined voltage coil in a base material are disclosed.

[31]

Also, a plurality of smart grid device (100) are smart grid device (100) identification information, the risky information, model name information comprising at least one smart grid device information along with information of smart grid voltage coil delivers the event detection device (200) can be sent. At this time, a plurality of smart grid device (100) are identification information, the risky information, model name at least one can be equal to each other.

[32]

And a plurality of smart grid device (100) of voltage coil receiving information from smart grid delivers the event detection device (200) has a analyzes the change information, determining whether or not the smart grid of security breach accident compared to other.

[33]

Unlike general PC or server system generally smart grid device, iteratively performs only the particular embedded devices, changes is relatively disclosed. Also, the same smart grid business the smart grid devices under similar environmental into a product for the application to installation and resident, to provide the same service based on the policies. The, smart grid Company are installed smart grid devices system change is almost similar shape.

[34]

The, smart grid device a breach of event detection device (200) is the smart grid devices utilizing characteristics of, time smart grid of system input port is made of a red substrate. The smart grid device detecting an object corresponding to a plurality of trend information model name or the same smart grid devices to smart grid information recording risky information corresponding mutual information similarity compared to trend information other. Well as grasp similar result, when the best similarity, abnormally activated and the corresponding smart grid device determined to be as follows.

[35]

Also, smart grid device a breach of event detection device (200) is generated by a particular security breach accident that the progression of interest smart grid device detecting a trend of information classifies information mutually compares.

[36]

Mutual comparison result, the maximum value or more similar degree, smart grid device a breach of event detection device (200) which receives security breach accident or determines, corresponding security breach accident is can be suspected.

[37]

[38]

Figure 2 shows a breach of event detection components of a smart grid device also one embodiment of the invention indicating block are disclosed.

[39]

Also such as 2, smart grid device a breach of event detection device (200) received by a receiver (210), analysis unit (220) and a judging section (230) having a predetermined wavelength.

[40]

First, receiver (210) comprises a plurality of smart grid device (100) each system and application log data from non-volatile memory dump Image system including change information d2..

[41]

And analyzing portion (220) of received a plurality of system if there is a change information, file system information including at least one input port and input port log data produce a smart grid device according trend information.

[42]

Also, analysis unit (220) includes a non-volatile memory dump analyzing the images is generated searches the files, comprising using at least one of modified time and access time information, file system produce a input port information.

[43]

And analyzing unit (220) has a time information searches the log data analysis and applications, produce a log data input port information.

[44]

Analysis unit (220) includes a non-volatile memory dump storing processes, the creation of the file, modifying, and deleting access time and event from analyzing the contents of at least one of the event occurs or, system and application log data to event occurs a time and event from analyzing the contents of each other.

[45]

Finally, a judging section (230) is smart grid device 1 (100 _ 1) smart grid device 1 has resistant corresponding trend information 1 (100 _ 1) rest subfields has resistant corresponding trend 2 drive the smart grid devices, smart grid device 1 (100 _ 1) of security breach accident occurred even under the substrate.

[46]

The, a judging section (230) is received from each file system remaining smart grid device input port and input port information one event log data obtained, time-wise first 2 produce a trend information.

[47]

And a judging section (230) the seam unit, one unit, during the progress of information associated with the first 2 main units and wall unit number 1 is set in first compares trend information.

[48]

Also, a judging section (230) adjusted to correspond to the kind of the comparison a setup file system log data using at least one input port and input port information 1 2 compares first trend information associated with the first trend information.

[49]

Descriptions for the sake of convenience, smart grid device a breach of event detection device (200) is detected target smart grid device 1 (100 _ 1) corresponding to the first 1 and the remainder smart grid devices has resistant corresponding trend information by comparing the trend information 2, smart grid device 1 (100 _ 1) or an accident security breach of which are described. However limited without, smart grid device a breach of event detection device (200) is trend information corresponding to a plurality of smart grid devices using security breach accident is suspected of detecting smart grid device may be filled.

[50]

The, a judging section (230) comprises a plurality of smart grid devices using input from the classification algorithms is moved along the trend information, information corresponding to the number of best smart grid device security breach accident progression determines that other.

[51]

Also, a judging section (230) includes a security breach accident is to determine the smart grid device for storing the security breach accident trend information corresponding to information corresponding to the breach accident progression compared, to determine the similar degree. Similar degree and the maximum value or more, smart grid device a breach of event detection device (200) is for storing the corresponding security breach accident or determines, corresponding security breach accident is can be suspected.

[52]

[53]

Embodiments of the invention also is less than the 3 and 4 also seen through the smart grid device a breach of event detection method more detailed as follows.

[54]

Figure 3 shows a one embodiment of the invention smart grid device a breach of event detection presents a flow operation are disclosed.

[55]

First, smart grid device a breach of event detection device (200) comprises a plurality of smart grid devices (100) receives a (S310) system from the change information.

[56]

Smart grid device a breach of event detection device (200) comprises a plurality of smart grid devices (100) from non-volatile memory dump Image, system and application log data system including receives a change information.

[57]

The, smart grid device a breach of event detection device (200) has a corresponding change information smart grid device identification information, the risky information, model name information comprising at least one smart grid voltage coil can be smart grid data storage device information along with information. Also, smart grid device a breach of event detection device (200) includes a smart grid device identification information, the risky information and model name information for managing change information based on the system database information can be stored.

[58]

The smart grid device a breach of event detection device (200) of received system change information to analyze, produce a trend information (S320).

[59]

Smart grid device a breach of event detection device (200) includes a non-volatile memory dump storing processes, stores file with time, modified, access and to deleting the corresponding event is confirmed, produce a file system input port information. The, file system can be input port information table format. Also, smart grid device a breach of event detection device (200) includes a non-volatile memory dump Image analysis, of the deleted file is generated files, the file system easily modified time and access time can be input port information.

[60]

The smart grid device a breach of event detection device (200) has a and application log data to, system and application event is confirmed with time, produce a log data input port information. The, log data can be input port information table format.

[61]

Also, smart grid device a breach of event detection device (200) includes a smart grid device information is generated based on a database can be progression information managing information.

[62]

Finally, smart grid device a breach of event detection device (200) includes a security breach accident occurred even under the other (S330).

[63]

Smart grid device a breach of event detection device (200) includes a smart grid device 1 (100 _ 1) smart grid device 1 has resistant corresponding trend information 1 (100 _ 1) rest subfields has resistant corresponding trend 2 drive the smart grid devices, smart grid device 1 (100 _ 1) of security breach accident occurred even under the substrate. The, remaining smart grid tools are smart grid device 1 (100 _ 1) identification information, the risky information, model name information is equal to the at least one can be.

[64]

Figure 4 shows a S330 in security breach accident to explain the order of Figure 3 also determine whether the process are disclosed.

[65]

Such as also 4, smart grid device a breach of event detection device (200) is 2 (S410) produce a time-wise first trend information.

[66]

Smart grid device a breach of event detection device (200) includes a smart grid device 1 (100 _ 1) rest subfields smart grid device input port and input port information received from each file system contents of trend information receiving one event log data obtained, time-wise first 2 produce a trend information. The, time unit is minutes, be a molding unit and one unit.

[67]

The smart grid device a breach of event detection device (200) compares a setup of the progress of information number (S420).

[68]

Smart grid device a breach of event detection device (200) the seam unit, one unit, main unit, and wall unit in number 1 2 compares first set trend information associated with the first trend information.

[69]

For example, mutual molding unit reference is established, component-wise progression to exploit information, one unit mutual reference is established, wise in that by the trend information, mutual reference main units or wall unit is established one-wise progression trend information can be obtained through the mutual comparisons.

[70]

Next smart grid device a breach of event detection device (200) is adjusted depending on the type of comparison compares a setup of the progress of information (S430).

[71]

Smart grid device a breach of event detection device (200) adjusted to correspond to the kind of the comparison a setup file system log data using at least one input port and input port information 1 2 compares first trend information associated with the first trend information.

[72]

Setting from a user can be supplied with the kind of mutual comparison, comparison between circuit network information input port file system, file system log data input port log data between circuit network information inputted through a microphone and input port information input port information set corresponding to the kind of mutual comparison between the combined information during a comparison can in order to perform a comparison.

[73]

Finally, smart grid device a breach of event detection device (200) includes classifying progression, security breach accident occurred even under the other (S440).

[74]

Smart grid device a breach of event detection device (200) comprises a plurality of smart grid devices progression using designation information inputted from classification algorithms. The smart grid device a breach of event detection device (200) is less than the threshold number of smart grid device security breach accident information corresponding to progression determines that other.

[75]

Also, smart grid device a breach of event detection device (200) includes a security breach accident is to determine the smart grid device for storing the security breach accident trend information corresponding to information corresponding to the breach accident progression compared, to determine the similarity.

[76]

Any smart grid device security breach accident offered or any smart grid devices where abnormally operating outside, smart grid device information of the target smart grid information recording a plurality of smart grid devices the same progression information received from the inputs. Designation information input and progression using classification algorithms.

[77]

The, smart grid device a breach of event detection device (200) is best classified smart grid device offers a progression with low number information corresponding to the data be abnormal accident or device.

[78]

Also, security breach accident is generated when the, smart grid device a breach of event detection device (200) is generated security breach accident is mounted generated security breach an accident the same security breach accident judges whether other. The, smart grid device a breach of event detection device (200) is generated by a particular security breach accident that the progression of interest smart grid device detecting a trend of information classifies information mutually compares.

[79]

Mutual comparison result, the maximum value or more similar degree, smart grid device a breach of event detection device (200) is an object detection device judges that the smart grid corresponding to security breach accident or, can corresponding security breach accident is suspected.

[80]

[81]

One embodiment of the invention through smart grid device also is less than the 5 and 6 also breach of event detection device further progression information generated detailed as follows.

[82]

Figure 5 shows a one embodiment of the invention smart grid device a breach of accident detector for analyzing non-volatile memory dump Image representing the result of example are disclosed.

[83]

As also shown in the 5, smart grid device a breach of event detection device (200) includes a non-volatile memory dump storing processes, the creation of the file, modifying, and deleting contents of database information corresponding to an event type table access time event generated can be stored.

[84]

[85]

Figure 6 shows a one embodiment of the invention smart grid device a breach of accident detector system and application log data representing the result of analysis of the example are disclosed.

[86]

Also such as 6, of [su[su] E grid delivers the event detection device (200) has a and application log data to, event time and content database information stored in the memory table type can be generated.

[87]

[88]

The laser diode smart grid device a breach of apparatus and methods for detecting accident as described embodiments but can be applied to configuration and method of defined, various modifications can be made to the embodiments all or a portion of a front end of the selectively combined each embodiments of the disapproval.

[89]

100: smart grid device 200: smart grid device a breach of event detection device 210: receiver 220: analysis unit 230: a judging section



[90]

Apparatus and method for detecting accident a breach of smart grid device are connected to the terminals. The smart grid device a breach of accident detector, a plurality of smart grid devices from each non-volatile memory dump Image system and application log data change information system including a receiving unit, the received plurality of the system if there is a change information, file system log data including at least one input port and input port information according the smart grid device generating trend information analysis section, the first smart grid device 1 has resistant corresponding trend information except the smart grid device 1 1 2 has resistant corresponding smart grid devices drive the progression, the determining determines whether the smart grid having a fluidic oscillator 1 accident offers having a predetermined wavelength.



A plurality of smart grid devices from each non-volatile memory dump Image system and application log data change information system including a receiving unit, the received plurality of the system if there is a change information, file system log data including at least one input port and input port information according the smart grid device generating trend information analysis section, the first smart grid device 1 has resistant corresponding trend information except the smart grid device 1 1 2 has resistant corresponding smart grid devices drive the progression, the smart grid having a fluidic oscillator 1 offers a judging section which determines whether the accident, the plurality of smart grid tools are, identification information, the risky information, characterized in that at least one of a second polarity consumers can selectively get smart grid device a breach of event detection device.

According to Claim 1, a judgment part, all of the other smart grid device input port and the input port information received from each of the file system log data obtained one event, time-wise the smart grid of trend information 2 delivers the event detection device.

According to Claim 2, a judgment part, molding unit, one unit, the number of main units and wall units set in the trend information comparing the trend information 1 2 smart grid device a breach of event detection device.

According to Claim 3, a judgment part, adjusted to correspond to the kind of the comparison set file system log data using the at least one input port and input port information 1 2 trend information comparing the trend information of smart grid delivers the event detection device.

According to Claim 4, a judgment part, the plurality of smart grid devices trend information using the input from the classification algorithms is moved along, the progression the smart grid device information corresponding to a number of best the security breach accident smart grid device judges that the breach of event detection device.

According to Claim 5, a judgment part, the security breach accident is to determine the smart grid device for storing the information corresponding to the progress of the accident by comparing the trend information corresponding to security breach accident, calculating the similarity of smart grid delivers the event detection device.

According to Claim 1, the analyzing unit is, the non-volatile memory dump analyzing the images is generated searches the files, including modifying at least one of time and access time using time information, the file system input port information of smart grid delivers the event detection device.

According to Claim 1, the analyzing unit is, the system and application log data analysis using searches the time information, the log data input port information of smart grid delivers the event detection device.

According to Claim 1, the analyzing unit is, the non-volatile memory dump storing processes, the creation of the file, modifying, and deleting at least one of access time and event occurs or analyzing the contents of the event, the system and application log data to, analyzing the contents of the event time and event occurs the smart grid device a breach of event detection device.

Deletion

Smart grid device a breach of event detection device breach of event detection method performed by a smart grid device, a plurality of smart grid devices from each non-volatile memory dump Image system and application log data receiving system including change information, the received plurality of the system if there is a change information, file system log data trend information including at least one input port and input port information generating device according the smart grid, smart grid device valve 1 1 1 1 has resistant corresponding trend information except the smart grid device has resistant corresponding trend 2 drive the smart grid devices, smart grid having a fluidic oscillator 1 offers the accident that determines whether the wherein, the plurality of smart grid tools are, identification information, the risky information, characterized in that at least one of a second polarity consumers can selectively get smart grid device a breach of event detection method.

According to Claim 11, delivers the smart grid having a fluidic oscillator 1 accident that determines whether the step, all of the other smart grid device input port and the input port information received from each of the file system log data obtained one event, time-wise the trend information 2 generating smart grid device a breach of event detection method.

According to Claim 12, molding unit, one unit, the number of main units and wall units set in the trend information 1 2 the trend information further comprises comparing the smart grid device a breach of event detection method.

According to Claim 13, adjusted to correspond to the kind of the comparison set file system log data using the at least one input port and input port information of the progress of information 1 2 compares the trend information further comprising smart grid device a breach of event detection method.

According to Claim 14, the plurality of smart grid devices trend information using the input from the classification algorithms is moved along, the smart grid device information corresponding to a number of best the progression determines the security breach accident delivers the event detection method further include the step of smart grid.

According to Claim 15, the security breach accident is to determine the smart grid device for storing the information corresponding to the progress of the accident by comparing the trend information corresponding to security breach accident, similarity to that smart grid device further comprising a breach of event detection method.

According to Claim 11, the smart grid device according the trend information generating step, the non-volatile memory dump analyzing the images is generated searches the files, including modifying at least one of time and access time using time information, the file system input port information of smart grid delivers the event detection method.

According to Claim 11, the smart grid device according the trend information generating step, the system and application log data analysis using searches the time information, the log data input port information of smart grid delivers the event detection method.

According to Claim 11, the smart grid device according the trend information generating step, the non-volatile memory dump storing processes, the creation of the file, modifying, and deleting at least one of access time and event occurs or analyzing the contents of the event, the system and application log data to, analyzing the contents of the event time and event occurs the smart grid device a breach of event detection method.

Deletion