The invention discloses a cloud network end cooperative defense method and
system based on end-side
edge computing, and relates to
information security of an
electric power industrial control system. The method comprises the following steps: setting an
edge computing center at a terminal side, collecting
industrial control system terminal equipment information and communication flow information, defining and identifying attribute characteristics of an
electric power industrial control terminal by utilizing equipment fingerprints, automatically collecting the fingerprints of the
electric power industrial control
terminal equipment by utilizing an Nmap scanning method, establishing a training model by a
decision tree algorithm, and achieving the dynamic
fingerprint authentication of the
terminal equipment; through setting a switch
mirror image, intelligent monitoring host flow control and
cloud computing center training flow baseline, industrial control terminal equipment flow
anomaly detection is realized, and a cloud cooperative defense technology based on
edge computing is realized. Through flow
data acquisition, information entropy quantification flow characteristic attribute preprocessing and improved semi-
supervised clustering K-means
algorithm training, abnormal flow detection of the electric power industrial control
intranet is realized, and cloud network real-time defense based on abnormal flow detection is realized.