Energy private network security situation awareness method and system fusing internet of things and artificial intelligence
By constructing a frequency and time reference axis and performing semantic parsing in the energy private network, the network security risks of the energy private network are resolved, resistance to time synchronization errors and malicious tampering is achieved, the reliability of timing and the accuracy of anomaly detection are improved, and highly robust network security protection is provided.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GUIZHOU INST OF COAL SCI
- Filing Date
- 2026-05-27
- Publication Date
- 2026-06-23
AI Technical Summary
Energy private networks face cybersecurity risks, including protocol message tampering, replay attacks, and injection of false commands. Traditional time synchronization mechanisms are susceptible to network latency or malicious tampering, making it difficult to guarantee data timing consistency. Furthermore, existing methods lack deep coupling with physical operating status and cannot effectively distinguish between legitimate control commands and malicious operations.
By acquiring frequency signals and network communication data streams from IoT nodes in the energy private network, frequency fluctuation feature sequences are extracted and a unified frequency-time reference axis for the entire network is constructed. Communication interaction data is mapped to this axis to generate frequency-anchored data sequences, and semantic parsing and semantic-temporal consistency verification are performed. Temporal reliability scores are calculated and abnormal control behaviors are identified.
It achieves resistance to time synchronization errors and malicious tampering, improves timing reliability and anomaly detection accuracy, and provides real-time, highly robust network security protection capabilities.
Smart Images

Figure CN122268689A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the fields of network information security and energy industry control technology, and in particular to a method and system for network security situation awareness of energy private networks that integrates the Internet of Things and artificial intelligence. Background Technology
[0002] During the production and transportation of coal, oil, and gas, dedicated energy networks face serious cybersecurity risks, including protocol message tampering, replay attacks, and injection of false commands. These attacks can disrupt production scheduling, safety monitoring, and the stability of energy supply, threatening energy security.
[0003] Traditional time synchronization mechanisms are susceptible to network latency or malicious tampering, making it difficult to guarantee the consistency of data timing among the massive number of IoT nodes in the energy private network; while simple network traffic analysis or protocol parsing methods lack deep coupling with the physical operating status of the energy network and cannot effectively distinguish between legitimate control commands and malicious operations.
[0004] Therefore, there is an urgent need for a network security situational awareness method that can utilize the operating frequency signals of energy networks to achieve physical information fusion, so as to provide reliable security for "source-grid-load-storage". Summary of the Invention
[0005] This application provides a method and system for energy private network network security situation awareness that integrates the Internet of Things and artificial intelligence, thereby improving the accuracy of network security situation detection.
[0006] This application provides the following solution:
[0007] According to the first aspect, a method for network security situation awareness of a private energy network integrating the Internet of Things (IoT) and artificial intelligence (AI) is provided. The method includes: acquiring energy network operating frequency signals and network communication data streams collected by multiple IoT nodes in the private energy network; extracting frequency fluctuation feature sequences and communication interaction data based on the energy network operating frequency signals and the network communication data streams; constructing a unified frequency-time reference axis for the entire network based on the frequency fluctuation feature sequences; mapping the communication interaction data to the frequency-time reference axis to generate a frequency-anchored data sequence; performing semantic parsing on the private energy network protocol messages in the communication interaction data to construct a semantic representation of control commands and their expected physical effects model; performing semantic-temporal consistency verification based on the frequency-anchored data sequence and the semantic representation of control commands to obtain a semantic-physical coupling residual characterizing the deviation between the actual effect of the control commands and the expected physical effects model; calculating a temporal reliability score for the communication data based on the semantic-physical coupling residual and the temporal consistency deviation calculated based on the frequency-time reference axis, and identifying abnormal control behaviors; inputting the temporal reliability score and abnormal control behaviors into a preset situation assessment model to output a network security situation value for the private energy network.
[0008] According to one achievable method in this application embodiment, the extraction of frequency fluctuation feature sequences and communication interaction data based on the energy network operating frequency signal and the network communication data stream includes: performing filtering, denoising, and frequency estimation processing on the energy network operating frequency signal to obtain the corresponding frequency fluctuation feature sequence; performing protocol identification, message parsing, and session reassembly on the network communication data stream to extract control commands and their associated communication context information; and aligning and associating the frequency fluctuation feature sequence with the control commands and their associated communication context information based on node identifiers and time tags to generate communication interaction data containing frequency feature identifiers.
[0009] According to one achievable method in this application embodiment, the step of constructing a unified frequency-time reference axis for the entire network based on the frequency fluctuation feature sequence includes: performing multi-scale decomposition on the frequency fluctuation feature sequence to extract frequency change components at different time scales; constructing a composite feature vector based on the frequency change components at different time scales, and performing correlation calculation between adjacent time windows to determine the continuity constraint of frequency change; performing temporal smoothing and anomaly removal on the frequency fluctuation feature sequence according to the continuity constraint to obtain a stable reference frequency sequence; generating a monotonically increasing time mapping relationship based on the reference frequency sequence, and constructing a unified frequency-time reference axis for the entire network accordingly.
[0010] According to one achievable method in this application embodiment, before mapping the communication interaction data to the frequency time reference axis and generating a frequency-anchored data sequence, the method further includes: correcting the original timestamps in the communication interaction data based on the frequency fluctuation characteristic sequence, reconstructing the true occurrence time sequence of communication events, so as to eliminate the impact of time synchronization errors or malicious time tampering on time series analysis.
[0011] According to one achievable method in an embodiment of this application, after mapping the communication interaction data to the frequency time reference axis and generating a frequency-anchored data sequence, the method further includes: constructing a sliding time window based on the frequency fluctuation feature sequence, performing similarity matching on the frequency feature subsequence corresponding to the communication interaction data, and obtaining a frequency consistency matching degree; when the frequency consistency matching degree is lower than a preset threshold, determining that the communication interaction data has a replay attack or timing tampering behavior.
[0012] According to one achievable method in this application embodiment, the step of semantically parsing the energy private network protocol messages in the communication interaction data and constructing a semantic representation of control commands and their expected physical effects model includes: parsing the fields of the energy private network protocol messages to extract the control object identifier, operation type, parameter setting value, and execution timing information; mapping the field parsing results to a structured control command semantic representation based on a preset protocol semantic rule base; constructing a corresponding energy network operating state variable and its change relationship model based on the control command semantic representation and the energy transmission network topology and operating constraints; and generating an expected physical effect model characterizing the expected action path and effect result of the control command in the power grid based on the energy network operating state variable and its change relationship model.
[0013] According to one achievable method in this application embodiment, the step of performing semantic-temporal consistency verification based on the frequency-anchored data sequence and the semantic representation of the control command to obtain a semantic-physical coupling residual characterizing the deviation between the actual effect of the control command and the expected physical effect model includes: determining the expected change path and action time window of the target energy network operating state variables based on the semantic representation of the control command and its corresponding expected physical effect model; extracting the grid state observation sequence associated with the control command from the frequency-anchored data sequence and aligning it according to the command timing determined based on the frequency-time reference axis; performing matching analysis based on the grid state observation sequence and the expected change path to calculate the state offset, timing offset, and sequence consistency index; and fusing the state offset, timing offset, and sequence consistency index to generate the semantic-physical coupling residual.
[0014] According to one achievable method in this embodiment, a timing reliability score for communication data is calculated based on the semantic-physical coupling residual and the timing consistency deviation corresponding to the frequency-time reference axis, and abnormal control behavior is identified. This includes: normalizing the state offset, timing offset, and sequence consistency index in the semantic-physical coupling residual to obtain a multidimensional residual feature vector; performing segmented statistical analysis on the timing consistency deviation corresponding to the frequency-time reference axis to extract time drift features and frequency matching features; constructing a timing reliability scoring function based on the multidimensional residual feature vector and the time drift features and frequency matching features, calculating the score for the communication data, and obtaining the corresponding timing reliability score value; when the timing reliability score value is lower than a preset threshold, determining that the corresponding control command is an abnormal control behavior, and determining the abnormality type based on the multidimensional residual feature vector.
[0015] According to one achievable method in the embodiments of this application, the method for constructing the preset situation assessment model includes: selecting semantic-physical coupling residuals, temporal reliability scores, and temporal consistency deviations as input variables to construct a multidimensional risk feature vector; performing statistical analysis on the multidimensional risk feature vector based on historical operational data and labeled security events to determine the risk weights corresponding to each input variable; constructing a risk mapping function based on the risk weights to map the multidimensional risk feature vector to a unified security situation value; and completing the construction of the situation assessment model based on the security situation value and preset security level classification rules.
[0016] According to the second aspect, a network security situation awareness system for energy private networks integrating the Internet of Things (IoT) and artificial intelligence (AI) is provided. The system includes: an energy network data acquisition unit configured to acquire energy network operating frequency signals and network communication data streams collected by multiple IoT nodes in the energy private network, and extract frequency fluctuation feature sequences and communication interaction data based on the energy network operating frequency signals and the network communication data streams; a frequency anchoring sequence generation unit configured to construct a unified frequency-time reference axis for the entire network based on the frequency fluctuation feature sequences, map the communication interaction data to the frequency-time reference axis, and generate a frequency-anchored data sequence; and a message semantic parsing unit configured to analyze energy private network protocol messages in the communication interaction data. The system performs semantic parsing to construct a semantic representation of control commands and a model of their expected physical effects. A semantic-physical coupling residual calculation unit is configured to perform semantic-temporal consistency verification based on the frequency-anchored data sequence and the semantic representation of the control commands, obtaining a semantic-physical coupling residual that characterizes the deviation between the actual effect of the control commands and the model of their expected physical effects. An abnormal control behavior identification unit is configured to calculate the temporal reliability score of the communication data based on the semantic-physical coupling residual and the temporal consistency deviation calculated based on the frequency-time reference axis, and identify abnormal control behaviors. A security situation assessment unit is configured to input the temporal reliability score and the abnormal control behaviors into a preset situation assessment model and output the network security situation value of the energy private network.
[0017] According to the specific embodiments provided in this application, the following technical effects are disclosed:
[0018] This invention provides a network security situational awareness method for energy private networks that integrates the Internet of Things (IoT) and artificial intelligence (AI). By collecting energy network operating frequency signals and network communication data streams generated by multiple IoT nodes within the energy private network, frequency fluctuation feature sequences are extracted, and a unified frequency-time reference axis is constructed for the entire network. Communication interaction data is precisely mapped to generate frequency-anchored data sequences, effectively resisting time synchronization errors and malicious tampering. Based on this, semantic parsing of energy private network protocol messages is performed, and semantic representations of control commands and their expected physical effects models are constructed. Subsequently, semantic-temporal consistency verification is performed based on the frequency-anchored sequences and semantic representations to obtain semantic-physical coupling residuals that characterize the deviation between the actual effect and the expected physical effect of control commands. Then, based on the residuals and temporal consistency deviations, a temporal reliability score of the communication data is calculated to identify abnormal control behaviors, and the results are input into a preset situational assessment model to output the network security situational value of the energy private network. This method achieves deep cross-domain fusion of physical signals and network behavior, significantly improving temporal reliability, anomaly detection accuracy, and situational awareness reliability. It provides real-time, highly robust network security protection capabilities for energy private networks, demonstrating outstanding technological advancement and practical value.
[0019] Of course, any product implementing this application does not necessarily need to achieve all of the advantages described above at the same time. Attached Figure Description
[0020] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0021] Figure 1 A flowchart of a network security situation awareness method for energy private networks that integrates the Internet of Things and artificial intelligence, provided for an embodiment of this application;
[0022] Figure 2 A schematic diagram illustrating the construction process of the frequency-time reference axis provided in the embodiments of this application;
[0023] Figure 3 A structural block diagram of an energy private network network security situation awareness system integrating the Internet of Things and artificial intelligence, provided in an embodiment of this application;
[0024] Figure 4 A schematic block diagram of an electronic device provided in an embodiment of this application. Detailed Implementation
[0025] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of this application are within the scope of protection of this application.
[0026] The terminology used in the embodiments of this invention is for the purpose of describing particular embodiments only and is not intended to limit the invention. The singular forms “a,” “the,” and “the” as used in the embodiments of this invention and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise.
[0027] It should be understood that the term "and / or" used in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Additionally, the character " / " in this article generally indicates that the preceding and following related objects have an "or" relationship.
[0028] Depending on the context, the word "if" as used here can be interpreted as "when," "when," "in response to determination," or "in response to detection." Similarly, depending on the context, the phrase "if determination" or "if detection (of the stated condition or event)" can be interpreted as "when determination," "in response to determination," "when detection (of the stated condition or event)," or "in response to detection (of the stated condition or event)."
[0029] Figure 1 A flowchart illustrating the energy private network security situational awareness method integrating the Internet of Things and artificial intelligence, provided as an embodiment of this application. Figure 1 As shown, the method may include the following steps:
[0030] Step 101: Obtain the energy network operating frequency signal and network communication data stream collected by multiple IoT nodes in the energy private network, and extract the frequency fluctuation feature sequence and communication interaction data based on the energy network operating frequency signal and the network communication data stream.
[0031] Step 102: Based on the frequency fluctuation feature sequence, construct a unified frequency and time reference axis for the entire network, map the communication interaction data to the frequency and time reference axis, and generate a frequency-anchored data sequence.
[0032] Step 103: Perform semantic parsing on the energy private network protocol messages in the communication interaction data, and construct a semantic representation of control commands and a model of their expected physical effects.
[0033] Step 104: Based on the frequency-anchored data sequence and the semantic representation of the control command, perform semantic-temporal consistency verification to obtain the semantic-physical coupling residual that characterizes the deviation between the actual action of the control command and the expected physical action model.
[0034] Step 105: Calculate the timing reliability score of the communication data based on the semantic-physical coupling residual and the timing consistency deviation calculated based on the frequency-time reference axis, and identify abnormal control behaviors.
[0035] Step 106: Input the time-series reliability score and abnormal control behavior into the preset situation assessment model, and output the network security situation value of the energy private network.
[0036] As can be seen from the above process, this invention provides a network security situational awareness method for energy private networks that integrates the Internet of Things (IoT) and artificial intelligence (AI). By collecting energy network operating frequency signals and network communication data streams generated by multiple IoT nodes in the energy private network, it extracts frequency fluctuation feature sequences and constructs a unified frequency-time reference axis for the entire network. This accurately maps communication interaction data to generate frequency-anchored data sequences, effectively resisting time synchronization errors and malicious tampering. Based on this, semantic parsing of energy private network protocol messages is performed, and a semantic representation of control commands and their expected physical effects model are constructed. Subsequently, semantic-temporal consistency verification is performed based on the frequency-anchored sequence and semantic representation to obtain the semantic-physical coupling residual, which characterizes the deviation between the actual effect and the expected physical effect of the control commands. Then, based on the residual and the temporal consistency deviation, a temporal reliability score of the communication data is calculated to identify abnormal control behaviors, and the results are input into a preset situational assessment model to output the network security situational value of the energy private network. This method achieves deep cross-domain fusion of physical signals and network behavior, significantly improving temporal reliability, anomaly detection accuracy, and situational awareness reliability. It provides real-time, highly robust network security protection capabilities for energy private networks, demonstrating outstanding technological advancement and practical value.
[0037] The following describes in detail each step of the above process and the effects that can be further produced, with reference to the embodiments. First, step 101, namely "collecting the energy network operating frequency signal and network communication data stream collected by multiple IoT nodes in the energy private network, and extracting frequency fluctuation feature sequence and communication interaction data based on the energy network operating frequency signal and the network communication data stream", will be described in detail with reference to the embodiments.
[0038] An energy private network refers to a dedicated communication network built within the energy industry to meet business needs such as production control, safety monitoring, and data transmission. This invention first utilizes multiple IoT nodes deployed within the energy private network to collect real-time energy network operating frequency signals and network communication data streams. These IoT nodes are distributed across various stages of energy production, transportation, and storage, capable of sensing various physical quantities such as pipeline pressure fluctuation frequency, flow pulsation frequency, and equipment operating frequency, while simultaneously capturing various communication data streams transmitted within the network.
[0039] After acquiring the raw signals and data, the system performs filtering, noise reduction, and frequency estimation on the energy network operating frequency signals to extract frequency fluctuation feature sequences that reflect changes in network operating status. Simultaneously, it performs protocol identification, message parsing, and session reassembly on the network communication data stream to extract control commands and their associated communication context information, thereby forming structured communication interaction data.
[0040] Subsequently, based on node identifiers and time tags, the system precisely aligns and correlates the extracted frequency fluctuation feature sequences with the communication interaction data. This process generates communication interaction data containing frequency feature identifiers, enabling a close correspondence between network layer communication behavior and physical layer frequency signals in both time and space dimensions, laying the foundation for subsequent frequency anchoring and cross-domain consistency verification.
[0041] Specifically, in a practical system, the acquired energy network operating frequency signal is first preprocessed. The original frequency signal... Noise is removed by performing low-pass filtering and median filtering sequentially, followed by frequency estimation using short-time Fourier transform or Hilbert-Huang transform to extract the frequency fluctuation feature sequence. Each of them It includes instantaneous frequency value, rate of frequency change, and amplitude characteristics.
[0042] Simultaneously, protocol identification is performed on the network communication data stream. Based on the port number and characteristic fields, the energy private network protocol used is determined, such as IEC 61850, DNP3, etc. Then, deep packet analysis and session reassembly are performed on the data packets to extract control commands. Together with its associated communication context information, including source node ID, target node ID, timestamp ts, operation type, parameter values, etc., a structured communication interaction dataset Comm-D is formed.
[0043] Finally, based on the unique identifier ID of the IoT node and the calibrated time stamp, the frequency fluctuation feature sequence F is spatiotemporally aligned with the communication interaction dataset Comm-D. Specifically, for each control command... Find its occurrence time window The corresponding frequency feature subsequence The following association mapping is used to generate communication interaction data containing frequency feature identifiers:
[0044]
[0045] in, This is the frequency fluctuation feature vector corresponding to the instruction. For node identification, Here, j represents the communication context information, and j is the sequence number of the control command. Through the above processing, the originally independent physical frequency signals and network communication commands are precisely correlated, providing a high-quality fused data foundation for the subsequent construction of frequency-time reference axes and semantic-physical consistency verification.
[0046] The following describes in detail step 102, namely, "based on the frequency fluctuation feature sequence, construct a unified frequency and time reference axis for the entire network, map the communication interaction data to the frequency and time reference axis, and generate a frequency-anchored data sequence", with reference to the embodiments.
[0047] In this invention, constructing a unified frequency-time reference axis across the entire network is the core step in achieving precise synchronization between physical signals and network data. First, the system performs multi-scale decomposition on the extracted frequency fluctuation feature sequence. Using methods such as wavelet decomposition or empirical mode decomposition, the original frequency sequence is split into frequency variation components at different time scales, such as long-term trend components, medium-term fluctuation components, and short-term noise components. These components at different scales respectively reflect the characteristics of the energy network in terms of macroscopic operating status, mesoscopic dynamic changes, and microscopic instantaneous disturbances.
[0048] Next, the system constructs a composite feature vector based on these frequency variation components at different time scales. This composite feature vector fuses multi-scale information to form a vector representation that comprehensively characterizes the frequency fluctuation patterns. Then, correlation calculations are performed between adjacent time windows, such as calculating Pearson correlation coefficients or mutual information, to determine the continuity constraints of frequency variations. These constraints can identify normal variation patterns in the frequency sequence that conform to physical laws, while also marking abnormal jumps that may be caused by noise or attacks.
[0049] Based on the aforementioned continuity constraints, the system performs time-series smoothing on the frequency fluctuation characteristic sequence and removes outlier data points that do not meet the continuity requirements, ultimately obtaining a stable, continuous, and representative reference frequency sequence. This reference frequency sequence can serve as the time base for the entire energy private grid, overcoming the limitations of traditional clock synchronization methods.
[0050] Finally, based on a stable reference frequency sequence, the system generates a monotonically increasing time mapping relationship, mapping the natural evolution of physical frequencies to a unified time coordinate axis. This constructs a unified frequency-time reference axis for the entire network, enabling communication data distributed across different geographical locations and IoT nodes to be aligned and compared within the same reliable time frame, providing a solid foundation for subsequent semantic temporal consistency verification and anomaly detection.
[0051] like Figure 2A schematic diagram illustrating the construction process of a frequency-time reference axis is provided. This process includes: Step 1: The system collects operating frequency signals reported by multiple IoT nodes in the energy private network in real time, such as pipeline pressure fluctuation frequency and equipment vibration frequency. After filtering and denoising the original signals, the frequency fluctuation feature sequence is extracted. Step 2: In this diagram, wavelet transform or empirical mode decomposition is used to decompose the frequency sequence into long-term trend components, medium-term fluctuation components, and short-term noise components. Step 3: The correlation of each component is calculated in adjacent time windows to determine continuity constraints. Outliers that do not meet the constraints are removed, and the sequence is time-series smoothed to obtain a stable reference frequency sequence. Step 4: Based on the stable reference frequency sequence, a monotonically increasing mapping relationship between frequency values and time is established, forming a unified time coordinate system for the entire network. All subsequent communication data is mapped onto this reference axis.
[0052] in, Figure 2 The first waveform in the diagram is the result of step 1, which is the original frequency fluctuation feature sequence containing noise; the second waveform is the result of step 2, which is the different components after multi-scale decomposition; the third waveform is the result of steps 3-4, which is the stable reference frequency sequence obtained after smoothing and constraint processing, and is finally used to construct a unified time reference axis.
[0053] After constructing a unified frequency and time reference axis for the entire network, the system projects the previously extracted and associated communication interaction data onto this reference axis. Specifically, for each communication record, the system finds the corresponding frequency feature position on the reference axis based on its original timestamp or node information, and then repositions the communication data into the time coordinate system defined by the reference axis.
[0054] Through this mapping process, each piece of communication data acquires an "anchor" based on the physical frequency of the energy network. Communication data that might have previously suffered from timestamp discrepancies, clock asynchrony, or malicious tampering is now uniformly calibrated to a reliable time frame determined by the natural evolution of the physical frequency. This generates a frequency-anchored data sequence, where each piece of data not only contains control commands and context information but also is bound to a corresponding frequency characteristic identifier.
[0055] As an implementable approach, before mapping the communication interaction data to the frequency time reference axis and generating a frequency-anchored data sequence, the method further includes: correcting the original timestamps in the communication interaction data based on the frequency fluctuation characteristic sequence, and reconstructing the true time sequence of communication events to eliminate the impact of time synchronization errors or malicious time tampering on time series analysis.
[0056] Specifically, the system searches for frequency fluctuation characteristics closest to the time of the communication record, and determines the true physical time of the communication event by observing the natural evolution of the frequency signal. Then, the system corrects the original timestamps and rearranges the order of the communication events to reconstruct a time series that conforms to physical reality. After correction, the time information of the communication interaction data no longer relies solely on the network clock, but is closely bound to the physical operating frequency of the energy network. This process effectively eliminates time synchronization errors and significantly enhances resistance to malicious time tampering.
[0057] As another feasible approach, after mapping the communication interaction data to the frequency time reference axis and generating a frequency-anchored data sequence, the present invention further includes: constructing a sliding time window based on the frequency fluctuation feature sequence, performing similarity matching on the frequency feature subsequence corresponding to the communication interaction data to obtain a frequency consistency matching degree; when the frequency consistency matching degree is lower than a preset threshold, it is determined that the communication interaction data has a replay attack or timing tampering behavior.
[0058] Specifically, after generating the frequency-anchored data sequence, the system further introduces a sliding time window mechanism to detect the frequency consistency of the communication data in real time. This step is an important means of identifying replay attacks and timing tampering. The system first constructs a series of continuous sliding time windows based on the frequency fluctuation feature sequence, with each window covering a fixed-length time interval.
[0059] For each piece of communication interaction data anchored to the frequency-time reference axis, the system extracts a frequency feature subsequence within its corresponding time window. Then, it performs a similarity matching calculation between this subsequence and the actual frequency fluctuation features within the current sliding window. Matching methods can include Euclidean distance, cosine similarity, or dynamic time warping algorithms, resulting in a frequency consistency matching score. A higher score indicates a closer match between the time of the communication data occurrence and the then-current physical frequency fluctuation pattern.
[0060] When the calculated frequency consistency matching degree is lower than a preset threshold, the system determines that the communication interaction data is abnormal. In actual implementation, the preset threshold for frequency consistency matching degree can be set to 0.85. In different energy private network scenarios, it can be fine-tuned according to the actual test conditions. For example, it can be set to 0.82~0.87 in oil and gas pipeline network environments and 0.84~0.88 in coal production environments. Specifically, this usually means that the data may be the result of a replay attack, that is, the attacker retransmits previously recorded legitimate data packets at the current moment, causing its frequency characteristics to not match the current physical operating state; it may also be that the attacker has performed time-series tampering, causing the time sequence of the data to conflict with the actual frequency evolution pattern.
[0061] The following describes in detail step 103, namely, "semantically parsing the energy private network protocol messages in the communication interaction data and constructing a semantic representation of control commands and their expected physical effects model," with reference to the embodiments.
[0062] Semantic parsing of energy private network protocol messages in communication interaction data is a crucial step in achieving deep integration of physical information. First, the protocol messages are parsed at the field level to extract key information from the original binary or text data packets, including the controlled object identifier, operation type, parameter settings, and execution timing information. These fields collectively describe the specific content of a control command and its expected execution time.
[0063] Next, the system calls the preset protocol semantic rule library to map the extracted field parsing results into a structured control command semantic representation. This structured representation adopts a unified standard format, such as using attribute value pairs or knowledge graphs, to transform the originally obscure protocol fields into semantic descriptions that can be understood by both computers and domain experts, such as clear instructions like "Close valve A, set the target pressure to 2.5MPa".
[0064] Then, based on the semantic representation of the control commands and combined with the topology and operational constraints of the energy transmission network, the system constructs a model of the corresponding energy network operating state variables and their changing relationships. For example, based on the pipeline topology and current operating status, the model predicts how key state variables such as pressure, flow rate, and temperature will change over time after the command is executed, as well as the mutual influence relationships between the variables.
[0065] Finally, based on the above-mentioned operational state variables and change relationship model, the system generates a model of expected physical effects. This model fully characterizes the expected action path and final result of control commands in the energy network, including the trajectory of physical quantities after command execution, the possible range of influence, and the expected steady-state value.
[0066] As an feasible approach, once a structured semantic representation of a control command is extracted, the system first loads the topology model of the current energy transmission network. This model includes the connection relationships and parameters of equipment such as pipelines, valves, pumping stations, and storage tanks. Next, the system initializes the energy network's operational state variables, such as pressure, flow, and temperature values for each pipeline segment, and the equipment status of key nodes, based on current operational constraints like maximum pressure limits, minimum flow requirements, and equipment operating states.
[0067] Then, based on the semantic content of the control command, such as "adjust valve B opening to 65%, target pressure set to 3.2 MPa", the system performs forward simulation using a physical mechanism model or a simplified mathematical model. For example, it uses the pipeline transient flow equation or equipment characteristic curves to calculate the trajectory of each state variable over time after the command is executed, including instantaneous response, transient process, and final steady-state value. Simultaneously, it records the action path of the command, i.e., which equipment and pipe sections the command will affect sequentially.
[0068] The final generated expected physical action model is output in time series form, including the expected change curves of key state variables after command execution, the impact time windows of key nodes, and a description of the overall physical action results. For example, the model might output, "It is expected that within 12 seconds after the command is issued, the pressure in the target pipe segment will rise from 2.8 MPa to 3.2 MPa, and the flow rate will increase by 15%. The entire process complies with safety constraints and there is no risk of exceeding limits." This model is then used to compare with actually observed frequency anchoring data to calculate the semantic-physical coupling residual.
[0069] The following describes in detail step 104, namely, "based on the frequency-anchored data sequence and the semantic representation of the control command, perform semantic-temporal consistency verification to obtain the semantic-physical coupling residual that characterizes the deviation between the actual action of the control command and the expected physical action model," with reference to the embodiments.
[0070] This invention performs semantic and temporal consistency verification on the semantic representation of data sequences and control commands. The system closely links the control commands of the network layer with the actual operating state of the physical layer, providing a reliable quantitative basis for subsequent abnormal behavior identification and situation assessment.
[0071] Based on the semantic representation of control commands and their corresponding expected physical action models, the system determines the expected change path and time window of the target energy network's operating state variables. For example, the system will specify how key state variables such as pressure and flow should change over time after the command is executed, and within which time period the main effects should manifest.
[0072] Next, the system extracts the actual power grid state observation sequence associated with the control command from the frequency-anchored data sequence and precisely aligns it according to the command timing determined based on the frequency-time reference axis. This ensures that the expected model and the actual observation data can be compared within the same time frame.
[0073] Then, the system performs a matching analysis based on the aligned actual observation sequence and the expected change path, calculating three key indicators: state offset, temporal offset, and sequence consistency indicator. The state offset can be represented as the cumulative difference between the actual observed value and the expected value, for example:
[0074]
[0075]
[0076] Timing offset reflects the deviation between the actual time of the effect and the expected time, for example:
[0077]
[0078] Sequential consistency metrics assess whether the order of changes in state variables conforms to expectations, for example:
[0079]
[0080] Finally, the system performs a weighted fusion of the three indicators to generate a semantic-physical coupling residual. This residual value quantifies the overall deviation between the actual physical effect of the control command and the expected model; the larger the residual, the higher the likelihood that the command execution effect is inconsistent with the expectation.
[0081] For example:
[0082]
[0083] in This is a weighting coefficient that can be adjusted according to different energy scenarios.
[0084] Preferably, after generating the semantic-physical coupling residual, the present invention further includes: constructing a joint uncertainty model that includes frequency measurement error, communication transmission delay disturbance, and semantic parsing uncertainty of control commands; performing uncertainty propagation analysis on the state offset, timing offset, and sequence consistency index in the semantic-physical coupling residual based on the joint uncertainty model to obtain the probability distribution and corresponding confidence interval of the semantic-physical coupling residual; calculating the residual confidence level according to the probability distribution, and adaptively adjusting the anomaly judgment threshold based on the confidence interval; when the residual confidence level is lower than the adaptive threshold, determining that the control command is a high-risk abnormal behavior.
[0085] After generating semantic-physical coupling residuals, the system further constructs a joint uncertainty model to improve the reliability and robustness of anomaly detection. This model comprehensively considers three main sources of uncertainty: frequency measurement error, communication transmission delay disturbance, and semantic parsing uncertainty of control commands. These uncertainties are modeled using probability distributions or interval forms to obtain a joint uncertainty model that can quantify the overall uncertainty.
[0086] Based on this joint uncertainty model, the system performs uncertainty propagation analysis on the state offset, temporal offset, and sequence consistency index in the semantic-physical coupled residuals. The propagation analysis employs methods such as Monte Carlo sampling or analytical propagation formulas to calculate the distribution of each component of the residual under the influence of uncertainty, ultimately obtaining the probability distribution and corresponding confidence intervals of the semantic-physical coupled residuals. For example, the residuals may follow an approximately normal distribution. ,in The mean of the residuals, The standard deviation is denoted as .
[0087] Next, the system calculates the residual confidence level based on the probability distribution of the residuals. This confidence level reflects the degree of reliability of the current residual value after considering various uncertainties, and its value typically ranges from 0 to 1. The higher the confidence level, the stronger the reliability of the residuals.
[0088] Then, the system adaptively adjusts the anomaly detection threshold based on the confidence interval of the residuals. When the confidence level of the residuals is high, the threshold can be tightened appropriately to improve detection sensitivity; when the confidence level is low, the threshold can be relaxed appropriately to reduce false alarms. This adaptive mechanism makes anomaly detection more intelligent and robust.
[0089] Finally, when the residual confidence level is lower than the adaptively adjusted threshold, the system determines that the corresponding control instruction is a high-risk abnormal behavior and may trigger a higher level of alarm or isolation measures.
[0090] By introducing joint uncertainty modeling and propagation analysis, this method effectively reduces the risk of misjudgment caused by measurement errors, time delays, or analytical biases, and significantly improves the accuracy and reliability of energy private network security situation awareness in complex and uncertain environments.
[0091] The following describes in detail step 105, namely, "calculating the timing reliability score of communication data and identifying abnormal control behavior based on the semantic-physical coupling residual and the timing consistency deviation calculated based on the frequency-time reference axis," with reference to the embodiments.
[0092] Semantic-physical coupling residuals reflect the overall deviation between the actual physical effect of control commands and the expected physical effect model, while the timing consistency deviation calculated based on the frequency-time reference axis reflects the degree of consistency between the communication events in the time series and the physical frequency signals. These two key indicators characterize the reliability of communication data from different dimensions.
[0093] The system integrates the two indicators mentioned above and constructs a timing reliability scoring function to quantitatively score each piece of communication data. This score comprehensively considers both physical action deviation and timing deviation, enabling a comprehensive assessment of the reliability of the communication data. A high score indicates that the execution process of the control command is highly consistent with physical and timing laws; a low score indicates the presence of anomalies.
[0094] Once the timing reliability score falls below a preset threshold, the system immediately determines that the corresponding control command is an abnormal control behavior. It can further combine the specific deviation dimension in the residual feature vector to help determine the possible types of anomalies, such as replay attacks, command tampering, or fake data injection.
[0095] Specifically, firstly, the system normalizes the state offset, temporal offset, and sequence consistency index in the semantic-physical coupling residual, mapping the indices with different dimensions to the same numerical range, thus obtaining a multi-dimensional residual feature vector. This vector comprehensively characterizes the multi-dimensional deviation between the actual execution effect of control commands and the expected model.
[0096] Simultaneously, the system performs segmented statistical analysis on the timing consistency deviations corresponding to the frequency-time reference axis, extracting time drift and frequency matching features. Time drift features reflect the degree of offset of communication events on the time axis, while frequency matching features reflect the degree of agreement between actual frequency fluctuations and expected patterns. These features together constitute important supplementary information for assessing the reliability of communication data.
[0097] Next, the system constructs a time-series reliability scoring function based on multidimensional residual feature vectors, time drift features, and frequency matching features. This function can take the form of a weighted linear combination or a machine learning model, for example:
[0098]
[0099] in, This is the weighting coefficient. This function scores each piece of communication data to obtain a corresponding time-series reliability score. The higher the score, the more reliable the communication data.
[0100] As an feasible approach, the time-series reliability scoring function can also be constructed using a multi-layered fusion nonlinear model. First, feature cross-combinations and higher-order combinations are performed on the multi-dimensional residual feature vector, time-drift features, and frequency-matching features to generate an extended feature set. Then, a radial basis function neural network is introduced as the core scorer.
[0101] The specific scoring function can be expressed as follows:
[0102]
[0103] in, This is the expanded high-dimensional feature vector; The weight matrix obtained during training; For activation functions; for The function maps the output to interval; and These represent the bias terms of the first and output layers of the neural network, respectively, used for bias correction of the model.
[0104] During model training, historical normal data is used as positive samples, and labeled attack events are used as negative samples. End-to-end optimization is performed using the cross-entropy loss function. An attention mechanism is also introduced, allowing the model to automatically focus on the dimension that contributes most to the residuals. In actual operation, this function can achieve dynamic weight adjustment; for example, when frequency-matching features fluctuate drastically, their weights are automatically increased.
[0105] Compared to simple weighted summation, this complex construction method has stronger nonlinear expression and adaptive capabilities. Under complex operating conditions, it can improve the F1 score of anomaly detection by 8 to 15 percentage points, significantly enhancing the accuracy and robustness of situational awareness of energy private grids.
[0106] Finally, when the calculated timing reliability score is lower than a preset threshold, the system determines that the corresponding control command is an abnormal control behavior. Simultaneously, the system determines the specific type of anomaly based on the prominent features of each dimension in the multidimensional residual feature vector, such as replay attacks, command tampering, spoofed data injection, or timing manipulation.
[0107] The following describes in detail step 106, namely, "inputting the time-series reliability score and abnormal control behavior into a preset situation assessment model and outputting the network security situation value of the energy private network," with reference to the embodiments.
[0108] This step comprehensively analyzes and quantifies the multi-dimensional security indicators generated in the preceding steps, providing operations and maintenance personnel with an intuitive security status assessment. In the previous steps, the system has calculated a time-series reliability score for each piece of communication data and identified possible abnormal control behaviors. These quantitative results and anomaly information together constitute important inputs to the situation assessment model.
[0109] The pre-defined situation assessment model is a trained or rule-configured intelligent assessment system. It uses time-series reliability scores, the type, severity, and frequency of abnormal control behaviors as core input variables, and performs comprehensive analysis through multi-dimensional risk feature vectors. This model comprehensively considers both the local risks of individual events and the overall situation across the entire network, enabling dynamic assessment of the current security status of the dedicated energy grid.
[0110] The pre-defined situation assessment model is constructed as follows: First, the system selects semantic-physical coupling residuals, temporal reliability scores, and temporal consistency deviations as the main input variables, and combines these variables to construct a multi-dimensional risk feature vector. This vector can comprehensively reflect the current risk status of the energy private grid in terms of physical consistency, temporal reliability, and overall deviation.
[0111] In the actual construction of the situation assessment model, the system first selects the semantic-physical coupling residual ( ), time series reliability score ( ) and timing consistency deviation ( Using these as core input variables, they are concatenated into a multidimensional risk feature vector:
[0112]
[0113] The subscript _norm represents the value after min-max normalization, and its value ranges from 0 to 1.
[0114] Then, based on a large amount of historical operational data and labeled security events, the system performs statistical analysis on the multidimensional risk feature vector. Through methods such as correlation analysis, principal component analysis, or information gain analysis, the system determines the degree of influence of each input variable on the overall risk, i.e., the corresponding risk weight. These weights reflect the importance of different indicators in the security assessment of the energy private grid. For example, the weight vector obtained after analysis is as follows:
[0115]
[0116] The sum of the weights is 1. The weighting coefficient represents the semantic-physical coupling residual. This weighting value is the highest because physical deviation is usually the most important risk signal. This represents the weighting coefficient for the time series reliability score; This represents the risk weight coefficient corresponding to the timing consistency deviation.
[0117] Next, based on the calculated risk weights, the system constructs a risk mapping function. This function transforms the multidimensional risk feature vector into a unified security posture value through weighted summation or nonlinear mapping. This posture value is typically a number between 0 and 100; a higher score indicates a lower current cybersecurity risk and a better posture. For example, a linear weighted mapping function is as follows:
[0118]
[0119] The function outputs a value between 0 and 100, with higher scores indicating better security.
[0120] Finally, the system constructs a model based on the calculated security situation values and pre-defined security level classification rules. For example: 90 to 100: safe; 70 to 89: low risk; 40 to 69: medium risk; 0 to 39: high risk.
[0121] Finally, based on the output security posture value and combined with preset security level classification rules, such as safe, early warning, alarm, and critical alarm, the system completes the construction of a posture assessment model. In actual operation, this model can receive input data in real time and quickly output the current network security posture value of the energy private network, providing important reference for security decision-making and emergency response.
[0122] Through this step, the system can not only detect individual abnormal events, but also output the overall security status of the energy private network from a global perspective, providing operation and maintenance personnel with intuitive security risk warnings and decision support. For example, when the status value continues to decline, the system can automatically trigger higher-level alarms or emergency response mechanisms.
[0123] To further illustrate the technical effects of this application, a specific implementation method and the test results of this implementation method are given below.
[0124] The method of this invention has been specifically implemented in an energy network environment that coordinates oil and gas pipelines with coal production within an energy group. This energy network comprises approximately 1200 IoT nodes, covering production sites, pipeline transportation, storage and transportation stations, and a dispatch center. The system is deployed on edge computing servers and a cloud-based situational awareness platform, and is implemented using a hybrid programming approach of Python and C++.
[0125] Under normal operating conditions, the system collects the energy network operating frequency signal and network communication data stream once per second. After constructing the frequency-time reference axis, mapping the communication data, semantic parsing, and verifying semantic-temporal consistency, the calculated average semantic-physical coupling residual is 0.12, and the average temporal reliability score is 0.93. In tests simulating spoofed data injection attacks and replay attacks, the system achieved a detection accuracy of 97.8% for instruction tampering attacks and 98.5% for replay attacks, with an average detection latency of 420 milliseconds and a false alarm rate controlled within 1.2%.
[0126] During a 30-day continuous operation test, the consistency rate between the network security posture value output by this method and the evaluation results by human experts reached 94.6%. When the posture value is below 65, the system can issue a high-risk warning 12-45 seconds in advance, providing sufficient response time for maintenance personnel. The test results show that the method of this invention significantly improves the energy private network's ability to detect and respond to complex network attacks, verifying its effectiveness and reliability in a real industrial environment.
[0127] The method provided in this application can be applied to various application scenarios, including but not limited to: In a coal intelligent production scheduling platform, this method integrates the operating frequency of mine equipment with IoT communication data to perform timing reliability assessment and situational awareness of control commands for key equipment such as coal mining machines and conveyor belts, effectively preventing production interruptions or safety accidents caused by network attacks. In the security operation and maintenance scenario of an integrated energy data center encompassing "source, grid, load, and storage," this method, as a core module, performs global situational assessment of cross-regional, multi-source, heterogeneous energy private networks, providing real-time network security situational values to the scheduling center, supporting rapid decision-making and emergency response, and enhancing the resilience and supply capacity of the entire energy system. This technology demonstrates high real-time performance, high reliability, and strong anti-attack capabilities in the above scenarios, exhibiting significant engineering application value.
[0128] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.
[0129] According to another embodiment, a network security situation awareness system for private energy networks that integrates the Internet of Things and artificial intelligence is provided. Figure 3 A schematic block diagram of an energy private network network security situation awareness system integrating IoT and AI is shown according to one embodiment. Figure 3 As shown, the device 300 includes:
[0130] The energy network data acquisition unit 301 is configured to acquire energy network operating frequency signals and network communication data streams collected by multiple IoT nodes in the energy private network, and extract frequency fluctuation feature sequences and communication interaction data based on the energy network operating frequency signals and the network communication data streams.
[0131] The frequency anchoring sequence generation unit 302 is configured to construct a unified frequency and time reference axis for the entire network based on the frequency fluctuation feature sequence, map the communication interaction data to the frequency and time reference axis, and generate a frequency anchoring data sequence.
[0132] The message semantic parsing unit 303 is configured to perform semantic parsing on the energy private network protocol messages in the communication interaction data, and construct a semantic representation of control commands and their expected physical effects model.
[0133] The semantic-physical coupling residual calculation unit 304 is configured to perform semantic-temporal consistency verification based on the frequency-anchored data sequence and the semantic representation of the control command, and obtain the semantic-physical coupling residual characterizing the deviation between the actual action of the control command and the expected physical action model.
[0134] The abnormal control behavior identification unit 305 is configured to calculate the timing reliability score of communication data based on the semantic-physical coupling residual and the timing consistency deviation calculated based on the frequency-time reference axis, and to identify abnormal control behaviors.
[0135] The security situation assessment unit 306 is configured to input the time-series reliability score and abnormal control behavior into a preset situation assessment model and output the network security situation value of the energy private network.
[0136] As an implementable approach, the energy network data acquisition unit 301, when extracting frequency fluctuation feature sequences and communication interaction data based on the energy network operating frequency signal and the network communication data stream, can be configured to: perform filtering, denoising, and frequency estimation processing on the energy network operating frequency signal to obtain the corresponding frequency fluctuation feature sequence; perform protocol identification, message parsing, and session reassembly on the network communication data stream to extract control commands and their associated communication context information; and align and associate the frequency fluctuation feature sequence with the control commands and their associated communication context information based on node identifiers and time tags to generate communication interaction data containing frequency feature identifiers.
[0137] As an implementable approach, the frequency anchoring sequence generation unit 302, when constructing a unified frequency-time reference axis for the entire network based on the frequency fluctuation feature sequence, can be configured to: perform multi-scale decomposition on the frequency fluctuation feature sequence to extract frequency change components at different time scales; construct composite feature vectors based on the frequency change components at different time scales, and perform correlation calculations between adjacent time windows to determine the continuity constraints of frequency changes; perform temporal smoothing and anomaly removal on the frequency fluctuation feature sequence according to the continuity constraints to obtain a stable reference frequency sequence; generate a monotonically increasing time mapping relationship based on the reference frequency sequence, and construct a unified frequency-time reference axis for the entire network accordingly.
[0138] As an implementable approach, the frequency anchoring sequence generation unit 302 can be configured to: correct the original timestamps in the communication interaction data based on the frequency fluctuation characteristic sequence before mapping the communication interaction data to the frequency time reference axis and generating the frequency anchoring data sequence, so as to reconstruct the true occurrence time sequence of the communication events and eliminate the impact of time synchronization errors or malicious time tampering on time series analysis.
[0139] As an implementable approach, after mapping the communication interaction data to the frequency time reference axis and generating a frequency-anchored data sequence, the frequency anchoring sequence generation unit 302 can be configured to: construct a sliding time window based on the frequency fluctuation feature sequence, perform similarity matching on the frequency feature subsequences corresponding to the communication interaction data, and obtain a frequency consistency matching degree; when the frequency consistency matching degree is lower than a preset threshold, it is determined that the communication interaction data has a replay attack or timing tampering behavior.
[0140] As an implementable approach, the message semantic parsing unit 303, when performing semantic parsing on the energy private network protocol messages in the communication interaction data and constructing the semantic representation of control commands and their expected physical action model, can be configured as follows: parsing the fields of the energy private network protocol messages to extract the control object identifier, operation type, parameter setting value, and execution timing information; mapping the field parsing results to a structured control command semantic representation based on a preset protocol semantic rule base; constructing a corresponding energy network operating state variable and its change relationship model based on the control command semantic representation and the energy transmission network topology and operating constraints; and generating an expected physical action model characterizing the expected action path and result of the control command in the power grid based on the energy network operating state variable and its change relationship model.
[0141] As an implementable approach, the semantic-physical coupling residual calculation unit 304, when performing semantic-temporal consistency verification based on the frequency-anchored data sequence and the semantic representation of the control command to obtain the semantic-physical coupling residual characterizing the deviation between the actual effect of the control command and the expected physical effect model, can be configured as follows: Based on the semantic representation of the control command and its corresponding expected physical effect model, determine the expected change path and action time window of the target energy network operating state variables; extract the grid state observation sequence associated with the control command from the frequency-anchored data sequence and align it according to the command timing determined based on the frequency-time reference axis; perform matching analysis based on the grid state observation sequence and the expected change path to calculate the state offset, timing offset, and sequence consistency index; and fuse the state offset, timing offset, and sequence consistency index to generate the semantic-physical coupling residual.
[0142] As an implementable approach, the abnormal control behavior identification unit 305, when calculating the timing reliability score of communication data and identifying abnormal control behaviors based on the semantic-physical coupling residual and the timing consistency deviation corresponding to the frequency-time reference axis, can be configured as follows: Normalizing the state offset, timing offset, and sequence consistency index in the semantic-physical coupling residual to obtain a multidimensional residual feature vector; performing segmented statistical analysis on the timing consistency deviation corresponding to the frequency-time reference axis to extract time drift features and frequency matching features; constructing a timing reliability scoring function based on the multidimensional residual feature vector and the time drift and frequency matching features, calculating the score for the communication data, and obtaining the corresponding timing reliability score value; when the timing reliability score value is lower than a preset threshold, determining the corresponding control command as an abnormal control behavior, and determining the abnormal type based on the multidimensional residual feature vector.
[0143] As an implementable approach, the construction method of the preset situation assessment model in the security situation assessment unit 306 includes: selecting semantic-physical coupling residuals, temporal reliability scores, and temporal consistency deviations as input variables to construct a multi-dimensional risk feature vector; performing statistical analysis on the multi-dimensional risk feature vector based on historical operational data and labeled security events to determine the risk weights corresponding to each input variable; constructing a risk mapping function based on the risk weights to map the multi-dimensional risk feature vector to a unified security situation value; and completing the construction of the situation assessment model based on the security situation value and preset security level classification rules.
[0144] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on its differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments. The system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. Components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without creative effort.
[0145] In addition, embodiments of this application also provide a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps of the method described in any of the foregoing method embodiments.
[0146] And an electronic device, comprising:
[0147] One or more processors; and
[0148] A memory associated with the one or more processors, the memory being used to store program instructions that, when read and executed by the one or more processors, perform the steps of the method described in any of the foregoing method embodiments.
[0149] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the method described in any of the foregoing method embodiments.
[0150] in, Figure 4 An exemplary architecture of an electronic device is shown, which may include a processor 410, a video display adapter 411, a disk drive 412, an input / output interface 413, a network interface 414, and a memory 420. The processor 410, video display adapter 411, disk drive 412, input / output interface 413, network interface 414, and memory 420 can communicate with each other via a communication bus 430.
[0151] The processor 410 can be implemented using a general-purpose CPU, microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits to execute relevant programs and implement the technical solution provided in this application.
[0152] The memory 420 can be implemented using ROM, RAM, static storage devices, dynamic storage devices, etc. The memory 420 can store the operating system 421 for controlling the operation of the electronic device 400, and the basic input / output system (BIOS) 422 for controlling the low-level operations of the electronic device 400. Additionally, it can store a web browser 423, a data storage management system 424, and an energy private network security situation awareness system 425 integrating IoT and AI, etc. The aforementioned energy private network security situation awareness system 425 integrating IoT and AI can be the application program that specifically implements the aforementioned steps in this embodiment. In summary, when implementing the technical solution provided in this application through software or firmware, the relevant program code is stored in the memory 420 and executed by the processor 410.
[0153] Input / output interface 413 is used to connect input / output modules to realize information input and output. Input / output modules can be configured as components in the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Input devices may include keyboards, mice, touch screens, microphones, various sensors, etc., and output devices may include displays, speakers, vibrators, indicator lights, etc.
[0154] Network interface 414 is used to connect a communication module (not shown in the figure) to enable communication and interaction between this device and other devices. The communication module can communicate via wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).
[0155] Bus 430 includes a pathway for transmitting information between various components of the device, such as processor 410, video display adapter 411, disk drive 412, input / output interface 413, network interface 414, and memory 420.
[0156] It should be noted that although the above-described device only shows the processor 410, video display adapter 411, disk drive 412, input / output interface 413, network interface 414, memory 420, bus 430, etc., in specific implementations, the device may also include other components necessary for normal operation. Furthermore, those skilled in the art will understand that the above-described device may only include the components necessary for implementing the solution of this application, and does not necessarily include all the components shown in the figures.
[0157] As can be seen from the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary general-purpose hardware platforms. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a computer program product. This computer program product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in various embodiments or some parts of the embodiments of this application.
[0158] The technical solutions provided in this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. Furthermore, those skilled in the art will recognize that, based on the ideas of this application, there will be changes in the specific implementation methods and application scope. Therefore, the content of this specification should not be construed as a limitation of this application.
Claims
1. A method for network security situation awareness of energy private networks integrating the Internet of Things and artificial intelligence, characterized in that, The method includes: The system acquires energy network operating frequency signals and network communication data streams collected by multiple IoT nodes in the energy private network, and extracts frequency fluctuation feature sequences and communication interaction data based on the energy network operating frequency signals and the network communication data streams. Based on the frequency fluctuation feature sequence, a unified frequency and time reference axis for the entire network is constructed, and the communication interaction data is mapped to the frequency and time reference axis to generate a frequency-anchored data sequence. Semantic parsing is performed on the energy private network protocol messages in the communication interaction data to construct a semantic representation of control commands and a model of their expected physical effects; Based on the frequency-anchored data sequence and the semantic representation of the control command, a semantic-temporal consistency verification is performed to obtain the semantic-physical coupling residual, which characterizes the deviation between the actual effect of the control command and the expected physical effect model. Based on the semantic-physical coupling residual and the timing consistency deviation calculated based on the frequency-time reference axis, the timing reliability score of the communication data is calculated, and abnormal control behavior is identified. The time-series reliability score and abnormal control behavior are input into a preset situation assessment model, and the network security situation value of the energy private network is output.
2. The method according to claim 1, characterized in that, The extraction of frequency fluctuation feature sequences and communication interaction data based on the energy network operating frequency signal and the network communication data stream includes: The energy network operating frequency signal is subjected to filtering, noise reduction, and frequency estimation processing to obtain the corresponding frequency fluctuation feature sequence. The network communication data stream is subjected to protocol identification, message parsing, and session reassembly to extract control commands and their associated communication context information; Based on node identifiers and time tags, the frequency fluctuation feature sequence is aligned and associated with the control command and its associated communication context information to generate communication interaction data containing frequency feature identifiers.
3. The method according to claim 1, characterized in that, The construction of a unified frequency-time reference axis for the entire network based on the frequency fluctuation feature sequence includes: The frequency fluctuation feature sequence is decomposed into multiple scales to extract frequency change components at different time scales; A composite feature vector is constructed based on the frequency change components at different time scales, and correlation calculation is performed between adjacent time windows to determine the continuity constraint of frequency change. Based on the aforementioned continuity constraint, the frequency fluctuation feature sequence is subjected to temporal smoothing and anomaly removal to obtain a stable reference frequency sequence; Based on the reference frequency sequence, a monotonically increasing time mapping relationship is generated, and a unified frequency and time reference axis for the entire network is constructed accordingly.
4. The method according to claim 1, characterized in that, Before mapping the communication interaction data to the frequency-time reference axis to generate a frequency-anchored data sequence, the method further includes: Based on the frequency fluctuation characteristic sequence, the original timestamps in the communication interaction data are corrected to reconstruct the true time sequence of communication events, so as to eliminate the impact of time synchronization errors or malicious time tampering on time series analysis.
5. The method according to claim 1, characterized in that, After mapping the communication interaction data to the frequency-time reference axis to generate a frequency-anchored data sequence, the method further includes: A sliding time window is constructed based on the frequency fluctuation feature sequence, and similarity matching is performed on the frequency feature subsequences corresponding to the communication interaction data to obtain the frequency consistency matching degree. When the frequency consistency matching degree is lower than a preset threshold, it is determined that the communication interaction data has a replay attack or timing tampering behavior.
6. The method according to claim 1, characterized in that, The step of semantically parsing the energy private network protocol messages in the communication interaction data and constructing a semantic representation of control commands and their expected physical effects includes: The energy private network protocol message is parsed to extract the control object identifier, operation type, parameter setting value and execution timing information; Based on a pre-defined protocol semantic rule base, the field parsing results are mapped into a structured control instruction semantic representation; Based on the semantic representation of the control commands, and combined with the topology and operational constraints of the energy transmission network, a corresponding model of the energy network operation state variables and their changing relationships is constructed. Based on the energy network operation state variables and their changing relationship model, a model of expected physical action is generated to characterize the expected action path and result of the control command in the power grid.
7. The method according to claim 1, characterized in that, The data sequence anchored based on the frequency and the semantic representation of the control command are subjected to semantic-temporal consistency verification to obtain the semantic-physical coupling residual, which characterizes the deviation between the actual action of the control command and the expected physical action model, including: Based on the semantic representation of the control commands and their corresponding expected physical action models, the expected change path and action time window of the target energy network operation state variables are determined; Extract the power grid state observation sequence associated with the control command from the frequency-anchored data sequence and align it according to the command timing determined based on the frequency time reference axis; Based on the power grid state observation sequence and the expected change path, a matching analysis is performed to calculate the state offset, time offset, and sequence consistency index. The state offset, timing offset, and sequence consistency index are fused to generate the semantic-physical coupling residual.
8. The method according to claim 1, characterized in that, Based on the semantic-physical coupling residuals and the timing consistency deviations corresponding to the frequency-time reference axes, a timing reliability score for the communication data is calculated, and abnormal control behaviors are identified, including: The state offset, temporal offset, and sequence consistency index in the semantic-physical coupling residual are normalized to obtain a multidimensional residual feature vector. Perform segmented statistical analysis on the timing consistency deviation corresponding to the frequency-time reference axis to extract time drift features and frequency matching features; Based on the multidimensional residual feature vector, the time drift feature, and the frequency matching feature, a time series reliability scoring function is constructed to score the communication data and obtain the corresponding time series reliability score value. When the timing reliability score is lower than a preset threshold, the corresponding control instruction is determined to be an abnormal control behavior, and the anomaly type is determined based on the multidimensional residual feature vector.
9. The method according to claim 1, characterized in that, The method for constructing the preset situation assessment model includes: Semantic-physical coupling residuals, temporal credibility scores, and temporal consistency deviations are selected as input variables to construct a multidimensional risk feature vector; Based on historical operational data and labeled security events, statistical analysis is performed on the multidimensional risk feature vector to determine the risk weight corresponding to each input variable. Based on the risk weights, a risk mapping function is constructed to map the multidimensional risk feature vectors into a unified security posture value; Based on the security situation value and the preset security level classification rules, the situation assessment model is constructed.
10. A network security situational awareness system for energy private networks integrating the Internet of Things and artificial intelligence, characterized in that, The system includes: The energy network data acquisition unit is configured to acquire energy network operating frequency signals and network communication data streams collected by multiple IoT nodes in the energy private network, and extract frequency fluctuation feature sequences and communication interaction data based on the energy network operating frequency signals and the network communication data streams. The frequency anchoring sequence generation unit is configured to construct a unified frequency-time reference axis for the entire network based on the frequency fluctuation feature sequence, map the communication interaction data to the frequency-time reference axis, and generate a frequency anchoring data sequence. The message semantic parsing unit is configured to perform semantic parsing on the energy private network protocol messages in the communication interaction data, and construct a semantic representation of control commands and a model of their expected physical effects. The semantic-physical coupling residual calculation unit is configured to perform semantic-temporal consistency verification based on the frequency-anchored data sequence and the semantic representation of the control command, and obtain the semantic-physical coupling residual characterizing the deviation between the actual action of the control command and the expected physical action model. An abnormal control behavior identification unit is configured to calculate the timing reliability score of communication data based on the semantic-physical coupling residual and the timing consistency deviation calculated based on the frequency-time reference axis, and to identify abnormal control behaviors. The security situation assessment unit is configured to input the time-series reliability score and abnormal control behavior into a preset situation assessment model and output the network security situation value of the energy private network.