A power system multi-modal graph attention attack tracing blocking method and device
By employing a multimodal graph attention attack tracing and blocking method, and utilizing the collaborative analysis of undirected abnormal flow graphs and directed alarm graphs, combined with graph attention mechanisms and non-causal reasoning, the problem of tracing the source of multi-step attacks in power systems is solved. This enables fine-grained attack behavior tracing and blocking, thereby improving the security and accuracy of power systems.
Patent Information
- Application Number
- CN202511141045.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-15
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2045-08-15
AI Technical Summary
Existing methods for tracing network attacks in power systems are insufficient to effectively identify multi-step attacks. Traditional defense systems are unable to cope with covert, multi-stage attacks and rely on expert knowledge and simulations, leading to false alarms and redundant alerts that overwhelm the real threats.
A multimodal graph attention attack tracing and blocking method is adopted. Through the collaborative analysis of undirected abnormal flow graphs and directed alarm graphs, combined with graph attention mechanism and non-causal reasoning method, real attack traffic data is screened out and attack chains are constructed. Negative causal associations are pruned to achieve fine-grained tracing.
It improves the security of the power system, reduces reliance on expert knowledge, enhances the reliability and accuracy of attack blocking, and can effectively identify the propagation path of multi-step attacks.
Smart Images

Figure CN120750633B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present application relate to the technical field of network attack blocking, and in particular to a power system multi-modal graph attention attack traceability blocking method and device. BACKGROUND
[0002] With the wide application of big data, cloud computing and Internet of Things technology in the power system, the power system is facing the vulnerabilities and risks of the Internet, which has brought challenges to the original security protection system of the power system. At present, attack mitigation / blocking technology means of the power system is mainly used to detect, intercept and prevent malicious behavior, so as to reduce its harm to the power system, business or users.
[0003] Reliable tracing of attack sources is the key to performing attack blocking. At present, intrusion detection systems based on deep packet inspection and rule matching are widely deployed in power monitoring systems. However, the alarm information generated by such systems is strongly isolated and highly redundant, which makes it difficult to depict the global process of the attack as the real threat is easily submerged by a large number of false positives and redundant alarms. At the same time, network attack patterns have evolved from single penetration to multi-stage attacks with strong concealment, which further weakens the detection capability of traditional defense methods, and the traditional security protection system is difficult to cope with the threat of concealed multi-stage attacks. Therefore, how to accurately identify major security incidents caused by multi-step attacks and reliably trace the attack sources using these alarms has become a major problem in the power system. SUMMARY
[0004] The following is a summary of the subject matter of the detailed description herein. This summary is not intended to limit the scope of the claims.
[0005] The main purpose of the embodiments of the present disclosure is to propose a power system multi-modal graph attention attack traceability blocking method and device, which realizes fine-grained attack behavior traceability through multi-modal collaborative analysis between the undirected abnormal flow graph and the directed alarm graph, and uses a non-causal reasoning method for attack chain analysis, which can guarantee the causal correlation of the alarm type and can minimize the dependence on expert knowledge, attack markers and simulation work.
[0006] The first aspect of the embodiments of the present application proposes a power system multi-modal graph attention attack traceability blocking method, which comprises:
[0007] In response to an attack blocking request of the power system, alarm data and traffic data of the power system are acquired;
[0008] Filtering out abnormal traffic data based on the matching of the traffic data and the alarm data, and constructing an undirected abnormal flow graph based on the abnormal traffic data; wherein the nodes in the undirected abnormal flow graph are the abnormal traffic data, and the edges are corresponding to the source node information and the destination node information in the alarm data, the source node information includes the source IP address and the source port number, and the destination node information includes the destination IP address and the destination port number;
[0009] Aggregating the nodes in the undirected abnormal flow graph based on a graph attention mechanism to obtain an aggregation result, and clustering the aggregation result to filter out real attack traffic data in the abnormal traffic data;
[0010] Generating a directed alarm graph based on the alarm data corresponding to the real attack traffic data; wherein the nodes in the directed alarm graph are the IP addresses of the alarm data, the edges in the directed alarm graph are directed edges from the source IP address to the destination IP address, and the attributes of the edges include the corresponding alarm types;
[0011] Traversing all nodes in the directed alarm graph, filtering out all nodes with an in-degree of 0 as starting points of initial attack chains, and generating all initial attack chains based on the starting points and the directed edges;
[0012] Traversing each of the initial attack chains, and pruning the initial attack chains in the case that there is a negative causal relationship between the alarm types on the edges of the initial attack chains, to obtain at least one final attack chain corresponding to the initial attack chains, and taking the initial attack chains as a final attack chain in the case that there is no negative causal relationship between the alarm types on the edges of the initial attack chains.
[0013] The power system multi-modal graph attention attack traceability blocking method provided in the embodiment has at least the following advantages:
[0014] The method constructs a complete process of matching, association, attack chain analysis and attack blocking. First, compared with the single data modal analysis paradigm of the prior art, the method uses the multi-modal collaborative matching of the alarm data and the flow data of the power system to filter out abnormal flow data. Then, based on the aggregation and clustering mechanism, the real attack flow data in the abnormal flow data is filtered out through the undirected abnormal flow graph, wherein the attention mechanism is used during aggregation to adaptively assign weights to different neighbors of flow information, thereby improving the accuracy of filtering out real attack flow data in abnormal flow data. Then, a directed alarm graph for alarm association is constructed according to the real attack flow data, and an initial attack chain is generated based on the directed alarm graph to realize the association and tracing of fine-grained multi-step attack behavior. Then, a non-causal reasoning method is proposed to prune the negative causal association between types in the initial attack chain to obtain the final attack chain. Finally, attack blocking is performed based on all the final attack chains to improve the security of the power system. Through the multi-modal collaborative analysis between the undirected abnormal flow graph and the directed alarm graph, the method realizes fine-grained attack behavior tracing. At the same time, the method uses a non-causal reasoning method for attack chain analysis, which can ensure the causal association of alarm types and also minimize the dependence on expert knowledge, attack markers and simulation work.
[0015] In some embodiments, the matching and filtering of abnormal flow data based on the flow data and the alarm data comprises:
[0016] Obtaining an initial attribute value of the alarm data;
[0017] Extracting a multi-tuple value from the initial attribute value, and matching the multi-tuple value with the flow data to filter out abnormal flow data.
[0018] In some embodiments, after the matching and filtering of abnormal flow data based on the flow data and the alarm data, the method further comprises:
[0019] In the case where there are at least two multi-tuple values corresponding to the alarm data matching the same flow data and the alarm types are the same, the at least two alarm data are merged into one alarm data according to a time sequence coverage strategy.
[0020] In some embodiments, the construction of the undirected abnormal flow graph based on the abnormal flow data comprises:
[0021] Constructing a bipartite graph based on the abnormal flow data; the nodes in the bipartite graph are source node information and destination node information in the alarm data, and the edges are abnormal flow data;
[0022] The undirected abnormal flow graph is constructed by using the union of the source node information and the destination node information of the bipartite graph as the edge of the undirected abnormal flow graph, and using the edge of the bipartite graph as the node of the undirected abnormal flow graph.
[0023] In some implementations, generating a directed alarm graph based on the alarm data corresponding to the actual attack traffic data includes:
[0024] Determine the IP address of the alarm data, the alarm type of the alarm data, and the start and end timestamps of the alarm data;
[0025] If the destination IP address of the first alarm data is the same as the source IP address of the second alarm data, and the end timestamp of the first alarm data is earlier than the start timestamp of the second alarm data, then establish the association between the first alarm data and the second alarm data.
[0026] A directed alarm graph is constructed based on the IP address of the alarm data, the alarm type of the alarm data, and the correlation between any two alarm data.
[0027] In some implementations, the aggregation of nodes in the undirected anomalous flow graph based on the graph attention mechanism includes:
[0028] A graph attention neural network is used to aggregate the nodes in the undirected abnormal flow graph; wherein, the first node in the graph attention neural network is... The process of focusing attention at different levels includes:
[0029] ;
[0030] ;
[0031] ;
[0032] in, To determine the aggregation depth of the graph attention neural network, As the central node The set of neighboring nodes, For neighboring nodes, To transfer traffic characteristics from the first Layer aggregation to the first Learnable parameters of the layer and The first Neighbor nodes in the layer With the central node Features For the first Neighbor nodes in the layer characteristics of the neighbor node in the i-th layer, ReLU activation function, is a trainable weight matrix of the i-th layer, attention score between the neighbor node and the center node , the i-th layer, is a trainable weight matrix of the i-th layer, is a learnable parameter of the i-th layer, is a concatenation operation, is a transpose, is an activation function. is an activation function. characteristics of the neighbor node in the i-th layer, characteristics of the neighbor node in the i-th layer, is an exponential function, is an activation function. is an activation function.
[0033] In some embodiments, the clustering the aggregation result to filter out the real attack traffic data in the abnormal traffic data comprises:
[0034] clustering the aggregation result based on K-means to divide the abnormal traffic data into real attack traffic data and normal traffic data;
[0035] After dividing the abnormal traffic data into real attack traffic data and normal traffic data, the method further comprises:
[0036] deleting the alarm data corresponding to the normal traffic data in the power system.
[0037] A second aspect of the embodiments of the present application proposes a power system multi-modal graph attention attack traceability blocking device, the device comprises:
[0038] a data acquisition module, configured to acquire alarm data and traffic data of a power system in response to an attack blocking request of the power system;
[0039] an abnormal flow graph construction module, configured to filter out abnormal traffic data based on matching of the traffic data and the alarm data, and construct an undirected abnormal flow graph based on the abnormal traffic data; wherein nodes in the undirected abnormal flow graph are the abnormal traffic data, and edges correspond to source node information and destination node information in the alarm data, the source node information includes a source IP address and a source port number, and the destination node information includes a destination IP address and a destination port number;
[0040] an attack traffic screening module, configured to aggregate nodes in the undirected abnormal flow graph based on a graph attention mechanism to obtain an aggregation result, and cluster the aggregation result to filter out real attack traffic data in the abnormal traffic data;
[0041] The alarm graph generation module is configured to generate a directed alarm graph based on alarm data corresponding to the real attack traffic data; wherein a node in the directed alarm graph is an IP address of the alarm data, and an edge in the directed alarm graph is a directed edge from a source IP address to a destination IP address, and an attribute of the edge includes a corresponding alarm type;
[0042] The attack tracing module is configured to traverse all nodes in the directed alarm graph, filter out all nodes with an in-degree of 0 as starting points of initial attack chains, and generate all initial attack chains based on the starting points and the directed edges; and traverse each of the initial attack chains, and in a case where there is a negative causal relationship between alarm types on edges of the initial attack chain, prune the initial attack chain to obtain at least one final attack chain corresponding to the initial attack chain, and in a case where there is no negative causal relationship between alarm types on edges of the initial attack chain, take the initial attack chain as a final attack chain.
[0043] A third aspect of the embodiments of the present application provides an electronic device, comprising at least one controller and a memory connected in communication with the controller; the memory stores instructions capable of being executed by the at least one controller, and the instructions are executed by the at least one controller to enable the at least one controller to perform the power system multi-modal graph attention attack tracing and blocking method described above.
[0044] A fourth aspect of the embodiments of the present application provides a computer readable storage medium, and the computer readable storage medium stores a computer program, and the computer program is executed to implement the power system multi-modal graph attention attack tracing and blocking method described above.
[0045] Additional aspects and advantages of the present application will be in part apparent and in part pointed out hereinafter. BRIEF DESCRIPTION OF DRAWINGS
[0046] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments or related technical descriptions. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0047] Figure 1 is a flowchart of an embodiment of the power system multi-modal graph attention attack tracing and blocking method provided by the present application;
[0048] Figure 2is a block diagram of an embodiment of a power system multi-modal graph attention attack traceability blocking method provided by the present application;
[0049] Figure 3 is a schematic diagram of an embodiment of an execution flow of an attack traceability module provided by the present application;
[0050] Figure 4 is a structural schematic diagram of an embodiment of a power system multi-modal graph attention attack traceability blocking device provided by the present application;
[0051] Figure 5 is a structural schematic diagram of an electronic device provided by the present application. DETAILED DESCRIPTION
[0052] In order to make the purpose, technical solutions and advantages of the present application clearer and more apparent, the present application will be further described in detail below in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application.
[0053] In the description of the present application, if the first, second, etc. are described, it is only for the purpose of distinguishing technical features, and should not be understood as indicating or implying relative importance or implicitly indicating the number of indicated technical features or the sequence of indicated technical features.
[0054] In the description of the present application, it should be understood that the position description, such as the above, the below, etc. indicates the position or location relationship based on the position or location relationship shown in the drawings, which is only for the convenience of describing the present application and simplifying the description, and does not indicate or imply that the indicated device or element must have a specific position, be constructed in a specific position and function, and therefore should not be understood as a limitation of the present application.
[0055] Before introducing the embodiments, the background of the present application will be introduced first:
[0056] In recent years, multi-step attack identification and traceability methods mainly revolve around three types of paradigms, including:
[0057] 1) Similarity-based correlation analysis; Similarity-based alarm correlation analysis method realizes the clustering and correlation of alarm events by quantitatively analyzing the feature similarity between network security alarms. The core of this method is to design an effective similarity measurement function. Some researchers only consider the comparison of a single attribute, while most focus on the combination of multiple attributes, such as port number, timestamp, source IP address, and destination IP address. It is worth noting that in the field, alarm events usually represent specific instances (instances), for example, an alarm event is: at a certain time, a suspected DDOS attack behavior is initiated from the first IP address to the second IP address, and the system generates an alarm record. Among them, DDOS attack is the alarm type, and similarly, there are other alarm types, such as abnormal access, which will not be described here.
[0058] 2) Attack sequence-based method; Attack sequence-based pattern matching method relies on a pre-defined attack knowledge base to identify complex attack scenarios by analyzing the time sequence characteristics of security events. This method usually needs to build an attack pattern library, and the MITRE ATT&CK framework provides a tactical chain model that has become an industry standard.
[0059] 3) Machine learning-based method; Machine learning-based methods represent the current technical frontier, with convolutional neural networks and graph convolutional networks performing outstandingly in this field. By training detection models with attack samples, attack features can be automatically extracted and new attack variants can be identified.
[0060] Although these methods have achieved certain success, they still have certain limitations. Existing researches mostly use single data modal analysis paradigm, relying only on traffic features can capture abnormal behavior, but there is a problem of missing attack chain causality; relying only on alarm data in alarm logs can build attack time sequence association, but it faces the dual challenges of strong dependence on expert knowledge and high sensitivity to alarm noise. These limitations make it difficult to meet the actual needs of power systems that require extremely high reliability.
[0061] As Figures 1 to 3 , one embodiment of the present application provides a power system multi-modal graph attention attack traceability blocking method to solve the above technical defects. The method includes the following steps S110 to S160:
[0062] Step S110, in response to the attack blocking request of the power system, obtaining the alarm data and traffic data of the power system.
[0063] After the user initiates an attack blocking request to the power system, the alarm events in the alarm log are reconstructed, and the structured alarm data is extracted to facilitate subsequent matching, merging, correlation analysis, and attack chain extraction operations. The following is the ontology description of the reconstructed alarm data:
[0064] (1) ;
[0065] represents the attributes of the alarm, including the start timestamp, end timestamp, type, source IP, destination IP, source port, target port, transmission protocol;
[0066] represents the relationship between the alarm data.
[0067] In this step, the traffic data can be collected based on "traffic collection device", "sensor", "intrusion detection device" and other devices.
[0068] After collecting the alarm data and traffic data in this embodiment, the abnormal traffic data is found by using the cooperative matching between the alarm data and the traffic data, which will be described in detail later.
[0069] Step S120, based on the traffic data and the alarm data matching, the abnormal traffic data is screened out, and based on the abnormal traffic data, the undirected abnormal flow graph is constructed.
[0070] Among them, the node in the undirected abnormal flow graph is the abnormal traffic data, and the edge is the source node information and the destination node information in the corresponding alarm data. The source node information includes the source IP address and the source port number, and the destination node information includes the destination IP address and the destination port number.
[0071] In this step, because the alarm data only contains part of the attack information, it cannot completely describe the attack process, and has certain limitations for the separation of false alarm data. Therefore, in order to better process the false alarm data, the corresponding abnormal traffic is used for analysis here, which can more comprehensively capture the details of the attack.
[0072] Therefore, the alarm data and traffic data extracted in step S110 are matched, and then the abnormal traffic data is screened out. Based on the above embodiment, the matching mode includes the following steps S210 to S220:
[0073] Step S210, obtaining the initial attribute value of the alarm data.
[0074] The initial attribute value is as shown in the above embodiment.
[0075] Step S220, extracting the multi-tuple value from the initial attribute value, and matching the traffic data based on the multi-tuple value, and screening out the abnormal traffic data.
[0076] In step S220, the network traffic can be divided into flows according to the source IP address, the source port, the destination IP address, the destination port and the transmission protocol. When an intrusion detection system (IDS) detects an attack in a data packet and generates an alarm data, the 5-tuple information extracted from the alarm data is matched with the corresponding flow and the alarm data is extracted. 5-tuple information extracted from the alarm data
[0077] In some embodiments, the method further includes the following steps (merging of redundant alarms):
[0078] In the case where the multi-tuple values corresponding to at least two alarm data match the same traffic data and the alarm types are the same, the at least two alarm data are merged into one alarm data according to a time sequence coverage strategy.
[0079] In this embodiment, for alarms matched to the same flow, it is further determined whether the alarm types are the same. If the alarm types are the same, the alarm data is merged to reduce redundant alarms.
[0080] The merging rule adopts a time sequence coverage strategy, that is, the alarm with the earliest starting time stamp is retained, and the ending time stamp thereof is updated to the latest time stamp of all the merged alarms, so as to compress the redundant alarms in the time and space dimensions and improve the compactness of the alarm data.
[0081] For example, when the multi-tuple attributes corresponding to multiple alarm data match the same traffic data, it indicates that the traffic data may trigger multiple alarms.
[0082] The step S120 of constructing an undirected abnormal flow graph based on the abnormal traffic data includes the following steps S310 to S320:
[0083] In step S310, a bipartite graph is constructed based on the abnormal traffic data. The nodes in the bipartite graph are the source node information and the destination node information in the alarm data, and the edges are the abnormal traffic data. The source node information includes the source IP address and the source port number, and the destination node information includes the destination IP address and the destination port number.
[0084] In step S320, the union of the source node information and the destination node information of the bipartite graph is taken as the edge of the undirected abnormal flow graph, and the edge of the bipartite graph is taken as the node of the undirected abnormal flow graph, to construct the undirected abnormal flow graph.
[0085] The undirected abnormal flow graph refers to a graph structure formed by converting the nodes and edges of the bipartite graph. The conversion process makes the abnormal traffic data the core analysis object of the graph structure, which facilitates subsequent aggregation of node features through a graph attention mechanism.
[0086] In designing a network traffic analysis model based on a graph neural network, the core modeling link lies in the identification and definition of node elements in the network topology structure. The traditional method tends to select IP addresses and port numbers as nodes to achieve effective classification of network traffic. This method can uniquely identify the endpoint information of network data flow and accurately depict the communication characteristics of a specific application service, thereby helping to build a comprehensive data flow feature description and its context environment, providing a basis for the topology description of network traffic. However, this strategy has certain limitations when it comes to expressing the relevant information of the edge (i.e., actual traffic), especially in cases where it is necessary to distinguish false positives based on traffic information.
[0087] To overcome these limitations and fully utilize the value of traffic information, a conversion mechanism from a bipartite graph to a line graph is proposed here to strengthen the expressiveness of edge information. Specifically, the mechanism includes two key stages: first, in step S310, a special bipartite graph is constructed: ; wherein, S represents a set of source nodes composed of source IP addresses and source port numbers; D represents a set of destination nodes composed of destination IP addresses and destination port numbers; and covers all edges connecting the two types of nodes, which represent actual transmission traffic. Then, in step S320, the bipartite graph is converted into a line graph, i.e., an undirected anomaly flow graph: ; wherein, . After conversion, the nodes of the anomaly flow graph correspond to the edges of the original bipartite graph, and the edges of the anomaly flow graph correspond to the nodes of the original bipartite graph.
[0088] Through the two conversions from a bipartite graph to an undirected anomaly flow graph, the network traffic classification task is transformed from an edge classification problem to a node classification problem, decoupling anomaly traffic data from network node information, allowing the aggregation analysis of anomaly traffic to focus more on the characteristics of the traffic itself, while preserving the topological association of source and destination nodes. This hierarchical construction method can effectively reduce the interference of isolated nodes and improve the accuracy of attack traffic identification.
[0089] In step S130, the nodes in the undirected anomaly flow graph are aggregated based on a graph attention mechanism to obtain an aggregation result, and the aggregation result is clustered to filter out real attack traffic data from the anomaly traffic data.
[0090] In this step, the core goal is to effectively eliminate the redundancies and false alarms in the alert data extracted in step S110 using graph aggregation and clustering analysis techniques based on the identified anomaly traffic data, generating high-confidence security alert data to lay the foundation for subsequent attack chain analysis.
[0091] Existing graph neural networks, such as GraphSAGE (Graph Sample and Aggregate E) and E-GraphSAGE (Enhanced Graph Sample and Aggregate E), can effectively process graph information, but they typically use fixed weights to aggregate neighbor node information. This static aggregation method has significant limitations in network traffic analysis: in real-world network environments, traffic patterns are dynamically heterogeneous, and the contribution of different neighbor traffic nodes to determining whether a central node (representing the traffic / alarm to be analyzed) constitutes a real attack varies significantly. Fixed weights cannot capture this dynamically changing importance of neighbors.
[0092] To address the aforementioned issues, this embodiment introduces an attention mechanism. Its core idea is to allow the model to adaptively learn to assign weights to different neighbors of each central node. Neighbors with higher importance receive greater weight during aggregation, and vice versa. This enables the model to dynamically adjust the aggregation process based on the specific characteristics of neighboring nodes and their relationship with the central node, focusing on the most relevant information.
[0093] For each node in the undirected abnormal flow graph , its first The process of focusing attention at each layer can be described as follows:
[0094] (2);
[0095] (3);
[0096] (4);
[0097] in, To determine the aggregation depth of the graph attention neural network, As the central node The set of neighboring nodes, For neighboring nodes, To transfer traffic characteristics from the first Layer aggregation to the first Learnable parameters of the layer and The first Neighbor nodes in the layer With the central node Features For the first Neighbor nodes in the layer Features It is the ReLU activation function. For the first Neighbor nodes in the layer attention scores between the center node , trainable weight matrix of the layer, learnable parameters of the layer, concatenation operation, transpose, feature of a neighbor node in the layer, natural exponential function, activation function. In a preferred embodiment, the value of = 2.
[0098] After the aggregation, the aggregated results are clustered to distinguish the real attack traffic from the normal traffic using the aggregator embeddings.
[0099] In some embodiments, since there is a higher possibility of neighbor relationship between real attack traffics in the undirected anomaly graph, the distance between the embedding representations of real attack traffics is closer. The K-means algorithm has a fast clustering speed and high execution efficiency, and is suitable for data based on distance distribution. Therefore, the K-means algorithm can be used for clustering, and the K value is manually set to 2 to distinguish the real attack traffic from the normal traffic. Then the alarm data corresponding to the normal traffic in the anomaly traffic data and the alarm data corresponding to the real attack traffic in the anomaly traffic data can be found, and the alarm data in the former part can be deleted, and the alarm data in the latter part can be used for subsequent processing.
[0100] In some embodiments, the clustering of the aggregated results in step S130 to screen out real attack traffic data in the anomaly traffic data includes:
[0101] Step S1310, clustering the aggregated results based on K-means to divide the anomaly traffic data into real attack traffic data and normal traffic data.
[0102] After dividing the anomaly traffic data into real attack traffic data and normal traffic data, the method further includes step S410:
[0103] Step S410, deleting the alarm data corresponding to the normal traffic data in the power system.
[0104] The anomaly traffic data classified as normal traffic will have its corresponding alarm data deleted, thereby deleting false alarms, improving the authenticity of the alarm data generated by the power system, and further improving the efficiency of attack blocking.
[0105] Step S140, generating a directed alarm graph based on the alarm data corresponding to the real attack traffic data. Among them, the node in the directed alarm graph is the IP address of the alarm data, the edge in the directed alarm graph is the directed edge from the source IP address to the destination IP address, and the attribute of the edge includes the corresponding alarm type.
[0106] In some embodiments, the alarm log can be regarded as a network connected by source IP addresses and target IP addresses. Therefore, IP hops can be used to further construct a directed alarm graph according to the relationship between the alarm data.
[0107] The alarm log can be regarded as a network structure composed of source IP addresses and target IP addresses. Based on this feature, the alarm data can be abstracted into a graph model to reveal its potential correlation and attack propagation path. To this end, it is necessary to first define and quantify the correlation between different alarm data. Specifically, consider the basic attributes contained in each alarm data, including source IP address, destination IP address, alarm start timestamp, alarm end timestamp, and alarm type.
[0108] If the alarm data The destination IP address is the same as the source IP address of another alarm data , it is considered that there may be potential attack jump behavior between them. This alarm association can be formally expressed as:
[0109] (5);
[0110] (6);
[0111] In addition, in order to ensure the time logic rationality of the alarm graph, exclude invalid associations with time in reverse order, and enhance the credibility of the attack path, only when the end timestamp of is earlier than the start timestamp of , the alarm association exists, that is:
[0112] (7);
[0113] Therefore, only when formulas (6) and (7) are satisfied at the same time, the alarm association will be established between the corresponding alarm data.
[0114] On this basis, combined with the alarm IP address and the alarm type, the following directed alarm graph is constructed:
[0115] (8);
[0116] Among them, and These represent the set of nodes and the set of edges, respectively. Each node uniquely corresponds to an IP address, and each edge is a directed connection from a source IP address to a destination IP address. To further enhance the semantic expressiveness of the graph model, the attribute information of the edges includes the corresponding alarm type, which describes the type of attack behavior that occurred between two alarm data.
[0117] For example, consider two related alarm data sets, alarm data I and alarm data II, with alarm types I and II, respectively. Alarm data I has a source IP address of IP1 and a destination IP address of IP2, while alarm data II has a source IP address of IP2 and a destination IP address of IP3. The resulting alarm graph is IP1 ---> IP2 ---> IP3, where the IP1 ---> IP2 edge represents alarm type I, and the IP2 ---> IP3 edge represents alarm type II.
[0118] Step S150: Traverse all nodes in the directed alarm graph, select all nodes with an in-degree of 0 as the starting point of the initial attack chain, and generate all initial attack chains based on the starting point and the directed edges.
[0119] After the directed alarm graph is constructed, potential multi-stage attack chains need to be extracted from the graph, and the source of the attack needs to be traced.
[0120] In-degree refers to the number of edges in a directed graph that point to a particular vertex. This is important because in constructing a directed alarm graph... At that time, the temporal sequence of alarm data had already been taken into account in the directed alarm graph. In the directed alarm graph, there is a temporal sequence between interconnected nodes. In this process, obtaining the head node of the attack chain only requires considering one case: that the node is a node with an in-degree of 0 in the directed alarm graph. By traversing the directed alarm graph Filter out the set of nodes with an in-degree of 0 from all nodes. , as a candidate starting point for the attack chain.
[0121] Then, for each head node A depth-first search is used to traverse all reachable paths to generate an initial attack chain set. Formalizing each initial attack chain for:
[0122] (9);
[0123] in, to The path must satisfy the property of temporal increment.
[0124] Step S160: Traverse each initial attack chain, and if there is a negative causal relationship between the alarm types on the edge of the initial attack chain, prune the initial attack chain to obtain at least one final attack chain corresponding to the initial attack chain. If there is no negative causal relationship between the alarm types on the edge of the initial attack chain, treat the initial attack chain as a final attack chain.
[0125] In this step, due to the complexity of multi-step attacks, there is a causal relationship between each individual attack. Each previous attack lays the groundwork for the next, forming a sequential and logical attack chain. Therefore, to gain a deeper understanding of the attack process and improve the granularity and interpretability of security analysis, it is necessary to further refine the complete attack chain. For all attack chains, further refinement is needed, namely, breaking the chain at each attack step. This will help security personnel better analyze and trace the causes and consequences of each attack.
[0126] Currently, the concept of causal correlation has been widely used in the field of alarm correlation analysis. However, due to the lack of attack rules in power systems and the difficulty of scanning network vulnerabilities, these methods are difficult to apply directly. Furthermore, while using the concept of causal correlation to determine the relationship between attacks may have good traceability for known attack relationships, its generalization ability is not strong enough for unknown attacks.
[0127] Therefore, this embodiment designs a negative causal association method. The core idea is to eliminate unnecessary causal edges in the attack chain and retain causal paths with high confidence. Then, the negative causal association method is used to prune the attack chain, which not only ensures the causal correlation of alarm types, but also minimizes the dependence on expert knowledge, attack tags, and simulation work.
[0128] like Figure 2 The “initial attack chain” contains chains of “type I and type II” and “type I and type III”. There is a non-causal relationship between “type I and type III”. Therefore, pruning the chain “type I and type III” will result in the chain “type III”.
[0129] For example, the original initial attack chain is: IP1 ---> IP2 ---> IP3;
[0130] IP1 ---> IP2 represents alarm type I, IP2 ---> IP3 represents alarm type II. Since there is no causal relationship between the two alarms, the chain needs to be broken. The final attack chain after the chain is broken becomes:
[0131] Final attack chain I: IP1--->IP2, final attack chain II: IP2--->IP3;
[0132] For example, the original initial attack chain is: IP1--->IP2--->IP3--->IP4--->IP5;
[0133] IP1--->IP2 represents alarm type I, IP2--->IP3 represents alarm type II, IP3--->IP4 represents alarm type III, and IP4--->IP5 represents alarm type IV. Since there is no causal relationship between alarm type II and alarm type III, and there is no causal relationship between alarm type III and alarm type IV. Therefore, it is necessary to break the chain, and the final attack chain after breaking is:
[0134] Final attack chain I: IP1--->IP2--->IP3, final attack chain II: IP3--->IP4, final attack chain III: IP4--->IP5;
[0135] It should be noted that the judgment of the causal relationship between the types in the alarm data is a key task in network security event analysis, fault diagnosis and operation and maintenance management, including but not limited to:
[0136] 1) Time series-based analysis; such as time sequence: cause events usually occur before result events. Time interval analysis: calculate the time delay distribution pattern between alarms.
[0137] 2) Analysis based on topological relationship; such as network topological correlation, alarms generated by the same host / device, device alarms on the same network path, and associated alarms on the service call chain, etc.
[0138] 3) Analysis based on alarms, etc.
[0139] Non-causal relationship is the reverse concept of causal relationship, which will not be introduced here.
[0140] The pruning operation refers to identifying negative causal relationship types in the attack chain and eliminating them. It can be determined by time stamp conflict, logical contradiction, etc. to eliminate false path interference.
[0141] If the time sequence of the types of all edges in the attack chain is continuous and the behavior logic is self-consistent, it is not necessary to prune and directly output it as an effective attack chain. This processing flow effectively avoids the problem of attack chain rupture caused by false judgment by distinguishing between real attack paths and false alarms. It provides a reliable data basis for subsequent blocking strategies.
[0142] Finally, security personnel can perform corresponding attack blocking based on all the final attack chains screened out to ensure the network security of the power system. For example,Figure 2 , the security personnel can perform corresponding attack blocking on the chain "type I and type II" and the chain "type III".
[0143] The power system multi-modal graph attention attack trace blocking method provided by the embodiment at least has the following beneficial effects:
[0144] The method constructs a complete process of matching, association, attack chain analysis and attack blocking. First, compared with the single data modal analysis paradigm of the prior art, the method uses the multi-modal collaborative matching of the alarm data and the flow data of the power system to filter out abnormal flow data. Then, based on the aggregation and clustering mechanism, the real attack flow data in the abnormal flow data is filtered out through the undirected abnormal flow graph. Then, a directed alarm graph is constructed according to the real attack flow data to realize the association and trace of the multi-step attack behavior in a fine-grained manner. Then, a non-causal reasoning method is proposed to prune the negative causal association between the types in the initial attack chain, and the final attack chain is obtained. Finally, attack blocking is performed based on all the final attack chains, which improves the security of the power system. The method realizes the trace of the attack behavior in a fine-grained manner by multi-modal collaborative analysis between the undirected abnormal flow graph and the directed alarm graph, extracts real attack flow from redundant alarms, and accurately constructs the attack propagation path. The method solves the problem of trace of multi-stage hidden attacks. At the same time, in order to reduce the dependence on expert knowledge and improve the detection ability of unknown attacks, the method innovatively uses a non-causal reasoning method for attack chain analysis, eliminates false associations through a dynamic pruning strategy, ensures the causal association of alarm types, and maximizes the reduction of dependence on expert knowledge, attack markers and simulation work, improves the reliability of attack blocking, and ensures the safe operation of the power system.
[0145] As Figures 2 to 3 The embodiment provides a power system multi-modal graph attention attack trace blocking method. The method is applied to a power system multi-modal graph attention attack trace blocking system. The system framework at least includes:
[0146] I. Alarm optimization module, the alarm optimization module constructs an abnormal flow graph through an alarm-abnormal flow matching mechanism, and effectively eliminates redundancy and false alarms in original alarms based on graph aggregation and clustering analysis technology to generate high-confidence security alarms.
[0147] The redundant alarms and false alarms are combined and deleted to obtain high-quality alarms, which help to accurately trace the attacks. In order to better reconstruct the attack scene and extract the attack path, an undirected abnormal flow graph is constructed using abnormal flow data Then an attack graph aggregation mechanism is designed, which can capture the information of the neighbor nodes of the target node by aggregating the information of the neighbor nodes, so as to better understand the characteristics of the abnormal samples, analyze the captured abnormal flows, and remove false positives. The specific introduction is as follows:
[0148] (1) Alarm preprocessing;
[0149] In order to facilitate subsequent matching, merging, association, attack chain extraction and other analysis work, it is necessary to reconstruct the uniform format of the alarm:
[0150] ;
[0151] Among them, represents the attributes of the alarm, including the start timestamp, end timestamp, type, source IP, destination IP, source port, target port, and transmission protocol; represents the relationship between alarms.
[0152] (2) Abnormal flow matching;
[0153] Since there are redundant alarms and false alarms in the large number of alarms generated by the intrusion detection system (IDS), it is necessary to merge and delete them. However, the alarm only contains part of the attack information and cannot completely describe the attack process, so it has certain limitations for separating false alarms. Therefore, in order to better handle false alarms, the corresponding abnormal flow is used for analysis, which can more comprehensively capture the details of the attack.
[0154] When the IDS detects the attack in the data packet and generates an alarm data, the 5-tuple information extracted from the is used to match the corresponding flow and extract it. For alarm data matched to the same flow, it is further determined whether the alarm types are the same. If they are the same, the alarm data of this type is merged to reduce redundant alarm data. The merging rule adopts a time sequence coverage strategy: the alarm data with the earliest start timestamp is retained, and its end timestamp is updated to the latest timestamp of all merged alarm data, thereby compressing the redundant alarm data in time and space dimensions and improving the compactness of the alarm data.
[0155] (3) Abnormal flow graph construction;
[0156] On the basis of the original "IP+port as node, flow as edge", in order to overcome the problem of insufficient expression ability of edge information in traditional graph structure, the embodiment proposes a conversion method from bipartite graph to line graph:
[0157] When using flow information to construct a graph, the source node and the destination node are not directly connected. Therefore, a bipartite graph ; wherein S denotes the set of source nodes, consisting of source IP addresses and source port numbers; D denotes the set of destination nodes, consisting of destination IP addresses and destination port numbers; and E covers all edges connecting these two types of nodes, representing the actual transmission traffic.
[0158] The bipartite graph is then converted into a line graph, i.e., an undirected anomaly flow graph:
[0159] wherein is converted. After conversion, the nodes of the anomaly flow graph correspond to the edges of the original bipartite graph, and the edges of the anomaly flow graph correspond to the nodes of the original bipartite graph. The network traffic classification task is converted from the original edge classification problem to the node classification problem.
[0160] (4) Anomaly flow graph aggregation;
[0161] In the actual network environment, the traffic pattern has dynamic heterogeneity, and the contribution of different neighbors to attack detection is significantly different. Therefore, the attention mechanism is added in this embodiment to adaptively assign weights to different neighbors of the anomaly traffic data. For each node in the undirected anomaly flow graph, its aggregation process can refer to the above formulas (2) to (4), which are not repeated here. The aggregation depth of the graph attention neural network can be set to two layers, and the second layer node integrates the feature representation of its neighbors to realize feature propagation within a two-hop range.
[0162] The attention mechanism is added in this embodiment to adaptively assign weights to different neighbors of the traffic information to improve the aggregation effect.
[0163] (5) False alarm processing;
[0164] The aggregation results are clustered using the K-means algorithm clustering to distinguish normal traffic and real attack traffic. If classified as normal traffic, the alarm log of the traffic is deleted in the system log.
[0165] II. Alarm graph construction module, the alarm graph construction module is based on the optimized high-quality alarm, further constructs the IP hop alarm graph, and the time sequence correlation between alarms is represented by a graph structure to provide key data support for multi-stage attack analysis.
[0166] The alarm log can be regarded as a network connected by source IP addresses and target IP addresses. Therefore, the IP hop can be used to further construct a directed alarm graph according to the relationship between the alarms.
[0167] III. Attack tracing module;
[0168] Since the time sequence of the alarms has been considered when the directed alarm graph is constructed, in the directed alarm graph, there is a time sequence between interconnected nodes, so obtaining the head node of the attack chain from the directed alarm graph only needs to consider one case, that is, the node is a node with an in-degree of 0 in the directed alarm graph. The algorithm filters out a set of nodes with an in-degree of 0 by traversing all nodes of the directed alarm graph: , as a candidate starting point of the initial attack chain.
[0169] For each head node , a depth-first search is performed on all reachable paths thereof to generate an initial attack chain set . Each initial attack chain is formalized as: , wherein the path from needs to satisfy the time sequence incrementality.
[0170] Due to a complex multi-step attack, there is a certain causal relationship between each single-step attack, and the previous single-step attack is to lay the foundation for the next step attack, so for all attack chains, it is necessary to further refine and further break the chain of each attack step, so as to help security personnel better analyze and trace the cause and effect of each attack. The negative causal correlation method is designed in this embodiment, and the core idea is to exclude the edges of unnecessary causal relationships in the attack chain and retain the causal paths with high confidence. Using the negative causal correlation method to prune the attack chain can not only guarantee the causal correlation of the alarm type, but also maximize the dependence on expert knowledge, attack markers and simulation work.
[0171] The attack tracing module accurately extracts effective attack chains by analyzing the high-quality time sequence directed alarm graph, so as to discover multi-stage attacks hidden in the power system, and then trace the source of such attacks, so as to help security personnel to block and isolate the attacks, thereby ensuring the safety of the power system.
[0172] The power system multi-modal graph attention attack tracing and blocking method provided in this embodiment at least has the following beneficial effects:
[0173] The method constructs a complete process of matching, association, attack chain analysis and attack blocking. First, compared with the single data modal analysis paradigm of the prior art, the method uses the multi-modal collaborative matching of the alarm data and the flow data of the power system to filter out abnormal flow data. For alarm data matched to the same flow, the same type of alarm data can be combined to reduce redundant alarm data. Then, based on the aggregation and clustering mechanism, the real attack flow data in the abnormal flow data is filtered out through the undirected abnormal flow graph. The attention mechanism is used in the aggregation process, which can adaptively assign weights to different neighbors of flow information, improve the accuracy of filtering out real attack flow data in abnormal flow data, and overcome the problem of insufficient edge information expression ability of traditional graph structure. Through the conversion method from bipartite graph to line graph, the network flow classification task is transformed from the original edge classification problem to the node classification problem, improving the efficiency of data analysis. Then, a directed alarm graph for alarm association is constructed according to the real attack flow data, and an initial attack chain is generated based on the directed alarm graph to realize the association and tracing of fine-grained multi-step attack behavior. Then, a non-causal reasoning method is proposed to prune the negative causal association between types in the initial attack chain to obtain the final attack chain. Finally, based on all the final attack chains, attack blocking is performed to improve the security of the power system. Through the multi-modal collaborative analysis between the undirected abnormal flow graph and the directed alarm graph, the method realizes fine-grained attack behavior tracing. At the same time, in order to reduce the dependence on expert knowledge and improve the detection ability of unknown attacks, the method innovatively uses a non-causal reasoning method for attack chain analysis, which can ensure the causal association of alarm types and reduce the dependence on expert knowledge, attack markers and simulation work to the maximum extent.
[0174] As Figure 4 In one embodiment of the present application, a power system multi-modal graph attention attack tracing and blocking device is provided, which comprises:
[0175] The data acquisition module 1100 is configured to acquire alarm data and flow data of the power system in response to an attack blocking request of the power system.
[0176] The abnormal flow graph construction module 1200 is configured to filter out abnormal flow data based on the matching of the flow data and the alarm data, and construct an undirected abnormal flow graph based on the abnormal flow data. The nodes in the undirected abnormal flow graph are abnormal flow data, and the edges are source node information and destination node information in the corresponding alarm data.
[0177] The attack flow screening module 1300 is configured to aggregate the nodes in the undirected abnormal flow graph based on the graph attention mechanism to obtain an aggregation result, and cluster the aggregation result to screen out real attack flow data in the abnormal flow data.
[0178] The alarm graph generation module 1400 is configured to generate a directed alarm graph based on alarm data corresponding to real attack traffic data; wherein a node in the directed alarm graph is an IP address of the alarm data, an edge in the directed alarm graph is a directed edge from a source IP address to a destination IP address, and an attribute of the edge includes a corresponding alarm type;
[0179] The attack tracing module 1500 is configured to traverse all nodes in the directed alarm graph, filter out all nodes with an in-degree of 0 as starting points of initial attack chains, and generate all initial attack chains based on the starting points and the directed edges; and is configured to traverse each initial attack chain, prune the initial attack chain in a case where there is a negative causal correlation between alarm types on edges of the initial attack chain, to obtain at least one final attack chain corresponding to the initial attack chain, and take the initial attack chain as a final attack chain in a case where there is no negative causal correlation between alarm types on edges of the initial attack chain.
[0180] It should be noted that the above-described power system multi-modal graph attention attack tracing and blocking method embodiments and the power system multi-modal graph attention attack tracing and blocking device embodiments are based on the same inventive concept, and therefore the related content of the above-described power system multi-modal graph attention attack tracing and blocking method embodiments is also applicable to the power system multi-modal graph attention attack tracing and blocking device embodiments, which will not be described here again.
[0181] The system constructs a complete process of matching, correlation, attack chain analysis, and attack blocking. First, compared with the single data modal analysis paradigm of the prior art, the method uses the multi-modal collaborative matching of alarm data and traffic data of the power system to filter out abnormal traffic data, then filters out real attack traffic data in the abnormal traffic data based on the aggregation and clustering mechanism through the undirected abnormal flow graph, then constructs a directed alarm graph based on alarm correlation according to the real attack traffic data, generates an initial attack chain based on the directed alarm graph, realizes the correlation and tracing of fine-grained multi-step attack behavior, then proposes a non-causal reasoning method to prune the negative causal correlation between types in the initial attack chain to obtain a final attack chain, and finally performs attack blocking based on all final attack chains to improve the security of the power system. The system realizes fine-grained attack behavior tracing by multi-modal collaborative analysis between the undirected abnormal flow graph and the directed alarm graph, extracts real attack traffic from redundant alarms, accurately constructs attack propagation paths, and solves the problem of tracing multi-stage covert attacks. At the same time, in order to reduce the dependence on expert knowledge and improve the detection ability of unknown attacks, the method innovatively uses a non-causal reasoning method for attack chain analysis, eliminates false correlations through a dynamic pruning strategy, can guarantee the causal correlation of alarm types, can minimize the dependence on expert knowledge, attack markers, and simulation work, can improve the reliability of attack blocking, and can ensure the safe operation of the power system.
[0182] Referring to Figure 5 The embodiment of the present application also provides an electronic device, the electronic device comprises:
[0183] at least one memory;
[0184] at least one processor;
[0185] at least one program;
[0186] The program is stored in the memory, and the processor executes the at least one program to realize the power system multi-modal graph attention attack trace blocking method provided in the present disclosure.
[0187] The electronic device can be any intelligent terminal including a mobile phone, a tablet computer, a personal digital assistant (PDA), a vehicle-mounted computer, etc.
[0188] The electronic device of the embodiment of the present application will be described in detail below.
[0189] The processor 1600 can be implemented in the form of a general central processing unit (CPU), a microprocessor, an application specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute related programs to realize the technical solutions provided by the embodiment of the present application.
[0190] The memory 1700 can be implemented in the form of a read only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 1700 can store function devices and other application programs, and the program codes of the technical solutions provided by the embodiment of the present application are saved in the memory 1700 and executed by the processor 1600 to realize the power system multi-modal graph attention attack trace blocking method of the embodiment of the present application.
[0191] The input / output interface 1800 is used to realize information input and output;
[0192] The communication interface 1900 is used to realize the communication interaction between the device and other devices, which can realize communication through wired mode (such as USB, network cable, etc.) or wireless mode (such as mobile network, WIFI, Bluetooth, etc.);
[0193] A bus 2000 transmits information between various components (for example, the processor 1600, the memory 1700, the input / output interface 1800, and the communication interface 1900) of the device.
[0194] The processor 1600, the memory 1700, the input / output interface 1800, and the communication interface 1900 are communicatively connected to each other within the device through the bus 2000.
[0195] The embodiment of the present application also provides a storage medium, which is a computer readable storage medium, and stores computer executable instructions for causing a computer to execute the power system multi-modal graph attention attack tracing blocking method.
[0196] The memory, as a non-transitory computer readable storage medium, can be used to store non-transitory software programs and non-transitory computer executable programs. In addition, the memory can include a high-speed random access memory, and can also include a non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state memory device. In some embodiments, the memory can optionally include a memory remotely arranged relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.
[0197] The embodiments described in the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art can know that, with the evolution of technology and the appearance of new application scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.
[0198] Those skilled in the art can understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and can include more or fewer steps than those shown in the figures, or combine certain steps, or different steps.
[0199] The device embodiments described above are only schematic, and the units described as separate components can or can not be physically separate, that is, can be located in one place, or can be distributed on multiple network units. Part or all of the modules can be selected according to actual needs to achieve the purpose of the embodiments of the present application.
[0200] Those skilled in the art can understand that all or some of the steps in the above disclosed method, the function modules / units in the device and the equipment can be implemented as software, firmware, hardware and their appropriate combinations.
[0201] The terms "first", "second", "third", "fourth", and the like in the description of this application and in the claims hereof, if any, are used for distinguishing between similar elements and not necessarily for describing a particular sequential or chronological order. It is to be understood that the use of the terms so termed herein is solely for the convenience of the reader and does not limit the scope of the application. It is also to be understood that the description and examples in this application are intended to cover all possible combinations where any of the several elements can represent one or more elements.
[0202] It should be understood that, in this application, "at least one" means one or more, "multiple" means two or more. "And / or" is used to describe the relationship between associated objects, which means that there can be three relationships, for example, "A and / or B" can mean: only A, only B, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects. "At least one of the following" or similar expressions means any combination of these items, including any combination of single or multiple items. For example, at least one of a, b or c, can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0203] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic, for example, the division of units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another device, or some features can be omitted or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed objects can be indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0204] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or they can be distributed on multiple network units. According to actual needs, some or all of the units can be selected to achieve the purpose of the embodiment of the present application.
[0205] In addition, each function unit in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software function unit.
[0206] When the integrated unit is realized in the form of a software function unit and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application, essentially or in the form of a contribution to the prior art, or all or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes multiple instructions for causing an electronic device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods of the embodiments of the present application. The aforementioned storage medium includes various media that can store program codes, such as a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0207] The above is a specific description of the preferred implementation of the embodiments of the present application, but the embodiments of the present application are not limited to the above implementation. Those skilled in the art can make various equivalent modifications or replacements without departing from the spirit of the embodiments of the present application, and these equivalent modifications or replacements are all included in the scope defined by the claims of the embodiments of the present application.
Claims
1. A method for power system multi-modal graph attention attack tracing and blocking, characterized in that, The method comprises: obtaining alarm data and traffic data of a power system in response to an attack blocking request of the power system; filtering out abnormal traffic data based on matching of the traffic data and the alarm data, and constructing an undirected abnormal flow graph based on the abnormal traffic data; wherein nodes in the undirected abnormal flow graph are the abnormal traffic data, and edges are corresponding source node information and destination node information in the alarm data, the source node information including a source IP address and a source port number, and the destination node information including a destination IP address and a destination port number; aggregating the nodes in the undirected abnormal flow graph based on a graph attention mechanism to obtain an aggregation result, and clustering the aggregation result to filter out real attack traffic data in the abnormal traffic data; generating a directed alarm graph based on alarm data corresponding to the real attack traffic data; wherein nodes in the directed alarm graph are IP addresses of the alarm data, and edges in the directed alarm graph are directed edges from a source IP address to a destination IP address, and attributes of the edges include corresponding alarm types; traversing all nodes in the directed alarm graph to filter out all nodes with an in-degree of 0 as starting points of initial attack chains, and generating all initial attack chains based on the starting points and the directed edges; traversing each of the initial attack chains, and pruning the initial attack chains in a case where there is a negative causal relationship between alarm types on edges of the initial attack chains to obtain at least one final attack chain corresponding to the initial attack chains, and taking the initial attack chains as a final attack chain in a case where there is no negative causal relationship between alarm types on edges of the initial attack chains.
2. The power system multi-modal graph attention attack traceback containment method of claim 1, wherein, The filtering out of abnormal traffic data based on matching of the traffic data and the alarm data comprises: obtaining initial attribute values of the alarm data; extracting a tuple value from the initial attribute values, and matching the tuple value with the traffic data to filter out abnormal traffic data.
3. The power system multi-modal graph attention attack traceback containment method of claim 2, wherein, After the filtering out of abnormal traffic data based on matching of the traffic data and the alarm data, the method further comprises: in a case where there are at least two tuple values corresponding to the alarm data matching the same traffic data and having the same alarm types, merging the at least two alarm data into one alarm data according to a time sequence coverage strategy.
4. The power system multi-modal graph attention attack traceback containment method of claim 1, wherein, The construction of an undirected abnormal flow graph based on the abnormal traffic data comprises: constructing a bipartite graph based on the abnormal traffic data; nodes in the bipartite graph are source node information and destination node information in the alarm data, and edges are abnormal traffic data; taking a union set of the source node information and the destination node information of the bipartite graph as edges of the undirected abnormal flow graph, and taking edges of the bipartite graph as nodes of the undirected abnormal flow graph to construct the undirected abnormal flow graph.
5. The power system multi-modal graph attention attack traceback containment method of claim 4, wherein, The generation of a directed alarm graph based on alarm data corresponding to the real attack traffic data comprises: determining IP addresses of the alarm data, alarm types of the alarm data, and start and end time stamps of the alarm data; In a case that a destination IP address of a first alarm data in any two alarm data is same as a source IP address of a second alarm data, and an end timestamp of the first alarm data is earlier than a start timestamp of the second alarm data, an association relationship between the first alarm data and the second alarm data is constructed; A directed alarm graph is constructed based on IP addresses of the alarm data, alarm types of the alarm data, and the association relationship between any two alarm data.
6. The power system multi-modal graph attention attack traceback containment method of claim 5, wherein, The aggregating the nodes in the undirected abnormal flow graph based on the graph attention mechanism comprises: aggregating nodes in the undirected anomaly flow graph using a graph attention neural network; wherein a first layer of attention in the graph attention neural network comprises the aggregation process of the layer of attention comprises: ; ; ; wherein is the aggregation depth of the graph attention neural network, is a central node is a set of neighbor nodes of the central node is a neighbor node, is a learnable parameter aggregating traffic features from the th layer to the th layer, and are features of the neighbor node and the central node in the th layer, is a feature of the neighbor node in the th layer, is a ReLU activation function, is an attention score between the neighbor node and the central node in the th layer, is a trainable weight matrix of the th layer, is a learnable parameter of the th layer, is a concatenation operation, is a transpose, is a feature of the neighbor node in the th layer, is a natural exponential function, is an activation function.
7. The power system multi-modal graph attention attack traceback containment method of claim 1, wherein, The clustering the aggregation result to filter out real attack traffic data in the abnormal traffic data comprises: The clustering the aggregation result based on K-means to divide the abnormal traffic data into real attack traffic data and normal traffic data; After the abnormal traffic data is divided into real attack traffic data and normal traffic data, the method further comprises: In the power system, the normal traffic data corresponding alarm data is deleted.
8. An apparatus for power system multi-modal graph attention attack traceback blocking, comprising: a power system multi-modal graph attention attack traceback blocking device. The device comprises: A data acquisition module configured to acquire alarm data and traffic data of a power system in response to an attack blocking request of the power system; An abnormal flow graph construction module configured to filter out abnormal traffic data based on the traffic data and the alarm data, and construct an undirected abnormal flow graph based on the abnormal traffic data; wherein nodes in the undirected abnormal flow graph are the abnormal traffic data, and edges are corresponding to source node information and destination node information in the alarm data, the source node information comprises a source IP address and a source port number, and the destination node information comprises a destination IP address and a destination port number; An attack traffic filtering module configured to aggregate the nodes in the undirected abnormal flow graph based on a graph attention mechanism to obtain an aggregation result, and cluster the aggregation result to filter out real attack traffic data in the abnormal traffic data; An alarm graph generation module configured to generate a directed alarm graph based on alarm data corresponding to the real attack traffic data; wherein nodes in the directed alarm graph are IP addresses of the alarm data, and edges in the directed alarm graph are directed edges from a source IP address to a destination IP address, and an attribute of the edge comprises a corresponding alarm type; An attack tracing module configured to traverse all nodes in the directed alarm graph, filter out all nodes with an in-degree of 0 as starting points of initial attack chains, and generate all initial attack chains based on the starting points and the directed edges; and configured to traverse each of the initial attack chains, and in a case that there is a negative causal relationship between alarm types on edges of the initial attack chain, prune the initial attack chain to obtain at least one final attack chain corresponding to the initial attack chain, and in a case that there is no negative causal relationship between alarm types on edges of the initial attack chain, take the initial attack chain as a final attack chain.
9. An electronic device, comprising: comprising at least one controller and a memory connected in communication with the controller; the memory storing instructions executable by the at least one controller, the instructions being executed by the at least one controller to cause the at least one controller to perform the power system multi-modal graph attention attack traceability blocking method of any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer readable storage medium stores computer executable instructions for causing a computer to perform the power system multi-modal graph attention attack traceability blocking method of any one of claims 1 to 7.
Citation Information
Patent Citations
Method, device and system for determining safety event of electric power monitoring system
CN110213077A
Attack tracing method and system
CN117155665A