Power grid network attack chain risk assessment and threat situation awareness blocking method

By constructing a directed attack graph and graph neural network model, screening out blockable nodes, and generating threat situation awareness and blocking recommendation reports, the problem of poor adaptability of the static blocking strategy of the power system is solved, and the security of the power system and the accuracy of the blocking recommendations are improved.

CN120750651AActive Publication Date: 2025-10-03WUQIANG XISHUI POWER PLANT OF WULING ELECTRIC POWER CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202511212980.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-28
Publication Date
2025-10-03
Estimated Expiration
2045-08-28

AI Technical Summary

Technical Problem

In the existing technology, the threat situation of the power system has the characteristics of dynamic evolution. Static blocking strategies are difficult to adapt to changes in the threat situation in real time, resulting in waste of blocking resources or untimely blocking, affecting the security of the power system.

Method used

By obtaining the log data, network traffic data and alarm data of the power system, a directed attack graph structure is constructed, and the graph neural network model is used to output the blockability probability, screen out the blockable nodes, and generate a threat situation awareness and blocking recommendation report.

Benefits of technology

It realizes intelligent blocking of power system threat situations, improves the safety of the power system and the accuracy of blocking recommendations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120750651A_ABST
    Figure CN120750651A_ABST
Patent Text Reader

Abstract

The invention discloses a blocking method for power grid network attack chain risk assessment and threat situation awareness, and the method comprises the steps: carrying out the blocking of the threat situation awareness based on an attack target, attack time, an attack event type, attack event influence equipment and an attack tool corresponding to each attack event; constructing a first association relationship between every two attack events through a preset attack mode library; constructing a first directed attack graph structure, and based on the first directed attack graph structure, outputting a first blocking probability corresponding to each first node through a graph neural network model; traversing all the first nodes, and screening out all the first nodes of which the first blocking probabilities are greater than a preset screening threshold as blocking nodes; and on the basis of the nodes capable of being blocked, the corresponding threat situation sensing and blocking suggestion report is generated, so that intelligent blocking of the threat situation is realized, and the security of the power system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field related to blocking of power grid network attack chain risk assessment and threat situation awareness, and in particular to a method for blocking of power grid network attack chain risk assessment and threat situation awareness. Background Art

[0002] Information assets are commercialized information that can be converted into corporate profits. As a special type of corporate asset, they play an increasingly important role in a company's production and operations. This is especially true for critical systems that affect national economy, people's livelihoods, and social stability.

[0003] Existing technologies often use static rules or manual decision-making models, triggering fixed blocking actions when matching features are detected. However, the threat landscape of power systems evolves dynamically, and the paths, strength, and exploitable vulnerabilities of attack chains change over time. Static blocking strategies struggle to adapt to these changes in the threat landscape in real time. Furthermore, they can waste blocking resources (such as repeatedly blocking difficult-to-block nodes) or fail to block them in a timely manner (such as missing a blockable node), resulting in attacks that cannot be effectively contained and seriously impacting power system security. Summary of the Invention

[0004] This application aims to at least address the technical problems existing in the prior art. To this end, this application proposes a method for risk assessment and threat situation awareness blocking of power grid network attack chains, which can screen out blockable nodes in real time and generate blocking recommendations for these nodes, thereby integrating risk assessments of multiple attack chains corresponding to these blockable nodes and achieving blocking of power grid network attack chains and threat situation awareness.

[0005] In a first aspect of the present application, a method for blocking risk assessment and threat situation awareness of a power grid network attack chain is provided, comprising the following steps: Obtain log data, network traffic data, and alarm data from the power system; Extracting the attack target, attack time, attack event type, attack event-affected device, and attack tool corresponding to each attack event from the log data, the network traffic data, and the alarm data; Based on the attack target, the attack time, the attack event type, the attack event-affected device, and the attack tool corresponding to each attack event, a first association relationship is established between each two attack events through a preset attack pattern library; Constructing a first directed attack graph structure, wherein a first node in the first directed attack graph structure is an attack event, a first edge in the directed attack graph structure is a directed edge from a first source node to a first target node, attributes of the first node include the attack target, the attack time, the attack event type, the attack event-affected device, and the attack tool, and an attribute of the first edge is the first association relationship; Based on the first directed attack graph structure, outputting a first blockability probability corresponding to each first node through a graph neural network model; Traversing all the first nodes, screening out all the first nodes whose first blockability probability is greater than a preset screening threshold as blockable nodes; Based on the blockable nodes, a corresponding threat situation awareness and blocking recommendation report is generated.

[0006] The method for blocking power grid network attack chain risk assessment and threat situation awareness according to the embodiment of the present application has at least the following beneficial effects: The method obtains the log data, network flow data and alarm data of the power system; extracts the attack target, attack time, attack event type, attack event-affected device and attack tool corresponding to each attack event from the log data, network flow data and alarm data; constructs the first association relationship between each two attack events through a preset attack pattern library based on the attack target, attack time, attack event type, attack event-affected device and attack tool corresponding to each attack event; constructs a first directed attack graph structure, wherein the first node in the first directed attack graph structure is the attack event, the first edge in the directed attack graph structure is a directed edge from the first source node to the first target node, and the attributes of the first node include attack target, attack time, attack event type, attack event-affected device and attack tool Equipment and attack tools, the attribute of the first edge is the first association relationship; based on the first directed attack graph structure, the first blockable probability corresponding to each first node is output through the graph neural network model; all first nodes are traversed, and all first nodes with a first blockable probability greater than a preset screening threshold are screened out as blockable nodes; based on the blockable nodes, corresponding threat situation awareness and blocking recommendation reports are generated. This application constructs an attack chain between nodes by constructing a first directed attack graph structure, and screens out blockable nodes based on the output blockable probability corresponding to each node, and then generates blocking recommendations for blockable nodes, thereby realizing risk assessment of multiple attack chains corresponding to integrated blockable nodes, realizing intelligent blocking of threat situations, and improving the safety of the power system.

[0007] According to some embodiments of the present application, before generating a corresponding threat situation awareness and blocking recommendation report based on the blockable node, the method further includes: Based on the first directed attack graph structure, outputting, through the graph neural network model, a risk potential energy value of the blockable node and a propagation weight value of a first edge with the blockable node as a source node, wherein the risk potential energy value is a scalar value used to characterize the risk potential of the node, and the propagation weight value is a value used to characterize the ability of the risk to propagate from the source node to the target node; Determining a first total risk value before blocking based on the risk potential energy value of the blockable node and the propagation weight value of the first edge with the blockable node as the source node; Determining a first post-blocking total risk value based on the risk potential energy value of the blockable node, the first blockable probability of the blockable node, and the propagation weight value of the blockable node; Calculating a first risk difference based on the first pre-blocking total risk and the first post-blocking total risk; The generating of a corresponding threat situation awareness and blocking recommendation report based on the blockable node includes: Based on the first risk difference and the blockable node, a corresponding threat situation awareness and blocking recommendation report is generated.

[0008] According to some embodiments of the present application, the training process of the graph neural network model includes: Obtaining historical log data, historical network traffic data, and historical alarm data of the power system; Extracting the historical attack target, historical attack time, historical attack event type, historical attack event-affected device, and historical attack tool corresponding to each historical attack event from the historical log data, the historical network traffic data, and the historical alarm data; Based on the historical attack target, the historical attack time, the historical attack event type, the historical attack event-affected device, and the historical attack tool corresponding to each historical attack event, a second association relationship is established between each two historical attack events through the preset attack pattern library; Constructing a second directed attack graph structure, wherein a second node in the second directed attack graph structure is the historical attack event, a second edge in the second directed attack graph structure is a directed edge from a second source node to a second target node, attributes of the second node include the historical attack target, the historical attack time, the historical attack event type, the historical attack event-affected device, and the historical attack tool, and an attribute of the second edge is the second association relationship; Constructing an initial graph neural network model, and performing simulated blocking training on the initial graph neural network model based on the second directed attack graph structure to obtain the risk potential energy value of the second node, the second blockability probability of the second node, and the propagation weight value of the second edge; determining a second total risk value before blocking based on the risk potential energy value of the second node and a second blockability probability of the second node; Determine a second post-blocking total risk value based on the risk potential value of the second node, the second blockability probability of the second node, and the propagation weight value of the second edge; Calculating a first loss value based on the second total risk value before blocking, the second total risk value after blocking, and the second blockable probability; When the first loss value reaches a preset loss threshold, the initial graph neural network model is used as the graph neural network model.

[0009] According to some embodiments of the present application, determining the second pre-blocking total risk value based on the risk potential energy value of the second node and the second blockability probability of the second node includes: Adding the risk potential energy values ​​of all the second nodes to obtain the total risk potential energy value of the second nodes; Multiplying the propagation weight value of each second edge by the risk potential energy value of the corresponding second target node to obtain a first risk potential energy value; Adding all the first risk potential energy values ​​to obtain a total first risk potential energy value; The first risk potential energy sum is added to the second node risk potential energy sum to obtain the second pre-blocking total risk value.

[0010] According to some embodiments of the present application, determining the second post-blocking total risk value based on the risk potential value of the second node, the second blockability probability of the second node, and the propagation weight value of the second edge includes: Calculating a blockability probability difference of each second node according to the second blockability probability; multiplying the blockability probability difference of each second node by the risk potential energy value of the corresponding second node to obtain a second risk potential energy value; Adding all the second risk potential energy values ​​to obtain a total second risk potential energy value; multiplying the blockability probability difference of the second node by the corresponding first risk potential energy value to obtain a third risk potential energy value; Adding all the third risk potential energy values ​​to obtain a total third risk potential energy value; The second risk potential energy value is added to the third risk potential energy value to obtain the second post-blocking total risk value.

[0011] According to some embodiments of the present application, calculating the first loss value based on the second total risk value before blocking, the second total risk value after blocking, and the second blockability probability includes: subtracting the second total risk value before blocking from the second total risk value after blocking to obtain a second risk difference; Adding all the second blockable probabilities to obtain a total second blockable probabilities; The first loss value is calculated based on the second blockable probability sum and the second risk difference.

[0012] According to some embodiments of the present application, calculating the first loss value based on the second blockable probability sum and the second risk difference includes: Multiplying the sum of the second blockable probabilities by a preset blocking parameter value to obtain a total blocking value; The first loss value is obtained by subtracting the total blocking value from the second risk difference value.

[0013] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become obvious from the description below, or will be learned through practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] The above and / or additional aspects and advantages of the present application will become apparent and easily understood from the description of the embodiments in conjunction with the following drawings, in which: Figure 1 This is a flow chart of a method for blocking risk assessment and threat situation awareness of a power grid network attack chain according to an embodiment of the present application; Figure 2 This is a schematic diagram of the structure of an embodiment of a blocking system for risk assessment and threat situation awareness of a power grid network attack chain provided by the present application; Figure 3 It is a structural diagram of an embodiment of the electronic device provided by this application. DETAILED DESCRIPTION

[0015] The following describes in detail embodiments of the present application. Examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present application and are not to be construed as limiting the present application.

[0016] In the description of this application, if there is a description of first, second, etc., it is only for the purpose of distinguishing technical features, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features or implicitly indicating the order of the indicated technical features.

[0017] In the description of this application, it should be understood that descriptions involving orientation, such as the orientation or positional relationship indicated by up, down, etc., are based on the orientation or positional relationship shown in the accompanying drawings, and are only for the convenience of describing this application and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation on this application.

[0018] In the description of this application, it should be noted that, unless otherwise clearly defined, terms such as setting, installing, and connecting should be understood in a broad sense, and technical personnel in the relevant technical field can reasonably determine the specific meaning of the above terms in this application based on the specific content of the technical solution.

[0019] Information assets are commercialized information that can be converted into corporate profits. As a special type of corporate asset, they play an increasingly important role in a company's production and operations. This is especially true for critical systems that affect national economy, people's livelihoods, and social stability.

[0020] Existing technologies often rely on static rules or manual decision-making models, triggering fixed blocking actions when matching signatures are detected. However, the threat landscape of power systems evolves dynamically, with the paths, strength, and exploitable vulnerabilities of attack chains changing over time. Static blocking strategies struggle to adapt to these changes in the threat landscape in real time. Furthermore, they can waste blocking resources (e.g., repeatedly blocking non-critical nodes) or fail to implement blocking measures in a timely manner (e.g., missing critical, blockable nodes). This can lead to attacks being unable to be effectively contained, seriously impacting power system security.

[0021] In order to solve the above technical defects, an embodiment of the present application provides a blocking method for power grid network attack chain risk assessment and threat situation awareness.

[0022] See Figure 1 , is a flow chart of a method for blocking risk assessment and threat situation awareness of a power grid network attack chain provided by an embodiment of the present application. The method is applied to electronic devices, which may be servers, etc. Figure 1 As shown in the figure, the blocking methods for risk assessment and threat situation awareness of the power grid network attack chain include: Step S101: Obtaining log data, network traffic data, and alarm data of the power system; Step S102: Extract the attack target, attack time, attack event type, attack event-affected device, and attack tool corresponding to each attack event from the log data, network traffic data, and alarm data; Step S103: Based on the attack target, attack time, attack event type, attack event-affected device, and attack tool corresponding to each attack event, a first correlation relationship is constructed between every two attack events using a preset attack pattern library; Step S104: Construct a first directed attack graph structure, wherein the first node in the first directed attack graph structure is an attack event, the first edge in the directed attack graph structure is a directed edge from the first source node to the first target node, the attributes of the first node include attack target, attack time, attack event type, attack event affected device, and attack tool, and the attribute of the first edge is a first association relationship; Step S105: Based on the first directed attack graph structure, output a first blockability probability corresponding to each first node through a graph neural network model; Step S106: traverse all first nodes and select all first nodes whose first blockability probability is greater than a preset screening threshold as blockable nodes; Step S107: Generate a corresponding threat situation awareness and blocking recommendation report based on the blockable nodes.

[0023] The aforementioned log data can be from various devices within the power system. Examples include SCADA system operation logs, distributed control system logs, communication logs from smart meters and remote terminal units, server system logs, firewall and intrusion detection system alarm logs, and security event logs from security information and event management platforms. These logs record device operating status, user behavior, network connections, and security events, and serve as essential data for identifying attacks.

[0024] This network traffic data can monitor network traffic within the power system (e.g., between OT networks, office networks, and control networks). This includes industrial control protocol traffic, monitoring and data acquisition communication traffic, and traditional Transmission Control Protocol / Internet Protocol traffic. Deep packet inspection and behavioral analysis of this traffic can reveal unusual activity, such as abnormal connections, use of unknown protocols, large-scale data transmission, or specific attack payloads.

[0025] The aforementioned alarm data can be generated from various security devices in the power system (e.g., firewalls, intrusion detection systems, intrusion prevention systems, and detection devices in advanced persistent threat detection systems), network devices (e.g., routers and switches), and industrial control devices. These alarms may include detections of viruses, malware, abnormal access, port scans, and denial-of-service attack attempts.

[0026] The preset screening threshold may be a constant value less than 1 that is preset according to actual needs.

[0027] The first edge starts from the first source node and points to the first target node.

[0028] The above-mentioned preset attack pattern library is based on historical attack event data, existing attack tactics, existing research results on new vulnerabilities and attack methods, etc., to obtain the atomic pattern of specific attack behavior (such as a port scan or a privilege escalation attempt), and identify the time, logic and causal relationship between atomic patterns to construct an attack sequence pattern. The attack sequence pattern can be a "ransomware attack" pattern, and a "ransomware attack" pattern may include "initial intrusion" "Lateral Movement" Data encryption "Ransomware notification", etc., and then use regular expressions to convert the attack sequence pattern into a rule set that can be recognized and matched by the system to obtain a preset attack pattern library.

[0029] The above-mentioned first association relationship may include a temporal relationship, a logical relationship, and a causal relationship. The temporal relationship can be used to indicate the order in which attack events occur. For example, event A may cause event B to occur. The logical relationship can be used to indicate the conditional dependency between attack events. For example, successfully obtaining a certain permission (attack event A) is a necessary condition for exploiting a certain vulnerability (attack event B). The causal relationship can be used to indicate that one attack event causes a state change of another attack event.

[0030] The above-mentioned threat situation awareness and blocking recommendation report can be a comprehensive document generated based on blockable nodes, which can be used to present the current network threat status faced by the power system and provide targeted blocking decisions.

[0031] The above-mentioned construction of the first association relationship between each two attack events based on the attack target, attack time, attack event type, attack event-affected device and attack tool corresponding to each attack event through the preset attack pattern library can be to match the attack target, attack time, attack event type, attack event-affected device and attack tool corresponding to each attack event with the preset attack pattern library to obtain the first association relationship between each two attack events.

[0032] The above-mentioned first blockability probability corresponding to each first node is output through the graph neural network model based on the first directed attack graph structure, which can be obtained by inputting the first directed attack graph structure into the graph neural network model to obtain the first blockability probability corresponding to each first node output by the graph neural network model.

[0033] The method obtains the log data, network flow data and alarm data of the power system; extracts the attack target, attack time, attack event type, attack event-affected device and attack tool corresponding to each attack event from the log data, network flow data and alarm data; constructs the first association relationship between each two attack events through a preset attack pattern library based on the attack target, attack time, attack event type, attack event-affected device and attack tool corresponding to each attack event; constructs a first directed attack graph structure, wherein the first node in the first directed attack graph structure is the attack event, the first edge in the directed attack graph structure is a directed edge from the first source node to the first target node, and the attributes of the first node include attack target, attack time, attack event type, attack event-affected device and attack tool Equipment and attack tools, the attribute of the first edge is the first association relationship; based on the first directed attack graph structure, the first blockable probability corresponding to each first node is output through the graph neural network model; all first nodes are traversed, and all first nodes with a first blockable probability greater than a preset screening threshold are screened out as blockable nodes; based on the blockable nodes, corresponding threat situation awareness and blocking recommendation reports are generated. This application constructs an attack chain between nodes by constructing a first directed attack graph structure, and screens out blockable nodes based on the output blockable probability corresponding to each node, and then generates blocking recommendations for blockable nodes, thereby realizing risk assessment of multiple attack chains corresponding to integrated blockable nodes, realizing intelligent blocking of threat situations, and improving the safety of the power system.

[0034] In some embodiments, before generating a corresponding threat situation awareness and blocking recommendation report based on the blockable node, the method further includes: Step S201: Based on the first directed attack graph structure, the graph neural network model outputs the risk potential value of the blockable node and the propagation weight value of the first edge with the blockable node as the source node. The risk potential value is a scalar value used to represent the node risk potential, and the propagation weight value is a value used to represent the ability of the risk to propagate from the source node to the target node. Step S202: determining a first total risk value before blocking based on the risk potential energy value of the blockable node and the propagation weight value of the first edge with the blockable node as the source node; Step S203: determining a first post-blocking total risk value based on the risk potential energy value of the blockable node, the first blockable probability of the blockable node, and the propagation weight value of the blockable node; Step S204: Calculate a first risk difference based on the first total risk before blocking and the first total risk after blocking; Generate corresponding threat situation awareness and blocking recommendation reports based on blockable nodes, including: Step S205: Generate a corresponding threat situation awareness and blocking recommendation report based on the first risk difference and the blockable nodes.

[0035] The determining of the first total risk value before blocking based on the risk potential value of the blockable node and the propagation weight value of the first edge with the blockable node as the source node may include the following steps: Step S2021: Add the risk potential energy values ​​of all blockable nodes to obtain the total risk potential energy value of the blockable nodes; Step S2022: Multiply the propagation weight value of each first edge with the blockable node as the source node by the risk potential energy value of the third target node to obtain a fourth risk potential energy value, where the third target node is the target node of the first edge with the blockable node as the source node; Step S2023: Add all fourth risk potential energy values ​​to obtain a total fourth risk potential energy value; Step S2024: Add the fourth risk potential energy value sum to the risk potential energy value sum of the blockable nodes to obtain a first total risk value before blocking.

[0036] The above-mentioned determination of the first post-blocking total risk value based on the risk potential energy value of the blockable node, the first blockable probability of the blockable node, and the propagation weight value of the blockable node may include the following steps: Step S2031: Calculate the blockable probability difference of each blockable node based on the first blockable probability of the blockable node; Step S2032: multiply the blockability probability difference of each blockable node by the risk potential energy value of each blockable node to obtain a fifth risk potential energy value; Step S2033: Add up all fifth risk potential energy values ​​to obtain a total fifth risk potential energy value; Step S2034: Obtain a sixth risk potential energy value by adding the blockable probability difference of the blockable node to the corresponding fourth risk potential energy value; Step S2035: Add all sixth risk potential energy values ​​to obtain a total sixth risk potential energy value; Step S2036: Add the fifth risk potential energy value and the sixth risk potential energy value to obtain a first post-blocking total risk value.

[0037] Calculating the blockable probability difference of each blockable node according to the first blockable probability of the blockable node may be performed by subtracting the first blockable probability of each blockable node from one to obtain the blockable probability difference of each blockable node.

[0038] This application calculates the first risk difference and generates a corresponding threat situation awareness and blocking recommendation report based on the first risk difference and the blockable nodes, thereby improving the accuracy of reading the threat situation awareness and blocking recommendation report and enabling users who read the threat situation awareness and blocking recommendation report to understand the situation more efficiently.

[0039] In some embodiments, the training process of the graph neural network model includes: Step S301: Acquire historical log data, historical network traffic data, and historical alarm data of the power system; Step S302: extract the historical attack target, historical attack time, historical attack event type, historical attack event-affected device, and historical attack tool corresponding to each historical attack event from the historical log data, historical network traffic data, and historical alarm data; Step S303: Based on the historical attack target, historical attack time, historical attack event type, historical attack event-affected device, and historical attack tool corresponding to each historical attack event, a second association relationship is constructed between every two historical attack events through a preset attack pattern library; Step S304: Construct a second directed attack graph structure, wherein the second node in the second directed attack graph structure is a historical attack event, the second edge in the second directed attack graph structure is a directed edge from the second source node to the second target node, the attributes of the second node include historical attack target, historical attack time, historical attack event type, historical attack event affected device, and historical attack tool, and the attribute of the second edge is a second association relationship; Step S305: Construct an initial graph neural network model. Based on the second directed attack graph structure, perform simulated blocking training on the initial graph neural network model to obtain the risk potential energy value of the second node, the second blockability probability of the second node, and the propagation weight value of the second edge. Step S306: determining a second total risk value before blocking based on the risk potential energy value of the second node and the second blockability probability of the second node; Step S307: determining a second post-blocking total risk value based on the risk potential value of the second node, the second blockability probability of the second node, and the propagation weight value of the second edge; Step S308: Calculate a first loss value based on the second total risk value before blocking, the second total risk value after blocking, and the second blockability probability; Step S309: When the first loss value reaches a preset loss threshold, the initial graph neural network model is used as the graph neural network model.

[0040] The above-mentioned second association relationship may include a time relationship, a logical relationship and a causal relationship.

[0041] The above-mentioned preset loss threshold can be a constant value preset according to actual needs.

[0042] The above-mentioned construction of the second association relationship between every two historical attack events through the preset attack pattern library based on the historical attack target, historical attack time, historical attack event type, historical attack event-affected device, and historical attack tool corresponding to each historical attack event can be performed by matching the historical attack target, historical attack time, historical attack event type, historical attack event-affected device, and historical attack tool corresponding to each historical attack event with the preset attack pattern library to obtain the second association relationship between every two historical attack events.

[0043] The above-mentioned second directed attack graph structure is based on which the initial graph neural network model is simulated and blocked for training, and the risk potential energy value of the second node, the second blockable probability of the second node and the propagation weight value of the second edge are obtained. The second directed attack graph structure is input into the initial graph neural network model for simulated and blocked training, and the risk potential energy value of the second node, the second blockable probability of the second node and the propagation weight value of the second edge are obtained.

[0044] This application calculates the first loss value through the second total risk value before blocking, the second total risk value after blocking and the second blockable probability, and iteratively updates the initial graph neural network model through the first loss value, thereby improving the accuracy of model prediction and the efficiency of model training.

[0045] In some embodiments, determining a second pre-blocking total risk value based on the risk potential energy value of the second node and the second blockability probability of the second node includes: Step S401: Add the risk potential energy values ​​of all second nodes to obtain the total risk potential energy value of the second nodes; Step S402: multiply the propagation weight value of each second edge by the risk potential energy value of the corresponding second target node to obtain a first risk potential energy value; Step S403: Add all first risk potential energy values ​​to obtain a total first risk potential energy value; Step S404: Add the first risk potential energy value sum to the second node risk potential energy value sum to obtain a second pre-blocking total risk value.

[0046] Specifically, the total risk value before the second blocking is calculated using the following formula: ; in, is the total risk value before the second blocking, For the The risk potential energy value of the second node, For the The risk potential energy value of the second node, For the first The second node is the source node and the The propagation weight value of the second edge with the second node as the target node.

[0047] This application can quantify the total risk value before blocking of the second node by calculating the total risk value before blocking, providing a data basis for the subsequent calculation of the loss value, and can also provide users with intuitive feedback on the total risk value before blocking of the node, which can be used to remind users the urgency of intelligent blocking of the threat situation.

[0048] In some embodiments, determining the second post-blocking total risk value based on the risk potential value of the second node, the second blockability probability of the second node, and the propagation weight value of the second edge includes: Step S501: Calculate the blockability probability difference of each second node according to the second blockability probability; Step S502: multiply the blockability probability difference of each second node by the risk potential energy value of the corresponding second node to obtain a second risk potential energy value; Step S503: Add up all the second risk potential energy values ​​to obtain a total second risk potential energy value; Step S504: multiply the blockability probability difference of the second node by the corresponding first risk potential energy value to obtain a third risk potential energy value; Step S505: Add up all third risk potential energy values ​​to obtain a total third risk potential energy value; Step S506: Add the second risk potential energy value and the third risk potential energy value to obtain a second post-blocking total risk value.

[0049] Calculating the blockable probability difference of each second node according to the second blockable probability may be performed by subtracting the second blockable probability of each second node from one to obtain the blockable probability difference of each second node.

[0050] Specifically, the total risk value after the second blockade is calculated using the following formula: ; in, is the total risk value after the second blockade, For the The second blockable probability of the second node. This application can quantify the total risk value after blocking of the second node by calculating the total risk value after blocking, providing a data basis for the subsequent calculation of the loss value, and can also provide users with intuitive feedback on the total risk value after blocking of the node, which can be used to remind users of the urgency of intelligent blocking of the threat situation.

[0051] The present application improves the accuracy of calculating the total risk potential energy value by comprehensively calculating the risk potential energy value of the second node itself and the risk potential energy value propagated by the node to multiple downstream nodes.

[0052] In some embodiments, the threat situation awareness and blocking recommendation report generated based on the blockable nodes may be a comprehensive document generated based on the blockable nodes, the total risk value before blocking, and the total risk value after blocking.

[0053] In some embodiments, calculating the first loss value based on the second total risk value before blocking, the second total risk value after blocking, and the second blockability probability includes: Step S601: Subtract the second total risk value before blocking from the second total risk value after blocking to obtain a second risk difference; Step S602: Add all second blockable probabilities to obtain a total second blockable probabilities; Step S603: Calculate a first loss value based on the second blockable probability sum and the second risk difference.

[0054] In some embodiments, calculating the first loss value based on the second blockable probability sum and the second risk difference includes: Step S701: multiply the second blockable probability sum by a preset blocking parameter value to obtain a total blocking value; Step S702: Subtract the total blocking value from the second risk difference to obtain a first loss value.

[0055] The above-mentioned preset blocking parameter value may be a constant value preset according to actual needs.

[0056] Specifically, the first loss value is calculated using the following formula: ; in, is the second risk difference, is the first loss value, It is the preset blocking parameter value.

[0057] This application calculates the first loss value by using the second blockable probability sum and the second risk difference, providing a data basis for subsequent model updates, thereby improving the convergence efficiency of the model training process and the accuracy of model prediction.

[0058] In addition, refer to Figure 2 One embodiment of the present application provides a blocking system for power grid network attack chain risk assessment and threat situation awareness, including a data acquisition module 1100, an attack event extraction module 1200, a first association relationship construction module 1300, a first directed attack graph structure construction module 1400, a model output module 1500, a node screening module 1600, and a report generation module 1700, wherein: The data acquisition module 1100 is used to obtain log data, network flow data and alarm data of the power system; The attack event extraction module 1200 is used to extract the attack target, attack time, attack event type, attack event-affected device, and attack tool corresponding to each attack event from log data, network traffic data, and alarm data; The first association relationship building module 1300 is used to build a first association relationship between each two attack events through a preset attack pattern library based on the attack target, attack time, attack event type, attack event-affected device, and attack tool corresponding to each attack event; The first directed attack graph structure construction module 1400 is used to construct a first directed attack graph structure, wherein the first node in the first directed attack graph structure is an attack event, the first edge in the directed attack graph structure is a directed edge from the first source node to the first target node, the attributes of the first node include the attack target, the attack time, the attack event type, the attack event-affected device, and the attack tool, and the attribute of the first edge is the first association relationship; The model output module 1500 is configured to output a first blockability probability corresponding to each first node through a graph neural network model based on the first directed attack graph structure; The node screening module 1600 is configured to traverse all first nodes and screen out all first nodes whose first blockability probability is greater than a preset screening threshold as blockable nodes; The report generation module 1700 is used to generate corresponding threat situation awareness and blocking recommendation reports based on the blockable nodes.

[0059] The system obtains the log data, network flow data and alarm data of the power system; extracts the attack target, attack time, attack event type, attack event-affected device and attack tool corresponding to each attack event from the log data, network flow data and alarm data; builds the first association relationship between each two attack events through a preset attack pattern library based on the attack target, attack time, attack event type, attack event-affected device and attack tool corresponding to each attack event; builds a first directed attack graph structure, wherein the first node in the first directed attack graph structure is the attack event, the first edge in the directed attack graph structure is a directed edge from the first source node to the first target node, and the attributes of the first node include attack target, attack time, attack event type, attack event-affected device and attack tool Equipment and attack tools, the attribute of the first edge is the first association relationship; based on the first directed attack graph structure, the first blockable probability corresponding to each first node is output through the graph neural network model; all first nodes are traversed, and all first nodes with a first blockable probability greater than a preset screening threshold are screened out as blockable nodes; based on the blockable nodes, corresponding threat situation awareness and blocking recommendation reports are generated. This application constructs an attack chain between nodes by constructing a first directed attack graph structure, and screens out blockable nodes based on the output blockable probability corresponding to each node, and then generates blocking recommendations for blockable nodes, thereby realizing risk assessment of multiple attack chains corresponding to integrated blockable nodes, realizing intelligent blocking of threat situations, and improving the safety of the power system.

[0060] It should be noted that this system embodiment and the above-mentioned method embodiment are based on the same inventive concept, so the relevant content of the above-mentioned method embodiment is also applicable to this system embodiment and will not be repeated here.

[0061] Figure 3 A schematic diagram of the rule mining hardware structure provided by an embodiment of the present application is shown.

[0062] The blocking device for risk assessment and threat situation awareness in the power grid network attack chain may include a processor 301 and a memory 302 storing computer program instructions.

[0063] Specifically, the processor 301 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present application.

[0064] Memory 302 may include a large-capacity memory for data or instructions. By way of example and not limitation, memory 302 may include a hard disk drive (HDD), a floppy disk drive, flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 302 may include removable or non-removable (or fixed) media. Where appropriate, memory 302 may be internal or external to the integrated gateway disaster recovery device. In a specific embodiment, memory 302 is a non-volatile solid-state memory.

[0065] In some embodiments, the memory 302 may include read-only memory (ROM), random access memory (RAM), magnetic disk storage media devices, optical storage media devices, flash memory devices, electrical, optical, or other physical / tangible memory storage devices. Thus, in general, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to an aspect of the present disclosure.

[0066] The processor 301 reads and executes computer program instructions stored in the memory 302 to implement any one of the power grid network attack chain risk assessment and threat situation awareness blocking methods in the above embodiments.

[0067] In one example, the blocking device for power grid network attack chain risk assessment and threat situation awareness may also include a communication interface 303 and a bus 310. Figure 3 As shown, the processor 301 , the memory 302 , and the communication interface 303 are connected via a bus 310 and communicate with each other.

[0068] The communication interface 303 is mainly used to implement communication between various modules, devices, units and / or equipment in the embodiments of the present application.

[0069] Bus 310 includes hardware, software, or both, coupling components of the grid cyberattack chain risk assessment and threat situation awareness blocking device to one another. By way of example, and not limitation, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industrial Standard Architecture (EISA) bus, a Front Side Bus (FSB), a HyperTransport (HT) interconnect, an Industrial Standard Architecture (ISA) bus, an InfiniBand interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local Area Network (VLB) bus, or other suitable buses, or a combination of two or more of these. Where appropriate, bus 310 may include one or more buses. Although the embodiments of the present application describe and illustrate specific buses, the present application contemplates any suitable bus or interconnect.

[0070] The blocking device for the risk assessment and threat situation awareness of the power grid network attack chain can execute the blocking method for the risk assessment and threat situation awareness of the power grid network attack chain in the embodiment of the present application based on the three-dimensional design model, thereby realizing the combination of Figure 1 and Figure 2 The paper describes a blocking method and system for risk assessment and threat situation awareness of power grid network attack chains.

[0071] In addition, in conjunction with the power grid network attack chain risk assessment and threat situation awareness blocking methods in the above-mentioned embodiments, embodiments of the present application may provide a computer storage medium for implementation. The computer storage medium stores computer program instructions; when the computer program instructions are executed by a processor, any of the power grid network attack chain risk assessment and threat situation awareness blocking methods in the above-mentioned embodiments is implemented.

[0072] It should be understood that the present application is not limited to the specific configurations and processes described above and illustrated in the figures. For the sake of brevity, a detailed description of known methods is omitted here. In the above embodiments, several specific steps are described and illustrated as examples. However, the method process of the present application is not limited to the specific steps described and illustrated. Those skilled in the art can make various changes, modifications, and additions, or change the order of the steps after understanding the spirit of the present application.

[0073] The functional blocks shown in the above block diagrams can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, and the like. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored in a machine-readable medium or transmitted over a transmission medium or communication link via a data signal carried in a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROMs, flash memory, erasable ROMs (EROMs), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, and the like. Code segments can be downloaded via a computer network such as the Internet or an intranet.

[0074] It should also be noted that the exemplary embodiments mentioned in this application describe some methods or systems based on a series of steps or devices. However, this application is not limited to the order of the above steps. In other words, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.

[0075] Aspects of the present disclosure have been described above with reference to flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present disclosure. It should be understood that each block in the flowcharts and / or block diagrams, as well as combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device to produce a machine such that execution of these instructions by the processor of the computer or other programmable data processing device enables the implementation of the functions / actions specified in one or more blocks in the flowcharts and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field programmable logic circuit. It should also be understood that each block in the block diagrams and / or flowcharts, as well as combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by dedicated hardware that performs the specified functions or actions, or by a combination of dedicated hardware and computer instructions.

[0076] The above description is only a specific embodiment of the present application. Those skilled in the art will clearly understand that for the convenience and brevity of description, the specific working processes of the systems, modules and units described above can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here. It should be understood that the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily think of various equivalent modifications or replacements within the technical scope disclosed in the present application, and these modifications or replacements should be included in the scope of protection of the present application.

Claims

1. A method for blocking risk assessment and threat situation awareness of power grid network attack chains, characterized in that: The method comprises: Obtain log data, network traffic data, and alarm data from the power system; Extracting the attack target, attack time, attack event type, attack event-affected device, and attack tool corresponding to each attack event from the log data, the network traffic data, and the alarm data; Based on the attack target, the attack time, the attack event type, the attack event-affected device, and the attack tool corresponding to each attack event, a first association relationship is established between each two attack events through a preset attack pattern library; Constructing a first directed attack graph structure, wherein a first node in the first directed attack graph structure is an attack event, a first edge in the directed attack graph structure is a directed edge from a first source node to a first target node, attributes of the first node include the attack target, the attack time, the attack event type, the attack event-affected device, and the attack tool, and an attribute of the first edge is the first association relationship; Based on the first directed attack graph structure, outputting a first blockability probability corresponding to each first node through a graph neural network model; Traversing all the first nodes, screening out all the first nodes whose first blockability probability is greater than a preset screening threshold as blockable nodes; Based on the blockable nodes, a corresponding threat situation awareness and blocking recommendation report is generated.

2. The method for blocking power grid network attack chain risk assessment and threat situation awareness according to claim 1 is characterized in that: Before generating a corresponding threat situation awareness and blocking recommendation report based on the blockable node, the method further includes: Based on the first directed attack graph structure, outputting, through the graph neural network model, a risk potential energy value of the blockable node and a propagation weight value of a first edge with the blockable node as a source node, wherein the risk potential energy value is a scalar value used to characterize the risk potential of the node, and the propagation weight value is a value used to characterize the ability of the risk to propagate from the source node to the target node; Determining a first total risk value before blocking based on the risk potential energy value of the blockable node and the propagation weight value of the first edge with the blockable node as the source node; Determining a first post-blocking total risk value based on the risk potential energy value of the blockable node, the first blockable probability of the blockable node, and the propagation weight value of the blockable node; Calculating a first risk difference based on the first pre-blocking total risk and the first post-blocking total risk; The generating of a corresponding threat situation awareness and blocking recommendation report based on the blockable node includes: Based on the first risk difference and the blockable node, a corresponding threat situation awareness and blocking recommendation report is generated.

3. The method for blocking power grid network attack chain risk assessment and threat situation awareness according to claim 2 is characterized in that: The training process of the graph neural network model includes: Obtaining historical log data, historical network traffic data, and historical alarm data of the power system; Extracting the historical attack target, historical attack time, historical attack event type, historical attack event-affected device, and historical attack tool corresponding to each historical attack event from the historical log data, the historical network traffic data, and the historical alarm data; Based on the historical attack target, the historical attack time, the historical attack event type, the historical attack event-affected device, and the historical attack tool corresponding to each historical attack event, a second association relationship is established between each two historical attack events through the preset attack pattern library; Constructing a second directed attack graph structure, wherein a second node in the second directed attack graph structure is the historical attack event, a second edge in the second directed attack graph structure is a directed edge from a second source node to a second target node, attributes of the second node include the historical attack target, the historical attack time, the historical attack event type, the historical attack event-affected device, and the historical attack tool, and an attribute of the second edge is the second association relationship; Constructing an initial graph neural network model, and performing simulated blocking training on the initial graph neural network model based on the second directed attack graph structure to obtain the risk potential energy value of the second node, the second blockability probability of the second node, and the propagation weight value of the second edge; determining a second total risk value before blocking based on the risk potential energy value of the second node and a second blockability probability of the second node; Determine a second post-blocking total risk value based on the risk potential value of the second node, the second blockability probability of the second node, and the propagation weight value of the second edge; Calculating a first loss value based on the second total risk value before blocking, the second total risk value after blocking, and the second blockable probability; When the first loss value reaches a preset loss threshold, the initial graph neural network model is used as the graph neural network model.

4. The method for blocking power grid network attack chain risk assessment and threat situation awareness according to claim 3 is characterized in that: The determining of a second total risk value before blocking based on the risk potential energy value of the second node and the second blockability probability of the second node includes: Adding the risk potential energy values ​​of all the second nodes to obtain the total risk potential energy value of the second nodes; Multiplying the propagation weight value of each second edge by the risk potential energy value of the corresponding second target node to obtain a first risk potential energy value; Adding all the first risk potential energy values ​​to obtain a total first risk potential energy value; The first risk potential energy sum is added to the second node risk potential energy sum to obtain the second pre-blocking total risk value.

5. The method for blocking power grid network attack chain risk assessment and threat situation awareness according to claim 4 is characterized in that: The determining of the second post-blocking total risk value based on the risk potential value of the second node, the second blockability probability of the second node, and the propagation weight value of the second edge includes: Calculating a blockability probability difference of each second node according to the second blockability probability; multiplying the blockability probability difference of each second node by the risk potential energy value of the corresponding second node to obtain a second risk potential energy value; Adding all the second risk potential energy values ​​to obtain a total second risk potential energy value; multiplying the blockability probability difference of the second node by the corresponding first risk potential energy value to obtain a third risk potential energy value; Adding all the third risk potential energy values ​​to obtain a total third risk potential energy value; The second risk potential energy value is added to the third risk potential energy value to obtain the second post-blocking total risk value.

6. The method for blocking power grid network attack chain risk assessment and threat situation awareness according to claim 3 is characterized in that: The calculating the first loss value based on the second total risk value before blocking, the second total risk value after blocking, and the second blockability probability includes: subtracting the second total risk value before blocking from the second total risk value after blocking to obtain a second risk difference; Adding all the second blockable probabilities to obtain a total second blockable probabilities; The first loss value is calculated based on the second blockable probability sum and the second risk difference.

7. The method for blocking power grid network attack chain risk assessment and threat situation awareness according to claim 6 is characterized in that: The calculating the first loss value based on the second blockable probability sum and the second risk difference value includes: Multiplying the sum of the second blockable probabilities by a preset blocking parameter value to obtain a total blocking value; The first loss value is obtained by subtracting the total blocking value from the second risk difference value.

Citation Information

Patent Citations

  • Network security situation awareness model and method based on attack graph

    CN110380896A

  • Network attack link tracking and threat situation reasoning method based on knowledge graph

    CN119544327A

  • Information large area flow monitoring method and system based on flow probe

    CN119544537A

  • Security situation assessment method of power network and related equipment

    CN119583121A

  • Web application firewall security defense method and system

    CN120074950A