Scanning method and system for hidden asset identification in electric power industrial control network

Through multi-protocol active detection, behavior clustering and graph neural network modeling, a full-process intelligent identification system is built, which solves the problem of hidden asset identification in power industrial control networks, achieves high-precision identification of silent devices and communication island devices, and improves the foresight of asset management and security protection.

CN120710801AActive Publication Date: 2025-09-26ZHANGZHOU POWER SUPPLY COMPANY STATE GRID FUJIANELECTRIC POWER +1

Patent Information

Application Number
CN202511191422.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-25
Publication Date
2025-09-26
Estimated Expiration
2045-08-25

AI Technical Summary

Technical Problem

Traditional scanning methods are unable to fully cover hidden assets in power industrial control networks, resulting in "blind spots" or "dead corners" in asset information, increasing network operation and maintenance and protection risks.

Method used

By adopting multi-protocol active detection, behavior clustering analysis, graph neural network modeling and temporal reasoning technology, a full-process intelligent identification system is built, including detection data collection, response behavior modeling, structural relationship analysis and abnormal equipment inference, supporting the accurate identification of assets with multiple industrial protocols.

Benefits of technology

It significantly improves the ability to identify hidden assets, and has the ability to intelligently identify silent equipment, communication island equipment and atypical response equipment. It has a wide recognition range, high accuracy, small disturbance and strong adaptability, which improves the integrity of power system asset management and the foresight of security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120710801A_ABST
    Figure CN120710801A_ABST
Patent Text Reader

Abstract

The invention provides a scanning method and system for hidden asset identification in an electric power industrial control network, and aims to solve the problem that silent, non-registered or illegal access equipment is difficult to discover by the existing asset surveying and mapping means. According to the method, multiple protocol induced detection messages are injected into a target network, equipment response data are collected, feature vectors are extracted, and abnormal equipment behaviors are identified by using an unsupervised clustering and anomaly detection algorithm; and meanwhile, in combination with a graph neural network and a hidden Markov model, modeling is performed on a network communication chain structure and a historical behavior sequence, and potential hidden asset nodes are deduced. According to the method, active discovery and risk reasoning of hidden assets can be realized on the premise of not influencing industrial control services, and the method is suitable for industrial control scenes such as transformer substations and dispatching centers in the power industry and has high safety, intelligence and feasibility.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of industrial control system security technology, and in particular to a scanning method and system for identifying hidden assets in an electric power industrial control network. Background Art

[0002] In modern power systems, Industrial Control Systems (ICS) are widely used in multiple links, including power generation, transmission, transformation, and distribution. Their subordinate devices, such as remote terminal units (RTUs), programmable logic controllers (PLCs), and intelligent electronic devices (IEDs), communicate and collaborate through various industrial protocols, forming a complex industrial communication network. To effectively manage and secure these devices, asset identification and status awareness are fundamental tasks. Currently, the power industry often uses network scanning and deep packet inspection technologies to inventory and classify network assets. However, due to the diversity of device protocols, sparse communication, and the long-term silence of some devices, traditional scanning methods cannot fully cover all online or latent assets, resulting in "blind spots" or "dead corners" in asset information, posing risks to subsequent network operations and protection.

[0003] Against this backdrop, power industrial control networks face a technical need to accurately identify hidden assets (such as devices with abnormal configurations, isolated communications, non-standard protocols, or silent operation). On the one hand, these devices may not be visible on centralized control platforms due to installation and configuration errors, communication errors, or network isolation. On the other hand, their latent behavior may also pose potential security risks or attack vectors. Therefore, the industry urgently needs an identification technology that balances scanning accuracy with disturbance control. This technology can integrate multi-source protocol behavior, communication structure characteristics, and time-series state information to achieve non-invasive, intelligent identification and traceability of hidden assets, addressing the capability gaps of traditional methods in low-visibility scenarios. Summary of the Invention

[0004] In view of this, the purpose of the present invention is to provide a scanning method and system for identifying hidden assets in power industrial control networks. This method comprehensively utilizes technologies such as multi-protocol active detection, behavioral clustering analysis, graph neural network modeling, and temporal reasoning to construct a full-process intelligent identification system from detection data acquisition, response behavior modeling, structural relationship analysis, to abnormal device inference. This method not only supports the accurate identification of assets with multiple industrial protocols, but also has the ability to model and discover potential hidden assets such as silent devices, communication island devices, and atypical response devices. It can effectively improve the integrity of power system asset management and the foresight of security protection.

[0005] To achieve the above objectives, the present invention adopts the following technical solution: a scanning method and system for identifying hidden assets in an electric power industrial control network, comprising the following specific steps:

[0006] S1: Construct a probe message set based on the power industry's industrial control protocol. A template-based syntax tree builder is used to generate protocol messages, i.e., P_protocol = Template(FUNC_CODE, ADDR, LEN, CRC). Diverse request combinations are generated by randomly perturbing and interpolating protocol structure fields. Probe messages from different protocols are interleaved and injected at set intervals to form a rhythmic probe flow. The injection order is dynamically adjusted based on the historical response success rate.

[0007] Specifically, P_protocol represents the protocol message; Template represents the protocol message template function; FUNC_CODE represents the function code, indicating the type of operation of this detection (such as reading a holding register, calling a command, etc.); ADDR represents the address, which is the address location of the target data unit in the device; LEN represents the length, which is the amount of data expected to be read in this request; CRC represents the cyclic redundancy check, which is a field used for message integrity verification;

[0008] S2: Perform protocol parsing on each response message. This parsing decodes the field structure according to the identified protocol type and extracts key elements for subsequent modeling.

[0009] S3: Construct a feature set of all device response vectors ; represents the response feature vector of the i-th device, i=1,...,n;

[0010] S4: To identify potential hidden assets outside the cluster, the Isolation Forest algorithm is used to build an anomaly detection model based on feature isolation;

[0011] S5: Build a device topology map based on the communication behavior between known devices , where the nodes Indicates device, edge Represents the communication relationship, and extracts communication features such as connectivity, communication frequency, and protocol distribution for each node as the initial input vector , using the graph convolutional network GCN model to learn node embedding

[0012] S6: Construct a hidden Markov model HMM based on the communication behavior sequence, assuming that the state set is , the observation set is the communication events of the device in different time windows, and the forward-backward algorithm is used in the training phase to transform the transfer matrix , emission matrix and the initial probability Perform estimation and use the Viterbi algorithm to calculate the most likely state path in the inference phase;

[0013] S7: Identifies forged messages based on the message structure and field content, including the legitimacy of the field length, control code, function code, and CRC (Cyclic Redundancy Check) check bits, as well as any illegal field combinations or unregistered device addresses. The detection logic uses a syntax template tree and regular expression rules for matching and verification. If a field value seriously deviates from the protocol definition, an illegal device code is present, or the message structure is malformed, the message is identified as a forged message.

[0014] S8: Based on the hidden asset identification results Build an adaptive scanning strategy and record the recognition success rate p(protocol i ) and the average response delay T i , modeling the strategy optimization as a multi-armed bandit problem, using the upper confidence bound algorithm, namely the Upper Confidence Bound strategy selection protocol combination, and calculating the upper bound UCB of the benefit of each combination i , the protocols and target segments with high expected returns are preferentially selected to perform the next round of scanning, where I represents the set of inferred hidden assets.

[0015] In a preferred embodiment, in S1, the selection of the protocol function code is limited to read-only / query type; the field perturbation logic is as follows: for the address field, a sliding window or random jump strategy is used, and the read length The injection interval is within a reasonable range, and the sending order is regulated by the dynamic adjustment mechanism of the protocol priority.

[0016] In a preferred embodiment, in S2, the key factors include response delay , data length , Number of fields , CRC check result and error flag, the protocol function code is embedded into the feature vector using one-hot encoding; at the same time, if there is a device identifier string field, character-level n-gram, n=3, encoding is used to represent it, and it is mapped to a dense vector space through the embedding layer, and finally all fields are spliced ​​into a unified device response vector. ; Indicates the time delay between the system sending a probe message and receiving a response from the device; L i The byte length of the response message; onehot fcodeIt is a one-hot encoding of the function code in the message, used to indicate the response type of the device to different protocol operations; n-gram desc Indicates the vector embedding after character-level n-gram segmentation of the string field in the response, which is used to characterize the device manufacturer or customized features; i Indicates the checksum field of the response data, which is used to identify whether the data packet structure is standard or contains abnormal splicing.

[0017] In a preferred embodiment, in S3, Gaussian mixture model GMM is used for clustering learning to measure the behavioral similarity between samples, and Mahalanobis distance is used as the distance function. ,in, represents the response feature vector of the jth device, is the feature covariance matrix, is the inverse matrix of the covariance matrix. The mean, variance and weight parameters of each cluster are iteratively optimized by the EM algorithm until the log-likelihood increment is lower than the set threshold. The output is Clusters representing typical device behaviors , providing a behavioral reference basis for anomaly detection

[0018] In a preferred embodiment, in S4, normal clustering samples are used in the training phase. Randomly select feature subsets to construct multiple binary decision trees. Each tree recursively divides the sample by randomly selecting the partitioning dimension and threshold to form an isolation path. In the inference stage, the new sample Calculate the average path length in all trees , define the anomaly scoring function as ,in is the normalization factor, if the score is above the threshold , it is determined to be an abnormal device and constitutes a potential hidden asset collection

[0019] In a preferred embodiment, in S5, the graph convolutional network The model uses the following update formula:

[0020]

[0021] in is the activation function, It is The trainable weight matrix of the layer graph convolution. After two layers of propagation, the node obtains the embedded representation of the aggregated neighbor information; through several layers of propagation learning, the structural representation of the device is obtained. ,Through cluster center offset, isolation metric or boundary density, abnormal nodes in the topology structure are judged, providing reasoning basis for hidden devices with missing graph structure; Indicates that node v is in The embedding vector of the layer, Indicates that its neighbor node u is in The embedding representation of the layer, N(v) is the set of neighbors of node v; d v and d u denote the degrees of nodes v and u respectively.

[0022] In a preferred embodiment, in S6, each device records whether communication occurs every 10 minutes as an observation sequence. ,in ∈{0,1}; model parameters The EM (Expectation–Maximization Algorithm) algorithm is used for learning, and the Viterbi algorithm is used in the prediction phase to recursively solve the maximum probability path:

[0023]

[0024] It represents the maximum probability value of the optimal path with state s at time t, Indicates at time The maximum probability of the optimal path from the previous state s'; It represents the transition probability from state s′ to the current state s, which is an item in the state transition matrix of the hidden Markov model HMM; Indicates that the observation value o is generated under the current state s t The probability of observation or emission; It means selecting the path with the highest probability from all possible previous states. If a device is in a silent state continuously and the probability of transitioning from the communication state to the silent state is less than 0.05, it is marked as a static hidden device and included in the inference result set.

[0025] In a preferred embodiment, in S8, the revenue of each protocol combination is Defined as:

[0026]

[0027] Each round of scanning selects the combined UCB with the current maximum UCB value i

[0028]

[0029] in is the average income, is the number of times used, t is the total number of rounds, and by recording the recognition efficiency of each protocol combination, the strategy is evaluated every 10 rounds, and the protocol redundancy injection mechanism is triggered based on the threshold to prevent local optimality.

[0030] The present invention also provides a scanning system for identifying hidden assets in an electric power industrial control network, which runs the above-mentioned scanning method for identifying hidden assets in an electric power industrial control network.

[0031] Compared with the existing technology, the present invention has the following beneficial effects: the present invention can significantly improve the ability to identify hidden assets in power industrial control networks. It not only supports active detection of multiple industrial protocols, but also can realize intelligent identification of silent devices, communication island devices and atypical response devices through unsupervised clustering, anomaly detection, graph neural network structure modeling and temporal reasoning. It has the advantages of wide recognition range, high accuracy, small disturbance and strong adaptability. It effectively makes up for the technical shortcomings of traditional scanning methods in low-visibility scenarios, and improves the integrity of asset management and the foresight of network protection in the power industry. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] Figure 1 Schematic diagram of a preferred embodiment of the present invention. DETAILED DESCRIPTION

[0033] The present invention will be further described below with reference to the accompanying drawings and embodiments.

[0034] It should be noted that the following detailed descriptions are illustrative and intended to provide further explanation of the present application. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which the present application belongs.

[0035] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present application; as used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form, and it should be understood that when the terms "comprise" and / or "include" are used in this specification, they indicate the presence of features, steps, operations, devices, components and / or their combinations.

[0036] like Figure 1 As shown, the present invention provides a scanning method for identifying hidden assets in an electric power industrial control network, comprising the following steps:

[0037] S1: The active scanning module constructs probe message sets based on common industrial control protocols in the power industry, including Modbus-TCP, IEC 60870-5-104, DNP3, and IEC 61850. These messages are constructed using valid, non-write function codes, such as Modbus function codes 0x03 (Read Holding Registers) and 0x2B (Read Device Identification), and IEC 61850 C_IC_NA_1 (Call Command) frames. To generate high-coverage probe packets, the system uses a template-based syntax tree builder to generate protocol messages: P_protocol = Template(FUNC_CODE, ADDR, LEN, CRC). This generates diverse request combinations by randomly perturbing and interpolating protocol structure fields. The system interleaves probe messages from different protocols at set intervals, forming a rhythmic probe flow. The injection order is dynamically adjusted based on historical response success rates, thereby increasing the probability of activating hidden devices.

[0038] S2: The system performs protocol parsing on each response message. The parser decodes the field structure according to the identified protocol type and extracts key elements such as response delay. , data length , Number of fields , CRC check result, error flag, etc., and the protocol function code is embedded in the feature vector using one-hot encoding. For example, the function code 0x03 is assigned a value of 1 in the corresponding dimension, and the rest are 0. At the same time, if there are string fields such as device identifiers, the system uses character-level n-gram (n=3) encoding to represent them, and maps them to a dense vector space through the embedding layer, and finally splices all fields into a unified device response vector. , used for subsequent modeling; where: Indicates the time delay from the system sending a probe message to receiving a device response, in milliseconds, used to characterize the timeliness of the device response; L i The byte length of the response message can reflect the complexity of the data structure returned by the device; onehot fcode It is a one-hot encoding of the function code in the message, used to indicate the response type of the device to different protocol operations; n-gram desc Indicates the vector embedding after character-level n-gram segmentation of the string field in the response (such as device identification, manufacturer information), which is used to characterize the device manufacturer or customized features; while CRC iThis field represents the checksum of the response data, used to identify whether the packet structure is standardized or contains unusual splicing. This vector, as an input feature, provides a multi-dimensional foundation of behavioral, semantic, and structural information, supporting subsequent clustering and anomaly detection modeling.

[0039] S3: Build a feature set for all device responses ; represents the response feature vector of the i-th device, i=1,...,n; It is the covariance matrix of all sample response vectors with a dimension of d×d, which is used to characterize the linear correlation and scale distribution between each feature dimension. This is the inverse of the covariance matrix and is used to perform a "normalized rotation" on the difference vector to account for the effects of varying scales or correlations between features. Multiplying all of these together represents the weighted sum of squares of feature differences under the covariance structure, representing the overall degree of difference under the constraints of feature correlation. The final square root operation gives the distance the same dimension as the Euclidean distance, making it easier to measure.

[0040] The system uses Gaussian mixture model (GMM) for cluster learning, measures the behavioral similarity between samples, and uses Mahalanobis distance as the distance function. ,in, represents the response feature vector of the jth device, is the feature covariance matrix, is the inverse matrix of the covariance matrix, and the mean, variance and weight parameters of each cluster are iteratively optimized through the EM algorithm to output Clusters representing typical device behaviors , providing a behavioral reference basis for anomaly detection.

[0041] S4: To identify potential hidden assets outside the cluster, the system uses Isolation Forest to build an anomaly detection model based on feature isolation, using normal cluster samples in the training phase. Randomly select feature subsets to construct multiple binary decision trees. Each tree recursively divides the sample by randomly selecting the partitioning dimension and threshold to form an isolation path. In the inference stage, the new sample Calculate the average path length in all trees , define the anomaly scoring function as ,in is the normalization factor, if the score is above the threshold , it is determined to be an abnormal device and constitutes a potential hidden asset collection.

[0042] S5: Build a device topology map based on the communication behavior between known devices , where the nodes Indicates device, edge Represents the communication relationship, and extracts communication features such as connectivity, communication frequency, protocol distribution, etc. for each node as the initial input vector , the system uses graph convolutional network (GCN) to learn node embedding, and the GCN model iterative update formula is Through several layers of propagation learning, the system obtains the structural representation of the device ,Through cluster center offset, isolation metric or boundary density, abnormal nodes in the topology structure are judged, providing reasoning basis for hidden devices with missing graph structure; Indicates that node v is in The embedding vector of the layer, Indicates that its neighbor node u is in The embedding representation of the layer, N(v) is the set of neighbors of node v; d v and d u denote the degree (i.e., number of neighbors) of nodes v and u respectively; It is The trainable weight matrix of the graph convolution layer; σ(⋅) is the activation function (such as ReLU). This formula implements the propagation and aggregation of node features in the graph structure. Degree-normalized weights prevent over-amplification of node information and ensure smooth propagation of features in local neighborhoods, thereby learning structure-aware embedding representations.

[0043] S6: The system constructs a hidden Markov model (HMM) based on the communication behavior sequence. Let the state set be , the observation set is the communication events of the device in different time windows, and the forward-backward algorithm is used in the training phase to transform the transfer matrix , emission matrix and the initial probability To estimate, use the Viterbi algorithm to calculate the most likely state path in the inference phase, and recursively calculate , predict the state of each device on the timeline. If a device is continuously predicted to be in the "silent" state and the transition probability is significantly lower than the average level, then the device is marked as a static hidden device and included in the inference result set; represents the maximum probability value of the optimal path to state s at time t (that is, the cumulative probability of the most likely path to state s); Indicates at time The maximum probability of the optimal path from the previous state s'; Represents the transition probability from state s′ to the current state s, which is an item in the state transition matrix of HMM; Indicates that the observation value o is generated under the current state s t The probability of observation or emission; It means choosing the path with the highest probability from all possible previous states.

[0044] S7: Identifies forged messages based on message structure and field content, mainly including: whether the field length, control code, function code and CRC check bit are legal, and whether there are illegal field combinations or unregistered device addresses. The detection logic is based on the syntax template tree and regular expression rules for matching and verification. If there are serious discrepancies between field values ​​and protocol definitions, illegal device codes or malformed message structures, the message is identified as a forged message anomaly. This module supports the configuration of message blacklist rules and format templates to enhance detection flexibility.

[0045] S8: The system identifies hidden assets based on the results Build an adaptive scanning strategy and record the recognition success rate p(protocol i ) and the average response delay T i , modeling the strategy optimization as a multi-armed bandit problem, using the Upper Confidence Bound (UCB) strategy selection protocol combination, and calculating the upper bound of the payoff for each combination ,in is the average income, represents the number of uses, t is the total number of rounds, and protocols and target segments with high expected returns are preferentially selected to perform the next round of scanning, thereby improving the system's detection capability in hidden areas and achieving continuous self-improvement of the efficiency of hidden asset identification.

[0046] The foregoing description is merely an embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Those skilled in the art will readily appreciate that the present invention is susceptible to various modifications and variations. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.

Claims

1. A scanning method for identifying hidden assets in an electric power industrial control network, characterized in that: The specific steps include: S1: Construct a probe message set based on the power industry's industrial control protocol. Use a template-based syntax tree builder to generate protocol messages, i.e., P_protocol = Template(FUNC_CODE, ADDR, LEN, CRC). Generate diverse request combinations by randomly perturbing and interpolating protocol structure fields. Interleave probe messages from different protocols at set intervals to form a rhythmic probe flow. The injection order is dynamically adjusted based on the historical response success rate. P_protocol represents the protocol message. Template(*) indicates the protocol message template function; FUNC_CODE indicates the function code; ADDR indicates the address; LEN indicates the length; CRC indicates the cyclic redundancy check; S2: Perform protocol parsing on each response message. This parsing decodes the field structure according to the identified protocol type and extracts key elements for subsequent modeling. S3: Construct a feature set of all device response vectors ; represents the response feature vector of the i-th device, i=1,...,n; S4: To identify potential hidden assets outside the cluster, the Isolation Forest algorithm is used to build an anomaly detection model based on feature isolation; S5: Build a device topology map based on the communication behavior between known devices , where the nodes Indicates device, edge Represents the communication relationship, and extracts communication features such as connectivity, communication frequency, and protocol distribution for each node as the initial input vector , adopt the graph convolutional network GCN model to learn node embedding; S6: Construct a hidden Markov model HMM based on the communication behavior sequence, assuming that the state set is , the observation set is the communication events of the device in different time windows, and the forward-backward algorithm is used in the training phase to transform the transfer matrix , emission matrix and the initial probability Perform estimation and use the Viterbi algorithm to calculate the most likely state path in the inference phase; S7: Identify forged messages based on the message structure and field content, including: whether the field length, control code, function code and CRC check bits are legal, and whether there are illegal field combinations or unregistered device addresses. The detection logic is based on the syntax template tree and regular expression rules for matching and verification. If there are field values ​​that seriously do not conform to the protocol definition, illegal device codes or malformed message structures, the message is identified as a forged message anomaly. S8: Based on the hidden asset identification results Build an adaptive scanning strategy and record the recognition success rate p(protocol i ) and the average response delay T i , modeling the strategy optimization as a multi-armed bandit problem, using the upper confidence bound algorithm, namely the Upper Confidence Bound strategy selection protocol combination, and calculating the upper bound UCB of the benefit of each combination i Select the protocol and target segment with high expected benefits to perform the next round of scanning. Represents a collection of inference hidden assets.

2. A scanning method for identifying hidden assets in an electric power industrial control network according to claim 1, characterized in that: In S1, the selection of protocol function codes is limited to read-only / query type; the field perturbation logic is as follows: for the address field, a sliding window or random jump strategy is used, and the read length The injection interval is within a reasonable range, and the sending order is regulated by the dynamic adjustment mechanism of the protocol priority.

3. A scanning method for identifying hidden assets in an electric power industrial control network according to claim 1, characterized in that: In S2, key factors include response delay , data length , Number of fields , CRC check result and error flag, the protocol function code is embedded into the feature vector using one-hot encoding; at the same time, if there is a device identifier string field, character-level n-gram, n=3, encoding is used to represent it, and it is mapped to a dense vector space through the embedding layer, and finally all fields are spliced ​​into a unified device response vector. ; Indicates the time delay between the system sending a probe message and receiving a response from the device; L i The byte length of the response message; onehot fcode It is a one-hot encoding of the function code in the message, used to indicate the response type of the device to different protocol operations; n-gram desc Indicates the vector embedding after character-level n-gram segmentation of the string field in the response, which is used to characterize the device manufacturer or customized features; i Indicates the checksum field of the response data, which is used to identify whether the data packet structure is standard or contains abnormal splicing.

4. A scanning method for identifying hidden assets in an electric power industrial control network according to claim 1, characterized in that: In S3, Gaussian mixture model GMM is used for clustering learning to measure the behavioral similarity between samples, and Mahalanobis distance is used as the distance function. ,in, represents the response eigenvector of the jth device, is the characteristic covariance matrix, The inverse matrix of the covariance matrix is ​​used to iteratively optimize the mean, variance and weight parameters of each cluster through the expectation maximization algorithm EM until the log-likelihood increment is lower than the set threshold, and the output is Clusters representing typical device behaviors , providing a behavioral reference basis for anomaly detection.

5. The scanning method for identifying hidden assets in an electric power industrial control network according to claim 1, characterized in that: In S4, normal clustering samples are used during the training phase. Randomly select feature subsets to construct multiple binary decision trees. Each tree recursively divides the sample by randomly selecting the partitioning dimension and threshold to form an isolation path. In the inference stage, the new sample Calculate the average path length in all trees , define the anomaly scoring function as ,in is the normalization factor, if the score is above the threshold , it is determined to be an abnormal device and constitutes a potential hidden asset collection.

6. The scanning method for identifying hidden assets in an electric power industrial control network according to claim 1, characterized in that: In S5, the graph convolutional network GCN model uses the following update formula: in is the activation function, It is The trainable weight matrix of the layer graph convolution. After two layers of propagation, the node obtains the embedded representation of the aggregated neighbor information; through several layers of propagation learning, the structural representation of the device is obtained. ,Through cluster center offset, isolation metric or boundary density, abnormal nodes in the topology structure are judged, providing reasoning basis for hidden devices with missing graph structure; Indicates that node v is in The embedding vector of the layer, Indicates that its neighbor node u is in The embedding representation of the layer, N(v) is the set of neighbors of node v; d v and d u denote the degrees of nodes v and u respectively.

7. The scanning method for identifying hidden assets in an electric power industrial control network according to claim 1, characterized in that: In S6, each device records whether communication occurs every 10 minutes as an observation sequence. ,in ∈{0,1}; model parameters The EM algorithm is used for learning, and the Viterbi algorithm is used in the prediction phase to recursively solve the maximum probability path: It represents the maximum probability value of the optimal path with state s at time t, Indicates at time The maximum probability of the optimal path from the previous state s'; It represents the transition probability from state s′ to the current state s, which is an item in the state transition matrix of the hidden Markov model HMM; Indicates that the observation value o is generated under the current state s t The probability of observation or emission; It means selecting the path with the highest probability from all possible previous states. If a device is in a silent state continuously and the probability of transitioning from the communication state to the silent state is less than 0.05, it is marked as a static hidden device and included in the inference result set.

8. The scanning method for identifying hidden assets in an electric power industrial control network according to claim 1, characterized in that: In S8, the revenue of each protocol combination Defined as: Each round of scanning selects the combined UCB with the current maximum UCB value i in is the average income, is the number of times used, t is the total number of rounds, and by recording the recognition efficiency of each protocol combination, the strategy is evaluated every 10 rounds, and the protocol redundancy injection mechanism is triggered based on the threshold to prevent local optimality.

9. A scanning system for identifying hidden assets in power industrial control networks, characterized in that Run the scanning method for identifying hidden assets in an electric power industrial control network as described in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Industrial control network security defense method and device, electronic equipment and storage medium

    CN116319022A

  • LLM-driven industrial network intrusion detection method and response system

    CN118381627A

  • Industrial control honey pot identification method based on multi-dimensional feature distribution

    CN119051889A

  • Power network unknown attack automatic discovery method based on protocol deep analysis

    CN119155091A

  • Network security defense method and system based on intrusion modeling trapping

    CN119996093A

Cited By

  • Asset state detection platform, asset state detection method, equipment and storage medium

    CN121262118A

  • Asset status detection platform, asset status detection methods, equipment and storage media

    CN121262118B

  • Upload rate control method of protocol message and electronic equipment

    CN121644004A