• ADDRESS:No.111 NanJing Road Shibi Industrial Area Panyu District of GuangZhou GuangDong,P.R.China
  • TEL:+86 20 83687691
  • FAX:+86 20 83687779
Special recording the digital substation system >



Special recording the digital substation system analysis of IEC61850 network
Communication network of digital substation IEC61850


Electric power automation system of digital substation and IEC61850 communication system, so that the rapid development of computer network has brought the network communication system of high speed for the power user, but also on the network management but also poses a severe challenge. Data communication in Ethernet too much, so the network and network equipment are under tremendous pressure on the load, the working efficiency and security. As digital power system management, operating personnel, must effectively understand the data transmission communication data transmission in the network is normal or not, and whether the IED network equipment overload operation, the internal LAN, LAN and Internet connection between is normal, IED is normal (such as: GOOSE information, information interoperability, fault recorder information, control information) and so on, at the same time, in the face of the network, the network of intermittent internal station control layer, process layer network network failure, must be able to quickly locate the fault point and its elimination.
L analysis of abnormal data in communication network;
L analysis of TCP in a communication network;
L analysis of the network IEC 61850 communication transceiver is normal;
L analysis in the FTP communication network is normal;
L analysis the existence of broadcast / multicast storm network; L
L analysis of the network transmission of GOOSE data packet is correctly; L
L analysis of network transmission IEC 61850 report the existence of fault;
L analysis of network network IED can not normally access fault;
L analysis of loop fault finding exist in the network;
- Finding Analysis of slow speed network fault;
Analysis of intermittent fault - finding network;
- card, line search in the network analysis and the rate of end equipment fault;
Network analysis system is a let IEC 61850 digital network management and operation, can be in a variety of network problems, an antidote against the disease network real time operation and management scheme, it to all the data in the transmission network of detection, analysis, diagnosis, record, help users to eliminate network accidents, avoid safety risk, improve network performance, increase network availability value. Management and operation people don't have to worry about network accidents are difficult to solve, network analysis system can help the network fault and safety risk will be reduced to the minimum, the network performance will gradually get promotion:
Troubleshooting networks, improve the network performance, enhance network security, network at any time to need for health analysis. Network analysis can know the use condition of network, network analysis is the basic and key work for the network management, the basic state only clear network and how it will be used for network management, to make the most powerful decision support. A tool system that can help the digital network to complete the following work:
Network traffic statistics - the station to the IED device node;
L understand the flow application composition and how it is used;
L monitor network bandwidth utilization rate;
Automatic diagnosis - provides network fault, fault location;
All data - network packet capture and detection of network transmission;
IP, port, host session and physical endpoint automatic discovery -;
L monitor intranet IEC 61850 file transfer content;
L provide data filtering and screening, to adjust the detection range;
- packet decoding analysis, analysis of IEC61850 data in depth;
Analysis of - color protocol tree development, network application;
- TCP data flow reconstruction, tracking the data transmission process;
L monitoring network connection, find the largest IED session;
L monitoring network errors, network error statistics and positioning;
L report with network communication and network data logging;
L provide various statistical analysis charts, historical sampling;
L snapshot recording network history data, provide data reference;
L detect potential communication security vulnerabilities, and provide the decision basis for the safe defense;
- IEC61850 high clear communication failure analysis, find the root of the problem.
Network analysis system integrated Ethernet leading expert analysis techniques provide accurate analysis of IEC61850 communication network in the current complex, provide the most comprehensive and in-depth data in network security, network performance, network failure, is the key of system required to present digital power system.


The technical features of 3.1.2
In Ethernet networks, all communication is the work in broadcasting mode, all of the network interface with a network segment has access to all the data transmission on the physical media, and each network interface has a unique hardware address, namely the MAC address. Under normal circumstances, a network interface can only the following two kinds of data frame response: a data frame matched with their MAC address and sent to the broadcast data of all machine frame. But in practical systems, the data sending and receiving are generally made of net card, and card working mode has the following 4:
L radio: this mode network card can receive to broadcast its own data frame of data frame and the network. (default)
L multicast: this mode the card only can receive the multicast data frames.
L direct: this mode the card can only receive send its own data frame.
L hybrid: this mode of the card can be received by all the data frame on network equipment.
From the above shows, although the card can only receive data sent to broadcast their own data and in the network by default, can force the network card in the promiscuous mode, then the card will receive all through the network equipment data, regardless of whether the data destination is who.
Network analysis software design strictly follows the Ethernet working modes. In the system, the network of every part of abstract as an object, such as the IP address, physical address, protocol, data package, these objects together organically, form the use of the term "works" system, the object and the project file is constantly changing, it changes the corresponding data in real time in the communication network representation. Network analysis software system based on the Ethernet sniffer technology, work to bypass access way. First the system will be installed on the device card set to promiscuous mode, all data the transmission through the sniffer technology to capture network packets, and then these data packets delivered to the internal system is analyzed, and then the analysis results are displayed in the interface of the system in real time.



²     分析网络中的异常数据通讯;
²     分析网络中的 TCP 通信;
²     分析网络中IEC 61850通讯收发是否正常;
²     分析网络中的 FTP 通信是否正常;
²     分析网络中是否存在广播/组播风暴; l     
²     分析网络中传输的GOOSE数据包是否正确; l    
²     分析网络的IEC 61850报告传输是否存在故障;
²     分析网络内网上IED不能正常访问故障;
²     分析查找网络存在的环路故障;
²     分析查找网络速度慢故障;
²     分析查找网络时断时续故障;
²     分析查找网络中的网卡、线路以及对端设备速率故障;
网络分析系统是一个让IEC 61850数字网络管理运行者,能够在各种网络问题中,对症下药的网络时实运行管理方案,它对网络中所有传输的数据进行检测、分析、诊断、记录,帮助用户排除网络事故,规避安全风险,提高网络性能,增大网络可用性价值。管理运行者不用再担心网络事故难以解决,网络分析系统可以帮把网络故障和安全风险会降到最低,网络性能会逐步得到提升:
²     全站到IED设备节点的网络流量统计;
²     了解流量应用组成以及如何被利用;
²     监测网络带宽利用率;
²     网络故障自动诊断,提供故障定位;
²     捕获网络数据包、检测网络传输的所有数据;
²     自动发现IP、端口、主机会话和物理端点;
²     监测内网IEC 61850文件传输内容;
²     提供数据过滤与筛选,来调节检测范围;
²     数据包解码分析、深入的IEC61850数据分析;
²     彩色协议树拓展、网络应用分析;
²     TCP数据流重建、跟踪数据传输过程;
²     监测网络连接情况、找出会话最大的IED;
²     监测网络错误,进行网络错误统计和定位;
²     详细的网络通讯报表和网络数据日志记录;
²     提供各种统计分析图表、历史采样;
²     快照记录网络历史数据、提供数据参照;
²     检测潜在通讯安全漏洞、为安全防御提供决策依据;
²     IEC61850通讯故障高清晰分析,查找问题根源。
3.1.2        技术特点
l 广播:这种模式下的网卡能接收发给自己的数据帧和网络中的广播数据帧。(默认)
l 组播:这种模式下的网卡只能够接收组播数据帧。
l 直接:这种模式下的网卡只能接收发给自己的数据帧。
l 混杂:这种模式下的网卡能接收通过网络设备上的所有数据帧。