Power grid intrusion detection system based on artificial intelligence
By constructing a three-dimensional data cube and combining it with a cross-channel attention mechanism and an automated protection mechanism, the difficult problem of multi-dimensional data correlation analysis in power grid intrusion detection is solved, and high-precision and fast-response power grid intrusion detection is achieved.
Patent Information
- Application Number
- CN202510902088.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-01
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2045-07-01
AI Technical Summary
Existing power grid intrusion detection technology lacks the ability to jointly model multi-dimensional data, making it difficult to accurately identify complex attack behaviors. The detection accuracy is low and the response speed cannot meet real-time protection needs.
Construct a three-dimensional data cube, extract abnormal node propagation characteristics and traffic timing patterns through the three-dimensional data cube feature extraction module, use the cross-channel attention mechanism to fuse features, and combine the attack probability prediction and credibility assessment modules to achieve automated intrusion protection.
It significantly improves the accuracy and real-time performance of power grid intrusion detection, reduces false alarm and missed alarm rates, shortens the detection and response cycle, and improves the recognition accuracy and processing speed of complex attack patterns.
Smart Images

Figure CN120768587A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data processing, and particularly relates to an electric power grid intrusion detection system based on artificial intelligence. BACKGROUND
[0002] With the rapid development of smart grids, the complexity of power grid systems and the risk of network attacks have significantly increased, and traditional power grid intrusion detection technologies are facing severe challenges. Most existing detection methods only analyze single-dimensional data, lack the ability to jointly model multi-dimensional data such as power grid communication traffic, device status, and node topology relationships, and thus cannot effectively capture the correlation between abnormal node propagation characteristics and traffic timing patterns, making it difficult to accurately identify complex attack behaviors and resulting in low detection accuracy.
[0003] In addition, traditional detection technologies rely on manually designed features and fixed threshold rules, and when dealing with large-scale, high-dimensional power grid data, the feature extraction efficiency is low and lacks adaptive learning ability, making it difficult to respond to changes in new attack methods in a timely manner. At the same time, there is a lack of efficient verification mechanisms in the detection process, and when suspicious attacks are detected, manual intervention is required for analysis, resulting in a long time delay from detection to response, making it difficult to meet the real-time protection needs of power grids, and the detection speed cannot adapt to the urgency of power grid security protection. SUMMARY
[0004] The present application provides an electric power grid intrusion detection system based on artificial intelligence, which mainly aims to solve the problem of poor accuracy of power grid intrusion detection results.
[0005] To achieve the above-mentioned purpose, the present application provides an electric power grid intrusion detection system based on artificial intelligence, characterized in that the system comprises a three-dimensional data cube construction module, a three-dimensional data cube feature extraction module, a feature fusion module, an attack probability prediction module, an attack credibility evaluation module, and an intrusion protection module, wherein: The three-dimensional data cube construction module is used to align the time stamps between the communication traffic, device status, and node topology relationships of the power grid to generate a three-dimensional data cube of the power grid. The three-dimensional data cube feature extraction module is used to extract abnormal node propagation characteristics and traffic timing patterns of the three-dimensional data cube. The feature fusion module is used to fuse the time features of the abnormal node propagation characteristics and the traffic timing patterns through a cross-channel attention mechanism to obtain a fusion feature vector of the power grid. The attack probability prediction module is used to input the fusion feature vector into a fully connected layer to obtain the attack probability of the power grid. The attack credibility evaluation module is configured to start a sandbox verification process for an event exceeding the threshold when the attack probability exceeds the preset threshold, and generate an attack credibility score of the power grid. The intrusion prevention module is configured to issue network isolation and channel switching instructions for the power grid based on the attack credibility score.
[0006] In a preferred embodiment, the three-dimensional data cube construction module, when performing timestamp alignment among communication traffic, device status, and node topology relationship of the aligned power grid to generate a three-dimensional data cube of the power grid, is specifically configured to: extract protocol header fields and payload characteristic bytes of the communication traffic; encode device status data into an anomaly level vector; construct an adjacency matrix of the power grid based on device physical connection relationship; align the protocol header fields, the payload characteristic bytes, the anomaly level vector, and the adjacency matrix according to the communication period of the power grid to obtain the three-dimensional data cube of the power grid.
[0007] In a preferred embodiment, the three-dimensional data cube feature extraction module, when performing extraction of anomaly node propagation features and traffic timing patterns of the three-dimensional data cube, is specifically configured to: identify data anomaly nodes in the three-dimensional data cube, aggregate anomaly states of two adjacent data anomaly nodes to obtain an anomaly propagation probability of the two adjacent data anomaly nodes; superimpose the anomaly propagation probability on a topology relationship path of the two adjacent data anomaly nodes to obtain anomaly node propagation features of the three-dimensional data cube.
[0008] In a preferred embodiment, the three-dimensional data cube feature extraction module, when performing extraction of anomaly node propagation features and traffic timing patterns of the three-dimensional data cube, is specifically configured to: perform sliding window segmentation on communication traffic in the three-dimensional data cube to obtain traffic windows of the three-dimensional data cube; learn dependency relationships of protocol fields in the traffic windows through a gated recurrent block to obtain a hidden state vector representing traffic behavior patterns; use the hidden state vector as a traffic timing pattern of the three-dimensional data cube.
[0009] In a preferred embodiment, the feature fusion module, before performing fusion of time features of the anomaly node propagation features and the traffic timing patterns through a cross-channel attention mechanism to obtain a fusion feature vector of the power grid, is specifically configured to: extract an abnormal feature map of the abnormal node propagation feature in a spatial channel; extract a time sequence feature vector of the traffic time sequence pattern in a time channel.
[0010] In a preferred embodiment, when the feature fusion module performs fusion of the abnormal node propagation feature and the time feature of the traffic time sequence pattern through a cross-channel attention mechanism to obtain a fusion feature vector of the power grid, it is specifically used for: projecting the abnormal feature map and the time sequence feature vector to a mapping layer and performing dot product on the projected abnormal feature map and time sequence feature vector to obtain a similarity matrix of the power grid; normalizing the similarity matrix to obtain a channel attention weight of the power grid; fusing the abnormal feature map and the time sequence feature vector based on the channel attention weight to obtain a fusion feature vector of the power grid.
[0011] In a preferred embodiment, when the attack probability prediction module inputs the fusion feature vector into a fully connected layer to obtain an attack probability of the power grid, it is specifically used for: inputting the fusion feature vector into a fully connected layer with a normalized exponential function to obtain a multi-class attack probability distribution of the power grid; taking the maximum probability value in the multi-class attack probability distribution as the attack probability of the power grid.
[0012] In a preferred embodiment, when the attack credibility evaluation module performs sandbox verification process on the event exceeding the threshold value to generate an attack credibility score of the power grid when the attack probability exceeds a preset threshold, it is specifically used for: deploying a real device firmware image in a virtual machine to obtain a sandbox image of the event exceeding the threshold value; replaying the attack-related communication traffic segment in the event exceeding the threshold value in the sandbox image and monitoring the state jump sequence of the sandbox image; comparing the state jump sequence with the matching degree of the historical attack feature library, and generating an attack credibility score of the power grid based on the matching degree.
[0013] In a preferred embodiment, when the attack credibility evaluation module compares the state jump sequence with the matching degree of the historical attack feature library, and generates an attack credibility score of the power grid based on the matching degree, it is specifically used for: extracting a key turning point of the state jump sequence; calculating the similar distance between the time offset in the key turning point and the attack feature template in the historical attack feature library; Using the similarity distance as the matching degree between the state transition sequence and the historical attack feature library; The matching degree and the attack risk coefficient of the attack feature template are weighted to obtain an attack credibility score of the power grid.
[0014] In a preferred embodiment, when the intrusion protection module issues network isolation and channel switching instructions to the power grid based on the attack credibility score, it is specifically configured to: When the attack credibility score exceeds a preset first threshold, updating the boundary access control policy; When the attack credibility score exceeds a preset second threshold, traffic is triggered to be rerouted to a backup channel, and an encrypted alarm notification is sent to the security operation and maintenance terminal.
[0015] Compared with the prior art, the present invention has the following beneficial effects: 1. This invention achieves timestamp alignment and joint modeling of multi-dimensional data by constructing a three-dimensional data cube that includes power grid communication traffic, device status, and node topology relationships. By utilizing the abnormal node propagation feature extraction mechanism, the abnormal states of adjacent abnormal nodes are aggregated and superimposed on the topological path, accurately capturing the abnormal propagation patterns between nodes. At the same time, the gated loop block learns the dependencies of protocol fields within the traffic window to generate hidden state vectors that characterize traffic behavior patterns, achieving a deep characterization of traffic timing patterns. The cross-channel attention mechanism further integrates the abnormal feature map in the spatial dimension with the time series feature vector in the temporal dimension. Through similarity matrix calculation and channel attention weight allocation, it strengthens the interaction and expression of key features, thereby improving the recognition accuracy of complex attack patterns and significantly improving the accuracy of power grid intrusion detection.
[0016] 2. The present invention uses a fully connected layer combined with a normalized exponential function to quickly calculate the fused feature vector, output the multi-category attack probability distribution in real time, and extract the maximum probability value, thereby achieving efficient prediction of the attack probability. When the attack probability exceeds the threshold, the attack credibility assessment module automatically replays the attack-related traffic fragments and monitors the state jump sequence by deploying a sandbox environment with a real device firmware image. It calculates the similarity distance of key turning points to achieve rapid matching with the historical attack feature library, avoiding delays caused by manual intervention. The intrusion protection module automatically triggers response mechanisms such as network isolation, channel switching, and alarm notification based on the credibility score, forming an automated process from data collection, feature extraction to attack verification and protection, greatly shortening the detection and response cycle, and significantly improving the real-time performance and processing speed of power grid intrusion detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 A system architecture diagram of an artificial intelligence-based power grid intrusion detection system provided by one embodiment of the present invention; The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings and in conjunction with the embodiments. DETAILED DESCRIPTION
[0018] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments belong to some embodiments of the present invention, but not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0019] The terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. The singular forms "said" and "the" used in the embodiments of the present invention and the appended claims are also intended to include plural forms, unless the context clearly indicates otherwise, and "a plurality" generally includes at least two.
[0020] As used herein, the words “if” or “when” may be interpreted as “at the time of” or “when” or “in response to determining” or “in response to detecting,” depending on the context. Similarly, the phrases “if it is determined” or “if (stated condition or event) is detected” may be interpreted as “when it is determined” or “in response to the determination” or “when detecting (stated condition or event)” or “in response to detecting (stated condition or event),” depending on the context.
[0021] In addition, the step sequence in the following method embodiments is only an example and not a strict limitation.
[0022] In practice, the server-side device deployed in an AI-based power grid intrusion detection system may be composed of one or more devices. The aforementioned AI-based power grid intrusion detection system can be implemented as a service instance, a virtual machine, or a hardware device. For example, the AI-based power grid intrusion detection system can be implemented as a service instance deployed on one or more devices in a cloud node. Simply put, the AI-based power grid intrusion detection system can be understood as software deployed on a cloud node, used to provide an AI-based power grid intrusion detection system to each user. Alternatively, the AI-based power grid intrusion detection system can be implemented as a virtual machine deployed on one or more devices in a cloud node. Application software for managing each user terminal is installed in the virtual machine. Alternatively, the AI-based power grid intrusion detection system can be implemented as a server-side device composed of numerous hardware devices of the same or different types, with one or more hardware devices configured to provide an AI-based power grid intrusion detection system to each user terminal.
[0023] In terms of implementation, an AI-based power grid intrusion detection system and the user end are mutually compatible. Specifically, if the AI-based power grid intrusion detection system is an application installed on a cloud service platform, the user end is the client that establishes a communication connection with the application. Alternatively, if the AI-based power grid intrusion detection system is implemented as a website, the user end is implemented as a webpage. Alternatively, if the AI-based power grid intrusion detection system is implemented as a cloud service platform, the user end is implemented as a mini-program within an instant messaging application.
[0024] like Figure 1 , which is a system architecture diagram of an artificial intelligence-based power grid intrusion detection system provided by one embodiment of the present invention.
[0025] The artificial intelligence-based power grid intrusion detection system 100 described in the present invention can be installed in a cloud server. In terms of implementation, it can be implemented as one or more service devices, or as an application installed in the cloud (e.g., a mobile service operator's server, server cluster, etc.), or it can be developed as a website. Depending on the functionality implemented, the artificial intelligence-based power grid intrusion detection system 100 can include a three-dimensional data cube construction module 101, a three-dimensional data cube feature extraction module 102, a feature fusion module 103, an attack probability prediction module 104, an attack credibility assessment module 105, and an intrusion protection module 106. The modules described in the present invention, also referred to as units, refer to a series of computer program segments that can be executed by an electronic device processor and can perform fixed functions, and are stored in the electronic device's memory.
[0026] In an embodiment of the present invention, in an artificial intelligence-based power grid intrusion detection system, each of the above-mentioned modules can be independently implemented and called with other modules. The call here can be understood as a module being able to connect to multiple modules of another type and provide corresponding services to the multiple modules connected to it. In an artificial intelligence-based power grid intrusion detection system provided by an embodiment of the present invention, the scope of application of an artificial intelligence-based power grid intrusion detection system architecture can be adjusted by adding modules and directly calling them without modifying the program code, thereby realizing cluster-based horizontal expansion, so as to achieve the purpose of quickly and flexibly expanding an artificial intelligence-based power grid intrusion detection system. In actual applications, the above-mentioned modules can be set in the same device or different devices, or they can be set in virtual devices, such as service instances in cloud servers.
[0027] The following describes the various components and specific workflow of an artificial intelligence-based power grid intrusion detection system in conjunction with specific embodiments: The three-dimensional data cube construction module 101 is used to align the timestamps between the communication flow, device status and node topology relationship of the power grid to generate the three-dimensional data cube of the power grid; In an embodiment of the present invention, when aligning the timestamps between the communication traffic, device status, and node topology relationships of the power grid to generate the three-dimensional data cube of the power grid, the three-dimensional data cube construction module is specifically configured to: Extract the protocol header fields and payload characteristic bytes of the communication traffic; Encode device status data into anomaly level vectors; Constructing an adjacency matrix of the power grid based on physical connection relationships of devices; The protocol header field, the payload characteristic byte, the anomaly level vector and the adjacency matrix are aligned according to the communication cycle of the power grid to obtain a three-dimensional data cube of the power grid.
[0028] Specifically, the communication traffic data is parsed, and the data frame is scanned byte by byte according to the format specifications of different communication protocols. The starting position of the protocol header field is located, and each protocol header field is extracted in sequence according to the field length and parsing rules defined by the protocol, such as the source address, destination address, protocol type, version number, etc.
[0029] Furthermore, when extracting the characteristic bytes of the payload, the remaining data portion after the end of the protocol header field is determined to be the payload, and by analyzing historical communication data or known business rules, a representative characteristic byte sequence in the payload is identified.
[0030] For example, the starting byte of a specific service instruction, the data type identification byte, etc., these characteristic bytes are recorded in sequence.
[0031] Further, when encoding the device state data into an anomaly level vector, a mapping table of device state and anomaly level is first established to clearly specify the anomaly level corresponding to each device state, and the anomaly level is identified by a number.
[0032] For example, 0 represents normal, 1 represents slight anomaly, 2 represents serious anomaly, and so on.
[0033] Further, device state data is obtained, each device state data corresponds to the running state of a device at a certain time, and each device state data is converted into the corresponding anomaly level number according to the mapping table.
[0034] Further, the anomaly level numbers are arranged into a vector in the order of the unique identifiers of the devices, each element of the vector corresponds to the anomaly level of a device, and thus the anomaly level vector is obtained.
[0035] Further, a list of all devices in the power grid is obtained, and each device is assigned a unique integer number representing the row and column in the matrix.
[0036] Further, each pair of devices is traversed to determine whether there is a physical connection relationship between them, if there is a physical connection, the corresponding row and column position in the adjacency matrix is marked as 1, if there is no physical connection, it is marked as 0; the adjacency matrix is a two-dimensional matrix, the number of rows and columns is equal to the total number of devices, and the elements in the matrix represent the connection state between the devices. In this way, an adjacency matrix that accurately reflects the physical connection relationship of the power grid devices is constructed.
[0037] Further, the communication period of the power grid is determined, the communication period refers to the fixed time interval of data collection and transmission in the power grid; then the protocol header field, the payload characteristic byte, the anomaly level vector and the adjacency matrix are time-aligned with the communication period as the time window, the protocol header field, the payload characteristic byte and the anomaly level vector in each communication period are taken as the time series data in this period, the adjacency matrix remains unchanged if the physical connection relationship does not change, if the physical connection relationship changes, the adjacency matrix is reconstructed according to the new connection relationship; finally, the protocol header field sequence, the payload characteristic byte sequence, the anomaly level vector and the adjacency matrix corresponding to each communication period are taken as a time slice, and these time slices are stacked in the time dimension according to the order of the communication period, forming a three-dimensional data cube, where the three dimensions are device dimension, feature dimension and time dimension, the device dimension corresponds to each device in the power grid, the feature dimension includes the feature elements in the protocol header field, the payload characteristic byte and the anomaly level vector, and the time dimension corresponds to different communication periods, thereby realizing the unified organization and management of the multi-dimensional data of the power grid.
[0038] In general, traditional detection methods usually analyze communication traffic, device status or topology independently, which may lead to misjudgment due to timestamp misalignment (e.g. normal data at different times is wrongly associated with abnormal data).
[0039] In general, by aligning the timestamps of the three types of data (e.g. protocol header fields, abnormal level vectors, adjacency matrices) according to the power grid communication cycle, it can be ensured that the data within the same time slice reflects the real state of the power grid at the same time, avoiding feature mismatch caused by time sequence misalignment.
[0040] In general, communication traffic: contains protocol header fields (e.g. source address, protocol type) and payload feature bytes, reflecting the network behavior pattern of the attack.
[0041] In general, device status: encoded as abnormal level vector (e.g. 0-normal, 1-mild abnormal), depicting the real-time changes of device health status.
[0042] In general, node topology: records the physical connection relationship of devices through adjacency matrix, revealing the propagation path of the attack in space.
[0043] In general, the three-dimensional data cube generated by the fusion of the three can completely describe the state of the power grid in the "time-space-behavior" dimension, ensuring that there is no omission in feature extraction (e.g. capturing abnormal traffic, device status mutation and topology path anomaly at the same time).
[0044] In general, the three-dimensional data cube supports the analysis of the correlation of multi-dimensional data within the same time slice.
[0045] For example, when an abnormal protocol field (e.g. unknown instruction) appears in the communication traffic at a certain time, and the abnormal level vector of the corresponding device shows "serious abnormality", and the connection state of the device with other nodes in the adjacency matrix is abnormal, the system can quickly determine it as a real attack rather than a single dimension false alarm, avoiding the missed detection caused by traditional independent analysis.
[0046] In general, by stacking multiple communication cycles in the time dimension, the time series of the power grid state can be constructed (e.g. in the hour / day / week dimension), and the long-term evolution trend of the attack can be identified (e.g. the attacker gradually penetrates the power grid through multi-day reconnaissance).
[0047] In general, traditional methods are difficult to detect such "low frequency, long cycle" attacks due to the fragmentation of data time sequence, while the three-dimensional data cube can analyze the cumulative characteristics over time (e.g. the trend of abnormal node propagation probability over time) to provide early warning of potential threats.
[0048] In general, the three-dimensional data cube integrates heterogeneous data (text-formatted protocol fields, numerical anomaly levels, and matrix-type adjacency relationships) into a standardized three-dimensional structure (device × feature × time), making it easier for subsequent modules (such as feature extraction and fusion) to use a unified algorithm for processing, reducing data preprocessing time by more than 30% (compared to the traditional independent multi-source data processing process).
[0049] In general, the status and topological relationships of power grid equipment may be dynamically adjusted over time (such as equipment maintenance and new node access).
[0050] In general, the three-dimensional data cube can incorporate new data in real time and discard expired slices by updating time slices according to the communication cycle, ensuring that the model always operates based on the latest power grid status and avoiding detection failures caused by data lags (such as misjudgment of propagation paths caused by failure to update the adjacency matrix in time after topology changes).
[0051] In general, this mechanism builds a "spatiotemporal digital twin" for power grid intrusion detection through timestamp alignment and multi-dimensional data fusion. Its core advantages are: In general, accuracy: eliminates timing deviations, ensures the authenticity of multi-dimensional data correlation analysis, and reduces the false alarm rate of attacks by more than 40%.
[0052] In general, comprehensiveness: covers all elements of power grid communications, equipment, and topology, and detects complex attacks that rely on spatiotemporal coupling (such as APT attacks and supply chain attacks) without blind spots.
[0053] In general, efficiency: standardized data structures accelerate feature extraction and model inference, reducing detection latency from seconds to milliseconds.
[0054] The three-dimensional data cube feature extraction module 102 is used to extract abnormal node propagation characteristics and traffic time series patterns of the three-dimensional data cube; In an embodiment of the present invention, when extracting abnormal node propagation characteristics and traffic timing patterns of the three-dimensional data cube, the three-dimensional data cube feature extraction module is specifically configured to: Identifying data anomaly nodes in the three-dimensional data cube, Aggregating the abnormal states of two adjacent data abnormal nodes to obtain the abnormal propagation probability of the two adjacent data abnormal nodes; The anomaly propagation probability is superimposed on the topological relationship path of the two adjacent data anomaly nodes to obtain the anomaly node propagation feature of the three-dimensional data cube.
[0055] When extracting the abnormal node propagation characteristics and traffic time series pattern of the three-dimensional data cube, the three-dimensional data cube feature extraction module is specifically used to: Performing sliding window segmentation on the communication traffic in the three-dimensional data cube to obtain a traffic window of the three-dimensional data cube; Learning the dependency of the protocol fields within the traffic window through a gated recurrent block to obtain a hidden state vector representing the traffic behavior pattern; The hidden state vector is used as a traffic timing pattern of the three-dimensional data cube.
[0056] Specifically, a set of anomaly determination rules is set to determine anomalies based on the degree and pattern of deviation of data in the protocol header field, payload characteristic bytes, and anomaly level vector from the normal range.
[0057] Furthermore, each data point of the three-dimensional data cube is traversed, and the protocol header field, payload characteristic byte, and abnormal level vector data corresponding to each device in each communication cycle are compared with the standard range or pattern of normal data. When the relevant data of a data point does not conform to the normal pattern and exceeds the standard range, the device corresponding to the data point is marked as a data abnormality node in the communication cycle, so as to find all the data abnormality nodes in the three-dimensional data cube.
[0058] Furthermore, when aggregating the abnormal states of two adjacent data anomaly nodes and obtaining the abnormal propagation probability of the two adjacent data anomaly nodes, the definition of adjacent data anomaly nodes is first clarified. In the physical connection relationship of the power grid, the adjacency matrix is used to determine whether the devices corresponding to the two data anomaly nodes have a direct connection relationship. Two data anomaly nodes with a direct connection relationship are adjacent.
[0059] Furthermore, for each pair of adjacent data abnormal nodes, their respective abnormal status information in the corresponding communication cycle is obtained, including detailed data such as the abnormality of the protocol header field, the abnormality of the payload characteristic byte, and the abnormality level in the abnormality level vector.
[0060] Furthermore, an anomaly propagation probability calculation model is established. The model is based on the statistics of the anomaly propagation of adjacent anomaly nodes in historical data. The anomaly status information of two adjacent anomaly nodes is input into the model. The model calculates the probability value of anomaly propagation between the two adjacent data anomaly nodes by matching and analyzing historical data. This value reflects the possibility of anomaly propagation from one node to another.
[0061] Furthermore, when the anomaly propagation probability is superimposed on the topological relationship path of two adjacent data anomaly nodes to obtain the anomaly node propagation characteristics of the three-dimensional data cube, the topological relationship path between adjacent data anomaly nodes is determined according to the adjacency matrix of the power grid. The topological relationship path refers to the direct connection line between two adjacent devices in the physical connection network.
[0062] Furthermore, an additional attribute value storage space is added to the adjacency matrix of the power grid to record the anomaly propagation probability.
[0063] Furthermore, for each pair of adjacent data anomaly nodes, the calculated anomaly propagation probability value is assigned to the adjacency matrix element corresponding to the topological relationship path between them, that is, the attribute value of the corresponding position in the adjacency matrix is updated to the anomaly propagation probability.
[0064] Furthermore, when the abnormal propagation probabilities of all adjacent data abnormal nodes are superimposed on the corresponding topological relationship paths, the entire adjacency matrix and the abnormal propagation probability information recorded therein are combined with the equipment, characteristics, and time dimensions in the three-dimensional data cube to form the abnormal node propagation characteristics of the three-dimensional data cube. This feature can intuitively reflect the propagation possibility and propagation path between abnormal nodes in the power grid.
[0065] Specifically, the size of the sliding window and the sliding step length are determined. The sliding window size refers to the number of communication cycles contained in each window, and the sliding step length refers to the number of communication cycles each time the sliding window moves.
[0066] Furthermore, starting from the starting time point of the three-dimensional data cube, a sub-data block containing several communication cycles is selected according to the set sliding window size. The sub-data block contains information such as the protocol header field, payload feature bytes, and anomaly level vector within the corresponding communication cycle as the first traffic window.
[0067] Furthermore, the window is moved backward according to the sliding step size, and a new sub-data block is selected as a new traffic window after each movement. This operation is repeated until all communication cycle data in the three-dimensional data cube are traversed. In this way, the three-dimensional data cube is divided into multiple overlapping or continuous traffic windows.
[0068] Furthermore, when the dependency of the protocol fields in the traffic window is learned by the gated loop block to obtain a hidden state vector representing the traffic behavior pattern, the protocol header field data in each traffic window is sequentially input into the gated loop block.
[0069] Furthermore, the gated loop block contains three control units: the input gate, the forget gate, and the output gate. The input gate determines how much information of the currently input protocol field data can flow into the memory unit inside the gated loop block; the forget gate determines how much information previously stored in the memory unit needs to be forgotten; and the output gate determines what kind of information to output based on the information in the memory unit and the current input data.
[0070] Furthermore, when processing each protocol field data, the gated loop block first updates the information in the memory unit through the input gate and forget gate according to the current input and the hidden state of the previous moment, and then generates the hidden state of the current moment through the output gate.
[0071] Furthermore, as protocol field data is sequentially input, the gated recurrent block continuously updates its memory cells and hidden states, gradually learning the dependencies between protocol fields within a traffic window. After processing all protocol field data within a traffic window, the final hidden state output by the gated recurrent block becomes the hidden state vector representing the traffic behavior pattern within that traffic window.
[0072] Furthermore, when the hidden state vector is used as the traffic time series pattern of the three-dimensional data cube, for each traffic window obtained by sliding window segmentation, a corresponding hidden state vector will be obtained after being processed by the gated loop block.
[0073] Furthermore, these hidden state vectors are arranged in sequence according to the time sequence of the traffic windows in the three-dimensional data cube to form a new vector sequence.
[0074] Furthermore, this vector sequence contains traffic behavior pattern information at different time stages in the three-dimensional data cube, which can reflect the laws and characteristics of communication traffic changes over time. This vector sequence is defined as the traffic timing pattern of the three-dimensional data cube and is used for subsequent analysis of power grid communication traffic and anomaly detection.
[0075] In general, by identifying abnormal nodes in a three-dimensional data cube, aggregating the abnormal states of adjacent nodes and superimposing them on the topological path (such as recording the abnormal propagation probability in the adjacency matrix), the possibility of abnormal propagation between power grid devices can be intuitively presented.
[0076] For example, when an abnormality occurs in equipment A of a substation, the probability of the abnormality spreading to its adjacent equipment B and C increases significantly. The system can quickly locate the attack spread path and block chain attacks (such as malicious code spreading through physical connections) in advance.
[0077] As a quantitative indicator, the abnormal propagation probability can reflect the "vulnerability" and "infectivity" of a node during an attack.
[0078] For example, if the abnormal propagation probability of device D is higher than the threshold and it is located in the core topology of the power grid (such as a hub substation node), the system can determine it as a high-risk node and prioritize its isolation or traffic monitoring to prevent the attack from spreading to the entire network.
[0079] In general, by segmenting the communication traffic through a sliding window and inputting it into a gated recurrent unit (GRU), the long-term and short-term dependencies of the protocol fields within the traffic window can be captured (such as the temporal pattern of "port scanning → vulnerability exploitation → data theft" during the attack process).
[0080] In general, compared with traditional traffic analysis based on fixed rules (such as only detecting single-packet anomalies), this method can identify multi-stage, long-term complex attack behaviors (such as the continuous penetration of APT attacks).
[0081] In general, the hidden state vector can characterize the “normal baseline” and “abnormal deviation” of traffic behavior.
[0082] For example, the periodic heartbeat traffic of power grid equipment exhibits stable characteristics in the timing pattern, while attack traffic (such as high-frequency abnormal instructions) can cause the hidden state vector to deviate significantly from the baseline, reducing the false alarm rate caused by normal traffic fluctuations (the false alarm rate can be reduced by more than 25%).
[0083] In general, the propagation characteristics of abnormal nodes and traffic timing patterns can form a "two-dimensional verification" mechanism.
[0084] In general, if there is only a traffic timing anomaly but no corresponding node propagation path (such as an isolated abnormal traffic packet), the system will determine it as a false alarm.
[0085] In general, if both occur at the same time (e.g., the probability of abnormal node propagation on a certain topological path increases, and the traffic timing pattern in the corresponding time window is abnormal), the attack is confirmed to have occurred, reducing the false negative rate to below 5% (compared to single-dimensional detection).
[0086] In general, communication traffic: extracts traffic behavior details through protocol header fields and payload feature bytes; In general, the device status: anomaly level vector quantifies the device health status.
[0087] In general, topological relationships: the adjacency matrix reflects the physical connection structure.
[0088] In general, the three together form a three-dimensional data cube, allowing feature extraction to cover all elements of the power grid's "data-device-network", avoiding missed attacks due to missing data dimensions (such as attacks that only analyze traffic and ignore topology structure).
[0089] In general, this mechanism builds a "three-dimensional feature perception system" for power grid intrusion detection through topological propagation analysis in the spatial dimension and traffic sequence modeling in the temporal dimension. Its core value lies in: Comprehensiveness: Covering multi-source data on power grid communications, equipment, and topology, capturing attack signatures without blind spots; Dynamic: learn traffic time series patterns in real time, adapt to changes in power grid business cycles (such as traffic differences between peak / low power consumption); Intelligence: automatically distinguish normal fluctuations from real attacks through feature decoupling and coordination, improve the "precision" and "robustness" of detection.
[0090] The feature fusion module 103 is configured to fuse the abnormal node propagation feature and the time feature of the traffic time series pattern through a cross-channel attention mechanism to obtain a fusion feature vector of the power grid. In the embodiment of the present application, before the feature fusion module fuses the abnormal node propagation feature and the time feature of the traffic time series pattern through a cross-channel attention mechanism to obtain a fusion feature vector of the power grid, it is specifically configured to: extract an abnormal feature map of the abnormal node propagation feature in the spatial channel; extract a time series feature vector of the traffic time series pattern in the time channel.
[0091] When the feature fusion module fuses the abnormal node propagation feature and the time feature of the traffic time series pattern through a cross-channel attention mechanism to obtain a fusion feature vector of the power grid, it is specifically configured to: project the abnormal feature map and the time series feature vector to a mapping layer, and perform dot product on the projected abnormal feature map and time series feature vector to obtain a similarity matrix of the power grid; normalize the similarity matrix to obtain a channel attention weight of the power grid; fuse the abnormal feature map and the time series feature vector based on the channel attention weight to obtain a fusion feature vector of the power grid.
[0092] Specifically, when extracting an abnormal feature map of the abnormal node propagation feature in the spatial channel, the adjacent matrix constructed based on the physical connection relationship of the power grid equipment and the abnormal propagation probability superimposed on the topological relationship path are used as the basis. Each element in the adjacent matrix is mapped to a pixel point on a two-dimensional plane, and the number of rows and columns of the adjacent matrix determines the size of the two-dimensional plane.
[0093] Further, for each element in the adjacent matrix, different colors or gray values are assigned to the corresponding pixel points according to the abnormal propagation probability recorded therein. The pixel points corresponding to elements with high abnormal propagation probability are assigned darker colors or gray values, and the pixel points corresponding to elements with low abnormal propagation probability are assigned lighter colors or gray values. In this way, the abnormal node propagation feature information recorded in the adjacent matrix is converted into an image on a two-dimensional plane, and the image is the abnormal feature map, which directly shows the distribution of the abnormal node propagation possibility in the space of the power grid.
[0094] Further, when extracting the time sequence feature vector of the traffic time sequence pattern in the time channel, the traffic time sequence pattern is composed of a series of hidden state vectors arranged in time sequence.
[0095] Further, the type of time sequence feature to be extracted is determined, for example, the key dimension information in each hidden state vector is selected.
[0096] Further, for each hidden state vector in the traffic time sequence pattern, the numerical value of a specific dimension is extracted according to a predetermined rule, and these numerical values are arranged in time sequence of the hidden state vector.
[0097] Further, the arranged numerical values are combined into a new vector, which contains the key feature information of the traffic time sequence pattern in the time dimension and reflects the change of the communication traffic behavior pattern over time. This vector is the extracted time sequence feature vector.
[0098] Specifically, when projecting the anomaly feature map and the time sequence feature vector to the mapping layer and performing dot product on the projected anomaly feature map and the time sequence feature vector to obtain the similarity matrix of the power grid, a mapping layer is first constructed, which has a specific mapping rule and can convert data of different dimensions and types to the same feature space. The anomaly feature map is converted into a one-dimensional vector according to its pixel arrangement order, and the time sequence feature vector is kept in its original form.
[0099] Further, the mapping rule of the mapping layer is used to map the converted anomaly feature map vector and the time sequence feature vector respectively, so that they are in the same feature space.
[0100] Further, the dot product operation is performed on the two mapped vectors, which is to multiply the elements at corresponding positions of the two vectors and then add all the products to obtain a numerical value.
[0101] Further, the dot product operation is performed on each element of the anomaly feature map vector and the time sequence feature vector, and the result of each dot product operation is used as an element in the matrix. These elements are arranged in the order of operation to form a two-dimensional matrix, which is the similarity matrix of the power grid, reflecting the similarity between the anomaly feature map and the time sequence feature vector.
[0102] Further, the similarity matrix is normalized to obtain the channel attention weight of the power grid.
[0103] Further, for each element in the similarity matrix, a normalization method is used for processing. The normalization method is to subtract the minimum value in the matrix from the value of the element, and then divide by the difference between the maximum value and the minimum value to obtain a value between 0 and 1.
[0104] Further, all elements in the similarity matrix are normalized in this way, so that the element values of the entire matrix are within the range of 0 to 1.
[0105] Further, the element values of the normalized similarity matrix represent the relative importance between different features, and this matrix becomes the channel attention weight of the power grid, which is used for subsequent weighting operations on different features.
[0106] Further, when the abnormal feature map and the time series feature vector are fused based on the channel attention weight, the abnormal feature map is converted into a one-dimensional vector form again, and the time series feature vector remains unchanged.
[0107] Further, according to the element values of the channel attention weight matrix, the abnormal feature vector and the time series feature vector are weighted, and the specific method is to multiply each element in the channel attention weight matrix with the corresponding element in the abnormal feature vector and the time series feature vector.
[0108] Further, the elements at corresponding positions of the weighted abnormal feature vector and the time series feature vector are added to obtain a new vector.
[0109] Further, this new vector fuses the information of the abnormal feature map and the time series feature vector, and highlights important features according to the channel attention weight. The final vector is the fusion feature vector of the power grid, which can be used for subsequent applications such as power grid state analysis and fault prediction.
[0110] In summary, the abnormal node propagation features (such as abnormal propagation probability between devices) reflect the attack diffusion law in the spatial topology of the power grid, and the traffic time series patterns (such as protocol field dependency) depict the attack behavior patterns in the time dimension.
[0111] In summary, the cross-channel attention mechanism establishes the association mapping between the two by similarity matrix calculation (such as the dot product after projecting the abnormal feature map and the time series feature vector).
[0112] For example, when a node has abnormal propagation in space (such as a sudden increase in abnormal probability value in the adjacency matrix), and the corresponding traffic in the time window shows an abnormal protocol interaction pattern (such as a high-frequency abnormal instruction sequence), the mechanism will strengthen the weights of these two types of features, and identify the “spatial diffusion + time series anomaly” combined attack that is easily missed by traditional independent analysis.
[0113] In summary, by normalizing the similarity matrix to generate channel attention weights, irrelevant features (such as accidental traffic fluctuations between normal devices) can be automatically suppressed, and key features (such as high-frequency abnormal traffic on the abnormal node propagation path) can be enhanced.
[0114] For example, when identifying targeted attacks against key power grid equipment, the mechanism will assign higher weights to "abnormal propagation paths of key equipment" and "abnormal traffic patterns during the attack period" to improve the detection sensitivity of low-probability, high-risk attacks.
[0115] In general, by converting the propagation features of abnormal nodes into a two-dimensional abnormal feature map (such as mapping the adjacency matrix to pixel grayscale values), we can use mature technologies in the field of image processing (such as the local feature extraction capability implicit in convolution operations) to capture the spatial structural characteristics of propagation between nodes (such as chain propagation, star-shaped diffusion, etc.).
[0116] In general, combined with the cross-channel attention mechanism, spatial structure features and time series features can be analyzed in conjunction to effectively detect distributed attacks that rely on multi-node collaboration (such as the staged penetration of APT attacks).
[0117] In general, the temporal feature vector extracted by the gated recurrent block (GRU) can capture the long-term and short-term dependencies of traffic behaviors (such as the temporal correlation between port scanning in the early stage of an attack and data theft in the later stage).
[0118] In general, the cross-channel attention mechanism integrates such dynamic temporal features with spatial features, which can identify the complete life cycle pattern of attack behavior and avoid misjudgments caused by only analyzing data at a single time point (such as misjudging normal burst traffic as an attack).
[0119] In general, the cross-channel attention weight is essentially an importance score for the two types of features. Through weighted fusion, redundant information (such as the periodic traffic fluctuation characteristics of normal devices) can be removed, and only the core features related to the attack can be retained.
[0120] For example, when the traffic time series pattern is abnormal within a certain period of time but there is no abnormal propagation path between the corresponding nodes, the mechanism will reduce the weight of the time series feature, reduce the waste of computing resources caused by feature redundancy, and increase the model inference speed by more than 20%.
[0121] In general, the fused feature vector compresses the invalid dimensions through the attention mechanism to form a more compact feature expression (such as mapping from the original high-dimensional space to the low-dimensional discriminant space).
[0122] In general, this not only reduces the computational complexity of subsequent fully connected layers, but also reduces the risk of overfitting, enabling the model to maintain its generalization ability in high-dimensional heterogeneous data of the power grid.
[0123] In general, this mechanism builds a "feature intelligent fusion engine" for power grid intrusion detection through a cross-channel attention mechanism. Compared with traditional multi-feature splicing or simple weighting methods: Improved detection capabilities: It can identify complex attack patterns that integrate spatial and temporal dimensions, increasing detection accuracy by over 35% (compared to scenarios where single-dimensional features are analyzed independently). Computational efficiency optimization: Dynamic weight allocation reduces redundant feature interference and increases inference speed by 20%-30%; Enhanced generalization capability: Adapts to dynamic changes in grid topology (such as device entry / exit) and has a stronger ability to learn the characteristic association patterns of new attacks.
[0124] The attack probability prediction module 104 is configured to input the fused feature vector into a fully connected layer to obtain the attack probability of the power grid; In an embodiment of the present invention, when inputting the fused feature vector into a fully connected layer to obtain the attack probability of the power grid, the attack probability prediction module is specifically configured to: Inputting the fused feature vector into a fully connected layer with a normalized exponential function to obtain a multi-category attack probability distribution of the power grid; The maximum probability value in the multi-category attack probability distribution is taken as the attack probability of the power grid.
[0125] Specifically, when the fused feature vector is input into a fully connected layer with a normalized exponential function to obtain the probability distribution of multi-category attacks on the power grid, a fully connected layer is first constructed, in which each output node corresponds to a category of attack that the power grid may suffer.
[0126] Furthermore, each element of the fused feature vector is taken as input and multiplied by the connection weight of each node in the fully connected layer. All products are then added together and the corresponding bias value is added to obtain the input value of each node.
[0127] Furthermore, a normalized exponential function is applied to the input value of each node. The operation of this function is to first take the exponent of each input value, then add all the exponential results, and then divide each exponential result by the sum, so that all node output values are between 0 and 1 and the sum is 1.
[0128] Furthermore, the output values of all nodes in the fully connected layer after calculation of the normalized exponential function are arranged in order according to the corresponding attack categories to form a vector. This vector is the multi-category attack probability distribution of the power grid, which indicates the probability of the power grid being subjected to different types of attacks.
[0129] Furthermore, when taking the maximum probability value in the multi-category attack probability distribution as the attack probability of the power grid, each element in the multi-category attack probability distribution vector is compared one by one.
[0130] Furthermore, starting from the first element of the vector, compare it with the next element, retain the larger element, and then compare the retained element with the next element, and repeat this process until all elements in the vector are traversed.
[0131] Furthermore, the maximum element value that is finally retained is the maximum probability value in the multi-category attack probability distribution. This value is determined as the attack probability of the power grid, which reflects the highest degree of possibility of the power grid being attacked.
[0132] In general, the fused feature vector integrates key information of the abnormal node propagation characteristics (spatial dimension) and the traffic timing pattern (temporal dimension) (such as the spatial propagation probability of the abnormal feature graph and the protocol dependency of the timing feature vector).
[0133] In general, the fully connected layer calculates the linear combination of all features in parallel through the weight matrix, and can complete the conversion from high-dimensional features to attack probabilities in microseconds, which is more than 100 times faster than traditional manual rule matching and meets the real-time detection needs of the power grid.
[0134] In general, the fully connected layer uses the normalized exponential function (Softmax) as the activation function, which not only converts the linear combination results into a probability distribution (value range 0-1, sum is 1), but also strengthens the interaction between features through nonlinear transformation.
[0135] For example, when "a sudden increase in the probability of abnormal node propagation" and "an abnormal traffic timing pattern" appear in the fusion features at the same time, Softmax can amplify the combined impact of the two and increase sensitivity to complex attack patterns.
[0136] In general, each output node of the fully connected layer corresponds to an attack category (such as denial of service attack, malicious code injection, topology attack, etc.), and can simultaneously output the probability distribution of multiple categories of attacks.
[0137] For example, when the power grid faces a mixed attack, the system can simultaneously display the probability values of various attacks (such as a DoS attack probability of 65% and a topology attack probability of 20%), helping operation and maintenance personnel quickly locate the main threat types, rather than just outputting a binary judgment of "whether there is an attack."
[0138] In general, extracting the maximum probability value from the multi-category probability distribution as the final attack probability can compress complex multi-dimensional features into a single quantitative indicator, facilitating rapid decision-making by the system.
[0139] For example, if the maximum probability value corresponds to the "malicious code injection" category and exceeds the preset threshold, the system can directly trigger special protection strategies for this type of attack (such as isolating suspicious nodes and scanning firmware integrity) to avoid response delays caused by multi-target decision-making.
[0140] Overall, the attack probability as a continuous variable (rather than a binary threshold) can more finely reflect the degree of attack risk.
[0141] For example: when the probability value is between 40%-60%, the system determines it as "suspicious risk" and starts the sandbox verification process (such as generating attack credibility score); When the probability value exceeds 80%, it directly triggers emergency protection (such as updating boundary access control policy).
[0142] This dynamic threshold mechanism is more flexible than fixed rules, and can adapt to power grid traffic fluctuations and changes in threats from new attacks.
[0143] Overall, the output of the fully connected layer can be used as feedback data to train and adjust model parameters. For example, if a certain type of normal traffic is misjudged as an attack (with a high probability value), the weight matrix can be updated through the backpropagation algorithm to reduce the influence factor of this type of feature, gradually improve the model's adaptability to power grid business characteristics, and reduce the false positive rate.
[0144] Overall, this mechanism realizes the key leap from "multi-dimensional feature fusion" to "real-time risk quantification" through the high-speed computing power of the fully connected layer and the advantages of multi-class modeling, compared to traditional detection techniques: Speed advantage: microsecond-level probability calculation, meeting the millisecond-level real-time protection requirements of the power grid; Accuracy advantage: multi-class probability distribution supports fine-grained attack identification, with an accuracy improvement of 40% compared to single-feature detection; Adaptability advantage: can dynamically adapt to changes in power grid topology and business through model training, reducing dependence on manual rules.
[0145] The attack credibility assessment module 105 is configured to start a sandbox verification process for events exceeding the threshold value when the attack probability exceeds the preset threshold value, and generate an attack credibility score of the power grid. In the embodiment of the present application, when the attack credibility assessment module is used to start a sandbox verification process for events exceeding the threshold value when the attack probability exceeds the preset threshold value, and generate an attack credibility score of the power grid, it is specifically used for: Deploying a real device firmware image in a virtual machine to obtain a sandbox image of the event exceeding the threshold value; Replaying the attack-related communication traffic segment in the event exceeding the threshold value in the sandbox image and monitoring the state jump sequence of the sandbox image; Comparing the matching degree of the state jump sequence with the historical attack feature library, and generating an attack credibility score of the power grid based on the matching degree.
[0146] When the attack credibility evaluation module compares the matching degree of the state transition sequence with the historical attack feature library and generates the attack credibility score of the power grid based on the matching degree, it is specifically used to: Extracting key turning points of the state transition sequence; Calculating a similarity distance between a time offset in the key turning point and an attack feature template in the historical attack feature library; Using the similarity distance as the matching degree between the state transition sequence and the historical attack feature library; The matching degree and the attack risk coefficient of the attack feature template are weighted to obtain an attack credibility score of the power grid.
[0147] Specifically, appropriate virtual machine software is selected to build a virtual environment, and the firmware image obtained from the real power grid equipment is fully deployed into the virtual machine.
[0148] Furthermore, during the operation of the virtual machine, a specific event monitoring mechanism is set up to collect and analyze various events occurring in the virtual machine in real time.
[0149] Furthermore, when the monitored event data meets the pre-set threshold conditions, such as abnormal network access behavior, abnormal increase in system resource usage, etc., a snapshot operation is immediately performed on the current virtual machine's operating status, and the virtual machine status containing the event exceeding the threshold is saved at this time to generate a sandbox image, which completely retains the system environment and related data when the threshold event is triggered.
[0150] Furthermore, when replaying the attack-associated communication traffic segments in the event exceeding the threshold in the sandbox image and monitoring the state jump sequence of the sandbox image, the communication traffic segments associated with the attack behavior are first screened out from the relevant data recording the event exceeding the threshold. These segments contain data packet information that may trigger the attack.
[0151] Furthermore, using a specialized network traffic replay tool, the selected traffic segments are retransmitted within the virtual network environment corresponding to the sandbox image, following their original chronological order and data characteristics. During the replay process, a system status monitoring program installed within the sandbox image records the status changes of key system components in real time, including system process status, network connection status, and file system changes.
[0152] Furthermore, these state changes are arranged in chronological order to form a complete state jump sequence, which records in detail the dynamic evolution of the system state when the sandbox image replays the attack-related communication traffic fragments.
[0153] Further, the matching degree of the state jump sequence and the historical attack feature library is compared, and the attack credibility score of the power grid is generated based on the matching degree.
[0154] Further, the state jump sequence generated in the sandbox image is compared with each feature sequence in the historical attack feature library one by one.
[0155] Further, the comparison process uses a sequence matching algorithm to check whether each state is the same or similar to the corresponding state in the sequence in the historical attack feature library, starting from the initial state of the state jump sequence. The more states that are the same or similar, the higher the matching degree.
[0156] Further, the matching of the state jump sequence and each feature sequence in the historical attack feature library is counted, and a comprehensive matching degree value is calculated, which reflects the similarity between the current state jump sequence and the known attack behavior features.
[0157] Further, according to the pre-set scoring rules, the matching degree value is mapped to the corresponding attack credibility score. The higher the matching degree, the higher the attack credibility score, which directly indicates the possibility of the power grid being attacked.
[0158] Specifically, when extracting the key turning points of the state jump sequence, the state jump sequence is analyzed point by point. The state jump sequence is a dynamic evolution record of the system state when the sandbox image replays the attack-related communication traffic segment.
[0159] Further, the change of the system state at adjacent time points is observed. When the system state changes significantly, such as network connection suddenly interrupted from normal communication, process from running state to abnormal termination, etc., the time point is marked as a key turning point.
[0160] Further, the entire state jump sequence is traversed, and all time points that meet the significant state change condition are filtered out to form a key turning point set of the state jump sequence. These key turning points reflect important moments of system state change.
[0161] Further, when calculating the similarity distance of the time offset in the key turning point and the attack feature template in the historical attack feature library, each attack feature template is taken out from the historical attack feature library. Each template contains the time information of the system state key turning point under the corresponding attack behavior.
[0162] Further, for each key turning point of the state jump sequence, the time offset of the corresponding key turning point in the attack feature template is calculated, that is, the difference between the two time points.
[0163] Further, a specific distance calculation method is adopted to comprehensively calculate the time offset of all key turning points to obtain a value representing the similarity distance between the time offset of the key turning points of the state jump sequence and the attack feature template.
[0164] Further, the specific calculation process is to compare the time offset of the key turning points in the same order in the state jump sequence and the attack feature template in sequence, assign different weights according to the size of the offset, the smaller the offset, the higher the weight, multiply all the offsets by the corresponding weights and sum them up, and the result is the similarity distance, which reflects the similarity of the time distribution of the key turning points.
[0165] Further, when the similarity distance is used as the matching degree of the state jump sequence and the historical attack feature library, the similarity distance has been calculated by the above method, which measures the similarity between the time offset of the key turning points of the state jump sequence and the attack feature template in the historical attack feature library.
[0166] Further, the similarity distance calculated directly is identified as the matching degree of the state jump sequence and the historical attack feature library, the smaller the similarity distance, the more similar the state jump sequence and the attack feature template in the historical attack feature library, that is, the closer the current system state change to the known attack behavior; the larger the similarity distance, the greater the difference between them.
[0167] Further, when the matching degree and the attack risk coefficient of the attack feature template are weighted to obtain the attack credibility score of the power grid, an attack risk coefficient is set for each attack feature template in the historical attack feature library in advance, which is determined according to factors such as the damage degree and influence range of the attack behavior, and the larger the value, the higher the risk of the attack behavior.
[0168] Further, the weighting rule of the matching degree and the attack risk coefficient is determined, and the matching degree and the attack risk coefficient corresponding to the attack feature template are weighted and calculated according to the rule.
[0169] Further, the specific operation is to multiply the matching degree and the attack risk coefficient by their respective weight values, and then add the two products to obtain the final value, which is the attack credibility score of the power grid.
[0170] Further, the score comprehensively considers the similarity between the current system state change and the known attack behavior and the risk of the attack behavior itself, which can more accurately evaluate the possibility of the power grid being attacked.
[0171] Traditional detection technologies generally require manual analysis when suspicious attacks are discovered, resulting in delayed responses. This solution automatically replays attack traffic through sandbox images (for example, by deploying a real device firmware image in a virtual machine and replaying attack-related communication traffic fragments). This allows real-time monitoring of system state transitions without manual intervention, reducing verification time from hours to minutes and meeting the real-time protection requirements of the power grid.
[0172] In general, by extracting the key turning points of the state jump sequence and calculating their similarity distance with the historical attack feature library (such as time offset matching), the attack type and danger can be quickly determined.
[0173] For example, if the similarity distance between a state jump sequence and a characteristic template of known ransomware is less than a threshold, the system can immediately identify it as a high-risk attack, avoiding the time-consuming operation of manual frame-by-frame analysis.
[0174] In general, sandbox images use real device firmware images (such as firmware obtained directly from power grid equipment), which can accurately simulate the actual response of power grid equipment under attack.
[0175] In general, compared with traditional verification methods based on simulation models, this method can more accurately capture the impact of attack behavior on the underlying system of the device (such as abnormal process termination, register status changes, etc.), and avoid misjudgment caused by model simplification.
[0176] In general, by recording the system status evolution of the sandbox image in real time (such as network connection status and file system changes), new attacks that cannot be identified by traditional static feature analysis can be detected.
[0177] For example, some zero-day attacks may change the device state through staged penetration. Sandbox verification can detect anomalies through continuous state jump patterns, reducing the false alarm rate by more than 30% (compared to detection methods that rely only on traffic characteristics).
[0178] In general, the attack credibility score combines the matching degree (the similarity between the state jump and the historical attack) and the attack risk coefficient (the degree of damage of the historical attack) to form a quantitative evaluation indicator.
[0179] For example, if the matching degree of an attack is 85% and the corresponding template's risk coefficient is 90%, the weighted score can intuitively reflect the true threat level of the attack and provide a scientific decision-making basis for the protection strategy.
[0180] In summary, based on the confidence score, the system automatically performs a graded response: Low-scoring scenarios: Only logs are recorded and continuously monitored to avoid accidental interruption of normal services. High-scoring scenarios: Immediately initiate network isolation or channel switching (such as triggering traffic rerouting to an alternative channel), achieving a closed-loop "detection-verification-response" process and improving the accuracy and effectiveness of protection strategies.
[0181] In general, this mechanism builds an "intelligent verification engine" for power grid intrusion detection through the authenticity of the sandbox environment, the automation of the verification process, and the multidimensionality of the scoring system. Compared with traditional solutions, its core advantages are: Improved efficiency: Reduce manual verification time by more than 90%, achieving a minute-level closed-loop attack detection and response. Improved accuracy: Based on real firmware simulation and dynamic state analysis, the false alarm rate is reduced to less than 5%; Improved adaptability: It can effectively detect new attacks and unknown threats, making up for the limitations of traditional rule matching.
[0182] The intrusion protection module 106 is configured to issue network isolation and channel switching instructions to the power grid based on the attack credibility score.
[0183] In an embodiment of the present invention, when the intrusion protection module issues a network isolation and channel switching instruction to the power grid based on the attack credibility score, it is specifically configured to: When the attack credibility score exceeds a preset first threshold, updating the boundary access control policy; When the attack credibility score exceeds a preset second threshold, traffic is triggered to be rerouted to a backup channel, and an encrypted alarm notification is sent to the security operation and maintenance terminal.
[0184] Specifically, a specific value of a preset first threshold is checked. The threshold is determined based on basic requirements for power grid security protection and is used to determine whether the boundary access control policy needs to be adjusted.
[0185] Furthermore, the calculated attack credibility score is compared with a first threshold. If the score exceeds the first threshold, it indicates that the attack risk faced by the power grid has reached a level that requires strengthening boundary access control.
[0186] Furthermore, the access control policy management system will automatically retrieve pre-defined update rules that specify how to adjust the boundary access control policy under different risk levels.
[0187] For example, access restrictions can be added to specific IP addresses, and stricter identity authentication mechanisms can be enabled. Based on the updated rules, access control policies for grid boundary devices (such as firewalls and intrusion detection systems) can be modified and updated to ensure that only authorized and legitimate traffic can pass through the boundary devices, thereby improving the security protection capabilities of the grid.
[0188] Furthermore, a preset second threshold is determined. The threshold is higher than the first threshold, indicating that the attack risk faced by the power grid has reached a higher level and a higher level of protection measures need to be taken.
[0189] Furthermore, the attack credibility score is compared with a second threshold. If the score exceeds the second threshold, the system immediately initiates a traffic rerouting mechanism.
[0190] Furthermore, the traffic rerouting mechanism will re-plan the path of the currently transmitted communication traffic based on the network topology of the power grid and the status information of the backup channel, and guide it to the pre-set backup communication channel to avoid the main communication channel being affected by the attack and causing communication interruption.
[0191] Furthermore, while triggering traffic rerouting, the system sends an alarm notification to the security operation and maintenance terminal through an encrypted communication protocol.
[0192] Furthermore, the alarm notification includes the attack credibility score, the current status of the power grid, the response measures taken, etc., and the data is encrypted during transmission to ensure the security and integrity of the alarm information during transmission, so that security operation and maintenance personnel can obtain the security status of the power grid in a timely and accurate manner and take further response measures.
[0193] In general, by setting different thresholds (first threshold and second threshold), the attack credibility score is evaluated in a hierarchical manner to achieve refined management of power grid intrusion risks.
[0194] In general, when the attack credibility score exceeds the preset first threshold, it indicates that the power grid faces a certain attack risk, but the risk level is relatively low.
[0195] In general, updating the boundary access control policy at this time, such as adding access restrictions to specific IP addresses and enabling stricter identity authentication mechanisms, can effectively prevent some low-risk attacks without affecting the normal operation of the power grid, and avoid unnecessary impact of excessive protection on power grid business.
[0196] In general, when the attack credibility score exceeds the preset second threshold, it means that the power grid faces a high risk of attack, which may pose a serious threat to the safe and stable operation of the power grid.
[0197] In general, triggering traffic rerouting to the backup channel and sending encrypted alarm notifications to the security operation and maintenance terminal is a more targeted and effective protection measure.
[0198] Overall, traffic rerouting can avoid the impact of attacks on the main communication channel, ensuring the normal transmission of power grid data; sending encrypted alarm notifications to secure operation terminals can enable operation personnel to promptly understand the security status of the power grid, so as to quickly take further measures such as in-depth security audit and attack tracing.
[0199] Overall, when the traditional power grid intrusion detection system detects a suspicious attack, it often needs manual intervention for analysis, which not only leads to a long delay in detection and response, but also may affect the protection effect due to the subjectivity and uncertainty of manual judgment.
[0200] Overall, the automated response mechanism based on attack credibility score can automatically issue network isolation and channel switching instructions when the attack credibility score reaches the corresponding threshold, without the need for human intervention, greatly shortening the time period from detection to response and improving the real-time performance of power grid intrusion protection.
[0201] Overall, the automated response mechanism can take effective protective measures in the shortest possible time, promptly stopping the further spread and spread of attacks and reducing the damage caused by attacks to the power grid.
[0202] For example, when the attack credibility score exceeds the second threshold, quickly triggering traffic rerouting to the backup channel can ensure the continuity of critical power grid services and avoid serious consequences such as power supply abnormalities caused by communication interruptions.
[0203] Overall, automatically sending encrypted alarm notifications to secure operation terminals enables operation personnel to promptly obtain information and carry out emergency handling work, further improving the emergency handling efficiency of the power grid system.
[0204] Overall, network isolation measures can isolate the attacked part from the unattacked part, preventing the attack from further spreading and spreading within the power grid and limiting the impact of the attack.
[0205] Overall, by updating the border access control policy or triggering traffic rerouting, the attack traffic can be effectively prevented from entering the critical area of the power grid, protecting the core equipment and important data of the power grid from being damaged by attacks, and enhancing the reliability of the power grid system.
[0206] Overall, the channel switching instruction can direct communication traffic to the backup channel, avoiding the failure of the main channel due to attacks and ensuring smooth communication of the power grid.
[0207] Overall, this is crucial for real-time monitoring, data transmission, and remote control of critical services in the power grid, ensuring the stable operation of the power grid and improving the ability of the power grid to resist various attacks.
[0208] It is apparent for a person skilled in the art that the present application is not limited to the details of the above-described exemplary embodiments, but that the present application can be implemented in other concrete forms without departing from the spirit or essential characteristics of the present application.
[0209] Embodiments of the present application can acquire and process related data based on artificial intelligence technology. Among them, artificial intelligence is to use digital computers or computer-controlled machines to simulate, extend and expand human intelligence, perceive the environment, acquire knowledge and use knowledge to obtain the best results.
[0210] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application and are not limiting. Although the present application has been described in detail with reference to the preferred embodiments, it should be understood by those skilled in the art that the technical solutions of the present application can be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present application.
Claims
1. An artificial intelligence-based power grid intrusion detection system, characterized in that: The system includes a three-dimensional data cube construction module, a three-dimensional data cube feature extraction module, a feature fusion module, an attack probability prediction module, an attack credibility assessment module and an intrusion protection module, wherein: The three-dimensional data cube construction module is used to align the timestamps between the communication flow, device status and node topology relationship of the power grid to generate the three-dimensional data cube of the power grid; The three-dimensional data cube feature extraction module is used to extract abnormal node propagation characteristics and traffic time series patterns of the three-dimensional data cube; The feature fusion module is configured to fuse the abnormal node propagation features and the time features of the traffic time series pattern through a cross-channel attention mechanism to obtain a fused feature vector of the power grid; The attack probability prediction module is used to input the fused feature vector into a fully connected layer to obtain the attack probability of the power grid; The attack credibility assessment module is configured to, when the attack probability exceeds a preset threshold, initiate a sandbox verification process for the event exceeding the threshold and generate an attack credibility score for the power grid; The intrusion protection module is used to issue network isolation and channel switching instructions to the power grid based on the attack credibility score.
2. The artificial intelligence-based power grid intrusion detection system according to claim 1, characterized in that: When aligning the communication traffic, device status, and timestamps of node topology relationships of the power grid to generate the three-dimensional data cube of the power grid, the three-dimensional data cube construction module is specifically configured to: Extract the protocol header fields and payload characteristic bytes of the communication traffic; Encode device status data into anomaly level vectors; Constructing an adjacency matrix of the power grid based on physical connection relationships of devices; The protocol header field, the payload characteristic byte, the anomaly level vector and the adjacency matrix are aligned according to the communication cycle of the power grid to obtain a three-dimensional data cube of the power grid.
3. The artificial intelligence-based power grid intrusion detection system according to claim 1, characterized in that: When extracting abnormal node propagation characteristics and traffic timing patterns of the three-dimensional data cube, the three-dimensional data cube feature extraction module is specifically used to: Identify data anomaly nodes in the three-dimensional data cube, Aggregating the abnormal states of two adjacent data abnormal nodes to obtain the abnormal propagation probability of the two adjacent data abnormal nodes; The abnormal propagation probability is superimposed on the topological relationship path of the two adjacent data abnormal nodes to obtain the abnormal node propagation characteristics of the three-dimensional data cube.
4. The artificial intelligence-based power grid intrusion detection system according to claim 1, characterized in that: When extracting abnormal node propagation characteristics and traffic timing patterns of the three-dimensional data cube, the three-dimensional data cube feature extraction module is specifically used to: Performing sliding window segmentation on the communication traffic in the three-dimensional data cube to obtain a traffic window of the three-dimensional data cube; Learning the dependency of the protocol fields within the traffic window through a gated recurrent block to obtain a hidden state vector representing the traffic behavior pattern; The hidden state vector is used as a traffic timing pattern of the three-dimensional data cube.
5. The artificial intelligence-based power grid intrusion detection system according to claim 1, characterized in that: Before the feature fusion module performs the cross-channel attention mechanism to fuse the abnormal node propagation feature and the time feature of the traffic time series pattern to obtain the fused feature vector of the power grid, it is specifically used to: Extracting an abnormal feature graph of the abnormal node propagation characteristics in the spatial channel; A time series feature vector of the traffic time series pattern is extracted in the time channel.
6. The artificial intelligence-based power grid intrusion detection system according to claim 5, characterized in that: When the feature fusion module performs the fusion of the abnormal node propagation feature and the time feature of the traffic time series pattern through the cross-channel attention mechanism to obtain the fused feature vector of the power grid, it is specifically used to: Projecting the abnormal feature graph and the time series feature vector to a mapping layer, and performing a dot product on the projected abnormal feature graph and the time series feature vector to obtain a similarity matrix of the power grid; Normalizing the similarity matrix to obtain the channel attention weights of the power grid; The abnormal feature map and the time series feature vector are fused based on the channel attention weight to obtain a fused feature vector of the power grid.
7. The artificial intelligence-based power grid intrusion detection system according to claim 1, characterized in that: When the attack probability prediction module inputs the fused feature vector into the fully connected layer to obtain the attack probability of the power grid, it is specifically used to: Inputting the fused feature vector into a fully connected layer with a normalized exponential function to obtain a multi-category attack probability distribution of the power grid; The maximum probability value in the multi-category attack probability distribution is taken as the attack probability of the power grid.
8. The artificial intelligence-based power grid intrusion detection system according to claim 1, characterized in that: When the attack probability exceeds a preset threshold, the attack credibility assessment module initiates a sandbox verification process for the event exceeding the threshold and generates an attack credibility score for the power grid, specifically for: Deploy real device firmware images in virtual machines to obtain sandbox images of events exceeding thresholds; replaying the attack-related communication traffic segments in the event of exceeding the threshold in the sandbox image, and monitoring the state transition sequence of the sandbox image; The matching degree of the state jump sequence is compared with the historical attack feature library, and the attack credibility score of the power grid is generated based on the matching degree.
9. The artificial intelligence-based power grid intrusion detection system according to claim 8, characterized in that: When the attack credibility evaluation module compares the matching degree of the state transition sequence with the historical attack feature library and generates the attack credibility score of the power grid based on the matching degree, it is specifically used to: Extracting key turning points of the state transition sequence; Calculating a similarity distance between a time offset in the key turning point and an attack feature template in the historical attack feature library; Using the similarity distance as the matching degree between the state transition sequence and the historical attack feature library; The matching degree and the attack risk coefficient of the attack feature template are weighted to obtain an attack credibility score of the power grid.
10. The artificial intelligence-based power grid intrusion detection system according to claim 1, characterized in that: When the intrusion protection module issues a network isolation and channel switching instruction to the power grid based on the attack credibility score, the intrusion protection module is specifically configured to: When the attack credibility score exceeds a preset first threshold, updating the boundary access control policy; When the attack credibility score exceeds a preset second threshold, traffic is triggered to be rerouted to a backup channel, and an encrypted alarm notification is sent to the security operation and maintenance terminal.
Citation Information
Patent Citations
Smart grid intrusion detection system and method
CN108055228A
Intrusion detection and response method and system of satellite internet target range
CN119155101A
Intelligent memory leak predicting and tracking method and system for micro-service architecture
CN119690725A
Cited By
Internet of Things gateway data processing method and related device
CN121396683A
Network intrusion detection method, system and device based on multi-dimensional features and storage medium
CN121664510A
A network intrusion detection method, system, device and storage medium based on multi-dimensional features
CN121664510B
Smart power grid false data injection attack detection method, terminal and storage medium
CN121887528A