Power system multi-mode graph attention attack traceability blocking method and device
Through the multimodal graph attention attack tracing and blocking method, the collaborative analysis of undirected anomaly flow graph and directed alarm graph is used to prune negative causal associations, which solves the tracing problem of multi-step attacks in the power system and improves the safety and tracing accuracy of the power system.
Patent Information
- Application Number
- CN202511141045.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-15
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2045-08-15
AI Technical Summary
Existing methods for tracing the source of cyber attacks on power systems are unable to effectively identify multi-step attacks and accurately trace their source. Traditional defense systems are unable to cope with covert multi-stage attacks, resulting in real threats being overwhelmed by massive false alarms and redundant alerts, and are heavily dependent on expert knowledge and simulation work.
A multimodal graph attention attack tracing and blocking method is adopted. Through the collaborative analysis of undirected anomaly flow graph and directed alarm graph, the graph attention mechanism is used to aggregate nodes, and the attack chain is pruned in combination with non-causal reasoning methods, reducing the dependence on expert knowledge and achieving fine-grained attack tracing.
It improves the security of the power system, reduces redundant alarms, improves the accuracy and reliability of attack tracing, reduces dependence on expert knowledge, and enhances the ability to detect unknown attacks.
Smart Images

Figure CN120750633A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the technical field of network attack blocking, and in particular to a method and device for tracing and blocking a multimodal graph attention attack on a power system. Background Art
[0002] The widespread application of big data, cloud computing, and the Internet of Things (IoT) in power systems has exposed them to internet vulnerabilities and risks, posing a significant challenge to existing security systems. Currently, attack mitigation (Blocking) technologies are primarily used to detect, intercept, and prevent malicious activity, minimizing the risk to power systems, businesses, and users.
[0003] Reliably tracing the source of an attack is crucial for attack blocking. Currently, intrusion detection systems based on deep packet inspection and rule matching are widely deployed in power monitoring systems. However, the alarm information generated by such systems is highly isolated and redundant, resulting in real threats being easily overwhelmed by a massive number of false positives and redundant alarms, making it difficult to depict the overall attack process. At the same time, network attack patterns have evolved from single penetration to highly concealed multi-stage attacks, further weakening the detection capabilities of traditional defense methods and making traditional security protection systems unable to cope with the threat of covert multi-stage attacks. Therefore, how to use these alarms to accurately identify major security incidents caused by multi-stage attacks and reliably trace the source of the attacks has become a major challenge in power systems. Summary of the Invention
[0004] The following is a summary of the subject matter described in detail herein. This summary is not intended to limit the scope of the claims.
[0005] The main purpose of the embodiments disclosed herein is to propose a method and device for tracing and blocking multimodal graph attention attacks in power systems. Through multimodal collaborative analysis between an undirected abnormal flow graph and a directed alarm graph, fine-grained attack behavior tracing is achieved. In addition, a non-causal reasoning method is used for attack chain analysis, which can ensure the causal correlation of alarm types and minimize dependence on expert knowledge, attack markers, and simulation work.
[0006] A first aspect of an embodiment of the present application provides a method for tracing and blocking a multimodal graph attention attack in a power system, the method comprising: Responding to an attack blocking request of the power system, obtaining alarm data and flow data of the power system; Abnormal traffic data is filtered out based on the matching of the traffic data and the alarm data, and an undirected abnormal flow graph is constructed based on the abnormal traffic data; wherein the nodes in the undirected abnormal flow graph are the abnormal traffic data, and the edges are the source node information and the destination node information corresponding to the alarm data, the source node information includes a source IP address and a source port number, and the destination node information includes a destination IP address and a destination port number; Aggregating nodes in the undirected abnormal flow graph based on a graph attention mechanism to obtain an aggregation result, and clustering the aggregation result to filter out real attack traffic data from the abnormal traffic data; Generate a directed alarm graph based on the alarm data corresponding to the real attack traffic data; wherein the nodes in the directed alarm graph are IP addresses of the alarm data, the edges in the directed alarm graph are directed edges from the source IP address to the destination IP address, and the attributes of the edges include corresponding alarm types; Traversing all nodes in the directed alarm graph, screening out all nodes with an in-degree of 0 as starting points of the initial attack chain, and generating all initial attack chains based on the starting points and the directed edges; Each of the initial attack chains is traversed, and when there is a negative causal correlation between the alarm types on the edges of the initial attack chain, the initial attack chain is pruned to obtain at least one final attack chain corresponding to the initial attack chain. When there is no negative causal correlation between the alarm types on the edges of the initial attack chain, the initial attack chain is used as a final attack chain.
[0007] This embodiment provides a method for tracing and blocking the source of multimodal graph attention attacks in a power system, which has at least the following advantages: This method constructs a complete process of matching, association, attack chain analysis, and attack blocking. First, compared to existing techniques that use a single data modality analysis paradigm, this method utilizes multimodal collaborative matching of power system alarm data and flow data to filter out abnormal flow data. Then, based on aggregation and clustering mechanisms, an undirected anomaly flow graph is used to filter out true attack flow data from the abnormal flow data. The aggregation utilizes an attention mechanism that adaptively assigns weights to different neighbors of flow information, improving the accuracy of filtering out true attack flow data from the abnormal flow data. A directed alarm graph of alarm associations is then constructed based on the true attack flow data. Based on this directed alarm graph, an initial attack chain is generated, enabling fine-grained association and tracing of multi-step attack behaviors. A non-causal reasoning method is then proposed to prune negative causal relationships between types in the initial attack chain, resulting in a final attack chain. Finally, attack blocking is performed based on all final attack chains, improving power system security. This method achieves fine-grained attack behavior tracing through multimodal collaborative analysis between the undirected anomaly flow graph and the directed alarm graph. At the same time, this method uses non-causal reasoning methods to perform attack chain analysis, which can ensure the causal correlation of alarm types and minimize the dependence on expert knowledge, attack markers and simulation work.
[0008] In some implementations, filtering out abnormal traffic data based on matching the traffic data and the alarm data includes: Obtaining an initial attribute value of the alarm data; A tuple value is extracted from the initial attribute value, and the tuple value is matched with the traffic data to filter out abnormal traffic data.
[0009] In some embodiments, after filtering out abnormal traffic data based on matching between the traffic data and the alarm data, the method further includes: In the case that there are at least two tuple values corresponding to the alarm data that match the same traffic data and the alarm types are the same, the at least two alarm data are merged into one alarm data according to a time sequence coverage strategy.
[0010] In some implementations, constructing an undirected abnormal flow graph based on the abnormal traffic data includes: Constructing a bipartite graph based on the abnormal traffic data; the nodes in the bipartite graph are the source node information and the destination node information in the alarm data, and the edges are the abnormal traffic data; The undirected abnormal flow graph is constructed by using the union of the source node information and the destination node information of the bipartite graph as the edge of the undirected abnormal flow graph and the edges of the bipartite graph as the nodes of the undirected abnormal flow graph.
[0011] In some implementations, generating a directed alarm graph based on the alarm data corresponding to the real attack traffic data includes: Determine the IP address of the alarm data, the alarm type of the alarm data, and the start and end timestamps of the alarm data; In the case where the destination IP address of the first alarm data of any two alarm data is the same as the source IP address of the second alarm data, and the end timestamp of the first alarm data is earlier than the start timestamp of the second alarm data, establishing an association relationship between the first alarm data and the second alarm data; A directed alarm graph is constructed based on the IP addresses of the alarm data, the alarm types of the alarm data, and the association relationship between any two alarm data.
[0012] In some implementations, aggregating nodes in the undirected anomaly flow graph based on a graph attention mechanism includes: A graph attention neural network is used to aggregate the nodes in the undirected abnormal flow graph; wherein the first The aggregation process of layer attention includes: ; ; ; in, is the aggregation depth of the graph attention neural network, Central node The set of neighbor nodes of is the neighbor node, To change the flow characteristics from Layer aggregation to the The learnable parameters of the layer, and Respectively Neighbor nodes in a layer With the central node Features, For the Neighbor nodes in a layer Features, is the ReLU activation function, For the Neighbor nodes in the layer With the central node The attention score between For the The trainable weight matrix of the layer, For the The learnable parameters of the layer, For splicing operation, is the transpose, For the Neighbor nodes in a layer Features, is the natural exponential function, is the activation function.
[0013] In some implementations, clustering the aggregation results to filter out real attack traffic data from the abnormal traffic data includes: Clustering the aggregation results based on K-means to divide the abnormal traffic data into real attack traffic data and normal traffic data; After dividing the abnormal traffic data into real attack traffic data and normal traffic data, the method further includes: In the power system, the alarm data corresponding to the normal flow data is deleted.
[0014] A second aspect of an embodiment of the present application provides a device for tracing and blocking a multimodal graph attention attack on a power system, the device comprising: A data acquisition module, configured to obtain alarm data and flow data of the power system in response to an attack blocking request of the power system; An abnormal flow graph construction module is used to filter out abnormal flow data based on the matching of the flow data and the alarm data, and to construct an undirected abnormal flow graph based on the abnormal flow data; wherein the nodes in the undirected abnormal flow graph are the abnormal flow data, and the edges are the source node information and destination node information corresponding to the alarm data, the source node information includes a source IP address and a source port number, and the destination node information includes a destination IP address and a destination port number; An attack traffic screening module is used to aggregate nodes in the undirected abnormal flow graph based on a graph attention mechanism to obtain an aggregated result, and cluster the aggregated result to screen out real attack traffic data from the abnormal traffic data; an alarm graph generation module, configured to generate a directed alarm graph based on the alarm data corresponding to the real attack traffic data; wherein the nodes in the directed alarm graph are IP addresses of the alarm data, the edges in the directed alarm graph are directed edges from the source IP address to the destination IP address, and the attributes of the edges include the corresponding alarm type; The attack tracing module is used to traverse all nodes in the directed alarm graph, screen out all nodes with an in-degree of 0 as the starting point of the initial attack chain, and generate all initial attack chains based on the starting point and the directed edges; and is used to traverse each of the initial attack chains and, if there is a negative causal correlation between the alarm types on the edges of the initial attack chain, prune the initial attack chain to obtain at least one final attack chain corresponding to the initial attack chain; if there is no negative causal correlation between the alarm types on the edges of the initial attack chain, use the initial attack chain as a final attack chain.
[0015] A third aspect of an embodiment of the present application proposes an electronic device, comprising at least one controller and a memory for communicating with the controller; the memory stores instructions that can be executed by the at least one controller, and the instructions are executed by the at least one controller to enable the at least one controller to execute a method for tracing and blocking a multimodal graph attention attack on a power system as described above.
[0016] A fourth aspect of an embodiment of the present application proposes a computer-readable storage medium, on which a computer program is stored. When the computer program is executed, it implements a method for tracing and blocking the attention attack on a multimodal graph of a power system as described above.
[0017] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become obvious from the description below, or will be learned through practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments or related technical descriptions. Obviously, the drawings described below are only some embodiments of the embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0019] Figure 1 This is a flow chart of an embodiment of a method for tracing and blocking a multimodal graph attention attack on a power system provided by the present application; Figure 2 This is a block diagram of an embodiment of a method for tracing and blocking a multimodal graph attention attack on a power system provided by the present application; Figure 3 This is a schematic diagram of an embodiment of the execution process of the attack tracing module provided by this application; Figure 4 This is a schematic structural diagram of an embodiment of a device for tracing and blocking a multimodal graph attention attack on a power system provided by the present application; Figure 5It is a structural diagram of the electronic device provided in this application. DETAILED DESCRIPTION
[0020] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0021] In the description of this application, if there is a description of first, second, etc., it is only for the purpose of distinguishing technical features, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features or implicitly indicating the order of the indicated technical features.
[0022] In the description of this application, it should be understood that descriptions involving orientation, such as the orientation or positional relationship indicated by up, down, etc., are based on the orientation or positional relationship shown in the accompanying drawings, and are only for the convenience of describing this application and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and function in a specific orientation, and therefore cannot be understood as a limitation on this application.
[0023] Before introducing the embodiments, some background information of this application is introduced: In recent years, multi-step attack identification and tracing methods have mainly focused on three paradigms, including: 1) Similarity-based correlation analysis: Similarity-based alarm association analysis methods cluster and correlate alarm events by quantitatively analyzing the feature similarities between network security alarms. The core of this method lies in designing an effective similarity measurement function. Some researchers only consider the comparison of a single attribute, while most focus on a combination of multiple attributes, such as port number, timestamp, source IP address, and destination IP address. It is worth noting that in the field, alarm events usually represent specific instances. For example, an alarm event is: at a certain moment, a suspected DDOS attack was launched from a first IP address to a second IP address, and the system generated an alarm record. Among them, DDOS attack is an alarm type. Similarly, there are other alarm types, such as abnormal access, which will not be detailed here.
[0024] 2) Attack sequence-based method: The attack sequence-based pattern matching method relies on a predefined attack knowledge base and identifies complex attack scenarios by analyzing the time series characteristics of security events. This method usually requires the construction of an attack pattern library, among which the tactical chain model provided by the MITRE ATT&CK framework has become an industry standard.
[0025] 3) Machine learning-based methods: Machine learning-based methods represent the current technological frontier. Convolutional neural networks and graph convolutional networks have performed outstandingly in this field. By training detection models with attack samples, they can automatically extract attack features and identify new attack variants.
[0026] While these methods have achieved some success, they still have limitations. Existing research often employs a single data modal analysis paradigm. While relying solely on traffic characteristics can capture anomalous behavior, it lacks causal relationships within the attack chain. Relying solely on alarm data from alarm logs can establish temporal correlations between attacks, but it faces the dual challenges of strong reliance on expert knowledge and high sensitivity to alarm noise. These limitations make it difficult to meet the practical needs of power systems, which have extremely stringent reliability requirements.
[0027] like Figures 1 to 3 In order to solve the above technical defects, an embodiment of the present application provides a method for tracing and blocking the multimodal graph attention attack in a power system, the method comprising the following steps S110 to S160: Step S110 : In response to an attack blocking request of the power system, alarm data and flow data of the power system are acquired.
[0028] After the user initiates an attack blocking request to the power system, the alarm events in the alarm log are reconstructed to extract structured alarm data, which facilitates subsequent matching, merging, correlation analysis, and attack chain extraction. The following is a description of the reconstructed alarm data: (1); Indicates the attributes of the alarm, including start timestamp, end timestamp, type, source IP, destination IP, source port, destination port, and transmission protocol; Indicates the relationship between alarm data.
[0029] In this step, the flow data can be collected based on devices such as "flow collection equipment", "sensors", and "intrusion detection equipment".
[0030] After collecting the alarm data and the traffic data, this embodiment uses the coordinated matching between the alarm data and the traffic data to find abnormal traffic data. Please refer to the subsequent introduction for details.
[0031] Step S120 , filtering out abnormal traffic data based on the matching of traffic data and alarm data, and constructing an undirected abnormal flow graph based on the abnormal traffic data.
[0032] Among them, the nodes in the undirected abnormal flow graph are abnormal traffic data, and the edges are the source node information and destination node information in the corresponding alarm data. The source node information includes the source IP address and source port number, and the destination node information includes the destination IP address and destination port number.
[0033] In this step, since the alarm data only contains partial attack information, it cannot fully describe the attack process, and there are certain limitations in separating false alarm data. Therefore, in order to better handle false alarm data, the corresponding abnormal traffic is used for analysis, which can capture the details of the attack more comprehensively.
[0034] Then, the alarm data extracted in step S110 is matched with the traffic data to filter out abnormal traffic data. Based on the above embodiment, the matching method includes the following steps S210 to S220: Step S210: Acquire the initial attribute value of the alarm data.
[0035] The initial attribute value is as in the above embodiment. shown.
[0036] Step S220 , extracting a tuple value from the initial attribute value, and matching the tuple value with the traffic data to filter out abnormal traffic data.
[0037] In step S220, network traffic can be divided into flows according to source IP address, source port, destination IP address, destination port and transport protocol. When an intrusion detection system (IDS) detects an attack in a data packet and generates alarm data, the alarm data is used to The 5-tuple extracted from information to match the corresponding stream and extract it.
[0038] In some embodiments, the method further includes the following steps (to achieve merging of redundant alarms): In the case that the tuple values corresponding to at least two alarm data match the same traffic data and the alarm types are the same, the at least two alarm data are merged into one alarm data according to the time sequence coverage strategy.
[0039] This embodiment further determines whether the alarms matching the same flow are of the same type. If they are the same, such alarm data are merged to reduce redundant alarms.
[0040] The merging rule adopts a time-series coverage strategy, which retains the alarm with the earliest start timestamp and updates its end timestamp to the latest timestamp of all merged alarms, thereby compressing redundant alarms in the temporal and spatial dimensions and improving the compactness of alarm data.
[0041] For example, when the tuple attributes corresponding to multiple alarm data match the same traffic data, it indicates that the traffic data may trigger multiple alarms.
[0042] Constructing an undirected abnormal flow graph based on abnormal traffic data in step S120 includes the following steps S310 to S320: Step S310, construct a bipartite graph based on the abnormal traffic data; the nodes in the bipartite graph are the source node information and destination node information in the alarm data, and the edges are the abnormal traffic data; wherein the source node information includes the source IP address and source port number, and the destination node information includes the destination IP address and destination port number.
[0043] Step S320 , using the union of the source node information and the destination node information of the bipartite graph as the edge of the undirected abnormal flow graph, and using the edges of the bipartite graph as the nodes of the undirected abnormal flow graph, to construct the undirected abnormal flow graph.
[0044] An undirected anomaly flow graph refers to a graph structure formed by transforming bipartite graph nodes and edges. This transformation process makes the anomaly flow data the core analysis object of the graph structure, facilitating the subsequent aggregation of node features through the graph attention mechanism.
[0045] When designing a network traffic analysis model based on a graph neural network, the core modeling step lies in identifying and defining node elements in the network topology. Traditional methods tend to use IP addresses and port numbers as nodes to effectively classify network traffic. This approach uniquely identifies the endpoints of network data flows and accurately characterizes the communication characteristics of specific application services. This facilitates the construction of a comprehensive description of data flow characteristics and their context, providing a foundation for depicting the network traffic topology. However, this strategy has limitations when it comes to expressing information about edges (i.e., actual traffic), particularly when it comes to distinguishing false positives based on traffic information.
[0046] To overcome these limitations and fully exploit the value of flow information, we propose a conversion mechanism from bipartite graphs to line graphs, aiming to enhance the expressiveness of edge information. Specifically, this mechanism consists of two key stages: First, in step S310, a special bipartite graph is constructed: ;in, Represents the source node set, consisting of source IP address and source port number; Represents the destination node set, consisting of the destination IP address and destination port number; This covers all edges connecting these two types of nodes, which represent the actual transmission traffic. Then, in step S320, the bipartite graph is converted into a line graph, that is, an undirected abnormal flow graph: ;in, After the transformation, the nodes of the abnormal flow graph correspond to the edges of the original bipartite graph, and the edges of the abnormal flow graph correspond to the nodes of the original bipartite graph.
[0047] By converting the bipartite graph twice to an undirected anomaly flow graph, the network traffic classification task is transformed from an edge classification problem to a node classification problem. This decouples anomaly traffic data from network node information, allowing aggregate analysis of anomaly traffic to focus more on the characteristics of the traffic itself while preserving the topological relationship between source and destination nodes. This hierarchical construction approach effectively reduces interference from isolated nodes and improves the accuracy of attack traffic identification.
[0048] In step S130, the nodes in the undirected abnormal flow graph are aggregated based on the graph attention mechanism to obtain an aggregation result, and the aggregation result is clustered to filter out the real attack traffic data in the abnormal traffic data.
[0049] In this step, the core goal is to use graph aggregation and cluster analysis technology based on the identified abnormal traffic data to effectively eliminate redundancy and false alarms in the alarm data extracted in step S110, generate high-confidence security alarm data, and lay the foundation for subsequent attack chain analysis.
[0050] While existing graph neural networks, such as GraphSAGE (Graph Sample and AggregatE) and E-GraphSAGE (Enhanced Graph Sample and AggregatE), can effectively process graph information, they typically use fixed weights to aggregate neighbor node information. This static aggregation approach has significant limitations in network traffic analysis: in real-world networks, traffic patterns are dynamically heterogeneous, and different neighboring traffic nodes significantly differ in their contribution to determining whether a central node (representing the current traffic / alert being analyzed) constitutes a true attack. Fixed weights cannot capture this dynamically changing neighbor importance.
[0051] To address these issues, this embodiment introduces the Attention Mechanism. Its core concept is to enable the model to adaptively learn to assign weights to the different neighbors of each central node. More important neighbors receive greater weight during aggregation, while less important ones receive less. This allows the model to dynamically adjust the aggregation process based on the specific characteristics of neighboring nodes and their relationship to the central node, focusing on the most relevant information.
[0052] For each node in the undirected anomaly flow graph , the first The aggregation process of layer attention can be described as: (2); (3); (4); in, is the aggregation depth of the graph attention neural network, Central node The set of neighbor nodes of is the neighbor node, To change the flow characteristics from Layer aggregation to the The learnable parameters of the layer, and Respectively Neighbor nodes in a layer With the central node Features, For the Neighbor nodes in a layer Features, is the ReLU activation function, For the Neighbor nodes in the layer With the central node The attention score between For the The trainable weight matrix of the layer, For the The learnable parameters of the layer, For splicing operation, is the transpose, For the Neighbor nodes in a layer Features, is the natural exponential function, is the activation function. In a preferred embodiment, it can be set =2.
[0053] After aggregation, the aggregated results are clustered and the aggregator embedding is used to distinguish real attack traffic from normal traffic.
[0054] In some embodiments, because there is a higher likelihood of neighbor relationships between real attack traffic in an undirected anomaly graph, the distances between embedded representations of real attack traffic are closer. The K-means algorithm has fast clustering speed and high execution efficiency, and is suitable for data based on distance distribution. Therefore, the K-means algorithm can be used for clustering, and the K value can be manually set to 2 to distinguish between real attack traffic and normal traffic. This allows the identification of alarm data corresponding to normal traffic in the abnormal traffic data, as well as alarm data corresponding to real attack traffic in the abnormal traffic data. The former alarm data can then be deleted, and the latter alarm data can be used for subsequent processing.
[0055] In some embodiments, clustering the aggregation results in step S130 to filter out real attack traffic data from the abnormal traffic data includes: Step S1310: Cluster the aggregation results based on K-means to divide the abnormal traffic data into real attack traffic data and normal traffic data.
[0056] After the abnormal traffic data is divided into real attack traffic data and normal traffic data, the method further includes step S410: Step S410: In the power system, the alarm data corresponding to the normal flow data is deleted.
[0057] The abnormal traffic data that is classified as normal traffic will have its corresponding alarm data deleted, thereby eliminating false alarms, improving the authenticity of the alarm data generated by the power system, and further improving the efficiency of attack blocking.
[0058] Step S140: Generate a directed alarm graph based on the alarm data corresponding to the actual attack traffic data. The nodes in the directed alarm graph are IP addresses of the alarm data, and the edges in the directed alarm graph are directed edges from the source IP address to the destination IP address. The attributes of the edges include the corresponding alarm type.
[0059] In some embodiments, the alarm log can be viewed as a network formed by connecting source IP addresses and target IP addresses. Therefore, a directed alarm graph can be further constructed using IP hops based on the relationship between the alarm data.
[0060] Alarm logs can be viewed as a network structure consisting of source and destination IP addresses. Based on this characteristic, alarm data can be abstracted into a graph model to reveal potential correlations and attack propagation paths. To achieve this, we first need to define and quantify the correlations between different alarm data. Specifically, we consider the basic attributes contained in each alarm data item, including the source IP address, destination IP address, alarm start timestamp, alarm end timestamp, and alarm type.
[0061] If the alarm data Destination IP address and another alarm data If the source IP addresses of the two are the same, it is considered that there may be potential attack jump behavior between them. The alarm association can be formally expressed as: (5); (6); In addition, to ensure the time logic rationality of the alarm diagram, eliminate invalid associations in reverse time sequence, and enhance the credibility of the attack path, only when The end timestamp is earlier than Alarm association is allowed only when the start timestamp is Existence, that is: (7); Therefore, only when equations (6) and (7) are satisfied at the same time, an alarm association will be established between the corresponding alarm data.
[0062] On this basis, the following directed alarm graph is constructed by combining the alarm IP address and alarm type: (8); in, and They represent node sets and edge sets, respectively. Each node uniquely corresponds to an IP address, and an edge is a directed connection from a source IP address to a destination IP address. To further enhance the semantic expressiveness of the graph model, the edge attributes include the corresponding alarm type, which is used to describe the attack behavior category between the two alarm data.
[0063] For example, consider two related alarm data sets, Alarm Data I and Alarm Data II, with alarm types I and II, respectively. Alarm Data I has a source IP address of IP1 and a destination IP address of IP2, while Alarm Data II has a source IP address of IP2 and a destination IP address of IP3. This generates an alarm graph: IP1 --->IP2 --->IP3. The IP1--->IP2 edge represents Alarm Type I, while the IP2--->IP3 edge represents Alarm Type II.
[0064] Step S150 traverses all nodes in the directed alarm graph, selects all nodes with in-degree 0 as starting points of the initial attack chain, and generates all initial attack chains based on the starting points and directed edges.
[0065] After the directed alarm graph is constructed, it is necessary to extract the potential multi-stage attack chain from the graph and trace the source of the attack.
[0066] Among them, in-degree refers to the number of edges pointing to a vertex in a directed graph. The temporal nature of the alarm data has been taken into consideration. In the diagram, there is a time sequence between the interconnected nodes. Therefore, from the directed alarm graph In the example above, obtaining the head node of the attack chain only requires considering one case, that is, the node is a node with an in-degree of 0 in the directed alarm graph. By traversing the directed alarm graph All nodes of , filter out the node set with in-degree 0 , as a candidate starting point of the attack chain.
[0067] Then, for each head node , use depth-first search to traverse all its reachable paths and generate the initial attack chain set Each initial attack chain is formalized for: (9); in, to The path must satisfy the timing increment.
[0068] Step S160: traverse each initial attack chain and, if there is a negative causal correlation between the alarm types on the edges of the initial attack chain, prune the initial attack chain to obtain at least one final attack chain corresponding to the initial attack chain. If there is no negative causal correlation between the alarm types on the edges of the initial attack chain, use the initial attack chain as a final attack chain.
[0069] In this step, due to the complexity of multi-step attacks, each single step has a certain causal relationship between them. The previous single-step attack paves the way for the next attack, forming a temporal and logical attack chain. Therefore, in order to gain a deeper understanding of the attack process and improve the granularity and explainability of security analysis, it is necessary to further refine the complete attack chain. For all attack chains, further refinement is required, that is, further breaking the chain of each attack step to help security personnel better analyze and trace the cause and effect of each attack.
[0070] Currently, the concept of causal association has been widely used in the field of alarm correlation analysis. However, due to the lack of attack rules in power systems and the difficulty of network vulnerability scanning, these methods are difficult to apply directly. Moreover, while using causal association to determine the relationship between attacks may have good traceability for known attack relationships, its generalization ability for unknown attacks is not strong enough.
[0071] Therefore, this embodiment designs a negative causal correlation method. Its core concept is to exclude unnecessary causal edges in the attack chain, retaining causal paths with high confidence. This method is then used to prune the attack chain. This not only ensures the causal relevance of the alert types, but also minimizes reliance on expert knowledge, attack markers, and simulations.
[0072] like Figure 2 In the "initial attack chain" part, there are chains of "type I and type II" and "type I and type III", and there is a non-causal relationship between "type I and type III". Therefore, the chain "type I and type III" is pruned to obtain the chain "type III".
[0073] For example, the original initial attack chain is: IP1 ---> IP2 ---> IP3; IP1 ---> IP2 indicates alarm type I, and IP2 ---> IP3 indicates alarm type II. Since there is no causal relationship between the two alarm types, the chain needs to be broken. The final attack chain after the break becomes: Final attack chain I: IP1--->IP2, final attack chain II: IP2--->IP3; For example, the original initial attack chain is: IP1 ---> IP2 ---> IP3 ---> IP4 ---> IP5; IP1 ---> IP2 indicates Alarm Type I, IP2 ---> IP3 indicates Alarm Type II, IP3 ---> IP4 indicates Alarm Type III, and IP4 ---> IP5 indicates Alarm Type IV. Since there is no causal relationship between Alarm Type II and Alarm Type III, and there is no causal relationship between Alarm Type III and Alarm Type IV, the chain needs to be broken. After the chain is broken, the final attack chain becomes: Final attack chain I: IP1 ---> IP2 ---> IP3, Final attack chain II: IP3 ---> IP4, Final attack chain III: IP4 ---> IP5; It is important to note that determining causal relationships between types of alarm data is a key task in network security incident analysis, fault diagnosis, and operation and maintenance management. This includes but is not limited to: 1) Time series-based analysis; for example, chronological order: the cause event usually occurs before the result event. Time interval analysis: calculate the delay distribution pattern between alarms.
[0074] 2) Analysis based on topological relationships; for example, network topology association, alarms generated by the same host / device, device alarms on the same network path, and associated alarms on the service call chain.
[0075] 3) Analysis based on alarms, etc.
[0076] Non-causal relationship is the opposite concept of causal relationship, and will not be repeated here.
[0077] The pruning operation refers to identifying and eliminating negative causal correlation types in the attack chain. Specifically, it can be determined through timestamp conflicts, logical contradictions, etc. to eliminate interference from incorrect paths.
[0078] If the time sequence of the types on all edges in an attack chain is continuous and the behavior is logically consistent, it is directly output as a valid attack chain without pruning. This process effectively avoids attack chain breaks caused by misjudgments by distinguishing true attack paths from false positives, providing a reliable data foundation for subsequent blocking strategies.
[0079] Finally, security personnel can block corresponding attacks based on all the final attack chains screened out to ensure the network security of the power system. Figure 2 , security personnel can block corresponding attacks on chains "Type I and Type II" and chain "Type III".
[0080] The method for tracing and blocking the multimodal graph attention attack on a power system provided by this embodiment has at least the following beneficial effects: This method constructs a complete process of matching, correlation, attack chain analysis, and attack blocking. First, compared with the existing technology that uses a single data modality analysis paradigm, this method uses multimodal collaborative matching of power system alarm data and flow data to filter out abnormal flow data. Then, based on aggregation and clustering mechanisms, it uses an undirected abnormal flow graph to filter out the actual attack flow data in the abnormal flow data. Then, based on the actual attack flow data, a directed alarm graph of alarm association is constructed to achieve fine-grained correlation and traceability of multi-step attack behaviors. A non-causal reasoning method is then proposed to prune negative causal associations between types in the initial attack chain, resulting in the final attack chain. Finally, attack blocking is performed based on all final attack chains, improving the security of the power system. Through multimodal collaborative analysis between the undirected abnormal flow graph and the directed alarm graph, this method extracts the actual attack flow from redundant alarms and accurately constructs the attack propagation path, achieving fine-grained attack behavior traceability and solving the traceability problem of multi-stage covert attacks. At the same time, in order to reduce dependence on expert knowledge and improve the ability to detect unknown attacks, this method innovatively adopts non-causal reasoning methods to analyze attack chains, eliminates false associations through dynamic pruning strategies, ensures the causal correlation of alarm types, and minimizes dependence on expert knowledge, attack markers, and simulation work, thereby improving the reliability of attack blocking and ensuring the safe operation of the power system.
[0081] like Figures 2 to 3 This embodiment provides a method for tracing and blocking the multimodal graph attention attack in a power system. This method acts on a system for tracing and blocking the multimodal graph attention attack in a power system. The system framework includes at least: 1. Alarm Optimization Module. The alarm optimization module constructs an abnormal flow graph through the alarm-abnormal flow matching mechanism, and based on graph aggregation and cluster analysis technology, effectively eliminates redundancy and false positives in the original alarm and generates high-confidence security alarms.
[0082] By merging and deleting redundant alarms and false alarms, we can obtain high-quality alarms and help accurately trace the source of the attack. In order to better reconstruct the attack scenario and extract the attack path, we use abnormal traffic data to build an undirected abnormal flow graph. Then, we designed an attack graph aggregation mechanism. By aggregating the information of neighboring nodes, we can capture the neighboring node information of the target node, thereby better understanding the characteristics of abnormal samples, analyzing the captured abnormal flow, and removing false positives. The details are as follows: (1) Alarm preprocessing; To facilitate subsequent analysis such as matching, merging, correlation, and attack chain extraction, the alerts need to be restructured into a unified format: ; in, Indicates the attributes of the alarm, including start timestamp, end timestamp, type, source IP, destination IP, source port, destination port, and transmission protocol; Indicates the relationship between alarms.
[0083] (2) Abnormal flow matching; Since there are redundant alarms and false alarms in the large number of alarms generated by the Intrusion Detection System (IDS), they need to be merged and deleted. However, the alarms only contain part of the attack information and cannot fully describe the attack process. There are certain limitations in separating false alarms. Therefore, in order to better handle false alarms, the corresponding abnormal flow is used for analysis to capture the details of the attack more comprehensively.
[0084] When IDS detects an attack in a data packet and generates alarm data, The 5-tuple extracted from Information is used to match the corresponding stream and extract it. For alarm data matching the same stream, the system further determines whether the alarm types are the same. If they are, the alarm data is merged to reduce redundant alarm data. The merging rule uses a time-series overlay strategy: the alarm data with the earliest start timestamp is retained, and its end timestamp is updated to the latest timestamp of all merged alarm data. This compresses redundant alarm data in the spatial and temporal dimensions, improving the compactness of alarm data.
[0085] (3) Construction of abnormal flow graph; Based on the original "IP+port as nodes and traffic as edges", to overcome the problem that traditional graph structures are unable to express edge information, this embodiment proposes a method for converting bipartite graphs into line graphs: When using traffic information to construct a graph, the source and destination nodes are not directly connected. To this end, a bipartite graph is constructed. ;in Represents the source node set, consisting of source IP address and source port number; Represents the destination node set, consisting of the destination IP address and destination port number; It covers all edges connecting these two types of nodes and represents the actual transmission traffic.
[0086] The bipartite graph is then converted into a line graph, i.e. an undirected anomaly flow graph: ,in After the conversion, the nodes of the abnormal flow graph correspond to the edges of the original bipartite graph, and the edges of the abnormal flow graph correspond to the nodes of the original bipartite graph. This converts the network traffic classification task from the original edge classification problem to a node classification problem.
[0087] (4) Abnormal flow graph aggregation; In actual network environments, traffic patterns are dynamically heterogeneous, and the contribution of different neighbor traffic to attack detection varies significantly. Therefore, in this embodiment, an attention mechanism is added to adaptively assign weights to different neighbors of abnormal traffic data. For each node in the undirected abnormal flow graph, the aggregation process can refer to the above formulas (2) to (4), which will not be repeated here. Here, the aggregation depth of the graph attention neural network can be set to two layers. The second layer nodes achieve feature propagation within a two-hop range by integrating the feature representations of their neighbors.
[0088] This embodiment adds an attention mechanism to adaptively assign weights to different neighbors of traffic information to improve the aggregation effect.
[0089] (5) False alarm handling; Clustering is performed on the aggregation results using the K-means algorithm to distinguish normal traffic from real attack traffic. If traffic is classified as normal, the alarm log for that traffic is deleted from the system log.
[0090] 2. Alarm graph construction module. The alarm graph construction module further constructs an IP hop alarm graph based on the optimized high-quality alarms, using a graph structure to represent the temporal correlation between alarms, providing key data support for multi-stage attack analysis.
[0091] The alarm log can be viewed as a network connected by source IP addresses and destination IP addresses. Therefore, a directed alarm graph can be constructed based on the relationship between alarms using IP hops. .
[0092] 3. Attack tracing module; Since the temporal nature of alerts is taken into account when constructing the directed alert graph, there is a temporal nature between interconnected nodes in the directed alert graph. Therefore, obtaining the head node of the attack chain from the directed alert graph only requires considering one case: that is, the node is a node with an in-degree of 0 in the directed alert graph. The algorithm traverses all nodes in the directed alert graph and filters out the set of nodes with an in-degree of 0: , as a candidate starting point for the initial attack chain.
[0093] For each head node , use depth-first search to traverse all its reachable paths and generate the initial attack chain set Each initial attack chain is formalized for: ,in, to The path must satisfy the timing increment.
[0094] Due to the complexity of multi-step attacks, there is a certain causal relationship between each single-step attack. The previous single-step attack is to pave the way for the next attack. Therefore, for all attack chains, it is necessary to further refine and further break the chain of each attack step to help security personnel better analyze and trace the cause and effect of each attack. This embodiment designs a negative causal association method. Its core idea is to retain causal paths with high confidence by excluding edges of non-essential causal relationships in the attack chain. Using the negative causal association method to prune the attack chain can not only ensure the causal correlation of the alarm type, but also minimize the dependence on expert knowledge, attack markers, and simulation work.
[0095] The attack tracing module analyzes high-quality time-series directed alarm graphs to accurately extract effective attack chains, thereby discovering multi-stage attacks hidden in the power system and tracing the source of such attacks to help security personnel block and isolate the attacks, thereby ensuring the safety of the power system.
[0096] The method for tracing and blocking the multimodal graph attention attack on a power system provided by this embodiment has at least the following beneficial effects: This method constructs a complete process of matching, association, attack chain analysis, and attack blocking. First, compared with the existing technology that adopts a single data modality analysis paradigm, this method uses multimodal collaborative matching of power system alarm data and flow data to filter out abnormal flow data. For alarm data matched to the same flow, similar alarm data can be merged to reduce redundant alarm data; then, based on the aggregation and clustering mechanism, the real attack flow data in the abnormal flow data is filtered out through the undirected abnormal flow graph. The attention mechanism is used in aggregation, which can adaptively assign weights to different neighbors of flow information, thereby improving the ability to filter out real attacks in abnormal flow data. To improve the accuracy of traffic data, and to overcome the inability of traditional graph structures to express edge information, a bipartite graph-to-line graph conversion method is used to transform the network traffic classification task from an edge classification problem to a node classification problem, improving data analysis efficiency. A directed alarm graph with alarm associations is then constructed based on real attack traffic data. An initial attack chain is generated from this directed alarm graph, enabling fine-grained multi-step attack behavior correlation and tracing. A non-causal reasoning method is then proposed to prune negative causal relationships between types in the initial attack chain, resulting in a final attack chain. Finally, attack blocking is performed based on all final attack chains, improving power system security. This method achieves fine-grained attack behavior tracing through multimodal collaborative analysis between an undirected anomaly flow graph and a directed alarm graph. Furthermore, to reduce reliance on expert knowledge and improve detection of unknown attacks, this method innovatively employs a non-causal reasoning method for attack chain analysis. This method ensures causal correlation between alarm types and minimizes reliance on expert knowledge, attack labeling, and simulation.
[0097] like Figure 4 One embodiment of the present application provides a device for tracing and blocking a multimodal graph attention attack on a power system, the device comprising: The data acquisition module 1100 is used to obtain alarm data and flow data of the power system in response to an attack blocking request of the power system; The abnormal flow graph construction module 1200 is used to filter out abnormal flow data based on the matching of flow data and alarm data, and to construct an undirected abnormal flow graph based on the abnormal flow data; wherein the nodes in the undirected abnormal flow graph are abnormal flow data, and the edges are the source node information and the destination node information in the corresponding alarm data; The attack traffic screening module 1300 is used to aggregate nodes in the undirected abnormal flow graph based on the graph attention mechanism to obtain an aggregated result, and cluster the aggregated result to screen out the real attack traffic data in the abnormal traffic data; The alarm graph generation module 1400 is configured to generate a directed alarm graph based on the alarm data corresponding to the real attack traffic data; wherein the nodes in the directed alarm graph are the IP addresses of the alarm data, and the edges in the directed alarm graph are directed edges from the source IP address to the destination IP address, and the attributes of the edges include the corresponding alarm type; The attack tracing module 1500 is used to traverse all nodes in the directed alarm graph, filter out all nodes with in-degree 0 as the starting point of the initial attack chain, and generate all initial attack chains based on the starting point and directed edges; and is used to traverse each initial attack chain and, if there is a negative causal correlation between the alarm types on the edges of the initial attack chain, prune the initial attack chain to obtain at least one final attack chain corresponding to the initial attack chain. If there is no negative causal correlation between the alarm types on the edges of the initial attack chain, the initial attack chain is used as a final attack chain.
[0098] It should be noted that the embodiment of the power system multimodal graph attention attack tracing and blocking device and the above-mentioned power system multimodal graph attention attack tracing and blocking method embodiment are based on the same inventive concept. Therefore, the relevant content of the above-mentioned power system multimodal graph attention attack tracing and blocking method embodiment is also applicable to the embodiment of the power system multimodal graph attention attack tracing and blocking device, and will not be repeated here.
[0099] This system constructs a complete process of matching, correlation, attack chain analysis, and attack blocking. First, compared to existing techniques that use a single data modality analysis paradigm, this method utilizes multimodal collaborative matching of power system alarm data and flow data to filter out abnormal flow data. Then, based on aggregation and clustering mechanisms, an undirected anomaly flow graph is used to filter out the actual attack flow data within the abnormal flow data. A directed alarm graph is then constructed based on the actual attack flow data, and an initial attack chain is generated based on the directed alarm graph, enabling fine-grained correlation and traceability of multi-step attack behaviors. A non-causal reasoning method is then proposed to prune negative causal relationships between types in the initial attack chain, resulting in a final attack chain. Finally, attack blocking is performed based on all final attack chains, improving the security of the power system. Through multimodal collaborative analysis between the undirected anomaly flow graph and the directed alarm graph, this system extracts the actual attack flow from redundant alarms, accurately constructs the attack propagation path, and achieves fine-grained attack behavior traceability, solving the traceability problem of multi-stage covert attacks. At the same time, in order to reduce dependence on expert knowledge and improve the ability to detect unknown attacks, this method innovatively adopts non-causal reasoning methods to analyze attack chains, eliminates false associations through dynamic pruning strategies, ensures the causal correlation of alarm types, and minimizes dependence on expert knowledge, attack markers, and simulation work, thereby improving the reliability of attack blocking and ensuring the safe operation of the power system.
[0100] Reference Figure 5 , an embodiment of the present application further provides an electronic device, the electronic device comprising: at least one memory; at least one processor; at least one program; The program is stored in the memory, and the processor executes at least one program to implement the above-mentioned power system multimodal graph attention attack tracing and blocking method implemented in the present disclosure.
[0101] The electronic device may be any intelligent terminal including a mobile phone, a tablet computer, a personal digital assistant (PDA), a car computer, etc.
[0102] The electronic device according to the embodiment of the present application is described in detail below.
[0103] The processor 1600 may be implemented as a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is configured to execute relevant programs to implement the technical solutions provided in the embodiments of the present application. The memory 1700 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 1700 can store function devices and other applications. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the program code is stored in the memory 1700 and is called by the processor 1600 to execute the power system multimodal graph attention attack tracing and blocking method of the embodiment of the present application.
[0104] Input / output interface 1800, used for information input and output; Communication interface 1900, used to implement communication interaction between this device and other devices, which can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WiFi, Bluetooth, etc.); Bus 2000 , which transmits information between various components of the device (e.g., processor 1600 , memory 1700 , input / output interface 1800 , and communication interface 1900 ); The processor 1600 , the memory 1700 , the input / output interface 1800 , and the communication interface 1900 are connected to each other in communication within the device via the bus 2000 .
[0105] An embodiment of the present application also provides a storage medium, which is a computer-readable storage medium. The computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to enable a computer to execute the above-mentioned power system multimodal graph attention attack tracing and blocking method.
[0106] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory may optionally include a memory remotely arranged relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0107] The embodiments described in this application are intended to more clearly illustrate the technical solutions of the embodiments of this application and do not constitute a limitation on the technical solutions provided by the embodiments of this application. Those skilled in the art will appreciate that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.
[0108] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than shown in the figures, or a combination of certain steps, or different steps.
[0109] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, i.e., they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of this embodiment.
[0110] Those skilled in the art will appreciate that all or some of the steps, devices, and functional modules / units in the methods disclosed above may be implemented as software, firmware, hardware, or appropriate combinations thereof.
[0111] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the numbers used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, device, product or equipment that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or equipment.
[0112] It should be understood that in this application, "at least one (item)" means one or more, and "plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.
[0113] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0114] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0115] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0116] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes multiple instructions for enabling an electronic device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes various media that can store programs, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0117] The above is a specific description of the preferred implementation of the embodiments of the present application, but the embodiments of the present application are not limited to the above-mentioned implementation methods. Technical personnel familiar with the art can also make various equivalent modifications or substitutions without violating the spirit of the embodiments of the present application. These equivalent modifications or substitutions are all included in the scope defined by the claims of the embodiments of the present application.
Claims
1. A method for tracing and blocking the multimodal graph attention attack in a power system, characterized in that: The method comprises: Responding to an attack blocking request of the power system, obtaining alarm data and flow data of the power system; Abnormal traffic data is filtered out based on the matching of the traffic data and the alarm data, and an undirected abnormal flow graph is constructed based on the abnormal traffic data; wherein the nodes in the undirected abnormal flow graph are the abnormal traffic data, and the edges are the source node information and the destination node information corresponding to the alarm data, the source node information includes a source IP address and a source port number, and the destination node information includes a destination IP address and a destination port number; Aggregating nodes in the undirected abnormal flow graph based on a graph attention mechanism to obtain an aggregation result, and clustering the aggregation result to filter out real attack traffic data from the abnormal traffic data; Generate a directed alarm graph based on the alarm data corresponding to the real attack traffic data; wherein the nodes in the directed alarm graph are IP addresses of the alarm data, the edges in the directed alarm graph are directed edges from the source IP address to the destination IP address, and the attributes of the edges include corresponding alarm types; Traversing all nodes in the directed alarm graph, screening out all nodes with an in-degree of 0 as starting points of the initial attack chain, and generating all initial attack chains based on the starting points and the directed edges; Each of the initial attack chains is traversed, and when there is a negative causal correlation between the alarm types on the edges of the initial attack chain, the initial attack chain is pruned to obtain at least one final attack chain corresponding to the initial attack chain. When there is no negative causal correlation between the alarm types on the edges of the initial attack chain, the initial attack chain is used as a final attack chain.
2. The method for tracing and blocking the multimodal graph attention attack in a power system according to claim 1 is characterized in that: The filtering out abnormal traffic data based on the matching of the traffic data and the alarm data includes: Obtaining an initial attribute value of the alarm data; A tuple value is extracted from the initial attribute value, and the tuple value is matched with the traffic data to filter out abnormal traffic data.
3. The method for tracing and blocking the multimodal graph attention attack in a power system according to claim 2 is characterized in that: After filtering out abnormal traffic data based on matching of the traffic data and the alarm data, the method further includes: In the case that there are at least two tuple values corresponding to the alarm data that match the same traffic data and the alarm types are the same, the at least two alarm data are merged into one alarm data according to a time sequence coverage strategy.
4. The method for tracing and blocking the multimodal graph attention attack in a power system according to claim 1 is characterized in that: The constructing of an undirected abnormal flow graph based on the abnormal traffic data includes: Constructing a bipartite graph based on the abnormal traffic data; the nodes in the bipartite graph are the source node information and the destination node information in the alarm data, and the edges are the abnormal traffic data; The undirected abnormal flow graph is constructed by using the union of the source node information and the destination node information of the bipartite graph as the edge of the undirected abnormal flow graph and the edges of the bipartite graph as the nodes of the undirected abnormal flow graph.
5. The method for tracing and blocking the multimodal graph attention attack on a power system according to claim 4 is characterized in that: The generating a directed alarm graph based on the alarm data corresponding to the real attack traffic data includes: Determine the IP address of the alarm data, the alarm type of the alarm data, and the start and end timestamps of the alarm data; In the case where the destination IP address of the first alarm data of any two alarm data is the same as the source IP address of the second alarm data, and the end timestamp of the first alarm data is earlier than the start timestamp of the second alarm data, establishing an association relationship between the first alarm data and the second alarm data; A directed alarm graph is constructed based on the IP addresses of the alarm data, the alarm types of the alarm data, and the association relationship between any two alarm data.
6. The method for tracing and blocking the multimodal graph attention attack in a power system according to claim 5 is characterized in that: The aggregating nodes in the undirected abnormal flow graph based on the graph attention mechanism includes: A graph attention neural network is used to aggregate the nodes in the undirected abnormal flow graph; wherein the first The aggregation process of layer attention includes: ; ; ; in, is the aggregation depth of the graph attention neural network, Central node The set of neighbor nodes of is the neighbor node, To change the flow characteristics from Layer aggregation to the The learnable parameters of the layer, and Respectively Neighbor nodes in a layer With the central node Features, For the Neighbor nodes in a layer Features, is the ReLU activation function, For the Neighbor nodes in the layer With the central node The attention score between For the The trainable weight matrix of the layer, For the The learnable parameters of the layer, For splicing operations, is the transpose, For the Neighbor nodes in a layer Features, is the natural exponential function, is the activation function.
7. The method for tracing and blocking the multimodal graph attention attack in a power system according to claim 1 is characterized in that: Clustering the aggregation results to filter out real attack traffic data from the abnormal traffic data includes: Clustering the aggregation results based on K-means to divide the abnormal traffic data into real attack traffic data and normal traffic data; After dividing the abnormal traffic data into real attack traffic data and normal traffic data, the method further includes: In the power system, the alarm data corresponding to the normal flow data is deleted.
8. A device for tracing and blocking the multimodal graph attention attack in a power system, characterized in that: The device comprises: A data acquisition module, configured to obtain alarm data and flow data of the power system in response to an attack blocking request of the power system; An abnormal flow graph construction module is used to filter out abnormal flow data based on the matching of the flow data and the alarm data, and to construct an undirected abnormal flow graph based on the abnormal flow data; wherein the nodes in the undirected abnormal flow graph are the abnormal flow data, and the edges are the source node information and destination node information corresponding to the alarm data, the source node information includes a source IP address and a source port number, and the destination node information includes a destination IP address and a destination port number; An attack traffic screening module is used to aggregate nodes in the undirected abnormal flow graph based on a graph attention mechanism to obtain an aggregated result, and cluster the aggregated result to screen out real attack traffic data from the abnormal traffic data; an alarm graph generation module, configured to generate a directed alarm graph based on the alarm data corresponding to the real attack traffic data; wherein the nodes in the directed alarm graph are IP addresses of the alarm data, the edges in the directed alarm graph are directed edges from the source IP address to the destination IP address, and the attributes of the edges include the corresponding alarm type; The attack tracing module is used to traverse all nodes in the directed alarm graph, screen out all nodes with an in-degree of 0 as the starting point of the initial attack chain, and generate all initial attack chains based on the starting point and the directed edges; and is used to traverse each of the initial attack chains and, if there is a negative causal correlation between the alarm types on the edges of the initial attack chain, prune the initial attack chain to obtain at least one final attack chain corresponding to the initial attack chain; if there is no negative causal correlation between the alarm types on the edges of the initial attack chain, use the initial attack chain as a final attack chain.
9. An electronic device, characterized in that: It includes at least one controller and a memory for communicating with the controller; the memory stores instructions that can be executed by the at least one controller, and the instructions are executed by the at least one controller to enable the at least one controller to execute the power system multimodal graph attention attack tracing and blocking method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to enable a computer to execute the power system multimodal graph attention attack tracing and blocking method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Method, device and system for determining safety event of electric power monitoring system
CN110213077A
Attack tracing method and system
CN117155665A
Attack detection method and device, electronic equipment and storage medium
CN117375998A
Systems and methods for determining causal relationships among network alarms
US20250233792A1
Graph neural network-based method, system, and apparatus for detecting network attack
WO2021258479A1
Cited By
Method for evaluating landslide-debris flow disaster chain based on graph neural network
CN121168286A
A landslide-debris flow disaster chain evaluation method based on a graph neural network
CN121168286B