Threat assessment method and device for power system assets, equipment and medium

The multivariate Gaussian hybrid model processes the asset data of the power system, which solves the problem of difficulty in integrating multiple types of data, and realizes efficient threat assessment and attack type identification.

CN120471425APending Publication Date: 2025-08-12GUANGDONG POWER GRID CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510463615.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-14
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

The prior art is difficult to integrate and analyze data of multiple types or multiple formats of power system equipment assets, resulting in inefficient evaluation.

Method used

The probability density distribution function of the multivariate Gaussian mixed model is used to calculate the asset data characteristics of the power system, and the target posterior probability of the asset is obtained, and the threat status of the asset is identified through clustering processing.

Benefits of technology

It realizes the integration and unified analysis of asset data in different formats or structures, improves the efficiency of threat assessment, and can identify the security status of assets or the types of attacks they face.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120471425A_ABST
    Figure CN120471425A_ABST
Patent Text Reader

Abstract

The invention provides a threat assessment method and device for power system assets, equipment and a medium, and the method comprises the steps: collecting target power system asset data, and extracting data features; the data features are calculated through a probability density distribution function based on a multivariate Gaussian mixture model, and the target posterior probability of the assets is obtained; carrying out clustering processing on all target posterior probabilities; and according to a clustering result, identifying a threat state of each asset so as to determine that the asset is in a safe state or faces an attack type. According to the method, asset data of different formats or structures can be processed through the probability density distribution function based on the multivariate Gaussian mixture model, so that the threat state of each asset is identified, and integration and unified analysis of different types of asset data are realized; the problem that information integration is difficult in the prior art is solved, the method can be used for threat identification of multi-source heterogeneous asset data, and the evaluation efficiency is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of power system equipment asset threat assessment, and in particular to a power system asset threat assessment method, device, equipment and medium. Background Art

[0002] Power systems typically consist of multiple complex devices, networks, and control systems, including substations, power plants, distribution networks, protection and control equipment, and communication systems. These devices and systems are often exposed to various potential security threats, such as cyberattacks, physical damage, internal threats, and equipment aging and failure. Furthermore, with the widespread adoption of information and automation technologies, and the increasing digitalization and intelligentization of power systems, the threat of cyberattacks is increasing. The vulnerability of power system assets not only affects the operational stability of equipment but can also have a serious impact on system security. Therefore, conducting accurate and scientific threat assessments of power system equipment assets has become a critical task to ensure the safe operation of power systems.

[0003] Threat assessment of power system equipment and assets is a key security measure in the power industry, ensuring the security of power system equipment, assets, and information systems. Existing threat assessment methods for power system equipment and assets often target specific data sources, such as device logs, network traffic, vulnerability scan results, or historical event data. These data have varying formats and structures. While existing technical solutions target specific data sources or formats, they struggle to integrate and analyze data of multiple types or formats, resulting in low assessment efficiency. Summary of the Invention

[0004] The present invention application provides a method, apparatus, equipment and medium for threat assessment of power system assets to solve the technical problem of how to improve assessment efficiency.

[0005] In order to solve the above technical problems, the present invention provides a method for threat assessment of power system assets, comprising:

[0006] Acquiring asset data of a plurality of assets of a target power system, and extracting data features from each of the asset data;

[0007] Calculating the data features by a probability density distribution function based on a multivariate Gaussian mixture model to obtain a target posterior probability for each asset, wherein the multivariate Gaussian mixture model is a combination of multiple Gaussian distributions;

[0008] All target posterior probabilities are clustered to obtain clustering results; and based on the clustering results, the threat state of each asset is identified to determine whether the asset is in a safe state or the type of attack it faces.

[0009] As a preferred solution, the probability density distribution function based on the multivariate Gaussian mixture model includes:

[0010]

[0011] Wherein, pm(x) is the probability density distribution function of the multivariate Gaussian mixture model, x is the data feature, μ k is the mean vector of data features in the kth threat state, ∑ k is the covariance matrix of the data features in the kth threat state, k represents the kth threat state, K represents a total of K threat states, π k represents the probability that the asset is in the kth threat state, and N represents the probability density distribution function of a single Gaussian distribution.

[0012] As a preferred solution, the data features are calculated by a probability density distribution function based on a multivariate Gaussian mixture model to obtain the target posterior probability of each asset, including:

[0013] Calculate the initial probability of each asset being in each threat state, the initial mean vector and the initial covariance matrix of each Gaussian distribution according to the data characteristics;

[0014] Calculating an initial posterior probability and a maximum likelihood value according to the initial probability, the initial mean vector and the initial covariance matrix;

[0015] The initial probability, the initial mean vector and the initial covariance matrix are iteratively optimized according to the maximum likelihood value, and when the difference between adjacent iterations of the maximum likelihood value is less than a preset threshold, the posterior probability obtained in the last iteration is used as the target posterior probability.

[0016] As a preferred solution, the calculation formula of the posterior probability is:

[0017]

[0018] Among them, γ ik represents the i-th asset x i The posterior probability of belonging to the kth threat state, π j represents the probability that the asset is in the jth threat state, μ j is the mean vector of data features in the jth threat state, ∑ j is the covariance matrix of the data features in the j-th threat state, j is the j-th threat state, K represents a total of K threat states, μ k is the mean vector of data features in the kth threat state, ∑ k is the covariance matrix of the data features in the kth threat state, π kIndicates the probability that the asset is in the kth threat state.

[0019] As a preferred solution, clustering all target posterior probabilities to obtain clustering results; and identifying the threat state of each asset based on the clustering results to determine whether the asset is in a safe state or the type of attack it faces, including:

[0020] All target posterior probabilities are clustered according to the following formula to obtain the clustering results:

[0021] λ i =argmaxγ ik ;

[0022] Among them, λ i The cluster labeling result of the i-th asset is used to indicate that the i-th asset belongs to the k-th cluster, and each cluster of the clustering result;

[0023] Based on the clusters corresponding to the assets in the clustering results, it is determined whether the assets are in a safe state or the type of attack they are facing, thereby realizing the identification of the threat state of each asset.

[0024] As a preferred solution, the calculation formula of the maximum likelihood value includes:

[0025]

[0026] Wherein, LL(D) represents the maximum likelihood value, and M represents the total number of assets.

[0027] As a preferred solution, the step of acquiring asset data of multiple assets of the target power system and extracting data features from each asset data includes:

[0028] Acquire multi-dimensional asset data for multiple assets in the target power system, the multi-dimensional asset data including network traffic, system logs, status monitoring, and configuration files of the devices;

[0029] The data features are extracted from the multi-dimensional asset data.

[0030] Accordingly, the present invention also provides a threat assessment device for power system assets, comprising an acquisition module, a calculation module and a threat assessment module; wherein,

[0031] The acquisition module is used to acquire asset data of multiple assets of the target power system and extract data features from each asset data;

[0032] The calculation module is configured to calculate the data features using a probability density distribution function based on a multivariate Gaussian mixture model to obtain a target posterior probability for each asset, wherein the multivariate Gaussian mixture model is a combination of multiple Gaussian distributions;

[0033] The threat assessment module is used to cluster all target posterior probabilities to obtain clustering results; and based on the clustering results, identify the threat status of each asset to determine whether the asset is in a safe state or the type of attack it faces.

[0034] As a preferred solution, the probability density distribution function based on the multivariate Gaussian mixture model includes:

[0035]

[0036] Wherein, pm(x) is the probability density distribution function of the multivariate Gaussian mixture model, x is the data feature, μ k is the mean vector of data features in the kth threat state, ∑ k is the covariance matrix of the data features in the kth threat state, k represents the kth threat state, K represents a total of K threat states, π k represents the probability that the asset is in the kth threat state, and N represents the probability density distribution function of a single Gaussian distribution.

[0037] As a preferred solution, the calculation module calculates the data features by a probability density distribution function based on a multivariate Gaussian mixture model to obtain the target posterior probability of each asset, including:

[0038] The calculation module calculates the initial probability of each asset being in each threat state, the initial mean vector and the initial covariance matrix of each Gaussian distribution according to the data features;

[0039] Calculating an initial posterior probability and a maximum likelihood value according to the initial probability, the initial mean vector and the initial covariance matrix;

[0040] The initial probability, the initial mean vector and the initial covariance matrix are iteratively optimized according to the maximum likelihood value, and when the difference between adjacent iterations of the maximum likelihood value is less than a preset threshold, the posterior probability obtained in the last iteration is used as the target posterior probability.

[0041] As a preferred solution, the calculation formula of the posterior probability is:

[0042]

[0043] Among them, γ ik represents the i-th asset x i The posterior probability of belonging to the kth threat state, π j represents the probability that the asset is in the jth threat state, μ j is the mean vector of data features in the jth threat state, ∑ jis the covariance matrix of the data features in the j-th threat state, j is the j-th threat state, K represents a total of K threat states, μ k is the mean vector of data features in the kth threat state, ∑ k is the covariance matrix of the data features in the kth threat state, π k Indicates the probability that the asset is in the kth threat state.

[0044] As a preferred solution, the threat assessment module clusters all target posterior probabilities to obtain clustering results; and based on the clustering results, identifies the threat state of each asset to determine whether the asset is in a safe state or the type of attack it faces, including:

[0045] The threat assessment module clusters all target posterior probabilities according to the following formula to obtain clustering results:

[0046] λ i =argmaxγ ik ;

[0047] Among them, λ i The cluster labeling result of the i-th asset is used to indicate that the i-th asset belongs to the k-th cluster, and each cluster of the clustering result;

[0048] Based on the clusters corresponding to the assets in the clustering results, it is determined whether the assets are in a safe state or the type of attack they are facing, thereby realizing the identification of the threat state of each asset.

[0049] As a preferred solution, the calculation formula of the maximum likelihood value includes:

[0050]

[0051] Wherein, LL(D) represents the maximum likelihood value, and M represents the total number of assets.

[0052] As a preferred solution, the acquisition module acquires asset data of multiple assets of the target power system and extracts data features from each asset data, including:

[0053] The acquisition module acquires multi-dimensional asset data of multiple assets in the target power system, wherein the multi-dimensional asset data includes network traffic, system logs, status monitoring and configuration files of the devices;

[0054] The data features are extracted from the multi-dimensional asset data.

[0055] Correspondingly, the present application also provides a terminal device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, and the processor implements the threat assessment method for power system assets when executing the computer program.

[0056] Correspondingly, the present application also provides a computer-readable storage medium, which includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the threat assessment method for power system assets.

[0057] Compared with the prior art, the present invention has the following beneficial effects:

[0058] The present invention application provides a threat assessment method, device, equipment and medium for power system assets. The threat assessment method includes: collecting asset data of multiple assets of the target power system, extracting data features from each of the asset data; calculating the data features through a probability density distribution function based on a multivariate Gaussian mixture model to obtain a target posterior probability for each of the assets, wherein the multivariate Gaussian mixture model is a combination of multiple Gaussian distributions; clustering all target posterior probabilities to obtain clustering results; and identifying the threat status of each asset based on the clustering results to determine whether the asset is in a safe state or the type of attack it faces. The present invention applies to extract the data features of each asset, and obtains the posterior probability of each asset by solving the probability density distribution function based on the multivariate Gaussian mixture model, and the multivariate Gaussian mixture model is a combination of multiple Gaussian distributions. In this way, asset data of different formats or structures can be processed by the probability density distribution function based on the multivariate Gaussian mixture model, and then all posterior probabilities are clustered. According to the clustering results, the threat status of each asset is identified, and it is determined whether each asset is in a safe state or facing a certain type of attack. The threat assessment method provided by the present invention application realizes the integration and unified analysis of different types of asset data, solves the information integration difficulties existing in the existing technical solutions, can be used for threat identification of multi-source heterogeneous asset data, and effectively improves the assessment efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] Figure 1 : A flow chart of an embodiment of a method for threat assessment of power system assets provided in the present invention.

[0060] Figure 2 : A structural diagram of an embodiment of a threat assessment device for power system assets provided in the present invention. DETAILED DESCRIPTION

[0061] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0062] Example 1

[0063] Please refer to Figure 1 , Figure 1 The present invention provides a method for threat assessment of power system assets, comprising steps S101 to S103; wherein:

[0064] Step S101 : acquiring asset data of a plurality of assets of a target power system, and extracting data features from each asset data.

[0065] In this step, it is assumed that the target power system contains M assets, that is, a total of M devices, networks and / or control systems of the same or different types, such as substations, power plants, distribution networks, protection and control equipment, and communication systems.

[0066] In a preferred embodiment, multidimensional asset data of multiple assets of the target power system is obtained, wherein the multidimensional asset data includes network traffic, system logs, status monitoring and configuration files of the equipment; and the data features are extracted from the multidimensional asset data.

[0067] After acquiring the asset data as described above, the asset data may be preprocessed to facilitate modeling and analysis in subsequent steps.

[0068] In addition, in order to accurately identify threats in subsequent steps, threat data when assets are attacked by various types of threats and security data during normal operation can be collected, and this data can be divided into training set data and test set data.

[0069] After obtaining asset data, data features can be extracted from it based on actual security goals and analysis requirements. For example, the types of data features include but are not limited to the amount of traffic received by the asset over a period of time, the number of ports accessed by the asset over a period of time, the number of TCP packets received by the asset over a period of time, the number of UDP packets received by the asset over a period of time, the number of files added / updated / deleted by the asset over a period of time, the number of failed login attempts to the asset over a period of time, the CPU usage of the asset over a period of time, and the average disk I / O of the asset over a period of time, etc.

[0070] Step S102 , calculating the data features by a probability density distribution function based on a multivariate Gaussian mixture model to obtain a target posterior probability for each of the assets, wherein the multivariate Gaussian mixture model is a combination of multiple Gaussian distributions.

[0071] In this step, assuming that N features are extracted from the asset data of M assets, an initial matrix can be constructed, for example:

[0072]

[0073] Where C is the initial matrix, C NM Represents the Nth feature of the Mth asset.

[0074] Furthermore, since different features may have different scales and units (for example, traffic rate is in bytes, and the number of login failures is an integer), this may cause some features to overly dominate the model learning process during training. Therefore, the data of the initial matrix C can be standardized, for example:

[0075] Calculate the mean μ and variance σ of each row of the matrix, and perform the following normalization on each value in the initial matrix C:

[0076]

[0077] Where c is the element of the initial matrix, and x is the normalized value of the initial matrix element.

[0078] Then we get the normalized matrix:

[0079]

[0080] Where X is the normalized matrix, x NM Indicates the normalized value of the Nth feature of the Mth asset.

[0081] In this embodiment, the Multivariate Gaussian Mixture Model (MGMM) is a probability-based clustering method that assumes that the data is composed of a mixture of multiple Gaussian distributions (normal distributions), each of which represents a cluster of data. Each cluster corresponds to a Gaussian distribution, and the model can represent the data distribution as a combination of multiple Gaussian distributions through a weighted average. GMM can be used for tasks such as density estimation, data clustering, and anomaly detection.

[0082] Preferably, the probability density distribution function based on the multivariate Gaussian mixture model in this step includes:

[0083]

[0084] Wherein, pm(x) is the probability density distribution function of the multivariate Gaussian mixture model, x is the data feature (which can be substituted into the elements in the normalized matrix X), μ k is the mean vector of data features in the kth threat state, ∑ k is the covariance matrix of the data features in the kth threat state, k represents the kth threat state, K represents a total of K threat states and one of them is a safe state (or normal operating state), π k is the mixing coefficient and represents the probability that the asset is in the kth threat state and N represents the probability density distribution function of a single Gaussian distribution.

[0085] From the above, the multivariate Gaussian mixture model is composed of a mixture of multiple Gaussian distributions (normal distributions). The probability density function of a single Gaussian distribution can be expressed as:

[0086] p(x)=N(x|μ,∑);

[0087] Where p(x) represents the probability density function of the Gaussian distribution.

[0088] Exemplarily, the probability density function of the Gaussian distribution can be further expressed as:

[0089]

[0090] Where μ is the N-dimensional mean vector, i.e., the vector of the mean combination of each feature in the normalized matrix X, ∑ is the covariance matrix between the N×N sample features, and det∑ is the determinant of the covariance matrix ∑.

[0091] In a preferred embodiment, calculating the data features by a probability density distribution function based on a multivariate Gaussian mixture model to obtain the target posterior probability of each asset includes:

[0092] The initial probability of each asset being in each threat state, the initial mean vector and the initial covariance matrix of each Gaussian distribution are calculated based on the data characteristics; the initial posterior probability and the maximum likelihood value are calculated based on the initial probability, the initial mean vector and the initial covariance matrix; the initial probability, the initial mean vector and the initial covariance matrix are iteratively optimized based on the maximum likelihood value, and when the difference between adjacent iterations of the maximum likelihood value is less than a preset threshold, the posterior probability obtained from the last iteration is used as the target posterior probability.

[0093] In this embodiment, posterior probability is a key concept in Bayesian statistics, representing an updated probability of an event occurring after obtaining new observations. In Bayesian inference, this embodiment combines prior knowledge (i.e., prior probability) with observed evidence to calculate the posterior probability of an event.

[0094] For example, the initial probability π1=π2=...=π k =1 / K; then K assets are uniformly selected from the M assets to initialize the mean of each Gaussian distribution, and the initial mean vector (μ1μ2...μ k ), the initial covariance matrix can be

[0095] Alternatively, the K-means algorithm can be used instead of manually setting the initial values. For example, use K-means to cluster the data to obtain K clusters. Then, the centroid of each cluster is used as the mean of the corresponding Gaussian distribution. For each cluster, the covariance matrix of the data points in the cluster is calculated as the covariance matrix of the Gaussian distribution, and the size of each cluster (the number of points in the cluster) is used as the mixing coefficient. The probability, mean vector, and covariance matrix obtained based on the K-means clustering results are used as the initial probability, initial mean vector, and initial covariance matrix.

[0096] Then calculate the initial posterior probability according to the following formula:

[0097]

[0098] Among them, γ ik represents the i-th asset x i The posterior probability of belonging to the kth threat state, π j represents the probability that the asset is in the jth threat state, μ j is the mean vector of data features in the jth threat state, ∑ j is the covariance matrix of the data features in the j-th threat state, j is the j-th threat state, K represents a total of K threat states, μ k is the mean vector of data features in the kth threat state, ∑ k is the covariance matrix of the data features in the kth threat state, π k Indicates the probability that the asset is in the kth threat state.

[0099] The initial probability, the initial mean vector and the initial covariance matrix are iteratively optimized according to the following formula:

[0100]

[0101] Among them, π′ k, μ′ k and ∑′ k They represent the initial probability, initial mean vector and initial covariance matrix after iterative optimization respectively.

[0102] This implementation uses maximum likelihood estimation to determine whether the model meets the conditions for terminating the iteration. Maximum likelihood estimation (MLE) is a statistical method used to estimate model parameters so as to maximize the probability that the model will generate the observed data given the data. In short, MLE finds a set of parameters that makes the observed data most likely to occur under the model.

[0103] Each time the initial probability, initial mean vector, and initial covariance matrix are iteratively updated, a new posterior probability and maximum likelihood value are calculated. The maximum likelihood value calculation formula includes:

[0104]

[0105] Wherein, LL(D) represents the maximum likelihood value, and M represents the total number of assets.

[0106] When the difference between the calculated maximum likelihood value and the previous iteration is less than a preset threshold (eg, 0.1), the posterior probability obtained in the last iteration is used as the target posterior probability.

[0107] Step S103 , clustering all target posterior probabilities to obtain clustering results; and based on the clustering results, identifying the threat state of each asset to determine whether the asset is in a safe state or the type of attack it faces.

[0108] In this step, all target posterior probabilities can be clustered according to the following formula to obtain clustering results:

[0109] λ i =argmaxγ ik ;

[0110] Among them, λ i The cluster labeling result of the i-th asset is used to indicate that the i-th asset belongs to the k-th cluster, and each cluster of the clustering result;

[0111] Based on the clusters corresponding to the assets in the clustering results, it is determined whether the assets are in a safe state or the type of attack they are facing, thereby realizing the identification of the threat state of each asset.

[0112] In this implementation, the k clusters contain k-1 types of attacks and security states that the assets may face. These k-1 types of attacks and security states that the assets may face together constitute k threat states of the assets.

[0113] The above clustering steps and the calculation of posterior target probabilities can be implemented using the training set. The clustering process and the multivariate Gaussian mixture model are then tested using the test set data to determine whether the output results can correctly classify the training set asset data into the corresponding categories.

[0114] Correspondingly, such as Figure 2 As shown, the present invention also provides a threat assessment device 200 for power system assets, including an acquisition module 201, a calculation module 202 and a threat assessment module 203; wherein,

[0115] The acquisition module 201 is used to acquire asset data of multiple assets of the target power system and extract data features from each asset data;

[0116] The calculation module 202 is configured to calculate the data features using a probability density distribution function based on a multivariate Gaussian mixture model to obtain a target posterior probability for each asset, wherein the multivariate Gaussian mixture model is a combination of multiple Gaussian distributions;

[0117] The threat assessment module 203 is configured to cluster all target posterior probabilities to obtain clustering results; and based on the clustering results, identify the threat status of each asset to determine whether the asset is in a safe state or the type of attack it faces.

[0118] As a preferred solution, the probability density distribution function based on the multivariate Gaussian mixture model includes:

[0119]

[0120] Wherein, pm(x) is the probability density distribution function of the multivariate Gaussian mixture model, x is the data feature, μ k is the mean vector of data features in the kth threat state, ∑ k is the covariance matrix of the data features in the kth threat state, k represents the kth threat state, K represents a total of K threat states, π k represents the probability that the asset is in the kth threat state, and N represents the probability density distribution function of a single Gaussian distribution.

[0121] As a preferred solution, the calculation module 202 calculates the data features using a probability density distribution function based on a multivariate Gaussian mixture model to obtain the target posterior probability of each asset, including:

[0122] The calculation module 202 calculates the initial probability of each asset being in each threat state, the initial mean vector and the initial covariance matrix of each Gaussian distribution according to the data features;

[0123] Calculating an initial posterior probability and a maximum likelihood value according to the initial probability, the initial mean vector and the initial covariance matrix;

[0124] The initial probability, the initial mean vector and the initial covariance matrix are iteratively optimized according to the maximum likelihood value, and when the difference between adjacent iterations of the maximum likelihood value is less than a preset threshold, the posterior probability obtained in the last iteration is used as the target posterior probability.

[0125] As a preferred solution, the calculation formula of the posterior probability is:

[0126]

[0127] Among them, γ ik represents the i-th asset x i The posterior probability of belonging to the kth threat state, π j represents the probability that the asset is in the jth threat state, μ j is the mean vector of data features in the jth threat state, ∑ j is the covariance matrix of the data features in the j-th threat state, j is the j-th threat state, K represents a total of K threat states, μ k is the mean vector of data features in the kth threat state, ∑ k is the covariance matrix of the data features in the kth threat state, π k Indicates the probability that the asset is in the kth threat state.

[0128] As a preferred solution, the threat assessment module 203 performs clustering processing on all target posterior probabilities to obtain clustering results; and identifies the threat state of each asset based on the clustering results to determine whether the asset is in a safe state or the type of attack it faces, including:

[0129] The threat assessment module 203 clusters all target posterior probabilities according to the following formula to obtain clustering results:

[0130] λ i =argmaxγ ik ;

[0131] Among them, λ i The cluster labeling result of the i-th asset is used to indicate that the i-th asset belongs to the k-th cluster, and each cluster of the clustering result;

[0132] Based on the clusters corresponding to the assets in the clustering results, it is determined whether the assets are in a safe state or the type of attack they are facing, thereby realizing the identification of the threat state of each asset.

[0133] As a preferred solution, the calculation formula of the maximum likelihood value includes:

[0134]

[0135] Wherein, LL(D) represents the maximum likelihood value, and M represents the total number of assets.

[0136] As a preferred solution, the acquisition module 201 acquires asset data of multiple assets of the target power system and extracts data features from each asset data, including:

[0137] The acquisition module 201 acquires multi-dimensional asset data of multiple assets in the target power system, wherein the multi-dimensional asset data includes network traffic, system logs, status monitoring, and configuration files of the devices;

[0138] The data features are extracted from the multi-dimensional asset data.

[0139] Correspondingly, the present application also provides a terminal device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, and the processor implements the threat assessment method for power system assets when executing the computer program.

[0140] The processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. The processor is the control center of the terminal and connects various parts of the entire terminal using various interfaces and lines.

[0141] The memory can be used to store the computer program, and the processor realizes various functions of the terminal by running or executing the computer program stored in the memory and calling the data stored in the memory. The memory can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, at least one application required for a function (such as a sound playback function, an image playback function, etc.); the data storage area can store data created according to the use of the mobile phone (such as audio data, a phone book, etc.). In addition, the memory can include a high-speed random access memory and can also include a non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart memory card (SmartMedia Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (Flash Card), at least one disk storage device, a flash memory device, or other volatile solid-state storage device.

[0142] Correspondingly, the present application also provides a computer-readable storage medium, which includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the threat assessment method for power system assets.

[0143] If the module integrated into the power system asset threat assessment device is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present invention can implement all or part of the process of the above-mentioned embodiment method by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, it can implement the steps of each of the above-mentioned method embodiments. The computer program includes computer program code, which can be in source code form, object code form, executable file, or some intermediate form. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium.

[0144] Compared with the prior art, the present invention has the following beneficial effects:

[0145] The present invention application provides a threat assessment method, device, equipment and medium for power system assets. The threat assessment method includes: collecting asset data of multiple assets of the target power system, extracting data features from each of the asset data; calculating the data features through a probability density distribution function based on a multivariate Gaussian mixture model to obtain a target posterior probability for each of the assets, wherein the multivariate Gaussian mixture model is a combination of multiple Gaussian distributions; clustering all target posterior probabilities to obtain clustering results; and identifying the threat status of each asset based on the clustering results to determine whether the asset is in a safe state or the type of attack it faces. The present invention applies to extract the data features of each asset, and obtains the posterior probability of each asset by solving the probability density distribution function based on the multivariate Gaussian mixture model, and the multivariate Gaussian mixture model is a combination of multiple Gaussian distributions. In this way, asset data of different formats or structures can be processed by the probability density distribution function based on the multivariate Gaussian mixture model, and then all posterior probabilities are clustered. According to the clustering results, the threat status of each asset is identified, and it is determined whether each asset is in a safe state or facing a certain type of attack. The threat assessment method provided by the present invention application realizes the integration and unified analysis of different types of asset data, solves the information integration difficulties existing in the existing technical solutions, can be used for threat identification of multi-source heterogeneous asset data, and effectively improves the assessment efficiency.

[0146] The specific embodiments described above further illustrate the objectives, technical solutions, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. In particular, it should be noted that any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included within the scope of protection of the present invention for those skilled in the art.

Claims

1. A method for threat assessment of power system assets, characterized in that: include: Acquiring asset data of a plurality of assets of a target power system, and extracting data features from each of the asset data; Calculating the data features by a probability density distribution function based on a multivariate Gaussian mixture model to obtain a target posterior probability for each asset, wherein the multivariate Gaussian mixture model is a combination of multiple Gaussian distributions; All target posterior probabilities are clustered to obtain clustering results; and based on the clustering results, the threat state of each asset is identified to determine whether the asset is in a safe state or the type of attack it faces.

2. A method for threat assessment of power system assets according to claim 1, characterized in that: The probability density distribution function based on the multivariate Gaussian mixture model includes: Wherein, pm(x) is the probability density distribution function of the multivariate Gaussian mixture model, x is the data feature, μ k is the mean vector of data features in the kth threat state, ∑ k is the covariance matrix of the data features in the kth threat state, k represents the kth threat state, K represents a total of K threat states, π k represents the probability that the asset is in the kth threat state, and N represents the probability density distribution function of a single Gaussian distribution.

3. A method for threat assessment of power system assets according to claim 1, characterized in that: The method of calculating the data features by using a probability density distribution function based on a multivariate Gaussian mixture model to obtain a target posterior probability for each asset includes: Calculate the initial probability of each asset being in each threat state, the initial mean vector and the initial covariance matrix of each Gaussian distribution according to the data characteristics; Calculating an initial posterior probability and a maximum likelihood value according to the initial probability, the initial mean vector and the initial covariance matrix; The initial probability, the initial mean vector and the initial covariance matrix are iteratively optimized according to the maximum likelihood value, and when the difference between adjacent iterations of the maximum likelihood value is less than a preset threshold, the posterior probability obtained in the last iteration is used as the target posterior probability.

4. A method for threat assessment of power system assets according to claim 3, characterized in that: The calculation formula of the posterior probability is: Among them, γ ik represents the i-th asset x i The posterior probability of belonging to the kth threat state, π j represents the probability that the asset is in the jth threat state, μ j is the mean vector of data features in the jth threat state, ∑ j is the covariance matrix of the data features in the j-th threat state, j is the j-th threat state, K represents a total of K threat states, μ k is the mean vector of data features in the kth threat state, ∑ k is the covariance matrix of the data features in the kth threat state, π k Indicates the probability that the asset is in the kth threat state.

5. A method for threat assessment of power system assets according to claim 4, characterized in that: The clustering process is performed on all target posterior probabilities to obtain clustering results; Based on the clustering results, the threat status of each asset is identified to determine whether the asset is in a safe state or faces an attack type, including: All target posterior probabilities are clustered according to the following formula to obtain the clustering results: l i =argmaxγ ik ; Among them, λ i The cluster labeling result of the i-th asset is used to indicate that the i-th asset belongs to the k-th cluster, and each cluster of the clustering result; Based on the clusters corresponding to the assets in the clustering results, it is determined whether the assets are in a safe state or the type of attack they are facing, thereby realizing the identification of the threat state of each asset.

6. A method for threat assessment of power system assets according to claim 3, characterized in that: The calculation formula of the maximum likelihood value includes: Wherein, LL(D) represents the maximum likelihood value, and M represents the total number of assets.

7. A method for threat assessment of power system assets according to any one of claims 1 to 6, characterized in that: The acquiring of asset data of a plurality of assets of the target power system and extracting data features from each asset data includes: Acquire multi-dimensional asset data for multiple assets in the target power system, the multi-dimensional asset data including network traffic, system logs, status monitoring, and configuration files of the devices; The data features are extracted from the multi-dimensional asset data.

8. A threat assessment device for power system assets, characterized in that: It includes acquisition module, calculation module and threat assessment module; among them, The acquisition module is used to acquire asset data of multiple assets of the target power system and extract data features from each asset data; The calculation module is configured to calculate the data features using a probability density distribution function based on a multivariate Gaussian mixture model to obtain a target posterior probability for each asset, wherein the multivariate Gaussian mixture model is a combination of multiple Gaussian distributions; The threat assessment module is used to cluster all target posterior probabilities to obtain clustering results; and based on the clustering results, identify the threat status of each asset to determine whether the asset is in a safe state or the type of attack it faces.

9. A terminal device, characterized in that: The method comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, the method for threat assessment of power system assets according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a stored computer program, wherein when the computer program is executed, the device where the computer-readable storage medium is located is controlled to execute the threat assessment method for power system assets according to any one of claims 1 to 7.