Information-oriented network malicious behavior message backtracking generation method
By constructing network node topology and anomaly identifiers, and reconstructing the attack chain in conjunction with the direction of information flow, the problems of inaccurate anomaly node location and incomplete path in traditional methods are solved, and the accurate tracing and security protection of malicious behavior in power grid networks are realized.
Patent Information
- Application Number
- CN202511116628.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-11
- Publication Date
- 2025-11-07
AI Technical Summary
Existing methods for tracing malicious network messages suffer from limited dimensions for identifying abnormal nodes, incomplete analysis of information propagation paths, and chaotic attack chain time sequences, leading to inaccurate tracing and wasted resources.
By constructing a network node topology and establishing a node anomaly identifier, information guidance analysis is performed based on the direction of information flow to reconstruct the attack chain of malicious behavior and generate malicious behavior message backtracking results.
It enables precise backtracking of malicious behavior in the power grid network, improves the completeness and accuracy of source tracing, shortens the time for anomaly detection, and enhances the efficiency of security incident response.
Smart Images

Figure CN120915537A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of network security, in particular to an information-oriented network malicious behavior packet backtracking generation method. BACKGROUND
[0002] With the development of network security technology, malicious behavior tracing in the power grid field has become a core requirement to protect critical infrastructure security. At present, the traditional network malicious behavior packet backtracking method mainly relies on single-point detection and one-way path tracing mode, which has problems such as single abnormal node identification dimension, incomplete information propagation path analysis, and chaotic attack chain time sequence.
[0003] The existing backtracking method only collects data through single-point node protocol feature matching, which leads to large deviation in abnormal node positioning and high risk of missed or misjudged. At the same time, without combining network topology structure, information flow direction and other associated data to compensate for the blind area of tracing, the detection result deviates significantly from the real attack path, which not only reduces the accuracy of malicious behavior tracing, but also easily leads to waste of security event response resources. SUMMARY
[0004] In order to solve the above technical problems, the present application provides an information-oriented network malicious behavior packet backtracking generation method, which improves the integrity, accuracy and timeliness of malicious behavior backtracking, and solves the problems of single abnormal node identification dimension, incomplete information propagation path analysis, chaotic attack chain time sequence and the like in the traditional method.
[0005] The embodiments of the present application disclose the following technical solutions: The embodiments of the present application provide an information-oriented network malicious behavior packet backtracking generation method, which comprises: determining a target power grid network, constructing a network node topology according to the target power grid network, the network node topology comprising a plurality of network nodes and information flow directions between the network nodes; constructing a node anomaly identifier for each network node, performing node anomaly detection on the plurality of network nodes through each node anomaly identifier, and obtaining a plurality of node detection results; when there is an abnormal node in the plurality of node detection results, performing information-oriented analysis from the abnormal node based on the information flow directions in the network node topology, and determining an information propagation path related to the abnormal node; based on the information propagation path, reconstructing a complete attack chain of malicious behavior in chronological order, and generating a malicious behavior packet backtracking result.
[0006] One or more technical solutions provided in the present application have at least the following technical effects or advantages: The application provides an information-oriented network malicious behavior packet backtracking generation method, which realizes accurate backtracking of network malicious behaviors of the power grid through multi-dimensional feature constraint node anomaly identification, topology-oriented information propagation path analysis and time sequence attack chain reconstruction. First, a network node topology is constructed, the information flow direction of each node is determined, and an anomaly identifier containing network protocol, traffic and behavior feature constraints is established for each node. The anomaly identifier network covering the whole domain is formed through historical data training. The current features are collected in real time and input into the model, and the node anomaly state is output. When an abnormal node is found, bidirectional backtracking is performed from the abnormal node based on the topology information flow direction, the records matching the abnormal packets in the historical data of the upstream nodes are reversely searched, the relevant records of the downstream nodes are forwardly searched, the associated nodes are marked and recursively backtracked to the network boundary, and the information propagation path is combined and constructed. Finally, the packet data of each node in the path is collected, sorted according to the time stamp to construct a time axis, and connected into a complete attack sequence to generate a backtracking report containing time, position and behavior.
[0007] The technical scheme of the application solves the problems of incomplete tracing and inaccurate analysis caused by fuzzy abnormal positioning, path breakage and time sequence confusion in the traditional network malicious behavior backtracking, realizes accurate network malicious behavior packet backtracking and process restoration based on information orientation, and provides technical support for the security protection of the power grid network. BRIEF DESCRIPTION OF DRAWINGS
[0008] In order to more clearly illustrate the technical solutions in the embodiments of the application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative labor.
[0009] Figure 1 A flowchart of an information-oriented network malicious behavior packet backtracking generation method provided by the embodiment of the application is shown in the figure. Figure 2 A flowchart of determining an information propagation path based on the information flow direction provided by the embodiment of the application is shown in the figure. DETAILED DESCRIPTION
[0010] The application provides an information-oriented network malicious behavior packet backtracking generation method, which is used to solve the technical problems of single abnormal node identification dimension, incomplete information propagation path backtracking, chaotic attack chain time sequence reconstruction and low multi-source packet data fusion efficiency in the prior art.
[0011] With reference to the drawings of the embodiments of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described. Obviously, the described embodiments are only a part of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the scope of protection of the present application.
[0012] In the description of the present application, the terms "first", "second" are used only for descriptive purposes, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined with "first", "second" can be explicitly or implicitly included one or more of the features. In the description of the present application, the meaning of "multiple" is two or more, unless otherwise specifically limited.
[0013] In the description of the present application, the term "for example" is used to indicate "as an example, illustration or description". Any embodiment described as "for example" in the present application is not necessarily interpreted as more preferred or more advantageous than other embodiments. The following description is given in order to enable any person skilled in the art to implement and use the present application. In the following description, details are listed for the purpose of explanation. It should be understood that a person of ordinary skill in the art can realize the present application without using these specific details. In other examples, well-known structures and processes will not be described in detail to avoid unnecessary details making the description of the present application obscure. Therefore, the present application is not intended to be limited to the shown embodiments, but is consistent with the broadest scope in accordance with the principles and characteristics disclosed in the present application.
[0014] Embodiments, as shown in the accompanying drawings Figure 1 The present application provides an information-oriented network malicious behavior packet traceback generation method, which comprises the following steps: S110: determining a target power grid network, constructing a network node topology according to the target power grid network, the network node topology comprising a plurality of network nodes and information flow directions between the network nodes; In the embodiments of the present application, in the intelligent scenario of power grid network security protection, to realize accurate traceback of malicious behavior, the information flow relationship between network nodes needs to be determined by constructing a topology structure.
[0015] Specifically, for the target power grid network, first, identify the multiple network levels it contains, each network level covering multiple level nodes, thereby forming a hierarchical network structure.
[0016] Further, analyze the intra-level node flow relationship between the level nodes in each network level to construct an intra-level topology, and analyze the inter-level information flow relationship between the network levels to construct an inter-level topology.
[0017] Finally, based on the intra-level topology and inter-level topology, a complete network node topology is generated, clearly presenting the network nodes and the information flow direction between nodes.
[0018] This step provides a basic framework reflecting the network structure of the power grid by hierarchical identification and topology construction, which provides a basis for subsequent node anomaly detection, information propagation path analysis, and attack chain reconstruction.
[0019] The method provided in the embodiments of the present application includes the following steps: Identify a plurality of network levels of the target power grid network, each network level including a plurality of level nodes; Analyze the intra-level node flow relationship between the level nodes in the plurality of network levels to construct an intra-level topology; Analyze the inter-level information flow relationship between the network levels to construct an inter-level topology; Based on the intra-level topology and the inter-level topology, generate the network node topology.
[0020] In the intelligent scenario of power grid network security protection, in order to realize accurate backtracking of malicious behavior packets, it is necessary to construct a network node topology that clearly presents network information flow through hierarchical topology.
[0021] Specifically, first, according to the actual structure and business type of the target power grid network, the entire power grid network is divided into a plurality of levels, such as a dispatching data network layer, a production control layer, and a substation bay layer, each level containing a plurality of level nodes such as data servers, switches, and protection devices, forming a three-dimensional network level structure.
[0022] For example, for a provincial power grid dispatching system, it can be divided into a dispatching master station layer (including data processing servers and other equipment), a plant station control layer (including substation monitoring devices), and a field device layer (including circuit breakers, mutual inductors, and other intelligent terminals), and each layer contains not less than 5 core nodes.
[0023] Further, for each network level, communication records between the nodes in the level are collected through traffic mirroring, protocol analysis, and other technical means, the intra-level node flow relationship such as the packet interaction mode between the data server and the switch, and the real-time data flow direction between the protection device and the measurement and control device are analyzed, and an intra-level topology is constructed.
[0024] Meanwhile, based on the cross-layer communication routing configuration and firewall, the vertical data transmission path between the scheduling master station layer and the station control layer is analyzed, such as the flow relationship of the control instruction transmitted by the data processing server to the remote device through the special safety isolation device, and the interconnection relationship between different station control layers. The inter-layer interface mapping method is used to build the inter-layer topology, and the rules and restrictions of cross-layer information flow are determined.
[0025] Finally, the topology in each layer is integrated according to the network layer dimension, and spliced through the interface association relationship of the inter-layer topology, to generate a network node topology containing device node position, layer attribution, information flow direction and transmission speed and other attributes. The network node topology presents the "layer-node-connection" ternary structure of the power grid network in a visual way, providing a basis for subsequent detection of device abnormalities and tracking of malicious behavior propagation paths.
[0026] S120: Construct a node anomaly identifier for each network node, and perform node anomaly detection on the plurality of network nodes through the node anomaly identifier to obtain a plurality of node detection results; In the intelligent scenario of power grid network security protection, in order to realize accurate identification of malicious behavior, a node anomaly identifier needs to be established for each network node and node anomaly detection needs to be performed to output corresponding node detection results.
[0027] Specifically, a first network node is selected from the power grid network nodes, and the node feature constraints of the first network node in normal working state are determined. The node feature constraints include network protocol feature constraints, traffic feature constraints and behavior feature constraints.
[0028] Further, the historical network protocol features, historical traffic features and historical behavior features of the node are extracted by collecting the historical communication data of the node, and a sample node feature set is constructed by integrating the historical network protocol features, historical traffic features and historical behavior features.
[0029] Further, the sample set is labeled based on the node feature constraints to generate a sample feature label set containing normal / abnormal labels, and a supervised learning algorithm is used to construct the node anomaly identifier of the node.
[0030] Similarly, the corresponding node anomaly identifier is constructed for the remaining network nodes according to the same steps, and global anomaly detection is performed.
[0031] Further, in the anomaly detection stage using the node anomaly identifier, the current network communication data of each node is collected in real time, the current network protocol features, current traffic features and current behavior features are extracted therefrom, and the current network protocol features, current traffic features and current behavior features are input into the corresponding node anomaly identifier. By comparing with the feature threshold of the training model and pattern matching, the corresponding node detection result is output, which provides the basis for abnormal node positioning for subsequent information propagation path analysis.
[0032] This step realizes global anomaly detection and accurate positioning of the power grid network node by constructing a multi-dimensional feature constraint node anomaly recognizer.
[0033] The step S120 in the method provided by the embodiment of the application comprises: extracting a first network node from the plurality of network nodes, and obtaining node feature constraints of the first network node, the node feature constraints comprising network protocol feature constraints, traffic feature constraints and behavior feature constraints; collecting historical communication data of the first network node, extracting historical network protocol features, historical traffic features and historical behavior features, and constructing a sample node feature set; labeling the sample node feature set according to the network protocol feature constraints, the traffic feature constraints and the behavior feature constraints to obtain a sample feature label set; constructing a node anomaly recognizer of the first network node based on the sample node feature set and the sample feature label set; constructing node anomaly recognizers for the remaining network nodes in the manner of constructing the node anomaly recognizer of the first network node to obtain node anomaly recognizers of the network nodes.
[0034] collecting current network communication data of each network node in real time, extracting current network protocol features, current traffic features and current behavior features to obtain current node features of each network node; inputting the current node features of each network node into the corresponding node anomaly recognizer for anomaly detection analysis to obtain a plurality of node detection results, the node detection result being a normal state or an abnormal state.
[0035] In the intelligent scenario of power grid network security protection, in order to realize accurate identification of malicious behavior, a node anomaly recognition system based on multi-dimensional feature constraints needs to be constructed.
[0036] Specifically, a first network node (such as a core switch or a data server) is selected from a target power grid network node set, and three types of node feature constraints, including network protocol feature constraints, traffic feature constraints and behavior feature constraints, of the network node are obtained through protocol analysis, traffic monitoring and behavior record checking. The network protocol feature constraints are used to standardize the protocol type, message format and port usage rules of node communication, to ensure that the network node complies with the power grid communication protocol standard; the traffic feature constraints are used to clearly define the bandwidth threshold, traffic timing distribution and abnormal fluctuation range of the network node, to ensure that the node traffic is within the normal business load range; and the behavior feature constraints are used to standardize the operation behavior mode, interaction timing and state conversion logic of the network node, to make it comply with the power grid business process specification.
[0037] Exemplarily, for a data server node of a certain substation, the network protocol feature constraint can be set to allow only TCP / IP protocol to transmit Web service data through port 8080, and the CRC check error rate of Modbus message needs to be less than 0.01%; the flow feature constraint can be set to that the daily average uplink flow does not exceed 150 Mbps, and a warning is triggered when the flow mutation rate exceeds 30% within 5 minutes; the behavior feature constraint can be set to that a device state message is sent to the monitoring master station every 20 minutes, and a response message is returned within 100 ms after receiving a data query instruction.
[0038] Further, the historical communication data of the node in the past 6 months is collected through the flow mirroring device, and after the noise messages are removed through data cleaning, three types of historical features including historical network protocol features, historical flow features and historical behavior features are extracted therefrom.
[0039] Specifically, in terms of historical network protocol features, the proportion of each protocol message (such as TCP proportion 60%, UDP proportion 35%) is counted, the port usage frequency (such as 22 port daily connection number 100±10 times) is counted, and the protocol abnormality rate (such as CRC check error rate <0.01%) is counted.
[0040] Similarly, in terms of historical flow features, daily flow records (such as early morning peak 9:30 flow average value 120 Mbps) are generated, burst flow conditions (such as only 2 times of flow surge exceeding 150 Mbps in the past 3 months) are recorded, and flow correlation features (such as Pearson correlation coefficient of flow change between master station and substation >0.85) are recorded.
[0041] Meanwhile, in terms of historical behavior features, the device self-checking period stability (such as average self-checking interval 15 minutes±10 seconds) is analyzed, the instruction response time delay distribution (such as 95% of instruction response time <80 ms) is analyzed, and the abnormal behavior frequency (such as only 3 times of unplanned restart in the past year) is counted, and the above three types of features are integrated in time sequence to construct a sample node feature set.
[0042] Further, based on the three types of feature constraints, the sample set is labeled, the feature records meeting the constraint conditions are labeled “normal”, the records violating the protocol format, exceeding the flow threshold or deviating from the behavior mode are labeled “abnormal”, and a labeled sample feature labeling set is formed.
[0043] Further, based on a deep neural network algorithm, the sample feature set is taken as input and the labeling label is taken as output, and a node anomaly recognizer of the first network node is constructed and trained.
[0044] The network adopts a three-layer fully connected architecture, the number of input layer neurons matches the feature dimension of the sample (e.g. 100-dimensional features correspond to 100 input neurons), the hidden layer is set to 2 layers (the number of neurons is 50 and 25 respectively), the output layer is 1 neuron (output 0 / 1 represents normal / abnormal), and ReLU is selected as the activation function to enhance the non-linear feature capturing ability.
[0045] In the model training phase, the sample feature set and the labeled label are divided into training set, validation set and test set according to the ratio of 7:2:1. For example, 700 groups of training set, 200 groups of validation set and 100 groups of test set are extracted from 1000 groups of historical samples.
[0046] At the same time, the training set is used to iteratively train the model, and the cross entropy is used as the loss function, and the Adam optimizer (learning rate is set to 0.001) is used to update the network parameters.
[0047] Specifically, the performance of the model is evaluated using the validation set every 50 iterations. After the first iteration, the accuracy of the validation set is 75%; when the iteration reaches 300 times, the accuracy is improved to 92%; when the iteration reaches 500 times and the accuracy of the validation set is stable above 98%, it is determined that the model converges, and the training of the abnormal identifier of the node is completed.
[0048] Further, according to the same process, a dedicated node abnormal identifier is constructed for the protection device, the remote terminal and all network nodes in the power grid.
[0049] Finally, an abnormal identification network covering all nodes is formed, and each identifier is trained for the characteristics of a specific node to achieve high-precision abnormal monitoring of the network nodes of the power grid.
[0050] For example, for the protection device node, the characteristics of the IEC61850 protocol interaction rules, the trip instruction flow peak value, the fault response time and the like are collected, and a dedicated abnormal identifier is constructed according to the same neural network architecture and training parameters.
[0051] Further, in the real-time detection phase, the probe equipment deployed in each network node collects the current network communication data in real time at a millisecond level. The collection range covers all messages sent and received by the node, traffic statistics information and operation records, ensuring the real-time and completeness of the data.
[0052] For example, for a substation monitoring host node, the communication messages of the node with the interval layer device, the inbound and outbound traffic data and the device self-checking records are collected in real time.
[0053] Further, the current network protocol features, the current traffic features and the current behavior features are extracted from the real-time collected network communication data to generate the current node features of each network node.
[0054] Further, the current node features of each network node are input into the corresponding node anomaly identifier, which calculates the input real-time feature data and the threshold matrix in the training model through forward propagation to match the Euclidean distance, and outputs a detection result of 0 or 1 (0 for normal and 1 for abnormal).
[0055] For example, after the current features of a certain data server are input into the anomaly identifier, the model calculates that the protocol feature deviation is 0.85, the traffic feature deviation is 0.92, and the behavior feature deviation is 0.3, and the comprehensive judgment result is 1 (abnormal), and generates alarm information of protocol and traffic anomaly, providing accurate abnormal node positioning for subsequent malicious behavior path tracing.
[0056] This scheme realizes real-time monitoring of all nodes in the power grid, greatly shortens the abnormal discovery time compared with the traditional timing detection scheme, and improves the network security event response efficiency.
[0057] S130: When there is an abnormal node in the plurality of node detection results, based on the information flow direction in the network node topology, information-oriented analysis is performed from the abnormal node to determine an information propagation path related to the abnormal node; In the embodiment of the application, in the intelligent scenario of power grid network security protection, in order to realize complete tracing of malicious behavior packets, after identifying the abnormal node, the information propagation path of the abnormal information is constructed based on the information flow logic of the network node topology.
[0058] Specifically, first, all abnormal nodes are identified from the plurality of node detection results, a first abnormal node is extracted, and abnormal packet information thereof is obtained. The abnormal packet is extracted from the current network communication data when the node is determined to be abnormal.
[0059] Further, taking the abnormal packet information as a tracking target, bidirectional tracing is performed from the first abnormal node based on the information flow direction in the network node topology.
[0060] Wherein, in reverse tracing, the upstream network node pointing to the first abnormal node is determined according to the topology information flow direction, and the record matching the abnormal packet information in its historical communication data is searched. If it matches, it is marked as an upstream associated node.
[0061] At the same time, according to the topology information flow direction, the downstream network node receiving information from the first abnormal node is determined, and the record related to the abnormal packet information in its historical communication data is searched. If it is related, it is marked as a downstream associated node, and recursive tracing is performed to the network boundary node.
[0062] Finally, the first abnormal node is combined with the corresponding upstream associated node and downstream associated node to construct an information propagation path of the first abnormal node, and the remaining abnormal nodes are processed in the same manner to obtain information propagation paths related to all abnormal nodes.
[0063] This step realizes accurate positioning of the abnormal information propagation path through bidirectional tracing and topological association, and provides a key path basis for subsequent reconstruction of a complete attack chain of malicious behavior.
[0064] As shown in the accompanying Figure 2 The step S130 in the method provided by the embodiment of the application includes: All abnormal nodes are identified from the plurality of node detection results, and a first abnormal node is extracted to obtain abnormal message information of the first abnormal node; According to the information flow direction in the network node topology, the upstream associated node that transmits the abnormal message information is identified by starting from the first abnormal node and performing reverse tracing with the abnormal message information as a tracing target; According to the information flow direction in the network node topology, the downstream associated node that receives the abnormal message information is identified by starting from the first abnormal node and performing forward tracing with the abnormal message information as a tracing target; The first abnormal node, the corresponding upstream associated node, and the downstream associated node are combined to construct an information propagation path of the first abnormal node; The remaining abnormal nodes are processed in the same manner as the first abnormal node to obtain information propagation paths related to the abnormal nodes.
[0065] In the embodiment of the application, in the intelligent scenario of power grid network security protection, to realize complete tracing and attack chain reconstruction of malicious behavior messages, bidirectional tracing analysis is carried out based on the information flow direction of the network node topology after obtaining abnormal node detection results.
[0066] Specifically, first, all abnormal nodes are selected from the plurality of node detection results, a first abnormal node is extracted (as a first abnormal node), and abnormal message information including protocol type, traffic characteristics, behavior mode, and other dimensions is extracted from current network communication data when the node is determined to be abnormal, as a core target object of tracing analysis.
[0067] Further, the abnormal message information is used as a tracing clue, and bidirectional path tracing is implemented from the first abnormal node based on the pre-constructed information flow direction in the network node topology.
[0068] The method provided in the embodiments of the present application comprises the following steps: According to the information flow direction in the network node topology, an upstream network node pointing to the first abnormal node is determined; A message record matching the abnormal message information is searched in the historical network communication data of the upstream network node; When the upstream network node has a matching message record, the corresponding upstream network node is marked as an upstream associated node; The reverse tracing is repeatedly performed on each upstream associated node recursively until a network boundary node is traced.
[0069] In the embodiments of the present application, in order to locate the source of the malicious behavior message, the reverse path tracing is carried out relying on the pre-constructed network node topology and taking the abnormal message information as a clue.
[0070] Specifically, after the first abnormal node is identified through node abnormality detection, first, according to the information flow direction defined in the network node topology, all upstream network nodes that may transmit information to the abnormal node are sorted out to form a preliminary tracing range.
[0071] Further, for each upstream network node, the historical network communication data stored by the upstream network node is searched to find a record highly matching the abnormal message information in terms of message content, protocol type, transmission time and the like.
[0072] For example, if the Modbus protocol function code of the abnormal message is 0x05 and the transmission timestamp is 2025-06-30-14:30:00, the message record with the same function code and similar timestamp needs to be searched in the historical data of the upstream node.
[0073] If a certain upstream network node has a record completely matching the abnormal message information, it is indicated that the node may be the source of the abnormal message or a key node in the transmission path of the abnormal message, and therefore the node is marked as an upstream associated node.
[0074] Further, in order to trace the source of the abnormal message, the upstream associated node is taken as a new starting point, and the above tracing process is repeatedly performed, that is, a more upstream network node pointing to the node is determined, the matching condition of the historical data is searched, a new associated node is marked, and the tracing is performed until a boundary node (such as a firewall, a boundary router and the like) of the power grid network is traced, thereby forming a complete reverse tracing chain.
[0075] The step of reverse tracing realizes accurate positioning of the abnormal message source through topology-oriented hierarchical search and repeated execution processing, effectively solves the problems of path interruption and difficult tracing in the traditional tracing method, and provides key support for root cause analysis of malicious behavior.
[0076] For example, in a network anomaly event of a certain substation, through reverse tracing of the abnormal node, the station control layer switch is gradually located from the interval layer device, and finally it is found that the boundary router exists abnormal message injection, which provides basis for root cause analysis of malicious behavior.
[0077] The step of "taking the abnormal message information as a tracking target, performing forward tracking from the first abnormal node, and identifying downstream associated nodes receiving the abnormal message information" in the method provided by the embodiment of the application comprises: determining downstream network nodes receiving information from the first abnormal node according to the information flow direction in the network node topology; searching for message records related to the abnormal message information in the historical network communication data of the downstream network node; when the downstream network node has related message records, marking the corresponding downstream network node as a downstream associated node; recursively repeating the forward tracking for each downstream associated node until a network boundary node is tracked.
[0078] In the embodiment of the application, to locate the propagation range of malicious behavior messages, the pre-constructed network node topology also needs to be relied on, and forward path tracing is carried out with the abnormal message information as a clue.
[0079] Specifically, after identifying the first abnormal node through node anomaly detection, first, according to the information flow direction defined in the network node topology, analyze all downstream network nodes that may receive information from the abnormal node to form a preliminary tracing range.
[0080] Further, for each downstream network node, search its stored historical network communication data to find records related to the abnormal message information in the dimensions of message content, protocol type, transmission time, etc.
[0081] For example, the abnormal message is a response packet of a certain control instruction, and the receiving record and subsequent processing record of the instruction need to be searched in the historical data of the downstream node.
[0082] Similarly, if a downstream network node has records related to the abnormal message information, it indicates that the node may be the receiving end or a key node in the propagation path of the abnormal message, and it is marked as a downstream associated node.
[0083] Further, to determine the propagation end point of the abnormal message, the above-mentioned tracing process is repeated with the downstream associated node as the new starting point, that is, the more downstream network nodes receiving information from the node are determined, the historical data association is retrieved, the new associated node is marked, and the boundary nodes (such as terminal devices, boundary routers, etc.) of the power grid network are tracked until a complete forward tracing chain is formed.
[0084] The steps of the forward tracing also achieve accurate positioning of the propagation range of the abnormal message through topology-oriented hierarchical retrieval, effectively solving the problems of incomplete propagation path and difficult determination of the end point in the traditional tracing method, and providing key support for the impact assessment of malicious behavior.
[0085] For example, in a substation network abnormal event, through forward tracing of the abnormal node, the station control layer monitoring host is gradually located from the interval layer device, and finally it is found that the boundary router has abnormal message forwarding records, which provides a basis for the analysis of the impact range of malicious behavior.
[0086] Further, after completing the bidirectional tracing of the first abnormal node, the upstream associated node, the first abnormal node and the downstream associated node identified are combined in the spatial dimension to form a complete information propagation path.
[0087] Among them, the path takes the topology structure as the framework and the abnormal message information as the clue, and clearly presents the propagation track of the abnormal information from the upstream node to the downstream node through the first abnormal node.
[0088] For example, a propagation path may present a chain structure of "boundary router - station control layer switch - interval layer device - terminal device", in which each node is connected through matching or associated records of abnormal message information.
[0089] Finally, for the remaining abnormal nodes, the same processing flow as the first abnormal node is adopted to finally combine and construct the information propagation path of each abnormal node. Through this standardized processing method, the tracing process of all abnormal nodes can be consistent and repeatable, avoiding the deviation caused by different node types or abnormal types.
[0090] This step forms a multi-dimensional information propagation path by structurally combining independent abnormal nodes and associated nodes, which not only can intuitively show the impact range of a single abnormal node, but also reflects the association relationship between multiple abnormal nodes, laying a foundation for the reconstruction of the complete attack chain of malicious behavior.
[0091] S140: Based on the information propagation path, reconstructing the complete attack chain of malicious behavior in chronological order to generate a malicious behavior message tracing result.
[0092] In the intelligent scenario of power grid network security protection in the embodiments of the present application, in order to realize comprehensive tracing of malicious behaviors, on the basis of obtaining the abnormal node information propagation path, the complete attack chain is formed through the message sequence reconstruction in the time dimension.
[0093] Specifically, first, historical network message data is collected from each node (including abnormal nodes, upstream associated nodes and downstream associated nodes) on the information propagation path, key information such as the timestamp, source address, target address, message content and protocol type of the message is extracted, and the integrity and accuracy of the data are ensured.
[0094] Further, all the collected messages are uniformly sorted according to the timestamp, and a complete time axis is constructed.
[0095] The time axis needs to accurately align the message timing of different nodes, and ensure that the messages from the upstream, abnormal and downstream nodes can be accurately mapped into the real time sequence of the attack event, laying a time reference for the subsequent construction of the attack chain.
[0096] Further, starting from the earliest abnormal message, the starting time and initial position of the attack event are determined.
[0097] Further, according to the information propagation path logic of “upstream node-abnormal node-downstream node”, the messages of each node are sequentially connected to form a chain structure of “attack entry-propagation path-impact range”.
[0098] In this process, key nodes such as intrusion points and data transfer points in the attack path are highlighted, and the specific malicious behaviors at each time point are analyzed in detail. For example, at a certain time, the upstream node sends a Modbus message carrying malicious code to the abnormal node, and the abnormal node forwards the abnormal instruction to its downstream node after receiving it.
[0099] Finally, the message sequence connected in time sequence and the key node information are integrated to generate an attack backtracking report containing three-dimensional elements of “time-position-behavior”.
[0100] The attack backtracking report presents the overall picture of the attack event in a visual way, clearly showing the complete process of the attack from initiation, propagation to impact. It not only locates the source of malicious behavior and the propagation track, but also identifies the key operation details in the attack process, providing comprehensive support for in-depth analysis, problem solving and defense optimization of network security events.
[0101] Through this step, systematic backtracking from scattered abnormal nodes to complete attack chains is realized, effectively solving the problem of fragmented attack process and unclear time sequence in traditional methods, and greatly improving the tracing ability of power grid network security events.
[0102] For example, in a certain substation network attack event, abnormal messages with timestamps of 2025-07-01-08:30:15, 08:30:20 and 08:30:25 are collected from a border router (an upstream associated node), a station control layer switch (an abnormal node) and a bay level device (a downstream associated node), and the protocol types of the abnormal messages are all Modbus and carry the same malicious code.
[0103] Further, after sorting the abnormal messages according to the time axis, it is found that the border router first sends the malicious message to the station control layer switch, the switch forwards the malicious message to the bay level device, and finally the device misacts. The backtracking report generated by integrating these information shows that the attack starts from the border router being invaded, propagates to the terminal device through the switch, and the whole process is completed within 10 seconds, which provides a clear basis for subsequent reinforcement of border protection and access restriction of the switch.
[0104] The embodiments of the present application achieve the following technical effects through the specific implementation manner described above: The present application proposes an information-oriented network malicious behavior message backtracking generation method. First, the target power grid network is determined, the network level is identified, the intra-layer and inter-layer information flow relationship is analyzed, the network node topology containing multiple network nodes and information flow directions is constructed, and the structural foundation for subsequent analysis is laid. Then, the network protocol, traffic and behavior feature constraints of each node are extracted, the historical communication data is collected to construct a sample feature set, the labeled sample feature set is used to train a node anomaly recognizer based on a deep neural network, the node state is detected in real time, and the normal / abnormal result is output. When an abnormal node is found, the topology information flow direction is relied on, the abnormal message is taken as the target for bidirectional backtracking, the upstream node matching record is reversely searched, the downstream node associated record is forwardly searched, and the propagation path is constructed after recursive tracking to the network boundary. Finally, the path node message data is collected, the time axis is constructed by sorting according to the timestamp, the attack sequence is connected in series, and the backtracking report containing "time-position-behavior" is generated, so that the attack chain is completely restored.
[0105] The method provided by the embodiments of the present application solves the problems of inaccurate positioning of abnormal nodes, incomplete information propagation path backtracking and disordered time sequence of attack chains in the traditional backtracking process through the technical scheme of "topology construction-abnormal detection-path backtracking-chain reconstruction", realizes accurate backtracking of malicious behavior messages and complete restoration of the attack process, and provides technical support for the security protection and attack response of the power grid network.
[0106] It should be noted that the above-mentioned embodiment sequences of the present application are merely for description only, but not for representing the advantages and disadvantages of the embodiments. And the above-mentioned embodiments of the present specification have been described. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multi-task processing and parallel processing are also possible or can be advantageous.
[0107] The above only describes the preferred embodiments of the present application, and does not limit the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
[0108] The specification and drawings are merely exemplary of the present application, and any and all modifications, variations, combinations or equivalents that are within the scope of the present application should be included. Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application belong to the scope of the present application and its equivalents, the present application is intended to include these modifications and variations.
Claims
1. An information-oriented network malicious behavior packet traceback generation method, characterized in that, The method comprises: determining a target power grid network, constructing a network node topology according to the target power grid network, the network node topology comprising a plurality of network nodes and information flow directions between the network nodes; constructing a node anomaly identifier for each network node, performing node anomaly detection on the plurality of network nodes through each node anomaly identifier to obtain a plurality of node detection results; when there is an abnormal node in the plurality of node detection results, performing information-oriented analysis from the abnormal node based on the information flow directions in the network node topology to determine an information propagation path related to the abnormal node; based on the information propagation path, reconstructing a complete attack chain of malicious behavior in chronological order to generate malicious behavior packet backtracking results.
2. The method of claim 1, wherein, According to the target power grid network, a network node topology is constructed, and the network node topology comprises a plurality of network nodes and information flow directions between the network nodes, which comprises: identifying a plurality of network levels of the target power grid network, each network level comprising a plurality of level nodes; analyzing the intra-level node flow relationship between the level nodes in the plurality of network levels to construct a plurality of intra-level topologies; analyzing the inter-level information flow relationship between the network levels to construct an inter-level topology; based on the plurality of intra-level topologies and the inter-level topology, the network node topology is generated.
3. The method of claim 1, wherein, Constructing a node anomaly identifier for each network node comprises: extracting a first network node from the plurality of network nodes and obtaining node feature constraints of the first network node, the node feature constraints comprising network protocol feature constraints, traffic feature constraints and behavior feature constraints; collecting historical communication data of the first network node, extracting historical network protocol features, historical traffic features and historical behavior features, and constructing a sample node feature set; labeling the sample node feature set according to the network protocol feature constraints, the traffic feature constraints and the behavior feature constraints to obtain a sample feature label set; based on the sample node feature set and the sample feature label set, a node anomaly identifier for the first network node is constructed; the node anomaly identifiers for the remaining network nodes are constructed in the same way as the node anomaly identifier for the first network node is constructed, to obtain the node anomaly identifiers for each network node.
4. The method of claim 1, wherein, Through each node anomaly identifier, node anomaly detection is performed on the plurality of network nodes to obtain a plurality of node detection results, which comprises: real-time collection of current network communication data of each network node, extraction of current network protocol features, current traffic features and current behavior features to obtain current node features of each network node; inputting the current node features of each network node into the corresponding node anomaly identifier for anomaly detection analysis to obtain a plurality of node detection results, the node detection results being normal state or abnormal state.
5. The method of claim 1, wherein, When there is an abnormal node in the plurality of node detection results, information-oriented analysis is performed from the abnormal node based on the information flow directions in the network node topology to determine an information propagation path related to the abnormal node, which comprises: identify all abnormal nodes from the plurality of node detection results, and extract a first abnormal node, obtain abnormal message information of the first abnormal node; According to the information flow direction in the network node topology, taking the abnormal message information as the tracking target, starting from the first abnormal node, performing reverse tracing, identifying the upstream associated nodes transmitting the abnormal message information; According to the information flow direction in the network node topology, taking the abnormal message information as the tracking target, starting from the first abnormal node, performing forward tracking, identifying downstream associated nodes receiving the abnormal message information; Combine the first abnormal node, the corresponding upstream associated node and the downstream associated node to construct the information propagation path of the first abnormal node; According to the processing manner of the first abnormal node, process the remaining abnormal nodes to obtain the information propagation path related to the abnormal nodes.
6. The method of claim 5, wherein, Taking the abnormal message information as the tracking target, starting from the first abnormal node, performing reverse tracing, identifying the upstream associated nodes transmitting the abnormal message information, comprising: According to the information flow direction in the network node topology, determine the upstream network node pointing to the first abnormal node; Retrieving the message record matching the abnormal message information in the historical network communication data of the upstream network node; When the upstream network node has a matching message record, mark the corresponding upstream network node as an upstream associated node; Recursively repeat the reverse tracing for each upstream associated node until the network boundary node is reached.
7. The method of claim 5, wherein, Taking the abnormal message information as the tracking target, starting from the first abnormal node, performing forward tracking, identifying downstream associated nodes receiving the abnormal message information, comprising: According to the information flow direction in the network node topology, determine the downstream network node receiving information from the first abnormal node; Retrieving the message record related to the abnormal message information in the historical network communication data of the downstream network node; When the downstream network node has a related message record, mark the corresponding downstream network node as a downstream associated node; Recursively repeat the forward tracking for each downstream associated node until the network boundary node is reached.
Citation Information
Cited By
Abnormal behavior detection method and system for electric power information communication network
CN121173608A
Anomaly behavior detection method and system for power information communication network
CN121173608B
Information association analysis method and system based on network comment big data
CN121189295A