Method and system for detecting and defending cross-domain threats of power system

By conducting cross-domain anomaly event correlation analysis on the physical domain and information domain in the power system, an attack traceability map is built and active defense rules are generated, which solves the problem that the existing technology cannot achieve cross-domain attack identification and defense, and achieves comprehensive and reliable security protection of the power system.

CN120223418AActive Publication Date: 2025-06-27LISHUI POWER SUPPLY COMPANY OF STATE GRID ZHEJIANG ELECTRIC POWER

Patent Information

Application Number
CN202510475156.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-16
Publication Date
2025-06-27
Estimated Expiration
2045-04-16

AI Technical Summary

Technical Problem

The existing security threat monitoring and defense solutions for power systems cannot achieve cross-domain abnormal event correlation analysis and cross-domain attack propagation path identification, and it is difficult to accurately perceive security threats and track defense in real time, and cannot guarantee the comprehensiveness and reliability of power system security protection.

Method used

By using the operation monitoring data of physical domain nodes and network traffic data of information domain nodes to identify abnormal events, and conduct cross-domain abnormal events correlation analysis, a complete attack traceability map is built, combined with the vulnerability information of key nodes, active defense rules are generated for adaptive security defense.

Benefits of technology

Real-time accurate identification of complex cross-domain attack risks, and timely and reliable adaptive defense, effectively improving the comprehensiveness and reliability of power system security protection and improving the ability to resist complex network attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223418A_ABST
    Figure CN120223418A_ABST
Patent Text Reader

Abstract

The invention provides a method and a system for detecting and defending cross-domain threats of a power system. The method comprises the following steps: after carrying out anomaly identification on operation monitoring data of a physical domain node in a target power grid region to obtain an anomaly identification result and carrying out denial of service attack identification according to network flow data of an information domain node to obtain an attack identification result, carrying out abnormal event association analysis on the anomaly identification result and the attack identification result to obtain an attack cross-domain anomaly identification result; according to key nodes and key risk propagation paths in a cross-domain attack chain generated based on a graph theory algorithm, generating an attack tracing atlas, and according to vulnerability information of the key nodes in the atlas, obtaining a corresponding power system topological graph and a corresponding communication network topological graph; and iteratively generating an active defense rule based on a game theory algorithm and a reinforcement learning algorithm, and issuing the active defense rule to the node. According to the method, the cross-domain attack risk is accurately perceived in real time and adaptive security defense is executed through cross-domain abnormal event association analysis, so that the comprehensiveness and reliability of security protection of the power system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power system security, and particularly to a method and system for detecting and defending against cross-domain threats in a power system. Background Art

[0002] The complete architecture of a power system includes an information domain and a physical domain that are closely connected and interact with each other. The physical domain mainly includes physical devices and facilities in links such as power generation, transmission, transformation, distribution, and power consumption. The information domain mainly involves aspects such as monitoring, control, protection, dispatching, and management of the power system. As an important infrastructure of modern society, the security and reliability of the operation of the power system have attracted much attention, and the corresponding security threat detection and defense issues have also become the focus of research in the industry.

[0003] Due to the characteristics that the multi-source data involved in the physical domain and the information domain have significant differences in multiple aspects such as time granularity, data format, and data quality, resulting in great difficulty in correlative analysis of cross-domain abnormal events, most of the existing security threat monitoring and defense solutions for power systems are limited to single-domain threat security protection of the physical domain or the information domain, and cannot achieve correlative analysis of cross-domain abnormal events and identification of cross-domain attack propagation paths. Facing the complex attack scenarios in which attackers in actual power system operation use multi-domain vulnerabilities to achieve cross-domain collaborative attack goals, it is simply impossible to achieve real-time and accurate perception of security threats and tracking defense, and it is difficult to ensure the comprehensiveness and reliability of power system security protection. Therefore, there is an urgent need to provide a cross-domain threat defense method that can identify cross-domain attack risks in real time and accurately and perform adaptive defense. Summary of the Invention

[0004] The purpose of the present invention is to provide a method for detecting and defending against cross-domain threats in a power system. By respectively using the operation monitoring data of physical domain nodes and the traffic data of information domain nodes to identify abnormal events in the physical domain and the information domain, correlatively analyzing the abnormal events in different domains to identify cross-domain abnormal propagation paths and construct a complete attack traceability map, and combining key node vulnerability analysis to generate active defense rules for corresponding physical domain nodes and information domain nodes to perform security defense, it can not only identify complex cross-domain attack risks in real time and accurately, but also perform reliable adaptive defense in a timely manner, thereby effectively improving the comprehensiveness and reliability of power system security protection.

[0005] In order to achieve the above purpose, it is necessary to provide a method and system for detecting and defending against cross-domain threats in a power system for the above technical problems.

[0006] In the first aspect, an embodiment of the present invention provides a method for detecting and defending against cross-domain threats in a power system, and the method includes the following steps: Obtain the operation monitoring data of each physical domain node in the target power grid area, and perform status anomaly identification based on the operation monitoring data to obtain the corresponding physical domain anomaly identification results; the physical domain anomaly identification results include abnormal measurement identification results, abnormal switch identification results, faulty equipment identification results, and regional fault levels; Obtain the network traffic data of each information domain node in the target power grid area, and perform denial-of-service attack identification based on the network traffic data to obtain the corresponding information domain attack identification results; Perform abnormal event correlation analysis on all physical domain anomaly identification results and all information domain attack identification results to obtain cross-domain attack anomaly identification results; Based on the power system topology diagram and communication network topology diagram corresponding to the cross-domain attack anomaly identification results, generate corresponding cross-domain attack chains based on graph theory algorithms; Identify the key nodes and key risk propagation paths in the cross-domain attack chain, and generate corresponding attack traceability maps based on the key nodes and the key risk propagation paths; Based on the vulnerability information of the key nodes in the attack traceability map, iteratively generate active defense rules based on game theory algorithms and reinforcement learning algorithms and issue them to the corresponding physical domain nodes and information domain nodes.

[0007] Further, the operation monitoring data includes operation parameter information and switch protection information; the operation parameter information includes voltage amplitude, current amplitude, voltage phase angle, current phase angle, voltage frequency, and current frequency; the switch protection information includes equipment switch status and switch opening and closing status information; The step of performing status anomaly identification based on the operation monitoring data to obtain the corresponding physical domain anomaly identification results includes: Compare each operation parameter information with the corresponding preset parameter safety threshold range to obtain abnormal measurement identification results; the abnormal measurement identification results include abnormal operation parameters and corresponding abnormal data types and abnormal occurrence timestamps; Compare the switch opening and closing status information with the corresponding equipment switch status to obtain abnormal switch identification results; the abnormal switch identification results include the status anomaly types and status anomaly occurrence timestamps corresponding to each abnormal switch identification number; Locate the abnormal switch area according to the abnormal switch identification results and the preset switch bus association coding table to obtain the corresponding faulty equipment identification results; the faulty equipment identification results include the fault area codes and fault timestamps corresponding to each faulty switch identification; Perform feature analysis on the abnormal measurement recognition results within the fault areas corresponding to the recognition results of each faulty device according to a preset neural network model, generate a corresponding feature abnormal weight matrix, and determine the abnormal level of the fault area according to the feature abnormal weight matrix to obtain the corresponding regional fault level.

[0008] Further, the information domain attack recognition result includes the denial-of-service attack recognition result of each target attack port and the corresponding attack level; The step of performing denial-of-service attack recognition based on the network traffic data to obtain the corresponding information domain attack recognition result includes: Perform abnormal traffic concentration recognition based on the network traffic data to obtain the port traffic aggregation recognition result; the network traffic data includes the number of network connections and the bandwidth utilization rate; According to the port traffic aggregation recognition result, obtain the inflow traffic monitoring data of each traffic aggregation port, and perform denial-of-service attack recognition based on the inflow traffic monitoring data to obtain the corresponding information domain attack recognition result.

[0009] Further, the step of performing abnormal traffic concentration recognition based on the network traffic data to obtain the port traffic aggregation recognition result includes: Compare each network traffic data with the corresponding preset rated threshold range to obtain traffic anomaly information; the traffic anomaly information includes the number of abnormal connections, the bandwidth utilization rate, and the anomaly occurrence time; According to the traffic anomaly information, obtain the relevant port traffic data, and perform trend anomaly recognition on the relevant port traffic data to obtain the corresponding port anomaly recognition result; the port anomaly recognition result includes the traffic data corresponding to each abnormal port number; According to a preset port traffic judgment matrix, perform traffic anomaly level division on each abnormal port to obtain the corresponding port traffic anomaly classification result; the preset port traffic judgment matrix is constructed based on preset level judgment indicators; the preset level judgment indicators include the port traffic fluctuation range, the traffic duration, and the traffic growth rate; According to each port traffic anomaly classification result, obtain the corresponding adjacent port traffic data, and perform abnormal traffic aggregation analysis based on the adjacent port traffic data to obtain the port traffic aggregation recognition result; the port traffic aggregation recognition result includes the number of ports within each traffic aggregation port group and the aggregation traffic direction corresponding to each traffic aggregation port group.

[0010] Further, the step of performing denial-of-service attack recognition based on the inflow traffic monitoring data to obtain the corresponding information domain attack recognition result includes: Determine whether the monitored inflow traffic data meets the preset traffic aggregation recognition conditions. If so, determine the corresponding traffic aggregation port as a traffic flood attack port, and obtain the set of source addresses of the data packets with the traffic flood attack port as the destination port; the preset traffic aggregation recognition conditions are that the inflow traffic exceeds the port baseline traffic by a preset multiple and the duration exceeds a preset time length; Perform distributed attack recognition, half-open connection recognition, and malformed packet recognition based on the source address connection data records corresponding to the set of source addresses of the data packets, and perform attack classification processing on the obtained abnormal feature recognition results according to a preset machine learning model to generate the denial-of-service attack recognition results; the denial-of-service attack recognition results include attack source features, attack types, attack durations, and detection timestamps; Perform source address dispersion analysis based on the set of source addresses of the data packets and preset dispersion recognition conditions to generate corresponding source address dispersion identifiers; the preset dispersion recognition conditions are that the minimum physical distance between addresses is greater than a preset distance threshold and the access proportion of each source address is less than a preset ratio; the source address dispersion identifiers include the access records, address locations, and access timestamps of each source address; Perform abnormal statistics on the incoming data packets of the traffic flood attack port according to the Transmission Control Protocol specification and preset check fields, and generate corresponding connection abnormal recognition results when the proportion of abnormal data packets exceeds the abnormal percentage threshold; the preset check fields include the handshake packet flag bit sequence, packet header length, and checksum; the connection abnormal recognition results include the number of abnormal packets, the total amount of incoming data packets, and the inspection time; Perform comprehensive analysis on the traffic flood attack identifier, source address dispersion identifier, and connection abnormal recognition results of the traffic flood attack port to obtain a comprehensive attack behavior score, and obtain the corresponding attack level according to the comprehensive attack behavior score; the traffic flood attack identifier includes the target port, inflow traffic, baseline traffic, attack start time, and attack duration.

[0011] Further, the step of performing abnormal event correlation analysis on all physical domain abnormal recognition results and all information domain attack recognition results to obtain attack cross-domain abnormal recognition results includes: Compare the abnormal occurrence timestamps of each physical domain abnormal recognition result with each information domain attack recognition result, and generate cross-domain abnormal correlation data according to the abnormal events where the nodes belong to the same physical area and the deviation of the abnormal occurrence timestamps is less than the preset fault response duration; the cross-domain abnormal correlation data includes the physical domain node labels, information domain node labels, time correlation degrees, space correlation degrees, and correlation timestamps corresponding to each cross-domain abnormal event; Construct a corresponding primary electrical equipment topology diagram and a secondary equipment communication topology diagram based on the cross-domain exception association data, as well as the physical connection relationship and communication link relationship of the equipment in the target power grid area, and obtain the abnormal nodes in the primary electrical equipment topology diagram and the secondary equipment communication topology diagram with a distance less than a preset connection layer threshold to generate corresponding associated group data; the associated group data includes a physical domain equipment list, an information domain equipment list, the physical distance between equipment, the communication link hop count, and the spatial association degree; Conduct feature analysis on the abnormal events in the associated group data according to a preset feature matching table, and identify the severity of the abnormal events through a preset feature combination counting judgment principle to obtain a high-level abnormal group; Establish a device connectivity graph corresponding to the high-level abnormal group, and obtain a corresponding group diffusion risk value according to the connection tightness between devices in the device connectivity graph; When the group diffusion risk value exceeds a preset warning value, generate the attack cross-domain anomaly recognition result; the attack cross-domain anomaly recognition result includes a list of risk devices, a diffusion warning level, and a warning release time.

[0012] Further, the steps of generating a corresponding cross-domain attack chain based on the graph theory algorithm according to the power system topology diagram and the communication network topology diagram corresponding to the attack cross-domain anomaly recognition result include: Establish a node mapping relationship matrix between the physical domain nodes in the power system topology diagram and the communication domain nodes in the communication network topology diagram; Traverse the abnormal nodes in the power system topology diagram and the communication network topology diagram through a depth-first search algorithm, and perform matching analysis on the physical adjacent nodes and communication adjacent nodes of each abnormal node according to the node mapping relationship matrix to generate an abnormal propagation node table; Calculate the shortest propagation paths of each pair of abnormal nodes in the abnormal propagation node table in the power system topology diagram and the communication network topology diagram respectively through Dijkstra's algorithm, and perform propagation impact evaluation on each shortest propagation path according to the link bandwidth utilization rate between communication nodes, the circuit breaker status quantity between physical nodes, and the protection device action signal, and generate a cascading impact path according to the corresponding impact evaluation result; Conduct path priority evaluation on each cascading impact path respectively according to a preset path priority index, and sort the cascading impact paths according to the corresponding priority evaluation result to generate the cross-domain attack chain; the preset path priority index includes node connection tightness, node bandwidth occupancy rate, node protection configuration, and node communication delay; the cross-domain attack chain includes the source node, destination node, and path priority corresponding to each propagation path.

[0013] Further, the steps of identifying key nodes and key risk propagation paths in the cross - domain attack chain and generating corresponding attack traceability graphs based on the key nodes and the key risk propagation paths include: Obtain the node connection relationship data of the cross - domain attack chain, calculate the node degree and betweenness centrality index of each node according to the node connection relationship data, and screen out key nodes according to the node degree and betweenness centrality index; Construct corresponding propagation paths according to the inter - node connection relationships of all key nodes, and perform risk assessment on each propagation path according to a preset path significance index to obtain key risk propagation paths; Based on the force - directed layout algorithm, perform visual layout on each key risk propagation path to generate a corresponding risk propagation layout scheme; According to the risk propagation layout scheme and preset graphical annotation rules, perform annotation processing on the corresponding key risk propagation paths to generate the attack traceability graph; the preset graphical annotation rules include coloring rules and icon sizes for different types of nodes, and node - to - node connection pixel setting rules based on the degree of influence between nodes.

[0014] Further, the vulnerability information includes the degree of lag of the node software version, the number of communication protocol vulnerabilities, and the patch update status; The steps of iteratively generating active defense rules according to the vulnerability information through game theory algorithms and reinforcement learning algorithms include: Perform weighted comprehensive analysis on the vulnerability information of each key node to obtain the corresponding node vulnerability score, and use the key nodes with the node vulnerability score exceeding a preset score threshold as high - risk nodes; Based on the vulnerability identification and preset attack - defense game payoff matrix of each high - risk node, perform multiple rounds of game iteration calculations based on the non - zero - sum game algorithm to generate an optimal defense strategy; the vulnerability identification includes vulnerability level, attack difficulty coefficient, and node vulnerability score; Generate corresponding initial defense rules according to the optimal defense strategy; the initial defense rules include port restriction rules, traffic control rules, and electrical parameter adjustment rules; Based on the preset rule evaluation index, perform simulation evaluation of the defense effect of the initial defense rules based on the reinforcement learning algorithm, and optimize the initial defense rules according to the corresponding evaluation results to generate the active defense rules; the preset rule evaluation index includes the percentage decrease in the attack success rate after rule execution, the percentage increase in device operation stability, and the percentage decrease in business impact.

[0015] In a second aspect, an embodiment of the present invention provides a detection and defense system for cross - domain threats in a power system, and the system includes: A physical domain anomaly recognition module, which is used to obtain the operation monitoring data of each physical domain node in the target power grid area, and perform status anomaly recognition based on the operation monitoring data to obtain corresponding physical domain anomaly recognition results; the physical domain anomaly recognition results include abnormal measurement recognition results, abnormal switch recognition results, faulty equipment recognition results, and regional fault levels; An information domain attack recognition module, which is used to obtain the network traffic data of each information domain node in the target power grid area, and perform denial-of-service attack recognition based on the network traffic data to obtain corresponding information domain attack recognition results; A cross-domain anomaly analysis module, which is used to perform anomaly event correlation analysis on all physical domain anomaly recognition results and all information domain attack recognition results to obtain attack cross-domain anomaly recognition results; An attack chain analysis module, which is used to generate a corresponding cross-domain attack chain based on the graph theory algorithm according to the power system topology diagram and communication network topology diagram corresponding to the attack cross-domain anomaly recognition results; A traceability map construction module, which is used to identify the key nodes and key risk propagation paths in the cross-domain attack chain, and generate a corresponding attack traceability map according to the key nodes and the key risk propagation paths; An attack defense processing module, which is used to iteratively generate active defense rules based on game theory algorithms and reinforcement learning algorithms according to the vulnerability information of the key nodes in the attack traceability map and send them to the corresponding physical domain nodes and information domain nodes.

[0016] The present application provides a method and system for detecting and defending against cross-domain threats in a power system. By means of the method, operation monitoring data of each physical domain node in a target power grid area is obtained, and based on the operation monitoring data, state anomaly identification is performed to obtain a physical domain anomaly identification result including an abnormal measurement identification result, an abnormal switch identification result, a faulty device identification result, and a regional fault level. Network traffic data of each information domain node in the target power grid area is obtained, and based on the network traffic data, denial-of-service attack identification is performed to obtain a corresponding information domain attack identification result. Then, all physical domain anomaly identification results and all information domain attack identification results are subjected to abnormal event correlation analysis to obtain an attack cross-domain anomaly identification result. Based on the power system topology diagram and communication network topology diagram corresponding to the attack cross-domain anomaly identification result, a corresponding cross-domain attack chain is generated based on graph theory algorithms, and key nodes and key risk propagation paths in the cross-domain attack chain are identified. Based on the key nodes and key risk propagation paths, a corresponding attack traceability map is generated, and based on the vulnerability information of the key nodes in the attack traceability map, an active defense rule is iteratively generated based on game theory algorithms and reinforcement learning algorithms and sent to the corresponding physical domain nodes and information domain nodes. Compared with the prior art, the method for detecting and defending against cross-domain threats in a power system comprehensively utilizes operation monitoring data of physical domain nodes and traffic data of information domain nodes for abnormal event identification, constructs a complete attack traceability map by performing correlation analysis on abnormal events in different domains and identifying cross-domain abnormal propagation paths, and generates an active defense rule in combination with key node vulnerability analysis for intelligent protection methods of automatic detection, analysis, and defense of adaptive security defense. It can not only accurately identify complex cross-domain attack risks in real time, but also perform reliable adaptive defense in a timely manner, thereby effectively improving the comprehensiveness and reliability of power system security protection, enhancing the ability of the power system to resist complex network attacks, and providing effective technical support for ensuring the safe and stable operation of the power grid. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 is a schematic flowchart of a method for detecting and defending against cross-domain threats in a power system according to an embodiment of the present invention; Figure 2 is a schematic structural diagram of a system for detecting and defending against cross-domain threats in a power system according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0018] In order to make the objectives, technical solutions, and beneficial effects of the present application clearer and more understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Obviously, the following described embodiments are a part of the embodiments of the present invention and are only used to illustrate the present invention, but not to limit the scope of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present invention.

[0019] The detection and defense method for cross - domain threats in the power system provided by the present invention can be understood as a solution that, based on the current application status where the existing power system security threat defense is only limited to single - domain threat monitoring and protection, unable to achieve cross - domain abnormal event correlation analysis and difficult to cope with complex attack scenarios such as cross - domain collaborative attacks. It is a cross - domain threat intelligent monitoring and protection solution that comprehensively utilizes the operation monitoring data of physical - domain nodes and the traffic data of information - domain nodes to conduct cross - domain abnormal event correlation analysis to construct a complete attack traceability map, and combines the vulnerability analysis of key nodes to generate active defense rules. The following embodiments will elaborate on the detection and defense method for cross - domain threats in the power system of the present invention.

[0020] In one embodiment, as Figure 1 shown, a detection and defense method for cross - domain threats in the power system is provided, including the following steps: S11. Obtain the operation monitoring data of each physical - domain node in the target power grid area, and perform status anomaly recognition based on the operation monitoring data to obtain the corresponding physical - domain anomaly recognition result; among them, the target power grid area can be understood as the power grid area in the power system that needs to perform security protection, and the area range can be adjusted according to actual application requirements; the corresponding physical nodes can be understood as each substation device actually deployed in the target power grid area.

[0021] In this embodiment, the operation monitoring data of physical - domain nodes can be understood as measurement data and status monitoring data that can reflect the operating conditions of real physical devices; to ensure the comprehensiveness and reliability of physical - domain anomaly analysis, preferably, the operation monitoring data is set to include operation parameter information and switch protection information, and the operation parameter information includes measurement data such as voltage amplitude, current amplitude, voltage phase angle, current phase angle, voltage frequency, and current frequency that can be obtained through the substation monitoring acquisition layer, and the switch protection information includes the device switch status (device operating status quantity) and switch opening and closing status information (switch opening and closing status information) that can be obtained through the substation equipment status monitoring device; correspondingly, the physical - domain anomaly recognition result can be understood as the anomaly analysis result obtained based on the analysis and processing of the operation monitoring data, including anomaly measurement recognition result, anomaly switch recognition result, faulty equipment recognition result, and regional fault level.

[0022] Specifically, the step of performing status anomaly recognition based on the operation monitoring data to obtain the corresponding physical - domain anomaly recognition result includes: Compare each operating parameter information with the corresponding preset parameter safety threshold range respectively to obtain an abnormal measurement identification result; among them, the preset parameter safety threshold range corresponding to each operating parameter information can be understood as the parameter value range under the normal operation of the physical device, and can be set according to actual application requirements. For example, the preset parameter safety threshold range of the voltage amplitude is within ten percent deviation of the rated voltage amplitude, the preset parameter safety threshold range of the current amplitude is not higher than twenty percent of the rated current, the preset parameter safety threshold range of the phase angle is not more than plus or minus fifteen degrees, and the preset parameter safety threshold range of the frequency is a deviation not exceeding 0.5 Hz of the rated frequency, etc., which are not specifically limited here. In actual applications, compare each operating parameter information with the corresponding preset parameter safety threshold range. If it exceeds the corresponding threshold range, it is determined that the operating parameter is abnormal data, and the corresponding abnormal identifier needs to be added, and then the corresponding abnormal measurement identification result including each abnormal operating parameter, the corresponding abnormal data type, and the abnormal occurrence timestamp can be obtained.

[0023] Compare the switch opening and closing state information with the corresponding device switch state to obtain an abnormal switch identification result; if the switch opening and closing state information does not match the actually collected device switch state quantity, it is considered that there is a switch abnormality problem, that is, the abnormal switch identification result includes the state abnormality type and the state abnormality occurrence timestamp corresponding to each abnormal switch identification number, and the state abnormality type can be determined according to the possible abnormal scenarios in the actual application scenario. In this embodiment, considering that the switch position signal in the substation monitoring device is collected by means of normally open and normally closed contacts, the switch position signal contacts may be worn due to long-term operation, resulting in inaccurate signals. The method of combining the switch opening and closing coil current signal and the switch energy storage motor working state signal is used to jointly judge the actual position state of the switch, effectively improving the accuracy of switch state monitoring.

[0024] Locate the abnormal switch area according to the abnormal switch identification result and the preset switch-bus association coding table to obtain the corresponding faulty device identification result; among them, the preset switch-bus association coding table can be understood as a mapping table of the association relationship between switch devices and buses, including various connection forms such as bus-coupler switches and double buses, sectional switches and buses, etc., which can be used to locate the electrical area to which the abnormally operating switch belongs. For example, switch 101 and bus 101 form a coding correspondence table. When switch 101 has an abnormality, by querying the switch-bus correspondence table, it can be determined that bus 101 to which switch 101 belongs is the faulty area; the corresponding faulty device identification result includes the faulty area code and the faulty timestamp corresponding to each faulty switch identification. In this embodiment, the preset switch-bus association coding table is used to locate the abnormal switch area. When the abnormal voltage and current data involve multiple bus areas, the abnormal data range can be judged by tracing the switch connection relationship, and all devices involved in the abnormal area can be located, realizing the accurate demarcation of the abnormal area in the substation.

[0025] Feature analysis is performed on the abnormal measurement recognition results in the fault areas corresponding to the recognition results of each faulty device according to a preset neural network model to generate a corresponding feature abnormal weight matrix, and the abnormal level of the fault area is determined according to the feature abnormal weight matrix to obtain the corresponding regional fault level; among them, the preset neural network model can be understood as a neural network that is pre-trained based on relevant data and can be used to effectively extract and analyze feature data such as voltage amplitude abnormal data, current amplitude abnormal data, phase angle abnormal data, and frequency abnormal data. The specific network structure can be set according to actual application requirements and will not be specifically limited here. The corresponding feature abnormal weight matrix can be understood as a feature importance weight matrix constructed from the analysis results obtained by the preset neural network model for feature extraction and classification of abnormal data in the bus areas of each substation and evaluating the importance of each feature to the model analysis results using interpretability analysis tools such as LIME and SHAP; the corresponding regional fault level can be understood as the fault level corresponding to the abnormal score obtained by comprehensively evaluating the abnormality based on the feature abnormal weight matrix and each abnormal data; it should be noted that the fault levels corresponding to different abnormal scores can be set according to actual application requirements and will not be specifically limited here.

[0026] In this embodiment, by comprehensively analyzing the operation parameter information and switch protection information of the physical domain nodes to identify physical domain device abnormalities, it is possible to achieve real-time and comprehensive perception of physical domain abnormalities in the power system, which is convenient for improving the reliability of physical domain abnormality event analysis.

[0027] S12. Obtain the network traffic data of each information domain node in the target power grid area, and perform denial-of-service attack recognition based on the network traffic data to obtain the corresponding information domain attack recognition result; among them, the information domain node can be understood as a key point or component related to information transmission and processing in the power system, which undertakes tasks such as data collection, transmission, processing, storage, and distribution. Considering that network attacks in the information domain are mainly achieved by sending relevant malicious traffic data packets, this embodiment preferably performs attack recognition based on the network traffic data of the information domain nodes. The specific network traffic data includes the number of network connections and bandwidth utilization rate collected from network monitoring and collection devices; the corresponding denial-of-service attack recognition can be understood as a process of first identifying the phenomenon of abnormal traffic accumulation at the port based on the network traffic data, and then performing targeted denial-of-service attack analysis based on the inflow traffic monitoring data of each traffic aggregation port. The information domain attack recognition result includes the denial-of-service attack recognition results and corresponding attack levels of each target attack port, and the denial-of-service attack recognition result includes attack source characteristics, attack types, attack duration, and detection timestamps.

[0028] Specifically, the step of identifying a denial-of-service attack based on the network traffic data to obtain a corresponding information domain attack identification result includes: Identifying abnormal traffic concentration based on the network traffic data to obtain a port traffic aggregation identification result; among them, the identification of abnormal traffic concentration can be understood as a process based on port connection number, bandwidth utilization rate, port traffic trend analysis, and traffic concentration port association analysis; the specific steps for obtaining the port traffic aggregation identification result include: Comparing each network traffic data with the corresponding preset rated threshold range to obtain traffic anomaly information; in practical applications, traffic anomaly situations where the connection number exceeds the preset connection number upper limit value or the bandwidth utilization rate exceeds the rated bandwidth range are identified. For example, if the network connection number exceeds 80% of the preset connection number upper limit value or the bandwidth utilization rate exceeds 75% of the rated bandwidth range, it is determined that there is a traffic anomaly situation, and corresponding traffic anomaly information including the abnormal connection number, bandwidth utilization rate, anomaly occurrence time, and anomaly duration is generated.

[0029] Based on the traffic anomaly information, obtaining relevant port traffic data and performing trend anomaly identification on the relevant port traffic data to obtain a corresponding port anomaly identification result; among them, the relevant port traffic data can be understood as the transmission traffic data of all network ports that may cause the above traffic anomaly situation; by comparing the transmission traffic data of each relevant port obtained in real time with the corresponding port historical average traffic, the port traffic trend anomaly phenomenon can be discovered in a timely manner, and all port information with traffic trend anomalies is collected to obtain a port anomaly identification result including the traffic data corresponding to each abnormal port number.

[0030] According to the preset port traffic judgment matrix, classifying the traffic anomaly levels of each abnormal port to obtain a corresponding port traffic anomaly classification result; among them, the preset port traffic judgment matrix can be understood as a port traffic anomaly level identification matrix constructed based on preset level determination indicators including port traffic fluctuation amplitude, traffic duration, and traffic growth rate. For example, a port traffic anomaly level discrimination matrix containing multiple port traffic anomaly levels can be established by combining three abnormal classification rules such as a port traffic fluctuation amplitude greater than 200%, a traffic duration greater than 30 minutes, and a traffic growth rate exceeding 50% per minute, and based on this discrimination matrix, discriminant analysis is performed on the traffic data of each abnormal port to obtain a corresponding traffic anomaly classification result.

[0031] According to the abnormal classification results of the traffic of each port, obtain the corresponding adjacent port traffic data, and perform abnormal traffic aggregation analysis based on the adjacent port traffic data to obtain the port traffic aggregation identification result; among them, the adjacent port traffic data can be understood as the port traffic data with horizontal or vertical business upstream and downstream relationships with the abnormal ports screened based on the abnormal classification results of the traffic of each abnormal port, considering the characteristics that the actual port usage is usually divided according to business functions and the abnormal existence of the corresponding business application ports is relevant. Specifically, the number of adjacent ports is determined based on the abnormal classification of traffic. For example, the higher the abnormal level, the more adjacent ports that need to be selected for correlation analysis. On the contrary, if the abnormal level is relatively low, only the adjacent ports in one business direction, either horizontal or vertical, can be selected for correlation analysis according to requirements. In this embodiment, the abnormal traffic aggregation analysis can be understood as an analysis process of determining whether the inflow traffic data of all adjacent ports of the abnormal port exceed the corresponding port traffic baseline threshold and whether the corresponding traffic growth rate exceeds the preset rate threshold; when multiple adjacent ports deviate from the traffic baseline simultaneously and show the same change trend, it can be determined that there is a traffic aggregation phenomenon. By analyzing the number of aggregated ports and the traffic transmission direction, a port traffic aggregation identification result including the number of intra-group ports corresponding to each traffic aggregation port group and the aggregated traffic direction is obtained, which is convenient for quickly positioning the impact range of the faulty service.

[0032] According to the port traffic aggregation identification result, obtain the inflow traffic monitoring data of each traffic aggregation port, and perform denial-of-service attack identification based on the inflow traffic monitoring data to obtain the corresponding information domain attack identification result; among them, the inflow traffic monitoring data of each traffic aggregation port is obtained by a network monitoring device to obtain the port inflow traffic. The corresponding denial-of-service attack identification can be understood as an analysis process of identifying whether there are traffic floods from numerous sources, incomplete connection attempts, and malformed packets based on the port inflow traffic; specifically, the step of performing denial-of-service attack identification based on the inflow traffic monitoring data to obtain the corresponding information domain attack identification result includes: Determine whether the monitored inflow traffic data meets the preset traffic aggregation recognition condition. If so, determine the corresponding traffic aggregation port as a traffic flood attack port, and obtain the set of source addresses of the data packets with the traffic flood attack port as the destination port. Among them, the preset traffic aggregation recognition condition is that the inflow traffic exceeds the port baseline traffic by a preset multiple and lasts for more than a preset duration. The port baseline traffic is an anomaly detection reference value calculated based on the traffic average during the normal operation period of the port. The corresponding preset multiple can be determined according to actual application requirements. For example, if the inflow traffic exceeds five times the port baseline traffic and lasts for more than three minutes, then determine that the traffic aggregation port is a traffic flood attack port, and add a traffic flood attack identifier including attributes such as the target port number, inflow traffic value, baseline traffic value, attack start timestamp, and attack duration to this port. To facilitate in-depth analysis of the attack traffic, it is necessary to obtain the source address information of all data packets received by the identified traffic flood attack port, and generate a set of source addresses of the data packets containing several data packet source addresses.

[0033] Perform distributed attack recognition, half-open connection recognition, and malformed packet recognition based on the source address connection data records corresponding to the set of source addresses of the data packets, and perform attack classification processing on the obtained anomaly feature recognition results according to a preset machine learning model to generate the denial-of-service attack recognition result. Among them, the source address connection data record can be understood as the connection data information obtained by tracking the communication connections of the IP addresses within each source address. The specific content can be selected according to actual needs. For example, it includes the current source address connection count, source address connection baseline value, source address count, and normal connection data packets and half-open connection data of each source address, etc. The specific steps of performing distributed attack recognition, half-open connection recognition, and malformed packet recognition based on the source address connection data record to generate the corresponding denial-of-service attack recognition result may include: Determine whether it meets the preset distributed attack condition that the current source address connection count exceeds the source address connection baseline value and lasts for a timeout, or the source address count exceeds the normal source address count threshold. If so, generate a distributed attack identifier including the source address list, connection baseline value, current connection count, and detection timestamp.

[0034] Respectively determine whether the half-open connection data of each source address, including the number of half-open connections, the duration of half-open connections, and the number of repeated connection requests, meets the preset half-open connection anomaly determination rule. If so, generate a source address half-open connection anomaly identifier corresponding to the abnormal source address, the number of half-open connections, the duration of half-open connections, and the detection timestamp; among them, the preset half-open connection anomaly determination rule can be determined according to the data items of the half-open connection data. For example, it can be set that when the number of half-open connections of the source address exceeds 2% of the server connection pool capacity, the duration of half-open connections exceeds 30 seconds, and the number of repeated connection requests from the same source address exceeds five times the normal value, one or several conditions are met simultaneously, then it is determined that there is a half-open connection anomaly.

[0035] According to the Transmission Control Protocol specification, perform content anomaly detection on the normal connection data packets of each source address to generate corresponding source address malformed packet identifiers; among them, content anomaly detection includes checking aspects such as the packet length field not matching the actual length, the value of the protocol version field being incorrect, the flag bit combination not meeting the protocol requirements, and the checksum calculation result being incorrect. If more than two check indicators are abnormal at the same time, the data packet is determined to be a malformed packet, and a malformed packet identifier including the abnormal field name, the corresponding field value, the standard value range, and the detection timestamp can be generated.

[0036] According to the preset machine learning model, respectively extract features from the distributed attack identifier, the source address half-open connection anomaly identifier, and the source address malformed packet identifier to obtain corresponding anomaly identifier feature values; among them, the preset machine learning model can be understood as a network model that is pre-trained based on relevant data and can be used to reliably extract features from the above-mentioned distributed attack identifier, source address half-open connection anomaly identifier, and source address malformed packet identifier. The specific model type and network structure are not specifically limited here.

[0037] Weight and fuse each anomaly identifier feature value according to the corresponding preset feature value weight to obtain the corresponding anomaly fusion feature, and classify the attack according to the anomaly fusion feature to generate the denial-of-service attack recognition result; among them, the preset feature value weight can be set according to actual application requirements, and the corresponding weighted fusion and attack classification can both refer to relevant existing technologies for implementation, which will not be elaborated here.

[0038] Perform source address dispersion analysis based on the set of data packet source addresses and preset dispersion identification conditions to generate corresponding source address dispersion identifiers. Among them, source address dispersion analysis can be understood as the analysis of the access frequency and address location of data packet source addresses. The corresponding preset dispersion identification conditions are that the minimum physical distance between addresses is greater than a preset distance threshold and the access proportion of each source address is less than a preset ratio. If the minimum geographical distance between source addresses in the data packet source address set exceeds the preset distance threshold and the access times of a single source address are lower than a preset percentage of the total access times, it is determined that there is dispersion in the data packet source addresses of this port, and a source address dispersion identifier including the access records, address locations, and access timestamps of each source address can be generated.

[0039] Perform abnormal statistics on the incoming data packets of the traffic flood attack port according to the Transmission Control Protocol (TCP) specification and preset check fields, and generate corresponding connection abnormal identification results when the proportion of abnormal data packets exceeds the abnormal percentage threshold. Among them, the preset check fields include the handshake packet flag bit sequence, packet header length, and checksum. In practical applications, each incoming data packet is parsed according to the TCP specification to obtain each preset check field, and it is judged whether each preset field meets the requirements. For example, it is detected whether the handshake packet flag bit sequence conforms to the connection establishment specification, whether the value of the packet header length field is less than 20 bytes, whether the value of the checksum field is calculated incorrectly, etc. If there is any kind of abnormality, it is considered that this data packet is an abnormal traffic packet. Then, all abnormal traffic packets are statistically summarized, and when the total number of abnormal data packets exceeds a certain percentage of the total number of sampled data packets, a connection abnormal identification result including the number of abnormal packets, the total number of incoming data packets, and the inspection time is generated.

[0040] Comprehensively analyze the traffic flood attack identifier, source address dispersion identifier, and connection abnormal identification result of the traffic flood attack port to obtain a comprehensive attack behavior score, and obtain the corresponding attack level according to the comprehensive attack behavior score. Among them, comprehensive analysis can be understood as being realized by extracting and analyzing various abnormal features through machine learning methods, which will not be elaborated here. It should be noted that the mapping relationship between the comprehensive attack behavior score and the attack level can be set according to actual needs.

[0041] In this embodiment, after first identifying abnormal traffic concentration based on network traffic data in the information domain, while combining machine learning methods for in-depth traffic analysis, comprehensive attack level analysis is carried out from aspects such as traffic flood attack identification, source address dispersion identification, and connection abnormal identification. This can not only effectively improve the accuracy of denial-of-service attack identification, but also ensure the reliability of attack level determination, providing guarantee for the effectiveness of information domain attack identification results.

[0042] S13. Perform cross - domain anomaly event correlation analysis on all physical domain anomaly recognition results and all information domain attack recognition results to obtain cross - domain attack anomaly recognition results. Among them, the cross - domain anomaly event correlation analysis can be understood as a cross - domain anomaly event correlation mapping analysis based on the certain sequential time correlation between information domain network attacks and physical domain device anomalies. Specifically, the steps of performing cross - domain anomaly event correlation analysis on all physical domain anomaly recognition results and all information domain attack recognition results to obtain cross - domain attack anomaly recognition results include: Compare the anomaly occurrence timestamps of each physical domain anomaly recognition result and each information domain attack recognition result, and generate cross - domain anomaly correlation data according to the anomaly events where the nodes belong to the same physical area and the deviation of the anomaly occurrence timestamps is less than the preset fault response duration. In practical applications, compare the anomaly measurement recognition results and anomaly switch recognition results in each physical domain anomaly recognition result with the denial - of - service attack recognition results in each information domain attack recognition result. When it is monitored that the communication port of the main transformer protection device is under a denial - of - service attack and at the same time the main transformer current measurement value shows abnormal fluctuations, and the time difference between the two anomaly events is one minute and thirty seconds, which is less than the preset fault response duration (such as three minutes), and the main transformer protection device and the main transformer are both in the same physical area, meeting the spatio - temporal correlation conditions, it is determined that there is a cross - domain anomaly event correlation. After all the comparison and analysis are completed, summarize all the information with cross - domain anomaly correlations to obtain cross - domain anomaly correlation data including the physical domain node labels, information domain node labels, time correlation degree, space correlation degree, and correlation timestamps corresponding to each cross - domain anomaly event. It should be noted that the time correlation degree can be quantified by the deviation of the anomaly occurrence time, and the space correlation degree can be quantified by the physical position distance between devices, which will not be elaborated here.

[0043] Construct a corresponding primary electrical equipment topology diagram and a secondary equipment communication topology diagram based on the cross-domain abnormal correlation data, as well as the physical connection relationship and communication link relationship of the equipment in the target power grid area, and obtain abnormal nodes in the primary electrical equipment topology diagram and the secondary equipment communication topology diagram with a distance less than a preset connection layer threshold to generate corresponding associated group data; among them, the primary electrical equipment topology diagram can be understood as a topology diagram constructed based on the physical domain node labels and equipment physical connection relationships involved in the cross-domain abnormal correlation data, and the secondary equipment communication topology diagram can be understood as a topology diagram constructed based on the information domain node labels and communication link relationships involved in the cross-domain abnormal correlation data. The specific topology diagram construction process can be implemented with reference to the existing topology diagram construction technology. The associated group data in this embodiment can be understood as the equipment association group division result obtained by classifying equipment nodes with direct or indirect connection layers within a certain range based on the actual physical connection and communication link, relying on the primary electrical equipment topology diagram and the secondary equipment communication topology diagram, including information such as the physical domain equipment list, information domain equipment list, physical distance between equipment, communication link hop count, and spatial association degree corresponding to each associated group.

[0044] Perform feature analysis on the abnormal events in the associated group data according to a preset feature matching table, and identify the severity of the abnormal events through a preset feature combination counting judgment principle to obtain high-level abnormal groups; among them, the preset feature matching table can be understood as a mapping relationship table constructed in advance based on the main associated features involved in various possible cross-domain abnormal correlation events, which can be used to perform preset feature extraction and analysis on the abnormal events in each associated group data. In practical applications, if the preset feature matching table includes multiple feature abnormal ranges such as voltage deviation exceeding 10%, current deviation exceeding 20%, abnormal protection action, port traffic exceeding five times the reference value, and the number of half-open connections exceeding the threshold, then match the corresponding feature values of the abnormal events in the actual associated group data, and count the statistics of all matched feature abnormal ranges. Determine the severity of the abnormal event according to the size of the feature matching combination count. The larger the feature matching combination count, the more severe it is. For example, an event with a combination count exceeding three or more is determined as a high-level abnormal event, and the corresponding associated group is set as a high-level abnormal group and added with a high-level abnormal identifier including abnormal index values, feature combination quantities, and abnormal event levels for subsequent analysis and use.

[0045] Build the device connectivity graph corresponding to the high-level anomaly group, and obtain the corresponding group diffusion risk value according to the connection tightness between devices in the device connectivity graph; among them, the device connectivity graph can be understood as a device connection topology graph established based on the analysis of the physical connection relationship or communication link relationship between devices in the high-level anomaly group. In practical applications, the analysis of the relationship between devices can be implemented by existing technologies such as neural networks, which will not be elaborated here; the corresponding connection tightness between devices can be measured based on the number of connection layers (link hops) between devices in the corresponding topology graph. The stronger the connection tightness between devices, the greater the group diffusion. Based on this, the required group diffusion risk value can be obtained according to the mapping relationship between the connection tightness between devices and the group diffusion risk value. It should be noted that device connectivity analysis can reveal the fault propagation path and be used to judge whether the fault will spread. Taking the bus fault as an example, when the bus protection device is attacked by the network and the protection function fails, the switchgear connected to the bus will trip in series because the fault cannot be removed in time, and the fault will extend from the communication network to the primary equipment, resulting in a power outage in a larger area; that is, based on the device connectivity graph for group diffusion risk analysis, it can ensure that the diffusion risk identification conforms to the actual application scenario, thereby ensuring the accuracy of the analysis result.

[0046] When the group diffusion risk value exceeds the preset warning value, generate the attack cross-domain anomaly recognition result; among them, the preset warning value can be set according to the actual application requirements. In practical applications, if the obtained group diffusion risk value exceeds the preset warning value, it is considered that there is an attack cross-domain anomaly event that needs to be urgently concerned and solved. The attack cross-domain anomaly recognition result including the risk device list, diffusion warning level, and warning release time can be generated accordingly. The risk device list is a list of risk devices involved in the group, and the diffusion warning level can be obtained by matching the corresponding group diffusion risk value.

[0047] In this embodiment, by adopting the spatio-temporal correlation cross-domain anomaly event correlation analysis method, the correlation relationship between anomaly events in the physical domain and the information domain can be effectively captured, thereby ensuring the accuracy of real-time perception of cross-domain attack risks.

[0048] S14. Based on the power system topology diagram and the communication network topology diagram corresponding to the attack cross - domain anomaly recognition result, generate a corresponding cross - domain attack chain using graph theory algorithms. Herein, the power system topology diagram can be understood as a topology relationship diagram constructed based on the electrical connection relationship data between physical domain devices involved in the attack cross - domain anomaly recognition result, according to the actual physical connection sequence among circuit breakers, buses, and transformers. And the communication network topology diagram can be understood as a topology relationship diagram constructed based on the communication network link data between information domain devices involved in the attack cross - domain anomaly recognition result, according to the communication port mapping relationship among monitoring hosts, network switches, and protection devices. The corresponding cross - domain attack chain can be understood as a cross - domain attack link obtained through the analysis of the power system topology diagram and the communication network topology diagram. Specifically, the steps of generating a corresponding cross - domain attack chain based on the power system topology diagram and the communication network topology diagram corresponding to the attack cross - domain anomaly recognition result using graph theory algorithms include: Establish a node mapping relationship matrix between the physical domain nodes in the power system topology diagram and the communication domain nodes in the communication network topology diagram. Herein, the node mapping relationship matrix can be understood as a cross - domain node mapping relationship matrix constructed based on the association relationship between physical domain nodes and information domain nodes in the attack cross - domain anomaly recognition result, to reflect the corresponding relationship between physical devices and communication devices. Its matrix elements are 0 or 1, and 1 indicates that the corresponding physical domain node and information domain node have an association relationship. For example, taking the transformer protection device as an example, the main transformer is a physical domain node, and its corresponding protection device is a communication domain node. The values at the corresponding positions in the mapping matrix are 1, indicating that they have a direct mapping relationship. Through this mapping relationship, cross - domain devices can be accurately located.

[0049] The power system topology diagram and the communication network topology diagram are traversed for abnormal nodes by means of a depth-first search algorithm, and according to the node mapping relationship matrix, matching analysis is performed on the physical adjacent nodes and communication adjacent nodes of each abnormal node to generate an abnormal propagation node table; among them, the abnormal propagation node table can be understood as being constructed by physical adjacent nodes directly connected to the abnormal node through the same circuit breaker in the power system topology diagram, or communication adjacent nodes directly connected to the abnormal node through the same switch in the communication network topology diagram, and includes an abnormal node table with physical domain node numbers with adjacent relationships and corresponding physical connection relationships, as well as communication domain node numbers with adjacent relationships and corresponding communication link relationships. The corresponding acquisition process can be understood as first using a depth-first search algorithm to traverse the devices with cross-domain anomalies, obtaining adjacent nodes directly connected by a circuit breaker for each abnormal node in the power topology diagram, and obtaining adjacent nodes directly connected by the same switch in the communication network diagram. If the adjacent nodes have a corresponding relationship in the node mapping relationship matrix, record the physical domain node number, communication domain node number, physical connection relationship, and communication link relationship to generate an abnormal propagation node table; it should be noted that during the adjacent node traversal process, two types of relationships, physical connection and communication connection, are distinguished. Taking the bus protection device as an example, the adjacent nodes directly connected to the bus in the physical domain include circuit breakers and transformers, and the adjacent nodes directly connected to the protection device in the information domain include network switches and monitoring hosts. When the bus protection device is attacked, the directly adjacent devices affected in both domains can be obtained simultaneously.

[0050] The Dijkstra algorithm is used to calculate the shortest propagation paths of each pair of abnormal nodes in the abnormal propagation node table in the power system topology diagram and the communication network topology diagram respectively. The propagation impact of each shortest propagation path is evaluated based on the link bandwidth utilization rate between communication nodes, the breaker status quantity between physical nodes, and the protection device action signal. And a cascading impact path is generated according to the corresponding impact evaluation result. The specific process of obtaining the cascading impact path can be understood as follows: for the node pairs recorded in the abnormal propagation node table, the Dijkstra algorithm is used to calculate the shortest path between nodes in the power system topology diagram and the communication network topology diagram respectively. Combining the link bandwidth utilization rate between communication nodes, the breaker status quantity between physical nodes, and the protection device action signal to establish an impact propagation index between nodes to evaluate the propagation impact of the shortest path between nodes, and determining the shortest path between nodes with the propagation impact evaluation value exceeding the preset threshold as the cascading impact path. It should be noted that the shortest path calculation considers the actual connection relationship between devices. Taking the switchgear as an example, the breakers in the physical domain are connected in series through the bus, and the protection devices in the information domain are cascaded through switches. When the protection device of the switchgear is attacked and causes the breaker to malfunction, the propagation direction of the fault impact can be determined by calculating the shortest path. The cascading impact path analysis combines multiple dimension indicators. Taking the substation monitoring network as an example, the link congestion is indicated when the switch port bandwidth utilization rate exceeds 80%. The abnormal operation of the device is indicated when the breaker changes from the closed position to the open position. The abnormal protection logic is indicated when the protection device frequently issues trip commands. The comprehensive evaluation of multiple abnormal indicators shows that the impact of the attack continues to expand.

[0051] According to the preset path priority metrics, the path priorities of each cascading impact path are evaluated respectively, and the cascading impact paths are sorted according to the corresponding priority evaluation results to generate the cross-domain attack chain. Among them, the preset path priority metrics include node connection tightness, node bandwidth occupancy rate, node protection configuration, and node communication delay. The corresponding cross-domain attack chain can be understood as a cross-domain attack link obtained by analyzing the cascading impact paths using the path sorting criterion designed based on the preset path priority metrics. And the cross-domain attack chain includes the source node, destination node, and path priority of each propagation path. It should be noted that the path priority sorting reflects the degree of influence between devices. As a key device, the communication delay between the breaker and the protection device connected to the transformer is less than ten milliseconds, the bandwidth occupancy rate is lower than twenty percent, and the connection tightness between nodes is high. Once attacked, it is easy to form a chain reaction, and such propagation paths often have a higher priority. The node connection tightness reflects the association strength between devices. The bus coupler breaker is connected to two buses at the same time, and the bus coupler protection device communicates with multiple measurement and control units. Once such tightly connected devices are affected by an attack, it is more likely to cause the spread of faults and should be focused on in the analysis of propagation paths. Moreover, the communication link performance metrics affect the attack propagation speed. When the link bandwidth between network devices is sufficient, the communication delay is small, and the packet loss rate is low, the attack impact spreads faster. When the link performance is limited, the attack impact propagation is blocked, and this difference directly affects the formation of cascading paths.

[0052] In this embodiment, the graph theory algorithm is used to calculate the propagation paths of attacks in the physical domain and the information domain, obtain the nodes where abnormal events occur and their adjacent nodes within one hop range, and analyze the cascading impact paths between the denial-of-service attack target device and the power grid monitoring and control devices, so as to obtain the critical paths from the source node to the destination node to form a cross-domain attack chain, which can effectively ensure the reliability of attack propagation path recognition and provide strong support for subsequent accurate cross-domain attack tracing.

[0053] S15. Identify the critical nodes and critical risk propagation paths in the cross-domain attack chain, and generate corresponding attack tracing graphs according to the critical nodes and the critical risk propagation paths. Among them, the critical nodes can be understood as important nodes for attack propagation obtained by evaluating nodes based on node degree and betweenness centrality. The corresponding critical risk propagation paths can be understood as high-risk propagation paths obtained by evaluating the significance of the propagation paths constructed by the critical nodes. Specifically, the steps of identifying the critical nodes and critical risk propagation paths in the cross-domain attack chain and generating corresponding attack tracing graphs according to the critical nodes and the critical risk propagation paths include: Obtain the node connection relationship data of the cross-domain attack chain, and calculate the node degree and betweenness centrality index of each node according to the node connection relationship data, and screen out the key nodes according to the node degree and betweenness centrality index; among them, the calculation methods of the node degree and betweenness centrality index can be implemented with reference to relevant existing technologies and will not be elaborated here; the screening process corresponding to the key nodes can be understood as judging whether the node degree and betweenness centrality index of each node meet the corresponding index threshold conditions, and taking the nodes that meet the conditions as key nodes. For example, nodes with a node degree exceeding four and a betweenness centrality greater than 0.3 are marked as key nodes and a corresponding node importance identifier including the node number, node degree, and betweenness centrality index value is generated.

[0054] Construct the corresponding propagation paths according to the inter-node connection relationships of all key nodes, and perform risk assessment on each propagation path according to the preset path significance index to obtain the key risk propagation paths; among them, the preset path significance index can be understood as an index for path feature analysis, preferably including the number of key nodes included, the connection strength between path nodes, and the number of path-influenced nodes, etc. When the number of key nodes included in a certain propagation path exceeds 30% of the total number of nodes, the connection strength between path nodes is greater than 0.5, and the number of path-influenced nodes exceeds three, it is considered that the risk of this propagation path is relatively high and can be used as a key risk propagation path, and a corresponding propagation path identifier including the path start point, path end point, and path significance value is generated. For example, taking the main transformer fault propagation link as an example, this path includes three key nodes: the main transformer protection device, the circuit breaker protection device, and the bus protection device, accounting for 40% of the total number of nodes. The nodes are directly connected through the measurement and control network, and the connection strength is 0.8, and the influence spreads to four adjacent devices. Then this path is a key risk propagation path.

[0055] Based on the force-directed layout algorithm, visualize the layout of each key risk propagation path to generate the corresponding risk propagation layout plan; among them, the execution process of the force-directed layout algorithm can be understood as realizing the node distribution through mechanical principles. The distance between devices with a shortest path length of three hops between nodes is set to 300 pixels. By applying gravitational force, adjacent nodes are brought closer, and at the same time, repulsive force is applied to prevent node overlap. Eventually, the node positions reach a state of force balance. An arrow is drawn every 100 pixels on the connection line to indicate the attack propagation direction; the process of obtaining the corresponding risk propagation layout plan can be understood as performing force-directed layout operations based on the propagation path identifiers of each key risk propagation path, setting the node spacing according to the shortest path length between nodes in the propagation link, determining the node coordinate positions through the balance of node gravitational force and repulsive force, and drawing arrows at fixed intervals on the connection lines between nodes to mark the propagation direction. Finally, a required layout plan including node positions, node spacing, and connection line directions is generated. It should be noted that when positioning nodes, the force-guided layout makes full use of spatial information. For example, core nodes such as hosts and switches in the substation monitoring network are located at the center of the layout. Nodes connected to multiple devices receive greater gravitational force and automatically gather towards the center, while edge nodes receive less gravitational force and are naturally distributed on the periphery, forming a well-defined layout structure.

[0056] According to the risk propagation layout plan and the preset graphical annotation rules, perform annotation processing on the corresponding key risk propagation paths to generate the attack traceability map; the preset graphical annotation rules include the coloring rules and icon sizes of different types of nodes, as well as the pixel setting rules for the connection lines between nodes based on the degree of influence between nodes; the corresponding attack traceability map can be understood as a traceability map obtained by coloring the nodes in the layout plan, setting the icon size values according to the node types, and setting the line thickness values according to the degree of influence values between nodes; specifically, the process of generating the attack traceability map can be understood as coloring the nodes through the preset graphical annotation rules. The attack source node at the starting point of the link is marked red and the icon size is set to twice the standard size. The intermediate propagation nodes are marked yellow and the icon size is set to the standard size. The affected nodes at the end point are marked orange and the icon size is set to 1.5 times the standard size. A propagation direction arrow is marked on the connection line and the line thickness is set according to the degree of influence between nodes. For example, the degree of influence between directly connected devices is relatively strong, and the line thickness is set to 4 pixels. The degree of influence between indirectly connected devices weakens, and the line thickness is reduced to 2 pixels, etc., which is convenient for quickly identifying the key propagation paths. Finally, a traceability map including the required node colors, icon sizes, and line thicknesses is obtained. It should be noted that in this embodiment, the attack propagation process is shown through the node coloring scheme, the attack chain is visually presented by the color change, and the visual impact can be effectively enhanced by the change of the icon sizes of different nodes, making the attack traceability map more intuitive in showing the attack path.

[0057] In this embodiment, by identifying the key nodes and propagation paths in the cross-domain attack chain, a visual presentation is formed to generate an attack traceability map, and the source nodes under attack, the affected destination nodes, and the intermediate propagation paths are marked in the map. The cascading impact chain from the denial-of-service attack target device to the physical domain anomaly can be highlighted, providing intuitive decision-making support for subsequent security analysis.

[0058] S16. Based on the vulnerability information of the key nodes in the attack traceability map, an active defense rule is iteratively generated based on the game theory algorithm and the reinforcement learning algorithm and sent to the corresponding physical domain nodes and information domain nodes; wherein, the vulnerability information includes the lag degree of the node software version, the number of communication protocol vulnerabilities, and the patch update status; specifically, the step of iteratively generating an active defense rule based on the game theory algorithm and the reinforcement learning algorithm according to the vulnerability information includes: The vulnerability information of each key node is subjected to weighted comprehensive analysis to obtain the corresponding node vulnerability score, and the key nodes with the node vulnerability score exceeding the preset score threshold are used as high-risk nodes; wherein, the weighted comprehensive analysis can be understood as a process of converting each vulnerability information into a corresponding index score value and performing weighted summation according to the corresponding preset weight coefficient to obtain the corresponding node vulnerability score; the corresponding preset score threshold can be set according to actual needs. While using the key nodes with the node vulnerability score exceeding the preset score threshold as high-risk nodes, a vulnerability identifier corresponding to the vulnerability level, attack difficulty coefficient, and vulnerability score is added to them. For example, the operating software version of the main transformer protection device of a certain substation lags behind the latest version by two version cycles, there are three known communication protocol vulnerabilities, and the security patch update lags behind for more than three months. The vulnerability score exceeds the high-risk threshold through weight calculation and is identified as a high-risk node with a relatively large security risk.

[0059] Based on the vulnerability identifier of each high-risk node and the preset attack and defense game payoff matrix, multi-round game iteration calculation is performed based on the non-zero-sum game algorithm to generate an optimal defense strategy; wherein, the preset attack and defense game payoff matrix can be understood as a payoff matrix applicable to the attack and defense confrontation calculation of high-risk nodes based on the attacker's gain value of obtaining administrative privileges by successfully invading, the defender's loss value of the operating equipment being damaged, the attacker's attack cost value, and the defender's investment value. The corresponding optimal defense strategy can be understood as a defense strategy with the maximization of benefits as the optimization goal, and the optimal defense strategy obtained through multi-round game iteration calculation includes information such as protection nodes, protection measures, and payoff values.

[0060] According to the optimal defense strategy, corresponding initial defense rules are generated; wherein, the initial defense rules can be understood as active defense measures including port limit rules, traffic control rules, and electrical parameter adjustment rules generated based on a three-item protection parameter table including port connection number limit, bandwidth limit, and current setting value limit established according to the optimal defense strategy. Considering the effectiveness of the active defense measures, in this embodiment, preferably, the active defense effect is simulated and verified, and the relevant rule parameters are dynamically adjusted based on the verification results.

[0061] Based on the preset rule evaluation indicators, the defense effect of the initial defense rules is simulated and evaluated using the reinforcement learning algorithm, and according to the corresponding evaluation results, the initial defense rules are optimized to generate the active defense rules; wherein, the preset rule evaluation indicators include the percentage decrease in the attack success rate after rule execution, the percentage increase in the device operation stability, and the percentage decrease in the business impact degree; in practical applications, a rule execution effect evaluation function can be constructed based on the preset rule evaluation indicators and combined with the reinforcement learning algorithm for defense effect simulation evaluation to iteratively optimize the initial defense rules until an optimized rule that meets the expectations is obtained as the final active defense rule for use.

[0062] In this embodiment, by obtaining the physical domain electrical device information and the vulnerability information of the information domain network devices to identify the key nodes in the attack traceability graph, and automatically analyzing the attacker's strategy through the game theory algorithm combined with the reinforcement learning algorithm to learn the optimal strategy of the defender, a targeted active defense measure is formed. While accurately perceiving the cross-domain attack risk in real time, adaptive defense protection is implemented in a timely manner, effectively improving the ability of the power system to resist complex network attacks.

[0063] In addition, after the active defense measures are sent to the corresponding physical domain electrical devices and information domain network devices, the device parameters can be remotely modified through the relevant device configuration management module to make the defense strategy take effect automatically locally, and the execution effect of the strategy is monitored and evaluated to form a closed-loop adaptive defense adjustment mechanism. The specific process is as follows: obtain the defense rule content from the active defense measures, and convert the defense rule content into a standard device configuration instruction including attributes such as rule type code, instruction operation code, parameter value code, and timestamp; construct an execution queue according to the standard device configuration instruction, generate an execution sequence according to the device area priority numerical order, and generate a corresponding execution status identifier according to the execution sequence; use a rule evaluation matrix to evaluate the execution status identifier, and calculate the corresponding execution quality score through three indicators: response time, activation time, and adjustment amplitude; monitor the execution quality score using a threshold-based adaptive mechanism, and optimize the instruction according to three indicators: configuration download success rate, rule activation accuracy rate, and attack protection rate to achieve adaptive defense closed-loop control.

[0064] In the embodiment of the present application, by comprehensively utilizing the operation monitoring data of physical domain nodes and the traffic data of information domain nodes to identify abnormal events, and through the correlation analysis of abnormal events in different domains and the identification of cross-domain abnormal propagation paths to construct a complete attack traceability map, and combining the vulnerability analysis of key nodes to generate active defense rules for the automatic detection, analysis and defense of adaptive security defense, the application defects of the existing power system security threat defense, which is only limited to single-domain threat monitoring and protection, unable to perform cross-domain abnormal event correlation analysis and difficult to cope with complex attack scenarios of cross-domain collaborative attacks, are effectively solved. It can not only accurately identify complex cross-domain attack risks in real time, but also perform reliable adaptive defense in a timely manner, thereby effectively improving the comprehensiveness and reliability of power system security protection, enhancing the ability of the power system to resist complex network attacks, and providing effective technical support for ensuring the safe and stable operation of the power grid.

[0065] It should be noted that although the steps in the above flowcharts are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders.

[0066] In one embodiment, as Figure 2 shown, a detection and defense system for cross-domain threats in a power system is provided. The system includes: A physical domain anomaly recognition module 1, configured to obtain the operation monitoring data of each physical domain node in the target power grid area, and perform status anomaly recognition according to the operation monitoring data to obtain corresponding physical domain anomaly recognition results; the physical domain anomaly recognition results include abnormal measurement recognition results, abnormal switch recognition results, faulty equipment recognition results and regional fault levels; An information domain attack recognition module 2, configured to obtain the network traffic data of each information domain node in the target power grid area, and perform denial-of-service attack recognition according to the network traffic data to obtain corresponding information domain attack recognition results; A cross-domain anomaly analysis module 3, configured to perform anomaly event correlation analysis on all physical domain anomaly recognition results and all information domain attack recognition results to obtain attack cross-domain anomaly recognition results; An attack chain analysis module 4, configured to generate a corresponding cross-domain attack chain based on the graph theory algorithm according to the power system topology map and the communication network topology map corresponding to the attack cross-domain anomaly recognition results; A traceability map construction module 5, configured to identify key nodes and key risk propagation paths in the cross-domain attack chain, and generate a corresponding attack traceability map according to the key nodes and the key risk propagation paths; An attack and defense processing module 6, configured to iteratively generate active defense rules based on game theory algorithms and reinforcement learning algorithms according to the vulnerability information of key nodes in the attack traceability graph, and send the rules to corresponding physical domain nodes and information domain nodes.

[0067] For the specific limitations of the detection and defense system for cross-domain threats in the power system, reference can be made to the limitations of the detection and defense method for cross-domain threats in the power system in the above text, and the corresponding technical effects can also be equivalently obtained, which will not be elaborated here. Each module in the above detection and defense system for cross-domain threats in the power system can be implemented in whole or in part by software, hardware, and their combinations. The above modules can be embedded in the processor of the computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each of the above modules.

[0068] In summary, the detection and defense method and system for cross-domain threats in the power system provided by the embodiments of the present invention realize obtaining the operation monitoring data of each physical domain node in the target power grid area, performing state anomaly recognition based on the operation monitoring data to obtain the physical domain anomaly recognition results including abnormal measurement recognition results, abnormal switch recognition results, faulty device recognition results, and regional fault levels, obtaining the network traffic data of each information domain node in the target power grid area, performing denial-of-service attack recognition based on the network traffic data to obtain the corresponding information domain attack recognition results, then performing abnormal event correlation analysis on all physical domain anomaly recognition results and all information domain attack recognition results to obtain attack cross-domain anomaly recognition results, and then based on the power system topology graph and communication network topology graph corresponding to the attack cross-domain anomaly recognition results, generating a corresponding cross-domain attack chain based on graph theory algorithms, and identifying the key nodes and key risk propagation paths in the cross-domain attack chain, generating a corresponding attack traceability graph according to the key nodes and key risk propagation paths, and according to the vulnerability information of the key nodes in the attack traceability graph, iteratively generating active defense rules based on game theory algorithms and reinforcement learning algorithms and sending them to the corresponding physical domain nodes and information domain nodes. The method comprehensively uses the operation monitoring data of physical domain nodes and the traffic data of information domain nodes to identify abnormal events, constructs a complete attack traceability graph through correlation analysis of abnormal events in different domains and identification of cross-domain abnormal propagation paths, and generates active defense rules in combination with key node vulnerability analysis for intelligent protection methods of automatic detection, analysis, and defense of adaptive security defense. It can not only accurately identify complex cross-domain attack risks in real time, but also perform reliable adaptive defense in a timely manner, thereby effectively improving the comprehensiveness and reliability of power system security protection, enhancing the ability of the power system to resist complex network attacks, and providing effective technical support for ensuring the safe and stable operation of the power grid.

[0069] Each embodiment in this specification is described in a progressive manner. For the parts that are the same or similar in each embodiment, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple. For the relevant parts, reference can be made to the description of the method embodiment. It should be noted that the technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0070] The above embodiments only represent several preferred embodiments of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be pointed out that for those of ordinary skill in the art in this technical field, without departing from the technical principle of the present invention, several improvements and substitutions can be made, and these improvements and substitutions should also be regarded as the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the protection scope of the claimed rights.

Claims

1. A method for detecting and defending cross-domain threats in a power system, characterized in that: The method comprises the following steps: Acquire operation monitoring data of each physical domain node in the target power grid area, and perform state abnormality identification based on the operation monitoring data to obtain corresponding physical domain abnormality identification results; Acquire network traffic data of each information domain node in the target power grid area, and perform denial of service attack identification based on the network traffic data to obtain corresponding information domain attack identification results; Perform abnormal event correlation analysis on all physical domain anomaly identification results and all information domain attack identification results to obtain cross-domain attack anomaly identification results; According to the power system topology map and the communication network topology map corresponding to the cross-domain anomaly identification result of the attack, a corresponding cross-domain attack chain is generated based on a graph theory algorithm; Identify key nodes and key risk propagation paths in the cross-domain attack chain, and generate corresponding attack source tracing graphs based on the key nodes and the key risk propagation paths; According to the vulnerability information of key nodes in the attack tracing map, active defense rules are iteratively generated based on game theory algorithms and reinforcement learning algorithms and sent to corresponding physical domain nodes and information domain nodes.

2. The method for detecting and defending against cross-domain threats in a power system according to claim 1, characterized in that: The operation monitoring data includes operation parameter information and switch protection information; the operation parameter information includes voltage amplitude, current amplitude, voltage phase angle, current phase angle, voltage frequency and current frequency; the switch protection information includes equipment switch state and switch opening and closing state information; the physical domain abnormality identification result includes abnormal measurement identification result, abnormal switch identification result, faulty equipment identification result and regional fault level; The step of performing state anomaly identification according to the operation monitoring data to obtain a corresponding physical domain anomaly identification result comprises: Compare each operating parameter information with the corresponding preset parameter safety threshold range to obtain an abnormal measurement identification result; the abnormal measurement identification result includes the abnormal operating parameter and the corresponding abnormal data type and the abnormal occurrence timestamp; Compare the switch opening and closing state information with the corresponding device switch state to obtain an abnormal switch identification result; the abnormal switch identification result includes the state abnormality type corresponding to each abnormal switch identification number and the state abnormality occurrence timestamp; According to the abnormal switch identification result and the preset switch bus association code table, the abnormal switch area is located to obtain the corresponding fault device identification result; the fault device identification result includes the fault area code and fault timestamp corresponding to each fault switch identifier; According to the preset neural network model, feature analysis is performed on the abnormal measurement identification results in the fault area corresponding to the identification results of each faulty device, and a corresponding feature abnormality weight matrix is ​​generated. The fault area abnormality level is determined according to the feature abnormality weight matrix to obtain the corresponding regional fault level.

3. The method for detecting and defending against cross-domain threats in a power system according to claim 1, characterized in that: The information domain attack identification result includes the denial of service attack identification result of each target attack port and the corresponding attack level; The step of performing denial of service attack identification according to the network traffic data to obtain a corresponding information domain attack identification result comprises: Abnormal traffic is centrally identified based on the network traffic data to obtain a port traffic aggregation identification result; the network traffic data includes the number of network connections and bandwidth utilization; According to the port traffic aggregation identification result, the inflow traffic monitoring data of each traffic aggregation port is obtained, and the denial of service attack is identified according to the inflow traffic monitoring data to obtain the corresponding information domain attack identification result.

4. The method for detecting and defending against cross-domain threats in a power system according to claim 3, characterized in that: The step of performing centralized identification of abnormal traffic according to the network traffic data to obtain a port traffic aggregation identification result comprises: Compare each network traffic data with the corresponding preset rated threshold range to obtain traffic anomaly information; the traffic anomaly information includes the number of abnormal connections, bandwidth utilization and the time when the anomaly occurs; According to the traffic anomaly information, relevant port traffic data is acquired, and trend anomaly identification is performed on the relevant port traffic data to obtain corresponding port anomaly identification results; the port anomaly identification results include traffic data corresponding to each abnormal port number; According to the preset port traffic judgment matrix, each abnormal port is classified into traffic abnormality levels to obtain the corresponding port traffic abnormality classification results; the preset port traffic judgment matrix is ​​constructed based on preset level judgment indicators; the preset level judgment indicators include port traffic fluctuation amplitude, traffic duration and traffic growth rate; According to the abnormal classification results of each port traffic, the corresponding adjacent port traffic data is obtained, and abnormal traffic aggregation analysis is performed based on the adjacent port traffic data to obtain the port traffic aggregation identification result; the port traffic aggregation identification result includes the number of ports in the group corresponding to each traffic aggregation port group and the direction of aggregated traffic.

5. The method for detecting and defending against cross-domain threats in a power system according to claim 3, characterized in that: The step of identifying a denial of service attack based on the inflow traffic monitoring data to obtain a corresponding information domain attack identification result comprises: Determine whether the inflow traffic monitoring data meets the preset traffic aggregation identification condition. If so, determine that the corresponding traffic aggregation port is a traffic flood attack port, and obtain the source address set of the data packet with the traffic flood attack port as the destination port; the preset traffic aggregation identification condition is that the inflow traffic exceeds the port baseline traffic by a preset multiple and lasts for more than a preset time; Distributed attack identification, half-open connection identification and deformed packet identification are performed according to the source address connection data record corresponding to the source address set of the data packet, and attack classification processing is performed on the obtained abnormal feature identification result according to the preset machine learning model to generate the denial of service attack identification result; the denial of service attack identification result includes attack source characteristics, attack type, attack duration and detection timestamp; Perform source address dispersion analysis according to the data packet source address set and a preset dispersion identification condition to generate a corresponding source address dispersion identifier; the preset dispersion identification condition is that the minimum physical distance between addresses is greater than a preset distance threshold and the access proportion of each source address is less than a preset ratio; the source address dispersion identifier includes the access record, address location and access timestamp of each source address; According to the transmission control protocol specification and the preset inspection field, the inflow data packets of the traffic flood attack port are counted abnormally, and when the proportion of abnormal data packets exceeds the abnormal percentage threshold, the corresponding connection abnormality identification result is generated; the preset inspection field includes the handshake packet flag bit sequence, the packet header length and the checksum; the connection abnormality identification result includes the number of abnormal packets, the total number of inflow data packets and the inspection time; The traffic flood attack identifier, source address dispersion identifier and connection anomaly identification result of the traffic flood attack port are comprehensively analyzed to obtain a comprehensive score of the attack behavior, and a corresponding attack level is obtained based on the comprehensive score of the attack behavior; the traffic flood attack identifier includes the target port, incoming traffic, baseline traffic, attack start time and attack duration.

6. The method for detecting and defending against cross-domain threats in a power system according to claim 1, characterized in that: The step of performing abnormal event correlation analysis on all physical domain abnormality identification results and all information domain attack identification results to obtain the attack cross-domain abnormality identification result includes: Compare the anomaly occurrence timestamps of each physical domain anomaly identification result with each information domain attack identification result, and generate cross-domain anomaly association data based on anomaly events in which the nodes belong to the same physical area and the anomaly occurrence timestamp deviation is less than the preset fault response time; the cross-domain anomaly association data includes the physical domain node number, information domain node number, time correlation, spatial correlation and correlation timestamp corresponding to each cross-domain anomaly event; According to the cross-domain abnormal association data, and the physical connection relationship and communication link relationship of the equipment in the target power grid area, a corresponding electrical primary equipment topology map and a secondary equipment communication topology map are constructed, and abnormal nodes whose distances in the electrical primary equipment topology map and the secondary equipment communication topology map are less than a preset connection layer threshold are obtained to generate corresponding association group data; the association group data includes a physical domain equipment list, an information domain equipment list, a physical distance between equipment, a communication link hop count, and a spatial association degree; Perform feature analysis on abnormal events in the associated group data according to a preset feature matching table, and identify the severity of abnormal events through a preset feature combination counting judgment principle to obtain a high-level abnormal group; Establishing a device connectivity graph corresponding to the high-level abnormal group, and obtaining a corresponding group diffusion risk value according to the degree of connection between devices in the device connectivity graph; When the group diffusion risk value exceeds the preset warning value, the attack cross-domain anomaly identification result is generated; the attack cross-domain anomaly identification result includes a risk device list, a diffusion warning level and a warning release time.

7. The method for detecting and defending against cross-domain threats in a power system according to claim 1, characterized in that: The step of generating a corresponding cross-domain attack chain based on a graph theory algorithm according to the power system topology map and the communication network topology map corresponding to the cross-domain anomaly identification result of the attack comprises: Establishing a node mapping relationship matrix between physical domain nodes in the power system topology diagram and communication domain nodes in the communication network topology diagram; Perform abnormal node traversal on the power system topology map and the communication network topology map through a depth-first search algorithm, and perform matching analysis on the physical adjacent nodes and the communication adjacent nodes of each abnormal node according to the node mapping relationship matrix to generate an abnormal propagation node table; The shortest propagation paths of each abnormal node in the abnormal propagation node table in the power system topology diagram and the communication network topology diagram are calculated respectively by using the Dykstra algorithm, and the propagation impact of each shortest propagation path is evaluated according to the link bandwidth utilization between communication nodes, the state quantity of the circuit breaker between physical nodes, and the action signal of the protection device, and the cascade impact path is generated according to the corresponding impact evaluation results; According to the preset path priority index, the path priority of each cascade impact path is evaluated respectively, and the cascade impact paths are sorted according to the corresponding priority evaluation results to generate the cross-domain attack chain; the preset path priority index includes node connection density, node bandwidth occupancy, node protection configuration and node communication delay; the cross-domain attack chain includes the source node, destination node and path priority corresponding to each propagation path.

8. The method for detecting and defending against cross-domain threats in a power system according to claim 1, characterized in that: The step of identifying the key nodes and the key risk propagation path in the cross-domain attack chain, and generating a corresponding attack source tracing map according to the key nodes and the key risk propagation path includes: Obtaining node connection relationship data of the cross-domain attack chain, and calculating the node degree and betweenness centrality index of each node according to the node connection relationship data, and screening key nodes according to the node degree and betweenness centrality index; According to the inter-node connection relationship of all key nodes, the corresponding propagation path is constructed, and the risk of each propagation path is evaluated according to the preset path significance index to obtain the key risk propagation path; Based on the force-directed layout algorithm, each key risk propagation path is visualized and laid out to generate the corresponding risk propagation layout plan; According to the risk propagation layout plan and preset graphical annotation rules, the corresponding key risk propagation paths are annotated to generate the attack tracing map; the preset graphical annotation rules include coloring rules and icon sizes for different types of nodes, and pixel setting rules for connecting lines between nodes based on the degree of influence between nodes.

9. The method for detecting and defending against cross-domain threats in a power system according to claim 1, characterized in that: The vulnerability information includes the node software version lag, the number of communication protocol vulnerabilities and the patch update status; The step of iteratively generating active defense rules through a game theory algorithm and a reinforcement learning algorithm according to the vulnerability information includes: The vulnerability information of each key node is subjected to weighted comprehensive analysis to obtain the corresponding node vulnerability score, and the key nodes whose node vulnerability scores exceed the preset score threshold are regarded as high-risk nodes; According to the vulnerability identification of each high-risk node and the preset attack and defense game benefit matrix, multiple rounds of game iterative calculations are performed based on the non-zero-sum game algorithm to generate the optimal defense strategy; the vulnerability identification includes the vulnerability level, attack difficulty coefficient and node vulnerability score; Generate corresponding initial defense rules according to the optimal defense strategy; the initial defense rules include port restriction rules, traffic control rules and electrical parameter adjustment rules; According to the preset rule evaluation indicators, the defense effect simulation evaluation of the initial defense rules is performed based on the reinforcement learning algorithm, and according to the corresponding evaluation results, the initial defense rules are optimized to generate the active defense rules; the preset rule evaluation indicators include the percentage decrease in attack success rate after the rule is executed, the percentage increase in equipment operation stability, and the percentage decrease in business impact.

10. A detection and defense system for cross-domain threats in power systems, characterized in that: The system comprises: A physical domain anomaly identification module is used to obtain the operation monitoring data of each physical domain node in the target power grid area, and identify the state anomaly according to the operation monitoring data to obtain the corresponding physical domain anomaly identification result; the physical domain anomaly identification result includes abnormal measurement identification result, abnormal switch identification result, faulty equipment identification result and regional fault level; An information domain attack identification module is used to obtain network traffic data of each information domain node in the target power grid area, and perform denial of service attack identification based on the network traffic data to obtain corresponding information domain attack identification results; The cross-domain anomaly analysis module is used to perform abnormal event correlation analysis on all physical domain anomaly identification results and all information domain attack identification results to obtain cross-domain attack anomaly identification results; An attack chain analysis module, used to generate a corresponding cross-domain attack chain based on a graph theory algorithm according to a power system topology map and a communication network topology map corresponding to the cross-domain anomaly identification result of the attack; A traceability graph construction module, used to identify key nodes and key risk propagation paths in the cross-domain attack chain, and generate corresponding attack traceability graphs according to the key nodes and the key risk propagation paths; The attack defense processing module is used to iteratively generate active defense rules based on the vulnerability information of key nodes in the attack tracing map and the game theory algorithm and reinforcement learning algorithm, and send them to the corresponding physical domain nodes and information domain nodes.

Citation Information

Patent Citations

  • Network attack physical side and information side collaborative tracing device for power grid information physical system

    CN111556083A

  • Attack tracing method based on multi-dimensional information

    CN115664703A

  • Power distribution terminal information-physics bidirectional cross-domain attack analysis method

    CN116566658A

  • Cross-domain attack path assessment method and device, equipment and storage medium

    CN117395043A

  • Attack path prediction method and device based on distributed energy system

    CN117579398A

Cited By

  • Multi-stage protection method and system for electric power system

    CN120528711A

  • Electric power safety monitoring management method

    CN120601625A

  • Multi-level power network threat collaborative identification method and system

    CN120658530A

  • Network security defense method and device for automatic fire alarm system

    CN120675820A

  • Network situation monitoring system and method

    CN120729633A