A power control method, system and apparatus based on security posture awareness and active response

By deploying global and local twins in the power control system and constructing a distributed digital twin model, the problem of insufficient fusion of multi-source heterogeneous information in existing technologies is solved. This enables real-time data transmission and closed-loop response across sites and regions, improves the perception accuracy and response speed of network attacks, and enhances the security resilience of the system.

CN122338751APending Publication Date: 2026-07-03NANJING GUODIAN NANZI POWER GRID AUTOMATION CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610407121.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-03-31
Publication Date
2026-07-03

AI Technical Summary

Technical Problem

Existing power network security situation awareness methods lack the fusion of multi-source heterogeneous information, making it difficult to reflect the power-physical coupling effect under complex attacks. They also lack scalability and adaptability, are unable to achieve distributed deployment across sites and regions, and lack automatic/semi-automatic closed-loop response capabilities, resulting in response delays and insufficient recovery.

Method used

By deploying global and local twins, a distributed digital twin model is constructed, which integrates multi-source heterogeneous data for security situation awareness and builds anomaly detection, causal analysis and proactive response mechanisms to achieve real-time data transmission and closed-loop response across sites and regions.

Benefits of technology

It improves the power control system's perception accuracy and response speed to network attacks, enhances the system's security resilience, enables real-time data transmission and closed-loop response across sites and regions, and optimizes the efficiency of anomaly detection and causal analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122338751A_ABST
    Figure CN122338751A_ABST
Patent Text Reader

Abstract

The application discloses a power control method, system and device based on security posture perception and active response. The method comprises the following steps: calculating a first global security posture assessment result and a dynamic response threshold based on intermediate results sent by each local twin, generating a response strategy template set when the comparison result of the two is greater than or equal to, combining an introduced response strategy parameter set to generate a first response strategy, executing the first response strategy when the first global security posture assessment result is not less than a preset execution threshold, and generating and executing a second response strategy when the first global security posture assessment result is less than the preset execution threshold; and calculating based on an updated twin system state of each local twin, and the calculation result is used for updating the response strategy parameter set. The application realizes abnormality detection, cause analysis, risk assessment and active response by deploying a global twin and a plurality of local twins, so that the perception accuracy, response speed and overall security resilience to network attacks and composite threats are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a power control method, system, and device based on security situation awareness and proactive response, belonging to the field of power control system security technology. Background Technology

[0002] As power systems gradually become more digitalized, networked, and intelligent, their dispatching and control processes increasingly rely on power communication networks and information systems. However, frequent cyberattacks, such as denial-of-service attacks, injection of false data, and tampering with control commands, have become significant hidden dangers to the safe operation of power systems.

[0003] Existing methods for power network security situational awareness mainly rely on network traffic feature detection and centralized digital twin modeling to identify and warn of attack paths. However, these methods still have the following limitations: they lack the fusion of multi-source heterogeneous information such as high-precision voltage information provided by synchronous phasor measurement units (PMUs), environmental data collected by Internet of Things (IoT) sensors, and external meteorological information, making it difficult to comprehensively reflect the power-physical coupling effect under complex attacks; existing methods mostly adopt centralized twin models, which suffer from insufficient scalability, model universality, and adaptability. At the same time, in large-scale power grid environments, data needs to be aggregated across regions to the central node, which inevitably increases communication latency and bandwidth pressure, and cannot effectively support distributed deployment across sites and regions; current security situation awareness mostly relies on anomaly detection methods based on big data or machine learning. These methods are mainly black-box models, which are difficult to output attack causal chains or provide interpretable results, lack the ability to extrapolate and predict potential future risks, and cannot provide forward-looking protection for the power grid; most only generate warnings or recommended solutions without further execution, lacking automatic / semi-automatic closed-loop response and recovery capabilities, resulting in response delays, insufficient recovery, and lack of closed-loop, making it impossible to quickly adjust when the system is abnormal.

[0004] Based on the above limitations, it is necessary to design a power control method, system, and device based on security situation awareness and proactive response, aiming to solve the following technical problems: how to construct a distributed digital twin model that integrates multi-physical domain information in the power control system, combine multi-source heterogeneous data to achieve interpretable security situation awareness, and form a closed-loop response mechanism of detection-decision-execution-feedback under the premise of ensuring real-time performance, thereby improving the system's perception accuracy, response speed, and overall security resilience against network attacks and complex threats. Summary of the Invention

[0005] The purpose of this invention is to provide a power control method, system, and device based on security situation awareness and proactive response. By deploying a global twin and several local twins, it can achieve anomaly detection, causal analysis, risk assessment, and proactive response, thereby improving the power control system's perception accuracy, response speed, and overall security resilience against network attacks and complex threats.

[0006] To achieve the above objectives, the present invention is implemented using the following technical solution.

[0007] In a first aspect, the present invention provides a power control method based on security situation awareness and proactive response, used to control a power control system, wherein the power control system includes a substation and a regional control center, and is executed by a global twin, comprising:

[0008] The first global security posture assessment result is obtained based on the twin system status, anomaly score set and attack cause graph sent by each local twin; each local twin is installed in a substation or regional control center;

[0009] A dynamic response threshold is constructed based on the attack causal chain sent by each local twin. The first global security situation assessment result is compared with the dynamic response threshold. When the first global security situation assessment result is greater than or equal to the dynamic response threshold, the handling priority of each target graph node is defined based on the anomaly score set and the attack causal chain. The target graph nodes are sorted based on the handling priority to obtain the response strategy template set.

[0010] A set of response strategy parameters is introduced, and a first response strategy is generated by combining it with a set of response strategy templates;

[0011] Comparing the first global security situation assessment result with a preset execution threshold, when the first global security situation assessment result is greater than or equal to the preset execution threshold, an execution command is sent to the disposal execution module that is connected to the global twin, so that the disposal execution module executes the first response strategy; when the first global security situation assessment result is less than the preset execution threshold, the global twin first notifies the dispatcher to revise the first response strategy through the human-machine collaborative monitoring module that is connected to it to obtain a second response strategy, and then sends an execution command to the disposal execution module so that the disposal execution module executes the second response strategy.

[0012] The second global security situation assessment result is calculated based on the updated state of the twin system, the set of anomaly scores, and the attack causality graph of each local twin, and is compared with the first global security situation assessment result to obtain the handling effect index.

[0013] The response strategy parameter set is updated based on the effectiveness indicators of the treatment.

[0014] In conjunction with the first aspect, optionally, the calculation method for the first global security situation assessment result is as follows:

[0015] The basic risk value is calculated based on the twin system state and anomaly score set;

[0016] Constructing a causal graph regulation function based on the attack causal graph;

[0017] The first global security situation assessment result is obtained by calculating based on the basic risk value and the cause-effect graph adjustment function.

[0018] In conjunction with the first aspect, optionally, the formula for calculating the basic risk value is:

[0019] ;

[0020] In the formula, For at any time The basic risk value; The target graph node is currently being updated. The graph node is an abstract representation of the equipment or functional unit in the power control system in the graph structure. This is the set of target graph nodes whose state is currently being updated. The target graph node weights are determined by the target graph nodes. The importance of the corresponding equipment or functional unit in the topology and operation of the power control system is determined; For target graph nodes At any moment The abnormal score; β is the state influence weight; Φ(X(t)) is the state risk feature extracted from the twin system state. For at any time The state of the twin system;

[0021] The formula for calculating the first global security situation assessment result is as follows:

[0022] ;

[0023] In the formula, This is the result of the first overall security situation assessment; For at any time Attack causality graph; This is the causal graph adjustment function.

[0024] Secondly, the present invention provides a power control method based on security situation awareness and proactive response, executed by a local twin deployed at the substation side or the regional control center side, comprising:

[0025] The preprocessed multi-source heterogeneous operating data is mapped to the internal digital twin model to obtain the twin system state;

[0026] A graph structure is constructed based on the state of the twin system, and an anomaly score set is calculated on the graph structure; the graph nodes in the graph structure represent devices or functional units in the topology of the power control system.

[0027] Based on the anomaly score set and the twin system state, an attack causality graph is constructed, and an attack causality chain is extracted from the attack causality graph.

[0028] Send the twin system status, anomaly score set, attack cause-effect graph, and attack cause-effect chain to the global twin through edge nodes;

[0029] The twin system state is updated based on the response execution results fed back by the handling execution module, and the anomaly score set and attack cause-effect graph are updated in sequence. The updated twin system state, anomaly score set and attack cause-effect graph are sent to the global twin through edge nodes.

[0030] In conjunction with the second aspect, optionally, the expression for the digital twin model is:

[0031] ;

[0032] In the formula, For digital twin models; These represent the electrical domain sub-model, the communication domain sub-model, and the physical environment domain sub-model, respectively. This refers to the coupling relationship between the electrical domain and the communication domain. This refers to the coupling relationship between the electrical domain and the physical environment domain. This refers to the coupling relationship between the communication domain and the physical environment domain.

[0033] The expression for the state of the twin system is:

[0034] ;

[0035] In the formula, For at any time The state of the twin system; For data mapping functions; For at any time The collected application-layer control and status monitoring data; For at any time Time-synchronized measurement data was collected. For at any time Collected network communication status data; For at any time Collected environmental sensor data; For at any time External condition data collected;

[0036] The expression for updating the state of the twin system is:

[0037] ;

[0038] In the formula, For at any time The state of the twin system, i.e., the updated state of the twin system; For state update functions; For at any time The first response strategy or the second response strategy; For at any time The attack causal chain; For at any time The response execution result. In conjunction with the second aspect, optionally, the expression for the anomaly score set is:

[0039] ;

[0040] In the formula, For at any time The set of abnormal scores; This refers to the target graph node whose status is currently being updated. For nodes At any moment Abnormal scores, and ;

[0041] In the formula, The function is used to map graph node features to normalized anomaly scores; This is the output layer weight matrix; For target graph nodes At any moment The Layer feature vectors;

[0042] in, ;

[0043] In the formula, It is a non-linear activation function; The neighboring graph nodes of the target graph node v; For target graph nodes The set of neighboring graph nodes; This is a normalization constant; The number of layers in the graph neural network; For the first Neighbor feature transformation weight matrix of the layer; For the first The weight matrix for feature transformation of self-graph nodes in a layer; For graph nodes At any moment The Layer feature vectors; For target graph nodes At any moment The Layer feature vectors.

[0044] In conjunction with the second aspect, optionally, the expression for the attack causal graph is:

[0045] ;

[0046] In the formula, For a moment Attack causality graph; For a moment A set of causal nodes, wherein the causal nodes are graph nodes in a graph structure that have causal relationships; For a moment The set of causal edges; For a moment The set of weights; Indicates causal attributes;

[0047] in, ;

[0048] In the formula, In the time window The set of multivariate time series data, which consists of twin system states and anomaly score sets; A collection of multivariate time series The first in Time series of 1 variable; For variable indexing;

[0049] in, ;

[0050] In the formula, and For the set of causal nodes Any two distinct variables in the equation; For variables For variables When Granger causality exists, a directed causal edge is established;

[0051] in, ;

[0052] In the formula, For variables For variables At any moment The strength of the causal influence;

[0053] The expression for the causal chain is:

[0054] ;

[0055] In the formula, For at any time causal chain; For at any time A directed causal path that starts from the source graph node, propagates through several intermediate graph nodes, and affects downstream graph nodes. For at any time The number of causal chains identified.

[0056] Thirdly, the present invention provides a power control system based on security situation awareness and proactive response, including a global twin, edge nodes, several local twins, a processing execution module, and a human-machine collaborative monitoring module, wherein each local twin is deployed on the substation side or the regional control center side.

[0057] The local twin maps the preprocessed multi-source heterogeneous operating data to the internal digital twin model to obtain the twin system state;

[0058] The local twin constructs a graph structure based on the twin system state and calculates the anomaly score set on the graph structure; the graph nodes in the graph structure represent devices or functional units in the power control system topology.

[0059] The local twin constructs an attack causal graph based on the anomaly score set and the twin system state, and extracts the attack causal chain from the attack causal graph;

[0060] The local twin sends the twin system status, anomaly score set, attack cause-effect graph, and attack cause-effect chain to the global twin through edge nodes;

[0061] The global twin calculates the first global security posture assessment result based on the twin system status, anomaly score set and attack cause graph sent by each local twin;

[0062] The global twin constructs a dynamic response threshold based on the attack causal chain sent by each local twin. It compares the first global security situation assessment result with the dynamic response threshold. When the first global security situation assessment result is greater than or equal to the dynamic response threshold, it defines the handling priority of each target graph node based on the anomaly score set and the attack causal chain. Based on the handling priority, it sorts each target graph node to obtain a set of response strategy templates.

[0063] The global twin introduces a set of response strategy parameters and combines them with a set of response strategy templates to generate the first response strategy;

[0064] The global twin compares the first global security situation assessment result with a preset execution threshold. When the first global security situation assessment result is greater than or equal to the preset execution threshold, it sends an execution command to the disposal execution module connected to the global twin to execute the first response strategy. When the first global security situation assessment result is less than the preset execution threshold, the global twin first notifies the dispatcher to revise the first response strategy through the human-machine collaborative monitoring module connected to it to obtain a second response strategy, and then sends an execution command to the disposal execution module to execute the second response strategy.

[0065] After the handling execution module executes the first response strategy or the second response strategy, it obtains the response execution result and feeds it back to each local twin.

[0066] Each local twin updates the twin system state based on the response execution results fed back by the handling execution module, and sequentially updates the anomaly score set and attack cause-effect graph. The updated twin system state, anomaly score set, and attack cause-effect graph are then sent to the global twin through edge nodes.

[0067] The global twin calculates the second global security situation assessment result based on the updated twin system state, anomaly score set and attack causality graph of each local twin, and compares it with the first global security situation assessment result to obtain the handling effect index.

[0068] The global twin updates the set of response strategy parameters based on the treatment effect indicators.

[0069] In conjunction with the third aspect, optionally, the expression for the processing priority is:

[0070] ;

[0071] In the formula, This refers to the target graph node whose status is currently being updated. The neighboring graph nodes of the target graph node v; For target graph nodes At any moment Priority of handling; For target graph nodes At any moment Abnormal scores; To satisfy the existence from point to Neighbor graph nodes of causal edges ; To attack the causal graph at time The set of causal edges; For at any time Target graph nodes For neighbor graph nodes The strength of the causal influence;

[0072] The expression for the dynamic response threshold is:

[0073] ;

[0074] In the formula, For a moment The dynamic response threshold, Basic safety threshold; For a moment The maximum propagation depth of the attack causal chain; For a moment The attack affects the percentage of graph nodes; For a moment The causal strength aggregation index; These are the structural sensitivity coefficient, the influence range sensitivity coefficient, and the causal intensity sensitivity coefficient, respectively.

[0075] The expression for the treatment effect index is:

[0076] ;

[0077] In the formula, For at any time The indicators of treatment effectiveness; This is the result of the first overall security situation assessment; This is the result of the second global security situation assessment;

[0078] The update formula for the response strategy parameters is:

[0079] ;

[0080] In the formula, For at any time The set of response strategy parameters, i.e., the updated response strategy parameters; For at any time The set of response strategy parameters, i.e., the response strategy parameters before the update; The learning rate is adjusted in response to updates to the policy parameters; This refers to the sensitivity or gradient information of the response strategy to the response strategy parameters. For at any time A collection of response strategy templates.

[0081] Fourthly, the present invention provides a power control device based on security situation awareness and proactive response, including a storage medium and a processor;

[0082] The storage medium is used to store instructions;

[0083] The processor is configured to operate according to the instructions to implement the method described in either the first aspect or the second aspect.

[0084] Compared with the prior art, the beneficial effects achieved by the present invention are as follows:

[0085] This invention effectively supports cross-site and cross-regional data transmission by deploying global and local twins, avoiding communication delays and alleviating bandwidth pressure. The first global security situation assessment result integrates the twin system status, anomaly score set, and attack cause-effect graph of each local twin. Based on this, combined with the response strategy parameter set and response strategy template set, a response strategy is selected and executed to achieve risk assessment and proactive response.

[0086] The local twins of this invention are deployed on the substation side or the regional control center side, respectively. They are combined with multi-source heterogeneous data of the corresponding region to perform local twin mapping and anomaly analysis, generate intermediate results including twin system status, anomaly score set, attack causal chain and attack causal graph, and transmit them to the global twin for centralized calculation of the first global security situation assessment result, that is, to assess global risk and realize anomaly detection and causal analysis.

[0087] This invention generates and executes corresponding response strategies based on intermediate results transmitted from local twins in the global twin, obtains response execution results, and feeds them back to each local twin for updating. After the update, it enters the next security situation awareness and proactive response cycle, realizing continuous iterative optimization of anomaly detection, causal analysis, risk assessment, and proactive response. This constitutes a closed-loop adaptive optimization security situation awareness and proactive response mechanism based on attack causal chains and feedback on handling effects, thereby achieving accurate perception, causal tracking, and collaborative handling of network attacks on power control systems. Attached Figure Description

[0088] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the embodiments will be briefly described below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort, wherein:

[0089] Figure 1 The diagram shown is an overall architecture diagram of a power control system based on security situation awareness and proactive response according to the present invention.

[0090] Figure 2 The diagram shown is a flowchart of a power control method based on security situation awareness and proactive response according to the present invention. Detailed Implementation

[0091] The technical solution of the present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the embodiments of the present invention and the specific features in the embodiments are detailed descriptions of the technical solution of the present invention, rather than limitations thereof. In the absence of conflict, the embodiments of the present invention and the technical features in the embodiments can be combined with each other.

[0092] Example 1

[0093] like Figure 1 and Figure 2 As shown in the figure, this embodiment introduces a power control system based on security situation awareness and proactive response, including a global twin, edge nodes, several local twins, a handling execution module, and a human-machine collaborative monitoring module. Each local twin is deployed on the substation side or the regional control center side, and is used to perform local twin mapping and anomaly analysis on the data of the corresponding area. The edge nodes are used to transmit intermediate information generated by the local twins for aggregation and forwarding. The global twin is used to receive the intermediate information and perform global situation fusion. The above data transmission and result uploading process can be realized through existing communication networks and data reporting mechanisms.

[0094] A local twin maps preprocessed multi-source heterogeneous operational data to an internal digital twin model to obtain the twin system state. In specific implementation, the multi-source heterogeneous operational data includes application-layer control data, status monitoring data, time-synchronization measurement data, network communication traffic characteristics, environmental sensor data, and external disaster information. The application-layer control data is generated by the SCADA system, the status monitoring data is generated by the SCADA system and PMU nodes, the time-synchronization measurement data is generated by the PMU nodes, the network communication traffic characteristics are generated by communication network equipment, the environmental sensor data is generated by IoT sensors, and the external disaster information is obtained from external data. The preprocessing includes time synchronization, data cleaning, and feature extraction. The time synchronization processing can be achieved using existing network time synchronization technology to ensure that data from different sources are fused under a unified time reference.

[0095] The local twin constructs a graph structure based on the twin system state and calculates the anomaly score set on the graph structure; the graph nodes in the graph structure represent devices or functional units in the power control system topology.

[0096] The local twin constructs an attack causal graph based on the anomaly score set and the twin system state, and extracts the attack causal chain from the attack causal graph;

[0097] The local twin sends the twin system status, anomaly score set, attack cause-effect graph, and attack cause-effect chain to the global twin through edge nodes;

[0098] The global twin calculates the first global security posture assessment result based on the twin system status, anomaly score set and attack cause graph sent by each local twin;

[0099] The global twin constructs a dynamic response threshold based on the attack causal chain sent by each local twin. It compares the first global security situation assessment result with the dynamic response threshold. When the first global security situation assessment result is greater than or equal to the dynamic response threshold, it defines the handling priority of each target graph node based on the anomaly score set and the attack causal chain. Based on the handling priority, it sorts each target graph node to obtain a set of response strategy templates.

[0100] The global twin introduces a set of response strategy parameters and combines them with a set of response strategy templates to generate the first response strategy;

[0101] The global twin compares the first global security situation assessment result with a preset execution threshold. When the first global security situation assessment result is greater than or equal to the preset execution threshold, it sends an execution command to the disposal execution module connected to the global twin to execute the first response strategy. When the first global security situation assessment result is less than the preset execution threshold, the global twin first notifies the dispatcher to revise the first response strategy through the human-machine collaborative monitoring module connected to it to obtain a second response strategy, and then sends an execution command to the disposal execution module to execute the second response strategy.

[0102] After the handling execution module executes the first response strategy or the second response strategy, it obtains the response execution result and feeds it back to each local twin.

[0103] Each local twin updates the twin system state based on the response execution results fed back by the handling execution module, and sequentially updates the anomaly score set and attack cause-effect graph. The updated twin system state, anomaly score set, and attack cause-effect graph are then sent to the global twin through edge nodes.

[0104] The global twin calculates the second global security situation assessment result based on the updated twin system state, anomaly score set and attack causality graph of each local twin, and compares it with the first global security situation assessment result to obtain the handling effect index.

[0105] The global twin updates the set of response strategy parameters based on the treatment effect indicators.

[0106] In one specific embodiment of the present invention, the expression for the processing priority is:

[0107] ;

[0108] In the formula, This refers to the target graph node whose status is currently being updated. The neighboring graph nodes of the target graph node v; For target graph nodes At any moment Priority of handling; For target graph nodes At any moment Abnormal scores; To satisfy the existence from point to Neighbor graph nodes of causal edges ; To attack the causal graph at time The set of causal edges; For at any time Target graph nodes For neighbor graph nodes The strength of the causal influence;

[0109] The expression for the dynamic response threshold is:

[0110] ;

[0111] In the formula, For a moment The dynamic response threshold, Basic safety threshold; For a moment The maximum propagation depth of the attack causal chain; For a moment The attack affects the percentage of graph nodes; For a moment The causal strength aggregation index; These are the structural sensitivity coefficient, the influence range sensitivity coefficient, and the causal intensity sensitivity coefficient, respectively.

[0112] The expression for the treatment effect index is:

[0113] ;

[0114] In the formula, For at any time The indicators of treatment effectiveness; This is the result of the first overall security situation assessment; This is the result of the second global security situation assessment;

[0115] The update formula for the response strategy parameters is:

[0116] ;

[0117] In the formula, For at any time The set of response strategy parameters, i.e., the updated response strategy parameters; For at any time The set of response strategy parameters, i.e., the response strategy parameters before the update; The learning rate is adjusted in response to updates to the policy parameters; This refers to the sensitivity or gradient information of the response strategy to the response strategy parameters. For at any time A collection of response strategy templates.

[0118] The power control method based on security situation awareness and proactive response in this invention will be described in detail below with reference to a specific implementation method.

[0119] like Figure 2 As shown, the technical solution of the present invention includes the following steps:

[0120] Step 1: Construct a digital twin model that integrates the electrical domain, communication domain, and physical environment domain.

[0121] First, the network topology, equipment operating parameters, and system constraint information of the power control system are obtained. Then, electrical domain sub-models, communication domain sub-models, and physical environment domain sub-models are constructed respectively. Finally, the coupling relationship between multiple physical domains is modeled in a unified manner, thus forming a digital twin model composed of multiple physical domain sub-models and their coupling relationships.

[0122] In the electrical domain, existing power flow analysis models are used to describe the steady-state operating characteristics of the system; therefore, the electrical domain sub-model... The expression is:

[0123] ;

[0124] ;

[0125] in The target node in the power network; For nodes In a power network topology, there are adjacent nodes that are electrically connected. and They are nodes The active and reactive power; and They are nodes and nodes The voltage amplitude; These are the parameters of the conductance matrix; These are the parameters of the susceptance matrix; For nodes and nodes The voltage phase angle difference.

[0126] In the communication domain, existing network performance modeling methods can be used to describe the operational state of control and communication links; therefore, the communication domain sub-model... The expression is:

[0127] ;

[0128] ;

[0129] in For nodes With nodes Between Communication latency at any given moment; For nodes With nodes Signal propagation delay between links; For nodes With nodes Between The delay caused by network queuing is constant. For data in nodes With nodes The processing latency required for protocol parsing and processing; For nodes With nodes Between The probability of packet loss in the link at any given time; For nodes With nodes The number of intermediate nodes or links included in the communication path between them; For the first in the communication path An intermediate node or link at time The probability of packet loss.

[0130] In the physical environment domain, existing environmental modeling methods can be used to describe the impact of temperature, humidity, electromagnetic interference, or equipment vibration on system operation; therefore, the physical environment domain sub-model... The expression is:

[0131] ;

[0132] ;

[0133] in For equipment At any moment Temperature state; The environmental heat exchange coefficient; For the environment where the device is located at any time Ambient temperature; For a moment The intensity of electromagnetic interference; This represents the baseline electromagnetic interference intensity of the system under conditions of no significant current change. This is the coupling coefficient between current and electromagnetic interference; For equipment At any moment The operating current.

[0134] The digital twin model can be represented as:

[0135] ;

[0136] in, For digital twin models; These represent the electrical domain sub-model, the communication domain sub-model, and the physical environment domain sub-model, respectively. This refers to the coupling relationship between the electrical domain and the communication domain. This refers to the coupling relationship between the electrical domain and the physical environment domain. This refers to the coupling relationship between the communication domain and the physical environment domain.

[0137] The three models described above are used to describe the system's operating state and belong to existing technology; they do not constitute the innovative point of this invention. The digital twin model M is used to perform high-fidelity mapping of the operating state of the real power control system and serves as the basis model for subsequent data fusion, anomaly detection, and risk assessment.

[0138] Step 2: Collect multi-source heterogeneous data and map it to a digital twin model deployed in a local twin.

[0139] At any moment It collects multi-source heterogeneous operating data of the power control system, including application layer control data, status monitoring data, time synchronization measurement data, network communication traffic characteristics, environmental sensor data, and external disaster information.

[0140] The collected data undergoes time synchronization, data cleaning, and feature extraction processing, and is then mapped to the digital twin model M using a feature mapping function to form a time-series model. The twin system state X(t) is given by the following formula: where the twin system state is a state vector characterizing the multi-physical domain operation characteristics of the power control system, and its expression can be:

[0141] ;

[0142] in For at any time The state of the twin system; For data mapping functions, For at any time The collected control and operation monitoring data, For at any time Collected time-synchronized measurement data, For at any time Collected network communication status data, For at any time Collected physical environment data, For at any time External condition data collected.

[0143] Step 3: Anomaly Detection Based on Topology

[0144] Based on the twin system state X(t), a graph structure corresponding to the power control system topology is constructed. :

[0145] ;

[0146] The set of nodes For power equipment or control nodes; edge set This refers to the electrical or communication connections between nodes.

[0147] On the aforementioned graph structure, the node state update process, which utilizes a graph neural network to propagate and aggregate node features, can be represented as follows:

[0148] ;

[0149] in For target graph nodes At any moment The Layer feature vectors; It is a non-linear activation function; This refers to the target graph node whose status is currently being updated. The neighboring graph nodes of the target graph node v; For target graph nodes The set of neighboring graph nodes; This is a normalization constant; The number of layers in the graph neural network; For the first Neighbor feature transformation weight matrix of the layer; For the first The weight matrix for feature transformation of self-graph nodes in a layer; For graph nodes At any moment The Layer feature vectors; For target graph nodes At any moment The Layer feature vectors.

[0150] Based on the changes in node characteristics, an anomaly score set S(t) for each node is calculated, which is used to characterize the degree of anomaly in the system at the current time:

[0151] , ;

[0152] in For at any time The set of abnormal scores; This refers to the target graph node whose status is currently being updated. For target graph nodes At any moment Abnormal scores; The function is used to map graph node features to normalized anomaly scores; This is the output layer weight matrix; For target graph nodes At any moment The Layer feature vectors;

[0153] Step 4: Causal Inference and Construction of Attack Causal Chains

[0154] Based on the anomaly score set S(t) and historical time series data of the twin system state X(t), wherein the historical time series data consists of the twin system state at different time points, a causal inference method is used to identify the causal relationships between anomaly events and construct an attack causal chain. This is used to describe the potential source of anomalies, their propagation paths, and their scope of impact, providing a basis for interpreting and responding to abnormal events. Specifically, it includes the following processes:

[0155] From the state of the twin system and abnormal scoring set All variables in the dataset constitute a multivariate time series set. Each variable corresponds to a node state, communication state, or physical environment state in the power system, and the multivariate time series is set. Each variable in the data is considered a causal analysis node, forming a causal node set:

[0156] ;

[0157] in A collection of multivariate time series The first in Time series of 1 variable; For variable indexing.

[0158] At the present moment Select a multivariate time series set In the time window The values ​​within the set of causal nodes. Any two distinct variables and Granger causality tests were performed based on the historical time series within the stated time window. This was achieved by constructing separate tests using only variables... Historical information prediction The baseline model, and simultaneously introducing variables Historical information prediction The augmented model was compared, and the prediction error variances of the two models were compared when variables were introduced. Historical information can significantly reduce the influence of variables When determining the variance of the prediction error, the decision variable is... For variables Granger causality exists, and at the causal nodes... With causal nodes Establish a directed causal edge between them This forms a set of causal edges:

[0159] ;

[0160] Furthermore, based on the introduced variables The degree of change in the variance of the prediction error before and after is used to determine the causal strength or confidence level of each directed causal edge, and this is used as the weight of the causal edge, thus obtaining the weight set:

[0161] ;

[0162] in For variables For variables At any moment The strength of the causal influence;

[0163] This leads to the construction of an attack causal graph describing the causal relationships of abnormal events:

[0164] ;

[0165] In obtaining the attack causality map Subsequently, high-confidence directed propagation paths are extracted from the attack causal graph based on causal edge weights, forming an attack causal chain to describe the attack source, propagation link, and scope of impact. :

[0166] ;

[0167] in For at any time A directed causal path that starts from the attack source node, propagates through several intermediate nodes, and affects downstream nodes is used to characterize the propagation sequence and scope of the attack. For at any time The number of causal chains identified. This invention does not merely construct causal relationships, but rather uses causal strength as a key driving parameter for subsequent risk fusion and response decisions.

[0168] Step 5: Global Risk Fusion Enhanced by Causal Graph

[0169] Attacking the causal graph Based on this, the global twin converges and merges the abnormal score set S(t) from each local twin and the twin system state X(t) to perform a fusion assessment of the overall security risk of the system, and obtains the first global security situation assessment result.

[0170] First, based on the abnormal rating set The basic risk value is obtained by weighting and aggregating the anomaly levels of each node in the twin system's state X(t):

[0171] ;

[0172] in For at any time The basic risk value; The target graph node is currently being updated. The graph node is an abstract representation of the equipment or functional unit in the power control system in the graph structure. This is the set of target graph nodes whose state is currently being updated. The target graph node weights are determined by the target graph nodes. The importance of the corresponding equipment or functional unit in the topology and operation of the power control system is determined; For target graph nodes At any moment The abnormal score; β is the state influence weight; Φ(X(t)) is the state risk feature extracted from the twin system state. For at any time The state of the twin system;

[0173] Furthermore, structural features of attack propagation are extracted from the attack causal graph, including the depth of attack propagation hierarchy, the scope of influence, and the causal strength, and a causal graph regulation function is constructed. This is used to characterize the amplification effect of attack propagation structures on system risks.

[0174] Based on the aforementioned cause-effect graph adjustment function, the basic risks are adjusted to obtain the first global security situation assessment result:

[0175] ;

[0176] in The result of the first global security situation assessment, i.e., at time [time missing] The following reflects the overall security posture of the system, which is influenced by the attack propagation structure.

[0177] This invention couples anomaly scoring with attack propagation structure through a causal graph adjustment function, thereby amplifying the modeling of overall system risk. This approach differs from traditional risk assessment methods that rely solely on anomaly intensity.

[0178] Step 6: Causal Chain-Driven Adaptive Response Decision

[0179] After obtaining the first overall security situation assessment results Then, further based on the attack causal chain The propagation characteristics are used to determine whether the system has entered the proactive response decision-making stage.

[0180] Based on the depth and scope of attack propagation in the attack causal chain, a dynamic response threshold related to the causal structure is constructed. This is used to reflect the system's sensitivity to different attack propagation patterns and determine whether to enter the response decision phase. The expression for the dynamic response threshold is:

[0181] ;

[0182] in For a moment The dynamic response threshold, Basic safety threshold; For a moment The maximum propagation depth of the attack causal chain; For a moment The attack affects the percentage of graph nodes; For a moment The causal strength aggregation index; These are the structural sensitivity coefficient, the influence range sensitivity coefficient, and the causal intensity sensitivity coefficient, respectively.

[0183] when At that time, the system enters the proactive response decision-making phase; when If the system determines that the conditions for an active response have not been met, it will enter the continuous monitoring phase.

[0184] The continuous monitoring phase includes: updating the status of the twin system based on the latest collected data. And calculate the set of abnormal scores for the next time step. ; Attack causal graph and attack causal chain set Incremental updates will be performed to maintain tracking of potential attack propagation structures; and the results of the first global security posture assessment will be updated. This record serves as a baseline for trend comparison and subsequent updates within later time windows. If it appears at a later time... If so, the system switches to the proactive response decision-making phase.

[0185] After entering the proactive response decision-making phase, based on the anomaly scores of each node in the attack causal chain and their propagation effect within the chain, the nodes in the causal chain are... Define the priority of handling:

[0186] ;

[0187] In the formula, , This refers to the target graph node whose status is currently being updated. The neighboring graph nodes of the target graph node v; For target graph nodes At any moment Priority of handling; For target graph nodes At any moment Abnormal scores; To satisfy the existence from point to Neighbor graph nodes of causal edges ; To attack the causal graph at time The set of causal edges; For at any time Target graph nodes For neighbor graph nodes The strength of the causal influence.

[0188] Nodes involved in attack propagation are prioritized, and a set of response strategy templates is generated based on the prioritization results. At the same time, a set of response strategy parameters is introduced. It is used to control the selection of response strategies, the weighting of handling priorities, and the intensity of response execution. This includes, but is not limited to, anomaly scoring weight coefficients, causal propagation impact weights, strategy template selection weights, and dynamic response threshold adjustment parameters. It involves generating a set of response strategy templates based on the attack causal chain. and the final execution response strategy During the process, the response strategy parameter set It serves as a decision parameter in the selection of response strategies and the parameter instantiation process.

[0189] In generating a set of response strategy templates Subsequently, based on the results of the first global security situation assessment and the preset execution threshold... Select a matching strategy template from the response strategy template set, and instantiate the strategy template with parameters based on the scope of influence of the attack causal chain to generate an executable first response strategy. Finally, determine the execution mode of the response strategy: when When, automatically execute the first response strategy; when In this scenario, a human-machine interface is used to display the response strategy and its associated attack causal chain information to the dispatcher. The dispatcher then confirms, adjusts, or rolls back the response strategy before executing the corresponding control operations, forming a revised second response strategy to avoid misjudgments or unexpected impacts under complex operating conditions. The final executed response strategy is either the first response strategy or the second response strategy, denoted as either the first or second response strategy. .

[0190] Step 7: Closed-loop adaptive update driven by treatment effect

[0191] The response strategy is executed after being automatically triggered or manually confirmed. Then, the response execution results are fed back to each local twin, and the system twin state is updated in a closed loop.

[0192] Specifically, at time Based on the current state of the twin system Response strategy to be executed and attacking causal chains Based on the structural characteristics, the system state evolution is updated using a causal-aware approach to obtain the updated twin system state:

[0193] ;

[0194] The state update function It is used to characterize the direct impact of response strategies on the system state, as well as the constraints of the propagation relationship reflected by the attack causal chain on the state evolution path.

[0195] Next, based on the changes in the overall system security posture before and after the response, the effectiveness of the response strategy will be evaluated by comparing the global security posture assessment results before and after the response, i.e., comparing the first global security posture assessment. With the second global security situation assessment Define the indicators of treatment effectiveness:

[0196] ;

[0197] in For at any time The effectiveness indicators of the response, i.e., the response time. The risk mitigation effect, when A positive value indicates that the action is effective; when... A non-positive value indicates that the treatment effect is insufficient.

[0198] Based on the aforementioned treatment effect indicators, the response strategy parameters are adaptively updated to optimize the subsequent response decision-making process, specifically as follows:

[0199] ;

[0200] in For at any time The set of response strategy parameters, i.e., the updated response strategy parameters; For at any time The set of response strategy parameters is used to control response threshold weights, handling priority coefficients, or strategy selection rules; The learning rate is adjusted in response to updates to the policy parameters; This refers to the sensitivity or gradient information of the response strategy to the response strategy parameters. For at any time This provides a set of response strategy templates. Through adaptive updates of the aforementioned parameters, the system can dynamically adjust its response strategies based on historical handling results, thereby achieving more accurate and efficient proactive responses to subsequent abnormal events.

[0201] By updating the twin system state and response strategy parameters Used for anomaly detection and response decisions in the next time period, it enables continuous iterative optimization of anomaly detection, causal analysis, risk assessment, and proactive response, forming a closed-loop adaptive optimization security situation awareness and proactive response mechanism based on attack causal chains and feedback on handling effects.

[0202] Example 2

[0203] Based on the same inventive concept as Embodiment 1, this embodiment introduces a power control method based on security situation awareness and proactive response, executed by a global twin, including:

[0204] The first global security posture assessment result is obtained by calculating based on the twin system status, anomaly score set and attack cause-effect graph sent by each local twin;

[0205] A dynamic response threshold is constructed based on the attack causal chain sent by each local twin. The first global security situation assessment result is compared with the dynamic response threshold. When the first global security situation assessment result is greater than or equal to the dynamic response threshold, the handling priority of each target graph node is defined based on the anomaly score set and the attack causal chain. The target graph nodes are sorted based on the handling priority to obtain the response strategy template set.

[0206] A set of response strategy parameters is introduced, and a first response strategy is generated by combining it with a set of response strategy templates;

[0207] Comparing the first global security situation assessment result with a preset execution threshold, when the first global security situation assessment result is greater than or equal to the preset execution threshold, an execution command is sent to the disposal execution module connected to the global twin to execute the first response strategy; when the first global security situation assessment result is less than the preset execution threshold, the global twin first notifies the dispatcher to revise the first response strategy through the human-machine collaborative monitoring module connected to it to obtain a second response strategy, and then sends an execution command to the disposal execution module to execute the second response strategy.

[0208] The second global security situation assessment result is calculated based on the updated state of the twin system, the set of anomaly scores, and the attack causality graph of each local twin, and is compared with the first global security situation assessment result to obtain the handling effect index.

[0209] The response strategy parameter set is updated based on the effectiveness indicators of the treatment.

[0210] In one specific embodiment of the present invention, the calculation method for the first global security situation assessment result is as follows:

[0211] The basic risk value is calculated based on the twin system state and anomaly score set;

[0212] Constructing a causal graph regulation function based on the attack causal graph;

[0213] The first global security situation assessment result is obtained by calculating based on the basic risk value and the cause-effect graph adjustment function.

[0214] In one specific embodiment of the present invention, the formula for calculating the basic risk value is as follows:

[0215] ;

[0216] In the formula, For at any time The basic risk value; The target graph node is currently being updated. The graph node is an abstract representation of the equipment or functional unit in the power control system in the graph structure. This is the set of target graph nodes whose state is currently being updated. The target graph node weights are determined by the target graph nodes. The importance of the corresponding equipment or functional unit in the topology and operation of the power control system is determined; For target graph nodes At any moment The abnormal score; β is the state influence weight; Φ(X(t)) is the state risk feature extracted from the twin system state. For at any time The state of the twin system;

[0217] The formula for calculating the first global security situation assessment result is as follows:

[0218] ;

[0219] In the formula, This is the result of the first overall security situation assessment; For at any time Attack causality graph; This is the causal graph adjustment function.

[0220] Example 3

[0221] Based on the same inventive concept as Embodiments 1 and 2, this embodiment introduces a power control method based on security situation awareness and proactive response, executed by a global twin, including:

[0222] The preprocessed multi-source heterogeneous operating data is mapped to the internal digital twin model to obtain the twin system state;

[0223] A graph structure is constructed based on the state of the twin system, and an anomaly score set is calculated on the graph structure; the graph nodes in the graph structure represent devices or functional units in the topology of the power control system.

[0224] Based on the anomaly score set and the twin system state, an attack causality graph is constructed, and an attack causality chain is extracted from the attack causality graph.

[0225] Send the twin system status, anomaly score set, attack cause-effect graph, and attack cause-effect chain to the global twin through edge nodes;

[0226] The twin system state is updated based on the response execution results fed back by the handling execution module, and the anomaly score set and attack cause-effect graph are updated in sequence. The updated twin system state, anomaly score set and attack cause-effect graph are sent to the global twin through edge nodes.

[0227] In one specific embodiment of the present invention, the expression of the digital twin model is:

[0228] ;

[0229] In the formula, For digital twin models; These represent the electrical domain sub-model, the communication domain sub-model, and the physical environment domain sub-model, respectively. This refers to the coupling relationship between the electrical domain and the communication domain. This refers to the coupling relationship between the electrical domain and the physical environment domain. This represents the coupling relationship between the communication domain and the physical environment domain; the expression for the state of the twin system is:

[0230] ;

[0231] In the formula, For at any time The state of the twin system; For data mapping functions; For at any time The collected application-layer control and status monitoring data; For at any time Time-synchronized measurement data was collected. For at any time Collected network communication status data; For at any time Collected environmental sensor data; For at any time External condition data collected;

[0232] The expression for updating the state of the twin system is:

[0233] ;

[0234] In the formula, For at any time The state of the twin system, i.e., the updated state of the twin system; For state update functions; For at any time The first response strategy or the second response strategy; For at any time The attack causal chain; For at any time The response execution result.

[0235] In one specific embodiment of the present invention, the expression for the abnormal score set is:

[0236] ;

[0237] In the formula, For at any time The set of abnormal scores; This refers to the target graph node whose status is currently being updated. For target graph nodes At any moment Abnormal scores, and ;

[0238] In the formula, The function is used to map graph node features to normalized anomaly scores; This is the output layer weight matrix; For target graph nodes At any moment The Layer feature vectors;

[0239] in, ;

[0240] In the formula, It is a non-linear activation function; The neighboring graph nodes of the target graph node v; For target graph nodes The set of neighboring graph nodes; This is a normalization constant; The number of layers in the graph neural network; For the first Neighbor feature transformation weight matrix of the layer; For the first The weight matrix for feature transformation of self-graph nodes in a layer; For graph nodes At any moment The Layer feature vectors; For target graph nodes At any moment The Layer feature vectors.

[0241] In one specific embodiment of the present invention, the expression of the attack cause-effect graph is:

[0242] ;

[0243] In the formula, For a moment Attack causality graph; For a moment A set of causal nodes, wherein the causal nodes are graph nodes in a graph structure that have causal relationships; For a moment The set of causal edges; For a moment The set of weights; Indicates causal attributes;

[0244] in, ;

[0245] In the formula, In the time window The set of multivariate time series data, which consists of twin system states and anomaly score sets; A collection of multivariate time series The first in Time series of 1 variable; For variable indexing;

[0246] in, ;

[0247] In the formula, and For the set of causal nodes Any two distinct variables in the equation; For variables For variables When Granger causality exists, a directed causal edge is established;

[0248] in, ;

[0249] In the formula, For variables For variables At any moment The strength of the causal influence;

[0250] The expression for the causal chain is:

[0251] ;

[0252] In the formula, For at any time causal chain; For at any time A directed causal path that starts from the source graph node, propagates through several intermediate graph nodes, and affects downstream graph nodes. For at any time The number of causal chains identified.

[0253] Example 4

[0254] This invention provides a power control device based on security situation awareness and proactive response, including a storage medium and a processor;

[0255] The storage medium is used to store instructions;

[0256] The processor is used to operate according to the instructions to implement the method of any one of Embodiments 2 or 3.

[0257] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0258] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0259] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0260] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0261] The embodiments of the present invention have been described above with reference to the accompanying drawings. However, the present invention is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of the present invention without departing from the spirit and scope of the claims. All of these forms are within the protection scope of the present invention.

Claims

1. A power control method based on security situation awareness and proactive response, used to control a power control system, the power control system including a substation and a regional control center, executed by a global twin, characterized in that, include: The first global security posture assessment result is obtained based on the twin system status, anomaly score set and attack cause graph sent by each local twin; each local twin is installed in a substation or regional control center; A dynamic response threshold is constructed based on the attack causal chain sent by each local twin. The first global security situation assessment result is compared with the dynamic response threshold. When the first global security situation assessment result is greater than or equal to the dynamic response threshold, the handling priority of each target graph node is defined based on the anomaly score set and the attack causal chain. The target graph nodes are sorted based on the handling priority to obtain the response strategy template set. A set of response strategy parameters is introduced, and a first response strategy is generated by combining it with a set of response strategy templates; Comparing the first global security situation assessment result with a preset execution threshold, when the first global security situation assessment result is greater than or equal to the preset execution threshold, an execution command is sent to the disposal execution module that is connected to the global twin, so that the disposal execution module executes the first response strategy; when the first global security situation assessment result is less than the preset execution threshold, the global twin first notifies the dispatcher to revise the first response strategy through the human-machine collaborative monitoring module that is connected to it to obtain a second response strategy, and then sends an execution command to the disposal execution module so that the disposal execution module executes the second response strategy. The second global security situation assessment result is calculated based on the updated state of the twin system, the set of anomaly scores, and the attack causality graph of each local twin, and is compared with the first global security situation assessment result to obtain the handling effect index. The response strategy parameter set is updated based on the effectiveness indicators of the treatment.

2. The security posture-aware and active-response based power control method of claim 1, wherein, The calculation method for the first global security situation assessment result is as follows: The basic risk value is calculated based on the twin system state and anomaly score set; Constructing a causal graph regulation function based on the attack causal graph; The first global security situation assessment result is obtained by calculating based on the basic risk value and the cause-effect graph adjustment function.

3. The security posture-aware and active-response-based power control method of claim 2, wherein, The formula for calculating the basic risk value is as follows: ; In the formula, For at any time The basic risk value; The target graph node is currently being updated. The graph node is an abstract representation of the equipment or functional unit in the power control system in the graph structure. This is the set of target graph nodes whose state is currently being updated. The target graph node weights are determined by the target graph nodes. The importance of the corresponding equipment or functional unit in the topology and operation of the power control system is determined; For target graph nodes At any moment The abnormal score; β is the state influence weight; Φ(X(t)) is the state risk feature extracted from the twin system state. For at any time The state of the twin system; The formula for calculating the first global security situation assessment result is as follows: ; In the formula, This is the result of the first overall security situation assessment; For at any time Attack causality graph; This is the cause-effect graph adjustment function.

4. A power control method based on security posture perception and active response, executed by a local twin deployed at a substation side or a regional control center side, characterized in that, include: The preprocessed multi-source heterogeneous operating data is mapped to the internal digital twin model to obtain the twin system state; A graph structure is constructed based on the state of the twin system, and an anomaly score set is calculated on the graph structure; the graph nodes in the graph structure represent devices or functional units in the topology of the power control system. Based on the anomaly score set and the twin system state, an attack causality graph is constructed, and an attack causality chain is extracted from the attack causality graph. Send the twin system status, anomaly score set, attack cause-effect graph, and attack cause-effect chain to the global twin through edge nodes; The twin system state is updated based on the response execution results fed back by the handling execution module, and the anomaly score set and attack cause-effect graph are updated in sequence. The updated twin system state, anomaly score set and attack cause-effect graph are sent to the global twin through edge nodes.

5. The security posture-aware and active-response-based power control method of claim 4, wherein, The expression for the digital twin model is: ; In the formula, For digital twin models; These represent the electrical domain sub-model, the communication domain sub-model, and the physical environment domain sub-model, respectively. This refers to the coupling relationship between the electrical domain and the communication domain. This refers to the coupling relationship between the electrical domain and the physical environment domain. This refers to the coupling relationship between the communication domain and the physical environment domain. The expression for the state of the twin system is: ; In the formula, For at any time The state of the twin system; For data mapping functions; For at any time The collected application-layer control and status monitoring data; For at any time Time-synchronized measurement data was collected. For at any time Collected network communication status data; For at any time Collected environmental sensor data; For at any time External condition data collected; The expression for updating the state of the twin system is: ; In the formula, For at any time The state of the twin system, i.e., the updated state of the twin system; For state update functions; For at any time The first response strategy or the second response strategy; For at any time The attack causal chain; For at any time The response execution result.

6. The security posture-aware and active-response-based power control method of claim 4, wherein, The expression for the abnormal score set is: ; In the formula, For at any time The set of abnormal scores; This refers to the target graph node whose status is currently being updated. For target graph nodes At any moment Abnormal scores, and ; In the formula, The function is used to map graph node features to normalized anomaly scores; This is the output layer weight matrix; For target graph nodes At any moment The Layer feature vectors; in, ; In the formula, It is a non-linear activation function; The neighboring graph nodes of the target graph node v; For target graph nodes The set of neighboring graph nodes; This is the normalization constant; The number of layers in the graph neural network; For the first Neighbor feature transformation weight matrix of the layer; For the first The weight matrix for feature transformation of self-graph nodes in a layer; For graph nodes At any moment The Layer feature vectors; For target graph nodes At any moment The Layer feature vectors.

7. The power control method based on security situation awareness and proactive response according to claim 4, characterized in that, The expression for the attack cause-effect graph is: ; In the formula, For a moment Attack causality graph; For a moment A set of causal nodes, wherein the causal nodes are graph nodes in a graph structure that have causal relationships; For a moment The set of causal edges; For a moment The set of weights; Indicates causal attributes; in, ; In the formula, In the time window The set of multivariate time series data, which consists of twin system states and anomaly score sets; A collection of multivariate time series The first in Time series of 1 variable; For variable indexing; in, ; In the formula, and For the set of causal nodes Any two distinct variables in the equation; For variables For variables When Granger causality exists, a directed causal edge is established; in, ; In the formula, For variables For variables At any moment The strength of the causal influence; The expression for the causal chain is: ; In the formula, For at any time causal chain; For at any time A directed causal path that starts from the source graph node, propagates through several intermediate graph nodes, and affects downstream graph nodes. For at any time The number of causal chains identified.

8. A power control system based on security situation awareness and proactive response, characterized in that, This includes a global twin, edge nodes, several local twins, a processing and execution module, and a human-machine collaborative monitoring module. Each local twin is deployed on the substation side or the regional control center side. The local twin maps the preprocessed multi-source heterogeneous operating data to the internal digital twin model to obtain the twin system state; The local twin constructs a graph structure based on the twin system state and calculates the anomaly score set on the graph structure; the graph nodes in the graph structure represent devices or functional units in the power control system topology. The local twin constructs an attack causal graph based on the anomaly score set and the twin system state, and extracts the attack causal chain from the attack causal graph; The local twin sends the twin system status, anomaly score set, attack cause-effect graph, and attack cause-effect chain to the global twin through edge nodes; The global twin calculates the first global security posture assessment result based on the twin system status, anomaly score set and attack cause graph sent by each local twin; The global twin constructs a dynamic response threshold based on the attack causal chain sent by each local twin. It compares the first global security situation assessment result with the dynamic response threshold. When the first global security situation assessment result is greater than or equal to the dynamic response threshold, it defines the handling priority of each target graph node based on the anomaly score set and the attack causal chain. Based on the handling priority, it sorts each target graph node to obtain a set of response strategy templates. The global twin introduces a set of response strategy parameters and combines them with a set of response strategy templates to generate the first response strategy; The global twin compares the first global security situation assessment result with a preset execution threshold. When the first global security situation assessment result is greater than or equal to the preset execution threshold, it sends an execution command to the disposal execution module connected to the global twin to execute the first response strategy. When the first global security situation assessment result is less than the preset execution threshold, the global twin first notifies the dispatcher to revise the first response strategy through the human-machine collaborative monitoring module connected to it to obtain a second response strategy, and then sends an execution command to the disposal execution module to execute the second response strategy. After the handling execution module executes the first response strategy or the second response strategy, it obtains the response execution result and feeds it back to each local twin. Each local twin updates the twin system state based on the response execution results fed back by the handling execution module, and sequentially updates the anomaly score set and attack cause-effect graph. The updated twin system state, anomaly score set, and attack cause-effect graph are then sent to the global twin through edge nodes. The global twin calculates the second global security situation assessment result based on the updated twin system state, anomaly score set and attack causality graph of each local twin, and compares it with the first global security situation assessment result to obtain the handling effect index. The global twin updates the set of response strategy parameters based on the treatment effect indicators.

9. The power control system based on security situation awareness and proactive response according to claim 8, characterized in that, The expression for the processing priority is: ; In the formula, This refers to the target graph node whose status is currently being updated. The neighboring graph nodes of the target graph node v; For target graph nodes At any moment Priority of handling; For target graph nodes At any moment Abnormal scores; To satisfy the existence from point to Neighbor graph nodes of causal edges ; To attack the causal graph at time The set of causal edges; For at any time Target graph nodes For neighbor graph nodes The strength of the causal influence; The expression for the dynamic response threshold is: ; In the formula, For a moment The dynamic response threshold, Basic safety threshold; For a moment The maximum propagation depth of the attack causal chain; For a moment The attack affects the percentage of graph nodes; For a moment The causal strength aggregation index; These are the structural sensitivity coefficient, the influence range sensitivity coefficient, and the causal intensity sensitivity coefficient, respectively. The expression for the treatment effect index is: ; In the formula, For at any time The indicators of treatment effectiveness; This is the result of the first overall security situation assessment; This is the result of the second global security situation assessment; The update formula for the response strategy parameters is: ; In the formula, For at any time The set of response strategy parameters, i.e., the updated response strategy parameters; For at any time The set of response strategy parameters, i.e., the response strategy parameters before the update; The learning rate is adjusted in response to updates to the policy parameters; This refers to the sensitivity or gradient information of the response strategy to the response strategy parameters. For at any time A collection of response strategy templates.

10. A power control device based on security situation awareness and proactive response, characterized in that, Including storage media and processor; The storage medium is used to store instructions; The processor is configured to operate according to the instructions to implement the method of any one of claims 1-3 or 4-7.