Abstract:
Power Internet of things(IoT)devices are more and more used in power system.Due to the diversity and complexity of equipment types,there is no mature solution for security detection.A security detection system for power IoT device was designed.Based on the key technologies such as equipment fingerprint identification,network protocol identification and firmware security analysis,comprehensive security analysis was conducted on power IoT devices from the perspectives of vulnerability,configuration security and firmware security,and the equipment security detection was realized.By means of automation,the efficiency of users’ safety detection was greatly improved.At present,the system has accumulated 23 613 brand libraries,11 firmware libraries,22protocol libraries,159 763 vulnerability libraries and 1 028 threat signature libraries. The power IoT device security detection system was used to carry out security detection on six devices such as power 5G terminal,5G CPE and 5G edge gateway,and a total of 274 security risks such as terminal key leakage,configuration error and insecure component were excavated. Compared the developed platform with well-known vulnerability scanning tools in the industry,the power IoT device security detection system has high accuracy and coverage.Meanwhile,the system was tested and verified in three typical power business scenarios,and a total of 590 security vulnerabilities were excavated,which effectively guarantes the security of power IoT terminal ontology.