A method for identifying critical substations of power grid considering cyber-physical cross-domain attacks

By constructing network attack paths and quantifying attack costs, a two-layer optimization model is established to identify key power plants and their internal circuit breakers in the power transmission system. This solves the problem of insufficient identification in existing technologies, enhances the power grid's defense capabilities, and ensures the safety and stability of the power system.

CN120281551BActive Publication Date: 2026-01-20NORTH CHINA ELECTRIC POWER UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510520135.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-24
Publication Date
2026-01-20
Estimated Expiration
2045-04-24

AI Technical Summary

Technical Problem

Existing cybersecurity protection technologies are insufficient in identifying critical power transmission system plants and assessing the impact of attacks. They lack systematic analysis and precise quantification of attack paths, resulting in unreasonable resource allocation and an inability to effectively defend against cross-domain cyber-physical attacks.

Method used

By constructing network attack paths, quantifying attack costs, establishing a two-layer optimization model, combining KKT conditions and the Fortune-Amat-McCarl method for relaxed complementary condition linearization, identifying key plants and their internal circuit breakers, and using MATLAB and CPLEX solvers for numerical calculations to optimize defense resource allocation.

Benefits of technology

It enables accurate identification and efficient defense of key power plants in the power transmission system, enhances the power grid's ability to resist cross-domain attacks, and ensures the safe and stable operation of the power system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281551B_ABST
    Figure CN120281551B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of power system, specifically relates to a kind of power transmission system key station identification method considering network-physical cross-domain attack, comprising the following steps: S1, the defense measure information of target substation is obtained: network defense measure configuration condition is obtained;S2, network attack path is built: according to the actual defense situation of substation, network attack path is proposed;S3, attack cost quantitative analysis: the attack cost paid by attacker in attack path is quantified;S4, attack cost clustering: attack cost is clustered;S5, attack optimization model is established: double-layer optimization model is established;S6, identification key station: double-layer optimization model is solved, finds system fragile station node, and power transmission system key station identification is carried out;The present application can help power transmission system to identify high-risk station in advance, optimize defense resource configuration, improve the ability of power grid to resist cross-domain attack.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to the technical field of power systems, in particular to a power transmission system key substation identification method considering network-physical cross-domain attacks. BACKGROUND

[0002] With the continuous improvement of the intelligence and informatization of the power system, the network security problem is increasingly prominent, and the power transmission system, as an important part of the national energy infrastructure, is facing increasingly severe network security threats. Attackers can use network vulnerabilities to penetrate power dispatching and control systems, thereby affecting the normal operation of physical devices, and even causing large-scale power outages. In recent years, the network attack means for the key substations of the power transmission system have been upgraded, and the attack methods have gradually developed from traditional single-point intrusion to coordinated attacks, involving malicious software, distributed denial-of-service attacks, logic bomb implantation, data tampering and other attack methods. How to identify the key substations of the power transmission system that are most vulnerable to attacks and evaluate the impact after the attacks has become an important issue for ensuring the safe and stable operation of the power system.

[0003] Although the existing network security protection technology has improved the security of the power system to a certain extent, there are still many deficiencies. First, the current research on network attack paths is not systematic enough, and there is a lack of complete path description of how attackers break through from outside the station to inside the station and control the key devices, and the role of defense measures such as firewalls and intrusion detection systems is not fully considered. Secondly, the existing research on attack cost quantification is not accurate enough, and it does not fully consider the intrusion costs of attackers in substations with different defense configurations, including the costs of firewall breakthrough, intrusion detection system deception, operator station permission acquisition and circuit breaker control. In resource-limited attack operations, unreasonable resource allocation may lead to attack failure. Therefore, accurate quantification of attack cost is crucial for network-physical cross-domain attack modeling. SUMMARY

[0004] The application provides a power transmission system key substation identification method considering network-physical cross-domain attacks, which identifies the key substations that have the most serious impact on the safety of the power grid, so as to deploy defense measures in advance and improve the ability of the power system to resist cross-domain attacks.

[0005] A power transmission system key substation identification method considering network-physical cross-domain attacks, comprising the following steps:

[0006] S1, obtaining defense measure information of a target substation: obtaining the network defense measure configuration of the target substation in the power transmission system, including firewalls and intrusion detection systems (IDS);

[0007] S2, constructing a network attack path: proposing a network attack path according to the actual defense situation of the substation;

[0008] S3, attack cost quantitative analysis: quantifying the attack cost paid by the attacker in the attack path, including the breaking-in cost C1, the deception cost C2, the decryption cost C3, the control capture cost C4, and the remote control cost C5;

[0009] S4, attack cost clustering: clustering the attack cost, and the clustering is the control capture substation cost and the remote control circuit breaker cost;

[0010] S5, establishing an attack optimization model: combining the attack cost and the limited attack resources of the attacker, and establishing a double-layer optimization model;

[0011] S6, identifying key substations: solving the double-layer optimization model, finding the vulnerable substation nodes of the system, and identifying the key substations of the power transmission system.

[0012] Optionally, the constructing a network attack path in S2 comprises:

[0013] S21, breaking through the firewall: the attacker breaks through the firewall network of the target substation;

[0014] S22, deceiving the intrusion detection system: performing a deception attack on the intrusion detection system (IDS);

[0015] S23, password cracking: cracking the operator station password and performing remote login;

[0016] S24, capturing the circuit breaker: capturing the control authority of the target circuit breaker;

[0017] S25, sending instructions: sending trip instructions to the target circuit breaker and concealing the instruction information.

[0018] Optionally, the breaking-in cost C1 is the cost of breaking through the firewall, the deception cost C2 is the cost of deceiving the intrusion detection system (IDS), the decryption cost C3 is the cost of cracking the operator station password, the control capture cost C4 is the cost of capturing the control authority of the circuit breaker, and the remote control cost C5 is the cost of sending trip instructions and concealing information.

[0019] Optionally, the control capture substation cost comprises: the breaking-in cost C1, the deception cost C2, and the decryption cost C3 of the control capture substation, and the remote control circuit breaker cost comprises: the control capture cost C4 and the remote control cost C5 of the remote control circuit breaker.

[0020] Optionally, the double-layer optimization model comprises an upper-layer optimization model and a lower-layer optimization model.

[0021] Optionally, the objective function of the upper-layer optimization model is to maximize the load loss of the attacker, representing the optimal attack decision of the attacker under the limited attack resources, and the decision variable is a binary variable of whether to launch a takeover attack on the substation and a binary variable of whether to remotely control the circuit breaker , which is expressed as:

[0022] ;

[0023] wherein, is the number of substations, is the load shedding amount of the substation node;

[0024] The constraint condition of the upper-layer optimization model is:

[0025] ;

[0026] ;

[0027] ;

[0028] ;

[0029] ;

[0030] ;

[0031] ;

[0032] wherein, is the set of substations, is the set of related circuit breakers of the transmission line in the substation T, is the set of transmission lines, is the remote control cost of the circuit breaker, is the network breaking cost C1 of the substation T, is the deception cost C2 of the substation T, is the decryption cost C3 of the substation T, is the takeover cost C4 of the circuit breaker S in the substation T, is the remote control cost C5 of the circuit breaker S in the substation T, is the attack resources available to the attacker, is a binary variable of whether to launch a takeover attack on the substation, is a binary variable of whether to remotely control the circuit breaker, is a binary variable of the circuit breaker state, is a binary variable of the related line state, is a binary variable of the substation state.

[0033] Optionally, the objective function of the lower-layer optimization model is to minimize the amount of load shedding when the power grid dispatches after the system is attacked, expressed as:

[0034] ;

[0035] The constraint condition of the lower-layer optimization model is:

[0036] ;

[0037] ;

[0038] ;

[0039] ;

[0040] ;

[0041] ;

[0042] wherein, represents the active power flow of the line mn, represents the power generation of the substation , represents the load of the substation , represents the phase angle of the node of the substation .

[0043] Optionally, the identification of the key substation in S6 comprises:

[0044] S61, converting the lower-layer optimization model: replacing the lower-layer optimization model with KKT (Karush-Kuhn-Tucker) condition, linearizing the complementary condition by Fortuny-Amat-McCarl method, and converting the lower-layer optimization model into equivalent linear constraint condition;

[0045] S62, constructing a single-layer linear model: converting the double-layer optimization model into a single-layer linear optimization model through KKT transformation;

[0046] S63, setting model example parameters: setting the attacker parameters, including the attack resources R available to the attacker, setting the defense parameters, including the target power grid network structure and the connection relationship of each substation, the defense measure configuration of each substation and the corresponding network breaking cost C1, deception cost C2, deciphering cost C3, circuit breaker control cost C4 and remote control cost C5, setting the corresponding connection relationship of the circuit breaker and the transmission line in each substation;

[0047] S64, Model conversion to MATLAB for solution: The converted single-layer linear optimization model is translated into MATLAB language, and numerical calculation is performed using the CPLEX solver to solve the optimization problem;

[0048] S65, Identify Key Substations: Given limited attack resources, find the optimal attack targets, including substations that cause the largest load shedding and their internal circuit breakers.

[0049] Optionally, the lower-level optimization model in S61 includes:

[0050] S611, Constructing the Lagrange function: Introducing Lagrange multipliers, we construct the Lagrange function, expressed as:

[0051] ;

[0052] in, For the corresponding Lagrange multiplier variables, For the corresponding Lagrange multiplier variables, For the corresponding Lagrange multiplier variables, For the corresponding Lagrange multiplier variables, For the corresponding Lagrange multiplier variables, For the corresponding Lagrange multiplier variables;

[0053] S612, KKT conditions: The KKT conditions are given as follows:

[0054] ;

[0055] ;

[0056] ;

[0057] ;

[0058] ;

[0059] ;

[0060] ;

[0061] in, For substation Electricity generation The 0-1 variables corresponding to the relevant relaxation complementarity conditions, For the active power flow of line mn The 0-1 variables corresponding to the relevant relaxation complementarity conditions, Load shedding at substation nodes 0-1 variables corresponding to the relevant relaxed complementary conditions, For a substation Phase angle of a node 0-1 variables corresponding to the relevant relaxed complementary conditions, Indicates a maximum value.

[0062] Advantages of the present application:

[0063] The present application, by modeling the defense measures, attack path and attack cost of the substation, establishes a collaborative attack double-layer optimization model based on DC power flow analysis, quantifies the network attack path as network breaking cost C1, deception cost C2, decryption cost C3, control cost C4 and remote control cost C5, and clusters them into control substation cost and remote control circuit breaker cost based on the sequence of attack steps, which helps to accurately evaluate the resource consumption and influence range of the attacker, makes the attack modeling more refined, and improves the scientificity and reliability of the key station identification.

[0064] The present application, by converting the lower layer optimization problem using KKT condition, and combining Fortuny-Amat-McCarl method to linearize the relaxed complementary condition, can convert the optimization problem into a single-layer linear optimization model, and then use MATLAB and CPLEX solver for numerical calculation, through the optimization model, the optimal attack target that maximizes the load loss of the power transmission system can be determined under the condition of limited attacker resources, so as to accurately identify the key station and its internal circuit breaker, and provide important theoretical support for the optimization of the power grid defense system, which can help the power transmission system to identify high-risk stations in advance, optimize the allocation of defense resources, and improve the ability of the power grid to resist cross-domain attacks. BRIEF DESCRIPTION OF DRAWINGS

[0065] In order to more clearly illustrate the technical solutions in the present application or prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are only a part of the present application, and other drawings can also be obtained by those skilled in the art without creative labor.

[0066] Figure 1 It is a network-physical cross-domain attack step and cost framework schematic diagram of the embodiment of the present application.

[0067] Figure 2 It is an identification method flowchart schematic diagram of the embodiment of the present application. DETAILED DESCRIPTION

[0068] The application will be described in greater detail in connection with the accompanying drawings and specific embodiments. It should be noted that the embodiments described below are best modes, preferred embodiments, and other alternative modes can be implemented by those skilled in the art for some well-known technologies; and the accompanying drawings are only used to more specifically describe the embodiments and are not intended to specifically limit the application.

[0069] It should be noted that the terms "one embodiment", "an embodiment", "exemplary embodiment", "some embodiments", etc. in the description indicate that the described embodiment can include a specific feature, structure or characteristic, but not necessarily every embodiment includes the specific feature, structure or characteristic. In addition, when a specific feature, structure or characteristic is described in connection with an embodiment, it should be within the knowledge of those skilled in the art to implement such a feature, structure or characteristic in connection with other embodiments, whether or not explicitly described.

[0070] Generally, the terms can be understood at least in part from the context in which they are used. For example, depending on the context, the term "one or more" as used herein can be used to describe any feature, structure, or characteristic in the singular or can be used to describe combinations of features, structures, or characteristics, whether large or small, whether related or unrelated to each other. In addition, the term "based on" can be understood as not necessarily intended to convey a set of exclusive factors, but can instead, depending on the context, allow for the existence of other factors not necessarily explicitly described.

[0071] As shown in Figures 1-2 A power system critical substation identification method considering cyber-physical cross-domain attacks includes the following steps:

[0072] 1. Cross-domain attack path and cost modeling:

[0073] (1) Propose an attack path:

[0074] To implement a "cyber-physical" cross-domain attack, first, enter the substation internal network without being detected by staff. Since most important substations are equipped with firewalls and intrusion detection systems (IDS) to identify unauthorized intrusion events, it is necessary to break through the firewall network and deceive the intrusion detection system, which requires the attacker's attack resources. After successfully entering the internal network, the operator station password needs to be cracked and the operation permission is obtained. After obtaining the operator station permission, the attacker sends a trip command to multiple circuit breakers in the station, remotely controls the circuit breaker trip. Thereafter, the attacker needs to continue to hide the command information and interfere with the remedial measures of the operating personnel, increase the power outage time, and worsen the power outage consequences. The specific steps and related costs are shown in Figure 1

[0075] The specific description is as follows: ​

[0076] STEP 1: attacker breaks the target substation firewall network;

[0077] STEP 2: deceive the intrusion detection system (IDS);

[0078] STEP 3: crack the operator station password and remotely log in;

[0079] STEP 4: seize the control authority of the target circuit breaker;

[0080] STEP 5: send a trip command to the target circuit breaker and conceal the command information.

[0081] (2) Quantify the attack cost:

[0082] The attacker needs to pay a certain attack cost for each attack step STEP1-STEP5. The attack costs C1-C5 together constitute the total cost of the attacker's network attack on a certain substation.

[0083] STEP1) Firewall breaking network corresponds to network breaking cost C1;

[0084] STEP2) IDS deception corresponds to deception cost C2;

[0085] STEP3) Operator station password cracking corresponds to cracking cost C3;

[0086] STEP4) Circuit breaker control authority seizure corresponds to control seizure cost C4;

[0087] STEP5) Send trip command and conceal information corresponds to remote control cost C5;

[0088] In order to simplify the analysis, various attack costs are clustered according to the actual attack steps. When the attacker conducts a network attack, he needs to seize the control of the substation first, and then can remotely control the trip attack of the circuit breaker in the station. Therefore, the above five kinds of network attack costs are aggregated as: substation control seizure cost and circuit breaker remote control cost .

[0089] Among them, the substation control seizure cost includes the network breaking cost C1, deception cost C2, and cracking cost C3 of the substation; the circuit breaker remote control cost includes the control seizure cost C4 and the remote control cost C5.

[0090] (3) Cooperative attack modeling:

[0091] Because of the difference of defense measures taken by different substations, the cost of attack by attackers on them is also different. Considering the network attack cost and the load loss consequences of attack of each substation, a bi-level optimization model is established based on direct current flow. The attacker can identify the key substations of power transmission system in the "cyber-physical" cross-domain attack, and the key substations and the related circuit breakers in the substations that can produce the optimal attack consequences under the limited attack resources are selected.

[0092] 2. Bi-level optimization model modeling:

[0093] (1) Parameter description:

[0094] is the set of substations, and is the index;

[0095] is the set of circuit breakers related to the transmission line in substation T, and is the index;

[0096] is the set of transmission lines, and mn is the index;

[0097] is the number of substations, ;

[0098] is the number of circuit breakers related to the transmission line in substation T, ;

[0099] is the cost of seizing control of substations, including the cost of breaking the network C1, the cost of deception C2 and the cost of breaking C3;

[0100] is the cost of remote control of circuit breakers, including the cost of seizing control C4 and the cost of remote control C5;

[0101] is the cost of breaking the network C1 of substation T;

[0102] is the cost of deception C2 of substation T;

[0103] is the cost of breaking C3 of substation T;

[0104] is the cost of seizing control C4 of circuit breaker S in substation T;

[0105] is the cost of remote control C5 of circuit breaker S in substation T;

[0106] ​​Attack resources available to the attacker;

[0107] Binary variable representing whether to launch a takeover attack on the substation, 1 represents attack, 0 represents no attack;

[0108] Binary variable representing whether to remotely control the circuit breaker, 1 represents attack, 0 represents no attack;

[0109] Binary variable representing the state of the substation, 0 represents being attacked, 1 represents not being attacked;

[0110] Binary variable representing the state of the circuit breaker, 0 represents being attacked, 1 represents not being attacked;

[0111] Binary variable representing the state of the relevant line, 0 represents being attacked, 1 represents not being attacked, Corresponding one by one;

[0112] The load shedding amount of the substation node;

[0113] Active power flow of line mn;

[0114] Power generation of substation ;

[0115] Load of substation ;

[0116] Phase angle of substation Node;

[0117] (2) Upper optimization model:

[0118] ① Objective function:

[0119] The attacker establishes an attack model with the maximum load loss as the attack target, representing the optimal attack decision of the attacker under the limited attack resources, and the decision variable is the substation And the circuit breaker switch In the station.

[0120] (1)

[0121] ② Upper constraint condition:

[0122] (2) ​

[0123] (3)

[0124] (4)

[0125] The above two formulas represent the change of substation, circuit breaker and related line state under network attack.

[0126] (5)

[0127] The above formula represents that only when the substation attack is successful, the circuit breaker in the station can be attacked.

[0128] (6)

[0129] The above formula represents the cost of seizing the substation T.

[0130] (7)

[0131] The above formula represents the cost of remotely controlling the circuit breaker S.

[0132] (8)

[0133] The above formula represents the attacker's attack resource limit.

[0134] (3) Lower optimization model:

[0135] ① Objective function:

[0136] The lower model represents the dispatching behavior of the power grid dispatching party after the system is attacked, and the objective function is to minimize the load shedding amount.

[0137] (9)

[0138] ② Constraint condition:

[0139] (10)

[0140] The above formula represents the equality constraint of the line mn active power flow.

[0141] (11)

[0142] The above formula represents the node power flow balance equation.

[0143] (12)

[0144] The above formula represents the node power generation constraint.

[0145] (13)

[0146] The above formula represents the active power flow constraint of the line.

[0147] (14)

[0148] The above formula represents the load shearing constraint.

[0149] (15)

[0150] The above formula represents the phase angle constraint of the nodes.

[0151] (4) Model solution:

[0152] The above model is a linear model. The lower-level linear optimization model can be directly replaced by the KKT (Karush–Kuhn–Tucker) conditions, and the complementary conditions can be linearized using the Fortune-Amat-McCarl method to obtain the equivalent linear constraints of the lower-level optimization model. Equations (A1)-(A7) represent the equivalent linear constraints of the lower-level optimization model. The details are as follows.

[0153] For the corresponding Lagrange multiplier variables;

[0154] For the corresponding Lagrange multiplier variables;

[0155] For the corresponding Lagrange multiplier variables;

[0156] For the corresponding Lagrange multiplier variables;

[0157] For the corresponding Lagrange multiplier variables;

[0158] For the corresponding Lagrange multiplier variables;

[0159] For substation Electricity generation The 0-1 variables corresponding to the relevant relaxation complementarity conditions;

[0160] For the active power flow of line mn The 0-1 variables corresponding to the relevant relaxation complementarity conditions;

[0161] Load shedding at substation nodes The 0-1 variables corresponding to the relevant relaxation complementarity conditions;

[0162] For substation Phase angle of the node 0-1 variables corresponding to the relevant slack complementary conditions;

[0163] denotes a maximum value.

[0164] ① Construct the Lagrange function:

[0165]

[0166] ② Corresponding KKT conditions:

[0167] (A1)

[0168] (A2)

[0169] (A3)

[0170] (A4)

[0171] (A5)

[0172] (A6)

[0173] (A7)

[0174] After the lower model is replaced by formula (A1)-(A7), the original double-layer model is converted into a single-layer linear model, which can be directly solved by the MATLAB solver.

[0175] 3. Key plant station identification:

[0176] In order to identify the key plant station, the relevant parameters of the attack party and the defense party in the above model are set in the example. The attack party parameter is the total attack resources R that the attack party can control. The defense party parameters include the target power system network structure and the connection relationship of each substation; the configuration of the defense measures in each substation and the corresponding network breaking cost C1, deception cost C2, decryption cost C3, circuit breaker control cost C4 and remote control cost C5; the corresponding connection relationship of the circuit breaker and the transmission line in each substation, etc.

[0177] After the example parameters are determined, the single-layer mathematical model can be converted into MATLAB language, the CPLEX solver is used, and the model is solved on the MATLAB software. After successful solving, the optimal attack substation and its internal circuit breaker of the attacker under the limited attack resources according to the maximum load shedding attack target of the target power system can be obtained, and the substation is the key plant station in the target power system.

[0178] ​The present application encompasses any alternatives, modifications, equivalent methods and solutions made to the essence and scope of the present application. In order to make the public have a thorough understanding of the present application, specific details are described in the following preferred embodiments of the present application, and the present application can also be fully understood without the description of these details to those skilled in the art. In addition, in order to avoid unnecessary confusion to the essence of the present application, well-known methods, processes, procedures, elements and circuits, etc. are not described in detail.

[0179] The above is only the preferred embodiment of the present application, and it should be pointed out that for ordinary skilled in the art, without departing from the principles of the present application, a number of improvements and refinements can also be made, which should be considered as the protection scope of the present application.

Claims

1. A method for critical substations identification of power transmission system considering cyber-physical cross-domain attacks, characterized in that, The method comprises the following steps: S1, obtaining defense measure information of a target substation: obtaining network defense measure configuration of the target substation in a power transmission system, including a firewall and an intrusion detection system; S2, constructing a network attack path: proposing a network attack path according to the actual defense situation of the substation; S3, attack cost quantitative analysis: quantifying attack costs paid by an attacker in the attack path, including a network breaking cost C1, a deception cost C2, a decryption cost C3, a control seizing cost C4 and a remote control cost C5; S4, attack cost clustering: clustering the attack costs, and the clustering is classified into a control seizing substation cost and a remote control circuit breaker cost; S5, establishing an attack optimization model: combining the attack costs and limited attack resources of the attacker, and establishing a double-layer optimization model; S6, identifying a key substation: solving the double-layer optimization model, finding a system vulnerable substation node, and identifying a key substation of the power transmission system; The double-layer optimization model comprises an upper-layer optimization model and a lower-layer optimization model; The objective function of the upper optimization model is to maximize the load loss of the attacker, representing the optimal attack decision of the attacker under the limited attack resources, and the decision variable is a binary variable of whether to launch a takeover attack on the substation and a binary variable of whether to remotely control the circuit breaker , which is represented as: ; wherein, is the number of substations, is the load shedding amount of the substation node; The constraint condition of the upper-layer optimization model is: ; ; ; ; ; ; ; wherein, is a set of substations, is a set of circuit breakers associated with transmission lines in substation T, is a set of transmission lines, is a cost of remote circuit breakers, is a blackout cost C1 for substation T, is a deception cost C2 for substation T, is a decryption cost C3 for substation T, is a takeover cost C4 for circuit breaker S in substation T, is a remote control cost C5 for circuit breaker S in substation T, is an attack resource available to an attacker, is a binary variable indicating whether a takeover of a substation is launched, is a binary variable indicating whether a remote control of a circuit breaker is launched, is a binary variable indicating the state of a circuit breaker, is a binary variable indicating the state of an associated line, is a binary variable indicating the state of a substation; The objective function of the lower-layer optimization model is to minimize the amount of load shedding when the power grid dispatcher implements scheduling after the system is attacked, and is expressed as: ; The constraint condition of the lower-layer optimization model is: ; ; ; ; ; ; wherein, Pmn represents the active power flow of the line mn, Pgen represents the power generation of the substation Pload represents the load of the substation θmn represents the phase angle of the substation θmn represents the phase angle of the substation θmn represents the phase angle of the substation θmn represents the phase angle of the substation 2.The method of claim 1, wherein, The network attack path in S2 comprises: S21, breaking through a firewall: an attacker breaks through a firewall network of a target substation; S22, deceiving an intrusion detection system: performing a deception attack on the intrusion detection system; S23, password cracking: cracking an operator station password and performing remote login; S24, seizing a circuit breaker: seizing control authority of a target circuit breaker; S25, sending an instruction: sending a trip instruction to the target circuit breaker and hiding instruction information. 3.The method of claim 2, wherein, The network breaking cost C1 is the cost of breaking through the firewall, the deception cost C2 is the cost of deceiving the intrusion detection system, the password cracking cost C3 is the cost of cracking the operator station password, the control seizing cost C4 is the cost of seizing the control authority of the circuit breaker, and the remote control cost C5 is the cost of sending the trip instruction and hiding the information.

4. The method of claim 3, wherein, The takeover substation cost The remote circuit breaker cost comprises a network compromise cost C1, a deception cost C2, and a decryption cost C3 of the takeover substation The remote circuit breaker cost comprises a takeover cost C4 and a remote cost C5.

5. The method of claim 4, wherein, The identification of the key substation in S6 comprises: S61, converting the lower-layer optimization model: replacing the lower-layer optimization model by using a KKT condition, linearizing a relaxation complementary condition by using a Fortuny-Amat-McCarl method, and converting the lower-layer optimization model into equivalent linear constraint conditions; S62, constructing a single-layer linear model: converting the double-layer optimization model into a single-layer linear optimization model by KKT transformation; S63, setting model example parameters: setting attack parameters of an attacker, including attack resources R available to the attacker, setting defense parameters, including a target power transmission system network structure and connection relationships of substation, defense measure configurations of the substation and corresponding network breaking costs C1, deception costs C2, password cracking costs C3, control seizing costs C4 and remote control costs C5, and setting corresponding connection relationships of circuit breakers and power transmission lines in each substation; S64, model conversion to MATLAB for solving: converting the converted single-layer linear optimization model into MATLAB language, performing numerical calculation by using a CPLEX solver, and solving the optimization problem. S65, identifying key substations: under the premise that the attacker attacks resources are limited, the optimal attack target is solved, including the substation and its internal circuit breaker that causes the maximum load shedding.

6. The method of claim 5, wherein, The conversion lower layer optimization model in S61 includes: S611, constructing a Lagrange function: a Lagrange multiplier is introduced, and a Lagrange function is constructed, which is expressed as: ; wherein is the corresponding Lagrange multiplier variable, is the corresponding Lagrange multiplier variable, is the corresponding Lagrange multiplier variable, is the corresponding Lagrange multiplier variable, is the corresponding Lagrange multiplier variable, is the corresponding Lagrange multiplier variable; S612, KKT condition: the KKT condition is given, which is expressed as: ; ; ; ; ; ; ; wherein, Generation of substation Generation of substation 0-1 variable corresponding to the relaxed complementary condition related to the slack bus, Active power flow of line mn 0-1 variable corresponding to the relaxed complementary condition related to the slack bus, Cut load of substation node 0-1 variable corresponding to the relaxed complementary condition related to the slack bus, Generation of substation Phase angle of substation node 0-1 variable corresponding to the relaxed complementary condition related to the slack bus, denotes a maximum number.

Citation Information

Patent Citations

  • Power generation and transmission system planning method for coping with information-physical collaborative attack

    CN112016085A

  • Information physical cooperative attack method, medium and device for power system

    CN115860521A