Verification methods, devices, equipment, and media for power grid attack protection
By constructing a multi-dimensional attack surface model and conducting simulated attacks, and dynamically filtering target elements, the problem that traditional power network protection verification cannot adapt to dynamic situations is solved, and the accurate verification of the power network protection system and the reflection of actual protection capabilities are realized.
Patent Information
- Application Number
- CN202610544148.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-04-23
- Publication Date
- 2026-07-14
AI Technical Summary
Traditional power grid protection verification methods cannot adapt to the dynamically changing attack and defense situations in real-world scenarios, resulting in verification results that fail to accurately reflect the actual effectiveness of the power grid protection system.
By identifying multiple attack dimensions such as devices, security vulnerabilities, attack paths, and business dependencies, an attack surface model is constructed. The current state of elements is obtained through simulated attacks, and target elements to be attacked are dynamically selected. The target state is then obtained through further simulated attacks to verify the effectiveness of the protection.
It achieves accurate verification of the power grid protection system, reflects its actual protection capabilities, breaks through the limitations of preset fixed scenarios in traditional verification, and can truly restore the dynamic evolution of attack and defense.
Smart Images

Figure CN122394897A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of power network protection verification technology, and in particular to a verification method, apparatus, equipment and medium for power network attack protection. Background Technology
[0002] With the development of power control system security and network attack and defense training technologies, power network target simulation verification technology has been widely used. Traditional power network protection verification typically involves statically collecting data on power equipment, security vulnerabilities, and network paths, building a fixed verification model, and then launching simulated attacks according to a preset script. The states of attack and defense elements only switch according to fixed rules, relying entirely on manually preset parameters and fixed scenarios, and lacking the ability to dynamically adjust and provide feedback optimization.
[0003] However, this type of static verification method cannot adapt to the dynamic attack and defense situation in real scenarios, ultimately resulting in the protection verification results failing to truly reflect the actual protection effect of the power network protection system. Summary of the Invention
[0004] Therefore, it is necessary to provide a verification method, device, equipment, and medium for power network attack protection that can accurately verify the actual protection effect of power networks, addressing the aforementioned technical problems.
[0005] Firstly, this application provides a verification method for power grid attack protection, including:
[0006] Determine the attack dimensions for the simulated power network; wherein the attack dimensions include at least one of the following: device dimension, security vulnerability dimension, attack path dimension, and service dependency dimension.
[0007] Based on the target data of the actual power equipment corresponding to the simulated power network under the attack dimension, an attack surface model of the simulated power network under the attack dimension is constructed.
[0008] A simulated attack is performed on the attack surface model to obtain the current state of each element in the attack surface model in response to the simulated attack; wherein each element corresponds to a target data.
[0009] Based on the protection verification target corresponding to the simulated attack and the current state of each element, determine the target element to be attacked;
[0010] The target element is subjected to a second simulated attack to obtain the target element's updated target state in response to the second simulated attack.
[0011] Based on the target state of the target element, the protection effectiveness of the simulated power network is verified, and the protection verification result of the power network is obtained.
[0012] In one embodiment, the step of verifying the protection effectiveness of the simulated power network based on the target state of the target element to obtain the protection verification result of the power network includes:
[0013] Based on the target state of the target element, generate protection test cases;
[0014] Based on the protection test cases, the protection effectiveness of the simulated power network is verified, and the verification results are obtained; wherein, the verification results include at least one of protection coverage, protection response lag time, and protection capability evaluation value;
[0015] If the verification result meets the preset verification conditions, the protection verification result of the power network is determined to be effective.
[0016] In one embodiment, the step of simulating an attack on the attack surface model to obtain the current state of each element in the attack surface model in response to the updated state of the simulated attack includes:
[0017] A simulated attack is performed on the attack surface model to obtain the current attack events occurring in the simulated power network during the simulated attack; wherein, the current attack events include at least one of attack behavior events, defense action events, state update events, and spoofing device trigger events;
[0018] Based on the state transition rules corresponding to the current attack event, the states of each element in the attack surface model are transitioned to obtain the current state of each element in response to the simulated attack update.
[0019] In one embodiment, the step of transitioning the state of each element in the attack surface model according to the state transition rule corresponding to the current attack event includes:
[0020] The states of each element are transitioned according to the state transition weights of each element in the attack surface model and the state transition rules corresponding to the current attack event.
[0021] In one embodiment, after obtaining the protection verification result, the method further includes:
[0022] Determine the verification feedback data; wherein, the verification feedback data includes the protection verification result, and at least one of the attack surface evolution log, attack behavior data and defense behavior data corresponding to the power network during this verification process;
[0023] Based on the verification feedback data, update the state transition weights of each element in the attack surface model and / or the device parameters of the spoofing devices in the simulated power network; wherein the device parameters include deployment location and / or simulation accuracy.
[0024] In one embodiment, the state transition rule includes:
[0025] In the case that the current attack event includes an attack behavior event or a state update event, for each element, if the element's state before migration is an undiscovered state, then the element's state is migrated to an exposed state; if the element's state before migration is a first state, then the element's state is kept in the first state; wherein, the first state includes other states besides the undiscovered state.
[0026] In the case where the current attack event includes a defensive action event, for each element, if the element's state before migration is an exposed state, then the element's state is migrated to a protected state or a repaired state; if the element's state before migration is a second state, then the element's state is maintained in the second state; wherein, the second state includes other states besides the exposed state.
[0027] In the case where the current attack event includes an attack behavior event, for each element, if the element's state before migration is a protected state, then the element's state is migrated to an attacked state; if the element's state before migration is a third state, then the element's state is maintained as the third state; wherein, the third state includes other states besides the protected state.
[0028] In the case where the current attack event includes a defensive action event or a decoy action event, for each element, if the element's state before migration is an exposed state, then the element's state is migrated to an undiscovered state; if the element's state before migration is a second state, then the element's state is maintained in the second state; wherein, the second state includes other states besides the protected state.
[0029] In one embodiment, determining the target element to be attacked based on the protection verification target corresponding to the simulated attack and the current state of each element includes:
[0030] Based on the current state of each element, determine the current attack strength and current protection coverage corresponding to the simulated attack;
[0031] The target element to be attacked is determined based on the current attack intensity, the current protection coverage, and the protection verification target corresponding to the simulated attack.
[0032] Secondly, this application also provides a verification device for power network attack protection, comprising:
[0033] The determination module is used to determine the attack dimensions against the simulated power network; wherein the attack dimensions include at least one of the following: device dimension, security vulnerability dimension, attack path dimension, and service dependency dimension.
[0034] The construction module is used to construct the attack surface model of the simulated power network in the attack dimension based on the target data of the actual power equipment corresponding to the simulated power network in the attack dimension.
[0035] An attack module is used to simulate an attack on the attack surface model to obtain the current state of each element in the attack surface model in response to the simulated attack; wherein each element corresponds to a target data.
[0036] The determining module is further configured to determine the target element to be attacked based on the protection verification target corresponding to the simulated attack and the current state of each element.
[0037] The attack module is also used to perform a second simulated attack on the target element to obtain the target element's updated target state in response to the second simulated attack.
[0038] The verification module is used to verify the protection effectiveness of the simulated power network based on the target state of the target element, and obtain the protection verification result of the power network.
[0039] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the above-mentioned verification method for power network attack protection.
[0040] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the above-mentioned verification method for power network attack protection.
[0041] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, implements the aforementioned verification method for power network attack protection.
[0042] The aforementioned verification methods, devices, equipment, and media for power network attack protection achieve full-dimensional modeling of the attackable range of simulated power networks by determining multiple attack dimensions such as equipment, security vulnerabilities, attack paths, and business dependencies, and constructing an attack surface model based on target data of actual power equipment. First, the current state of elements is obtained through simulated attacks; then, target elements to be attacked are dynamically selected based on the protection verification target and the current state, breaking the limitations of preset fixed scenarios in traditional verification. The target elements are then subjected to another simulated attack to obtain the target state, thereby completing the verification of protection effectiveness. Through simulated attacks and state evolution, the dynamic evolution process of real attack and defense is restored, enabling the protection verification results to accurately reflect the actual protection capabilities of the power network protection system, achieving precise verification of the power network target protection system. Attached Figure Description
[0043] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0044] Figure 1 This is an application environment diagram of the verification method for power network attack protection in some embodiments of this application;
[0045] Figure 2 This is a flowchart illustrating the verification method for power network attack protection in some embodiments of this application;
[0046] Figure 3 This is a flowchart illustrating the verification method for power network attack protection in some embodiments of this application;
[0047] Figure 4 This is a flowchart illustrating the verification method for power network attack protection in other embodiments of this application;
[0048] Figure 5 This is a flowchart illustrating the verification method for power network attack protection in some embodiments of this application;
[0049] Figure 6 This is a flowchart illustrating the verification method for power network attack protection in other embodiments of this application;
[0050] Figure 7 This is a structural block diagram of a power network attack protection verification device in some embodiments of this application;
[0051] Figure 8 This is a diagram showing the internal structure of a computer device in some embodiments of this application. Detailed Implementation
[0052] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0053] It should be noted that the terms "first," "second," etc., used in this application can be used to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish the first element from the second element. The terms "comprising" and "having," and any variations thereof, used in this application, are intended to cover non-exclusive inclusion. The term "multiple" used in this application refers to two or more. The term "and / or" used in this application refers to one of the embodiments, or any combination of multiple embodiments.
[0054] The power network attack protection verification method provided in this application embodiment can be applied to, for example, Figure 1 In the application environment shown, terminal 102 communicates with server 104 via a network. A data storage system can store the data that server 104 needs to process. The data storage system can be integrated onto server 104 or located in the cloud or on other network servers. Terminal 102 sends a power grid attack protection verification request to server 104. Server 104 receives the power grid attack protection verification request, executes the power grid attack protection verification method, and feeds back the power grid protection verification result to terminal 102. Terminal 102 can be, but is not limited to, various personal computers, laptops, smartphones, tablets, drones, low-altitude aircraft, IoT devices, and portable wearable devices. IoT devices can include smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, projection devices, etc. Portable wearable devices can include smartwatches, smart bracelets, head-mounted devices, etc. Head-mounted devices can be virtual reality (VR) devices, augmented reality (AR) devices, smart glasses, etc. Server 104 can be a standalone physical server, a server cluster or distributed system consisting of multiple physical servers, or a cloud server that provides cloud computing services.
[0055] In one exemplary embodiment, such as Figure 2 As shown, a verification method for power grid attack protection is provided, which is then applied to... Figure 1 Taking the server in the example of this, the explanation includes:
[0056] Step 202: Determine the attack dimensions for the simulated power network.
[0057] The attack dimensions include at least one of the following: device dimension, security vulnerability dimension, attack path dimension, and business dependency dimension.
[0058] Among them, the simulated power network can be a virtual simulation test environment built to resemble a real power system, including virtual power equipment, network connections, and business scheduling processes, used to conduct network protection verification; the device dimension can be an analysis dimension focusing on power industrial control equipment, network equipment, and business systems in the network; the security vulnerability dimension can be an analysis dimension focusing on known vulnerabilities, configuration weaknesses, and protocol defects existing in devices and systems; the attack path dimension can be an analysis dimension focusing on network connections, authorized links, and data transmission channels accessible to attackers; and the business dependency dimension can be an analysis dimension focusing on the relationship between devices and business processes.
[0059] Optionally, based on the actual needs of power network protection verification, at least one of the following can be selected from the device dimension, security vulnerability dimension, attack path dimension, and business dependency dimension to determine the core perspective for attack surface analysis of the simulated power network.
[0060] Step 204: Based on the target data of the actual power equipment corresponding to the simulated power network in the attack dimension, construct the attack surface model of the simulated power network in the attack dimension.
[0061] The actual power equipment can be various power industrial control devices that are actually deployed in real-world scenarios and mapped by the simulation environment, including physical power equipment such as PLCs (Programmable Logic Controllers), servers, gateways, relay protection devices, and terminals; the target data can be relevant data collected from the actual power equipment in terms of device dimensions, security vulnerability dimensions, attack path dimensions, and business dependency dimensions, such as device configuration information, vulnerability information, network connectivity data, and business relationships; the attack surface model can be a comprehensive model used to characterize the attackable objects, vulnerabilities, attack paths, and business dependencies of the simulated power network.
[0062] Optionally, construct an attack surface set AS=(A,V,P,B), i.e., an attack surface model, which covers the core elements of power targets (power targets can be objects that are simulated, attacked, and protected in power network security ranges or training platforms, such as simulated power equipment):
[0063] Asset Dimension A (i.e., Equipment Dimension): Includes power industrial control equipment (PLC, RTU (Remote Terminal Unit), SCADA (Supervisory Control And Data Acquisition) server), network equipment (firewall, switch), business systems (dispatch automation system, remote operation and maintenance platform), and attributes such as type, protocol compatibility (e.g., support for power system communication protocols, IEC60870-5-104), and physical location for each asset.
[0064] Vulnerability dimension V (i.e., security vulnerability dimension): includes known vulnerabilities (CVSS (Common Vulnerability Scoring System) score, exploitation difficulty), configuration weaknesses (weak passwords, excessively broad permissions), protocol defects (plaintext transmission, no authentication), and adaptability to power control protocol characteristics (such as ModbusTCP (Modbus Transmission Control Protocol, a TCP-based Modbus protocol) function code abuse vulnerability).
[0065] Access path dimension P includes network connection (IP port mapping, routing path), access control link (user permissions - device access rights - business operation rights), and data transmission channel (5G / V2X communication link).
[0066] Business Dependency Dimension B: Based on the power business process (dispatch instruction issuance → relay protection execution → telemetry data reporting), construct a business dependency graph G. B =(V B E B V B For business nodes, E B This is a dependency relationship. Where V... B With E B It is the power network service dependency graph G B The two core components correspond to vertices and edges in the logic of graph construction. V B This refers to the core nodes in the power business process that possess independent business functions, and are the basic units for constructing a business dependency graph. B V B The logical connections, sequential execution, and causal triggering among various business nodes are the core of characterizing the interrelationships in the power business process.
[0067] Optionally, the asset dimension (A) focuses on the collection of basic information of power industrial control equipment, network equipment, and business systems, and obtains data by means of ledger sorting + on-site detection + protocol adaptability verification. First, extract basic attributes such as equipment type, model, physical location, and affiliated business domain from the existing equipment asset ledger of power enterprises, then verify the online status of devices through network scanning detection, supplement real-time information such as IP addresses and device operating status, and finally conduct protocol adaptability verification for power industrial control characteristics to detect whether the device supports dedicated industrial control protocols such as IEC60870-5-104 and ModbusTCP and complete protocol attribute annotation, ultimately achieving full-attribute collection of various assets such as PLCs, RTUs, SCADA servers, and firewalls.
[0068] The vulnerability dimension (V) identifies three types of vulnerabilities: known vulnerabilities, configuration weaknesses, and protocol defects, and obtains data through multi-source identification + threat determination + attribute annotation. First, connect to the vulnerability database and obtain attributes such as the score, exploitation difficulty, and impact range of known vulnerabilities through asset fingerprint matching; then identify configuration weaknesses such as weak passwords, overly broad permissions, and open unnecessary ports through remote configuration auditing and local device inspections; at the same time, conduct protocol packet capture and reverse analysis for power industrial control protocols such as ModbusTCP and IEC60870-5-104 to identify protocol inherent defects such as plaintext transmission, lack of identity authentication, and abuse of function codes; finally, screen out vulnerabilities that are strongly associated with power business and are easily exploited through threat determination, eliminate weak vulnerabilities with no actual attack value, and complete the effectiveness verification and attribute annotation of vulnerabilities.
[0069] The access path dimension (P) collects information around three layers of paths: network connections, permission links, and data transmission channels, and obtains data through topology detection + permission auditing + link investigation. With the help of network topology scanning tools, sort out network connection relationships such as IP port mapping, routing paths, and network partitions between devices; from the permission management module of the power business system and device access control policies, sort out the complete permission link of user permission - device access right - business operation right; at the same time, investigate the types, transmission directions, and business data types carried by data transmission channels such as 5G, V2X, and dedicated optical fibers in the power network, and clarify the data flow path in the power network.
[0070] The core of the business dependency dimension (B) is to construct a business dependency graph GB=(V B ,E B ), and obtains data through process sorting + linkage analysis + graph construction. First, combine the operation specifications of core businesses such as power dispatching, relay protection, and telemetry and telecontrol to extract business nodes with independent functions such as dispatching order issuance, relay protection execution, and telemetry data reporting, and form V BThe data is then aggregated; further analysis is conducted on the logical relationships, sequential execution, and causal triggering relationships between the systems / devices corresponding to each business node to form E. B The dependency set is then used; finally, graph theory is employed to construct a graph of the sorted business nodes and dependencies, clarifying the association weight and influence scope of each node, thus completing the data collection for this dimension.
[0071] Optionally, based on data related to device, vulnerability, attack path, and business dependency dimensions, an attack surface model containing different elements is constructed. Each element corresponds to a single data point related to a device, vulnerability, attack path, or business dependency. Then, each element in the attack surface model is standardized by assigning a unique identifier and attribute vector to each element, such as a vulnerability element vector. This vulnerability element vector quantifies and encodes the key attributes of the vulnerability element, forming a feature vector including vulnerability level, asset importance, and exposure status. A vulnerability element can be a single, detectable, attackable, and protectable vulnerability or weak asset in the power network, such as a high-risk vulnerability or a PLC with a configuration defect. This results in the attack surface model, supporting subsequent state management and evolution. For example, a structured attribute vector for a vulnerability element can be represented as:
[0072] V i =[ID V Type V Severity V Asset ID Protocol V ]
[0073] Among them, V i Construct structured attribute vectors for vulnerable elements; ID V A unique identifier for vulnerability; a unique code assigned to each vulnerable element in the power grid; Type V Vulnerability type, used to define the dimension to which the vulnerability belongs; Severity V Vulnerability severity is a quantitative indicator of the degree of harm caused by the exploitation of a vulnerability; Asset ID Protocol is a unique identifier for vulnerability-related assets, used to clearly identify the specific power grid asset to which the vulnerability is attached. V The vulnerability is associated with the power control protocol, which is used to identify the type of power control protocol on which the vulnerability is based. Step 206: Simulate an attack on the attack surface model to obtain the current state of each element in the attack surface model after the simulated attack.
[0074] Each element corresponds to a target data.
[0075] Among them, the elements can be target data in the attack surface model and under each attack dimension; the simulated attack can be a simulated attack behavior launched against the attack surface model in a simulation environment; the current state can be the real-time attack and defense state of each element in the model after being subjected to a simulated attack, updated according to the state transition rules, including undiscovered, exposed, protected, repaired, bypassed, etc.
[0076] Optionally, a simulated attack is launched on the constructed attack surface model, causing the simulated attack to act on each element within the model corresponding to the target data. The element states are then triggered to change according to preset state transition rules, thus obtaining the updated current state of each element after the attack. Step 208: Based on the protection verification target corresponding to the simulated attack and the current state of each element, the target element to be attacked is determined.
[0077] The protection verification target can be the specific purpose set for this power network protection verification, that is, the protection focus to be verified through simulated attacks, such as verifying the protection effectiveness of a certain type of vulnerability, the blocking capability of a certain attack path, and the protection reliability of core services; the target element can be a specific element selected from all elements of the attack surface model that is related to the protection verification target and whose current state is suitable for further simulated attacks (such as being in an exposed, bypassed, or other attackable state).
[0078] Optionally, obtain the protection verification target corresponding to this simulated attack, and then determine the protection direction that needs to be verified; then sort out the current state of all elements in the attack surface model, filter out the elements whose current state meets the conditions for further attack (such as being attackable) and can support the realization of the protection verification target, and determine them as the target elements to be attacked.
[0079] Step 210: Perform a simulated attack on the target element again to obtain the target element's updated target state in response to the simulated attack.
[0080] The target state can be the latest attack and defense state of the target element after it has been simulated again.
[0081] Optionally, for the target element, launch a simulated attack again according to the actual attack logic; obtain the state changes of the target element under the simulated attack and record its response behavior (such as the state changing from exposed to bypassed, from protected to bypassed, etc.); finally determine the specific state of the target element after the simulated attack, i.e. the target state.
[0082] Step 212: Based on the target state of the target element, verify the protection effectiveness of the simulated power network to obtain the protection verification result of the power network.
[0083] Among them, the protection verification result can be the result of whether the simulated power network protection system is effective.
[0084] Optionally, based on the specific state of each target element (e.g., a target element is in a protected state or a target element is in a bypassed state), and combined with the protection verification objectives corresponding to this simulated attack (e.g., verifying the effectiveness of core equipment protection, attack path blocking capabilities, etc.), the protection effect reflected by each target state is analyzed. If the target element is in a protected or repaired state, it indicates that the corresponding protection measures are effective; if it is in a bypassed or exposed state, it indicates that there are weaknesses in the corresponding protection. Finally, the protection effect analysis of all target elements is summarized to comprehensively judge the effectiveness of the overall protection system of the simulated power network.
[0085] The aforementioned verification method for power network attack protection achieves full-dimensional modeling of the attackable range of the simulated power network by determining multiple attack dimensions, including equipment, security vulnerabilities, attack paths, and business dependencies, and constructing an attack surface model based on target data of actual power equipment. It first obtains the current state of elements through simulated attacks, then dynamically selects target elements to be attacked based on the protection verification target and the current state, breaking the limitations of preset fixed scenarios in traditional verification. The target elements are then subjected to another simulated attack to obtain the target state, thereby completing the verification of protection effectiveness. Through simulated attacks and state evolution, the dynamic evolution process of real attack and defense is restored, enabling the protection verification results to accurately reflect the actual protection capabilities of the power network protection system, achieving precise verification of the power network target protection system.
[0086] In one exemplary embodiment, such as Figure 3 As shown, based on the target state of the target element, the protection effectiveness of the simulated power network is verified, and the protection verification results of the power network are obtained, including:
[0087] Step 302: Generate protection test cases based on the target state of the target element.
[0088] Among them, protection test cases can refer to standardized test items used for subsequent repeated verification, extended testing or automated attack and defense drills, including attack targets, attack methods and expected protection results.
[0089] Optionally, based on the target state of the target element after the attack, the corresponding weak links, effective attack methods and verifiable protection points can be identified. Based on this, information such as attack conditions, verification indicators and judgment rules can be extracted and organized in a structured manner according to the test case specification to finally form reusable and executable protection test cases.
[0090] Optionally, the closed-loop verification process in this embodiment is as follows: attack surface change - automatic test case generation - verification execution - feedback results. That is, when the attack surface evolves due to defensive actions (such as blocking IPs (Internet Protocol)), the system automatically generates micro-subsequent attack cases (i.e., protection test cases). Micro-subsequent attack cases can be represented as:
[0091] Case Mini =[Target New Attack Method Expected Result ]
[0092] Among them, Case Mini This is a micro-follow-up attack use case; Target New It is a new attack target (i.e., the target element); Attack Method It is an attack method; Expected Result This is the expected verification result.
[0093] Step 304: Based on the protection test cases, verify the protection effectiveness of the simulated power network and obtain the verification results.
[0094] The verification results include at least one of the following: protection coverage, protection response lag time, and protection capability assessment value.
[0095] Among them, protection coverage can be the proportion of attack targets, vulnerabilities or paths that are effectively protected out of all test targets; protection response lag time can be the time interval from the occurrence of an attack to the protection device / system taking action such as interception or alarm; protection capability assessment value can be protection generalization capability, used to evaluate the ability of power network protection rules to cope with variant attacks.
[0096] Optionally, dynamic protection coverage can be expressed as:
[0097] Coverage D =(NumberofProtected Elements ) / (NumberofActive Elements )
[0098] Among them, Coverage D It is the dynamic protection coverage rate; Number of Protected Elements It is the number of protected attack surface elements; NumberofActive Elements It is the number of active attack surface elements; Active Elements This refers to currently active attack surface elements (such as those that have been exposed or bypassed).
[0099] The protection response lag time can be expressed as:
[0100] Delay R =T Effective -T Expose
[0101] Among them, Delay R To protect against response delay time; T Expose T represents the exposure time of attack surface elements. Effective This indicates the effective date of the protection strategy. 504
[0102] The generalization capability of protection can be expressed as:
[0103] Generalization=(NumberofVariant AttacksBlocked ) / (Total VariantAttacks )
[0104] Among them, Generalization refers to the ability to generalize protection; Number of Variant AttacksBlocked This represents the number of intercepted variant attacks; Total VariantAttacks This represents the total number of variant attacks.
[0105] Step 306: If the verification result meets the preset verification conditions, determine that the protection verification result of the power network is effective.
[0106] Among them, the preset verification conditions can be pre-set standard thresholds or rules used to determine whether the protection meets the standards, such as the protection coverage rate not being lower than a certain percentage, the response time not exceeding a certain value, and the evaluation value reaching a certain score; the effective protection characterizes the power network's protection measures as meeting the preset security requirements, that is, successfully resisting attacks under the specified indicators and achieving the expected protection goals.
[0107] Optionally, preset verification conditions may include pre-defined coverage thresholds, response lag time thresholds, and capability assessment thresholds. These thresholds are then compared with their corresponding protection coverage, protection response lag time, and protection capability assessment values. Based on the comparison results, the power network protection verification result is determined. For example, setting the coverage threshold to 0.8, the response lag time threshold to 30 seconds, and the capability assessment threshold to 0.75 allows for the determination of the power network protection verification result when the coverage threshold is set to 0.8. D ≥0.8, Delay RWhen ≤30s and Generalization≥0.75, the protection system is determined to be effective under the current attack surface state, that is, the protection verification result of the power network is determined to be effective; otherwise, if at least one of the preset verification conditions is not met, the protection verification result of the power network is determined to be ineffective.
[0108] In this embodiment, verification is the core step in verifying the power network target protection system. It addresses the pain points of existing technologies, such as limited verification scenarios, lack of closed-loop mechanisms, and inability to quantify and evaluate performance. Furthermore, it adapts to the adaptive security architecture requirements of continuous monitoring and dynamic adjustment in power industrial control systems. It upgrades protection verification from static compliance checks to dynamic performance verification, automatically generating micro-subsequent attack cases after attack surface evolution to verify the actual effectiveness of protection and identify protection bypasses. It also constructs a closed-loop verification process encompassing attack surface changes, test case generation, verification execution, and result feedback. Simultaneously, by calculating three core indicators, including dynamic protection coverage, and setting quantitative thresholds, it achieves objective quantitative evaluation and standardized judgment of protection effectiveness. This accurately verifies the defense-in-depth and generalization capabilities of the protection system, provides key quantitative data support for module training feedback and strategy optimization, and offers concrete and implementable decision-making basis for the evaluation of power network security training results and the transformation of power companies' actual security construction from "compliance-driven" to "performance-driven."
[0109] In one exemplary embodiment, such as Figure 4 As shown, a simulated attack is performed on the attack surface model to obtain the current state of each element in the attack surface model in response to the simulated attack, including:
[0110] Step 402: Simulate an attack on the attack surface model to obtain the current attack events occurring in the simulated power network during the simulated attack process.
[0111] The current attack event includes at least one of the following: attack behavior event, defense action event, status update event, and spoofing device trigger event.
[0112] Among them, the current attack event can be any attack and defense related event that occurs during this simulated attack; the attack behavior event can be an attack operation related to intrusion, probing, exploitation of vulnerabilities, etc. initiated by the attacker; the defense action event can be a defense response related event such as alarm, interception, isolation, etc. generated by the protection device or system; the state update event can be a non-attack and defense event triggered in the attack surface model based on preset timing conditions, used to drive the automatic state transition of each element; the masquerade device trigger event can be a related event generated after the decoy or masquerade device in the simulated network is detected or triggered by the attack behavior.
[0113] Optionally, a simulated attack is launched on the attack surface model. During the attack execution, various events generated in the simulated power network are collected and recorded in real time. At least one type of event is extracted from types such as attack behavior, defense response, state update, and spoofing device triggering to obtain the current attack event corresponding to this attack.
[0114] Step 404: According to the state transition rules corresponding to the current attack event, the state of each element in the attack surface model is transitioned to obtain the current state of each element in response to the simulated attack update.
[0115] Among them, the state transition rules can be standardized rules for the state changes of each element in the pre-defined attack surface model, which clarifies the logic, conditions and results of the element's transition from the current state to the target state when different current attack events occur.
[0116] Optionally, determine all current attack events collected during this simulated attack, clarify the specific types and triggering conditions of each type of event; then obtain the pre-set state transition rules and match the state transition logic corresponding to each type of current attack event; then, for each element in the attack surface model, determine whether it is triggered by the current attack event, and if it is triggered, complete the transition from the original state to the new state according to the matched state transition rules; finally, record the latest state of all elements after completing the state transition, which is the current state of each element in response to the simulated attack update.
[0117] In this embodiment, by collecting current attack events such as attack behavior, defense actions, time-triggered state updates, and spoofing device triggers in real time during the attack process, and dynamically adjusting the state of each element in the attack surface model according to the corresponding state transition rules, it is possible to achieve real-time synchronization and dynamic evolution of the attack and defense situation. This alleviates the limitation of traditional static verification models in being unable to reflect temporal changes and attack and defense interactions, and makes the element states more consistent with the dynamic evolution process in the attack and defense of real power networks.
[0118] In one exemplary embodiment, such as Figure 4 As shown, based on the state transition rules corresponding to the current attack event, the states of each element in the attack surface model are transitioned, including:
[0119] Step 402: Based on the state transition weights of each element in the attack surface model and the state transition rules corresponding to the current attack event, the state of each element is transitioned.
[0120] Among them, the state transition weight can be a quantified coefficient pre-assigned to each element in the model to characterize the ease or priority of the element's state change under an attack event, and reflects the sensitivity of different elements to attacks and the probability of state change.
[0121] Optionally, after obtaining the current attack event, first match its corresponding state transition rule, then combine the state transition weight of each element in the attack surface model to comprehensively judge whether each element meets the transition conditions and transition priority, and then update the element state to finally obtain the current state of each element after being updated under the influence of the attack.
[0122] In this embodiment, by introducing weights into state transitions, a nondeterministic dynamic attack and defense simulation model is constructed. This makes the simulation results no longer singular and fixed, but rather, through numerous simulations, covers multiple probabilistic paths where attacks may succeed, thus realistically reflecting the complexity and uncertainty of real-world networks. Ultimately, this improves the coverage and depth of protection verification testing.
[0123] In one exemplary embodiment, such as Figure 5 As shown, after obtaining the protection verification results, the verification method for power grid attack protection also includes:
[0124] Step 502: Determine the verification feedback data.
[0125] The verification feedback data includes the protection verification results, as well as at least one of the following during the verification process: the attack surface evolution log, attack behavior data, and defense behavior data of the power network.
[0126] The verification feedback data includes a comprehensive data set of the entire protection verification process and the final conclusion; the attack surface evolution log can be a time-series log that records the state transitions of each element in the attack surface model during the entire verification process, as triggered by attack events and time; the attack behavior data can be information related to all simulated attacks during the verification process, including behavioral characteristic data such as attack target, attack method, attack timing, attack path, and number of attacks; and the defense behavior data can be various response data generated by the protection system during the verification process, including defense trigger time, interception action, alarm information, isolation strategy, and other defense execution information.
[0127] Optionally, after completing the power network protection effectiveness verification, the final protection verification results are summarized, and at least one of the attack surface evolution logs, attack behavior data, and defense behavior data from this verification process is extracted simultaneously, and the above information is integrated into verification feedback data.
[0128] Step 504: Based on the verification feedback data, update the state transition weights of each element in the attack surface model and / or the device parameters of the spoofing devices in the simulated power network.
[0129] The equipment parameters include deployment location and / or simulation accuracy.
[0130] Among them, the camouflage device can be a decoy node or camouflage asset deployed in the simulated network to lure attacks and detect intrusion behavior; the deployment location can be the node and network layer where the camouflage device is placed in the simulated power network topology; the simulation accuracy can be the degree to which the camouflage device simulates the characteristics, protocol behavior and business logic of real power equipment.
[0131] Optionally, based on the information such as defense weaknesses, attack preferences, and abnormal state evolution reflected in the verification feedback data, the state transition weights of each element in the attack surface model can be adjusted in a targeted manner to make it more in line with the actual attack and defense response rules; at the same time, the deployment location and / or simulation accuracy of camouflage devices in the simulated power network can be optimized to achieve iterative updates of the model and camouflage strategy.
[0132] Optionally, this embodiment collects attack surface evolution logs (i.e., attack and defense behavior data (including attack behavior data and defense behavior data) and protection verification results during the training process to form a feedback dataset (i.e., verification feedback data). The feedback dataset can be represented as follows:
[0133] Feedback=[(AS(t),Attack Act Defense Act Verify Result )]
[0134] Where Feedback is the training feedback dataset; AS(t) is the attack surface set at time t; Attack Act It is the attacker's attack behavior data (i.e., attack behavior data); Defense Act This is the defensive behavior data of the defending side (i.e., defensive action data); Verify Result This is the result of the verification of the effectiveness of the protection.
[0135] Optionally, this embodiment uses a reinforcement learning algorithm to optimize the weights of the state transition rules, and the objective function can be expressed as:
[0136] L=λ1×Coverage D -λ2×Delay R -λ3×Attack SuccessRate
[0137] Where L is the objective function value for evolution rule optimization; λ1, λ2, and λ3 are all index weight coefficients, for example, λ1 can be set to 0.4, λ2 can be set to 0.3, and λ3 can be set to 0.3; Coverage D It is dynamic protection coverage; Delay R It is the protection response lag time; Attack SuccessRate It represents the attacker's attack success rate.
[0138] In this embodiment, the core of weight optimization focuses on the trigger weights of attack surface state transition rules, while the index weight λ of the objective function is a fixed value and does not participate in the optimization. This process uses reinforcement learning algorithms as the core method and maximizing the objective function L as the sole optimization objective. First, the training feedback dataset undergoes standardized preprocessing, including cleaning, feature extraction, and labeling. Then, a reinforcement learning optimization model adapted to the power industrial control scenario is built, defining the agent, state space, action space, and reward function centered on the L value. Next, basic initial weights are assigned to the transition rules according to the core asset protection requirements of power industrial control, and scenario-adaptive weighting is applied. Subsequently, iterative training is conducted using a hybrid mode of offline batch training and online real-time fine-tuning. The weights of corresponding transition rules are strengthened or weakened based on changes in the L value. The training results are determined by setting quantitative convergence thresholds for L-value fluctuations and core protection indicators. The optimal weights are extracted to form a dedicated weight table, which is then embedded into the state transition rule function for deployment. At the same time, a weight periodic update mechanism is established based on the training and verification results to achieve continuous iterative optimization. The entire optimization process is adapted to the characteristics of power industrial control scenarios, focusing on optimizing core transition rules, adjusting in conjunction with decoy strategies, and adapting weight optimization biases according to the difficulty of training. The optimized weights can improve the realism of attack surface evolution, forcing the defender to strengthen its protection capabilities, ultimately achieving a dual improvement in training realism and protection verification depth.
[0139] Optionally, in this embodiment, the exposure strategy is optimized by adjusting the exposure strategy parameters based on the protection verification results. For example, if the defender's generalization ability is insufficient, the exposure ratio of variant vulnerabilities is increased. In this embodiment, the decoy strategy is optimized by dynamically adjusting the decoy deployment location and simulation accuracy based on the probability of the attacker triggering the decoy, thereby improving the success rate of decoy capture. Specifically, based on core indicators such as the decoy trigger probability, capture success rate, and attacker attack path preferences in the training feedback data, combined with the asset distribution, business dependency graph, and high-risk attack surface characteristics of the power industrial control network, the decoy deployment location and simulation accuracy are dynamically adjusted according to the power industrial control protocol and business process requirements, and the adjustment results are synchronously linked to Decoy. Strategy The parameters are implemented in a coordinated manner with the vulnerability exposure strategy. Deployment locations are adjusted according to the probability of contact. Low-contact decoys are moved to high-frequency scanning areas by attackers, medium-contact decoys are placed along the business link, and high-contact decoys with low success rates are deployed in a clustered hierarchical manner. Core power protection areas are pre-positioned for routine defense. The simulation accuracy is set at three levels: basic, intermediate, and advanced. The accuracy is adjusted up or down according to the attacker's contact situation and attack depth. The accuracy configuration can also be adapted to the training difficulty. If the decoy is identified, the accuracy is reduced first and then the position is adjusted.
[0140] In this embodiment, verification feedback data is formed by integrating protection verification results, attack surface evolution logs, attack behavior data, and defense behavior data. Based on this feedback data, the state transition weights of each element in the attack surface model are dynamically updated. At the same time, the deployment location and simulation accuracy of camouflage devices in the simulated power network are adjusted, which enables closed-loop iterative optimization of the attack and defense verification system.
[0141] In an exemplary embodiment, the state transition rule includes: when the current attack event includes an attack behavior event or a state update event, for each element, if the element's state before the transition is an undiscovered state, then the element's state is transitioned to an exposed state; if the element's state before the transition is a first state, then the element's state is maintained as the first state; wherein, the first state includes other states besides the undiscovered state.
[0142] In the case where the current attack event includes a defensive action event, for each element, if the element's state before migration is an exposed state, then the element's state is migrated to a protected state or a repaired state; if the element's state before migration is a second state, then the element's state is maintained in the second state; wherein, the second state includes other states besides the exposed state.
[0143] In the case where the current attack event includes an attack behavior event, for each element, if the element's state before migration is a protected state, then the element's state is migrated to an attacked state; if the element's state before migration is a third state, then the element's state is maintained as the third state; wherein, the third state includes other states besides the protected state.
[0144] In the case where the current attack event includes a defensive action event or a decoy action event, for each element, if the element's state before migration is an exposed state, then the element's state is migrated to an undiscovered state; if the element's state before migration is a second state, then the element's state is maintained in the second state; wherein, the second state includes other states besides the protected state.
[0145] Among them, the undiscovered state can be the initial state in which the element has not yet been detected by the attack and is not exposed or perceived; the exposed state can be the state in which the element has been detected or scanned by the attack and is in the state in which it can be further attacked; the protected state can be the state in which the element has been covered by the defense mechanism and is in the protected state; the repaired state can be the state in which the vulnerabilities or weaknesses of the element have been repaired and no longer have the conditions to be exploited; the attacked state can be the state in which the element is being attacked or has been successfully attacked after the protection has been breached.
[0146] Optionally, in this embodiment, a five-state machine is defined for each element of the attack surface, and the set of states can be represented as:
[0147] S = {S0: Not detected, S1: Exposed, S2: Protected, S3: Repaired, S4: Bypassed}
[0148] Wherein, S is the complete set of states of all elements on the attack surface, covering the entire lifecycle states of core elements such as power network vulnerabilities and assets; S0, S1, S2, S3 and S4 are all single state identifiers of attack surface elements, serving as the basic nodes for state transitions.
[0149] A state transition trigger event can be represented as:
[0150] E = {E1: Attack trigger, E2: Defensive action trigger, E3: Time trigger, E4: Decoy trigger}
[0151] Among them, E is the complete set of trigger events that can drive the state transition of attack surface elements, covering all scenarios such as attack and defense behaviors, time progression, and decoy interactions; E1, E2, E3, and E4 are all single trigger event identifiers and are the core conditions for triggering state transitions; and E1 is the attack behavior event, E2 is the defense action event, E3 is the state update event, and E4 is the decoy action event.
[0152] The state transition rules are as follows: When a model element is in the undiscovered state S0, if event E1 (the attacker performs a scanning operation and identifies the corresponding network asset) or event E3 (the preset vulnerability disclosure time node is reached), the element transitions from the undiscovered state S0 to the exposed state S1; when a model element is in the exposed state S1, if event E2 (the protection end deploys protection policies, such as updating the intrusion detection system signature database), the element transitions from the exposed state S1 to the protected state S2; when a model element is in the exposed state S1, if event E2 (the protection end performs vulnerability patching and configuration optimization) is triggered... If an element is in a protected state S2 and event E1 is triggered (the attacker uses a variant of the attack to bypass the existing protection mechanism), the element will migrate from the protected state S2 to the bypassed state S4, i.e., the attacked state. If an element is in a protected state S2 and event E2 is triggered (the protection end performs an asset concealment operation, such as closing unnecessary communication ports) or event E4 (the attacker triggers a decoy node, and the system performs concealment on the real assets), the element will migrate from the exposed state S1 back to the undiscovered state S0.
[0153] Optionally, this embodiment uses a discrete event simulation algorithm to drive the attack surface evolution, that is, to drive the state transition of each element in the attack surface model. For example, the evolution formula can be:
[0154] AS(t+Δt)=AS(t)∪V i →S j |E k ∈E,Rule(V i ,S c current, E k )=S j
[0155] Where AS is the set of attack surfaces of the power network; AS(t) is the set of attack surfaces at the current time t; AS(t+Δt) is the set of attack surfaces at the next time step after time step Δt; Δt is the time step of attack surface evolution (e.g., 10s); V i For a standardized single vulnerability element; S c urrent is the current state of the fragile element Vi; S j V, a fragile element i The target state after migration; E k This is a single event that triggers a state transition; Rule(·) is a state transition rule function used to ensure that the attack surface dynamically changes in real time in response to offensive and defensive actions.
[0156] This embodiment uses the attack surface dynamic evolution formula as its core driving engine. A default evolution time step of 10 seconds is used. First, a five-state machine is bound to all attack surface elements, the initial vulnerability state is uniformly set to S0, and evolution-related parameters are configured. Then, a multi-dimensional monitoring engine is built with a set time step to collect and verify the validity of four types of triggering events: attack, defense, time, and decoy. For valid events, the current state of the target vulnerability element is extracted, and the target state is determined through a preset state transition rule function. Subsequently, incremental evolution is strictly performed according to the evolution formula, and the state transition results are superimposed onto the current attack surface set to form a new attack surface set. It completes conflict verification and uses vulnerability as the core migration carrier to achieve full-dimensional collaborative evolution across three dimensions: assets, access paths, and business dependencies. After evolution, the attack surface set is updated in real time and evolution logs with power control-specific fields are fully stored and the evolution results are visualized. The above process is executed in a step-by-step loop until the training ends. During implementation, the event triggering priority of E4>E2>E1>E3 is followed, the evolution behavior is designed to fit the characteristics of power control protocols, manual intervention in the evolution process is supported, and distributed computing is used to ensure high-performance evolution. All evolution operations will provide real-time traceable relevant data synchronously.
[0157] In this embodiment, by distinguishing the type of the current attack event and combining the different states of each element before migration to perform branching and conditional state transition control, the state changes of elements in the attack surface model can strictly conform to the real attack and defense confrontation logic, and achieve accurate state evolution in scenarios such as attack detection, vulnerability timeliness, defense deployment, and decoy deception.
[0158] In one exemplary embodiment, such as Figure 6 As shown, based on the protection verification target corresponding to the simulated attack and the current state of each element, the target element to be attacked is determined, including:
[0159] Step 602: Determine the current attack strength and current protection coverage corresponding to the simulated attack based on the current state of each element.
[0160] Among them, the current attack intensity can be a quantitative indicator calculated based on the high-risk states of elements such as being exposed, attacked, or bypassed, and is used to characterize the threat level, penetration effect, and destructive capability of this simulated attack on the simulated power network; the current protection coverage rate can be a quantitative indicator obtained based on the proportion of elements in a safe state such as being protected or repaired, and is used to reflect the coverage and comprehensiveness of the simulated power network protection measures for the attacked targets.
[0161] Optionally, the current state of all elements in the attack surface model is traversed, and the current attack intensity corresponding to this simulated attack is calculated by statistically analyzing the number and threat level of elements in the exposed, attacked, or bypassed states. At the same time, the proportion of elements in the protected or repaired states to all threatened elements is calculated to determine the current protection coverage.
[0162] Step 604: Determine the target element to be attacked based on the current attack intensity, current protection coverage, and protection verification target corresponding to the simulated attack.
[0163] Optionally, based on the attack penetration trend reflected by the current attack intensity and the weak protection areas reflected by the current protection coverage, and in conjunction with the protection verification targets preset for this simulated attack, elements that match the verification requirements, have insufficient protection coverage, or have high attack value can be selected from the attack surface model and used as target elements for subsequent attacks.
[0164] Optionally, based on the training objective T (such as verifying zero-day defense and lateral movement detection) and the real-time offensive and defensive situation, the overall quantitative set of the real-time offensive and defensive situation of the power network is determined, and the overall quantitative set of the real-time offensive and defensive situation of the power network can be expressed as:
[0165] S R T=(Attack Intensity, Defense Coverage )
[0166] Among them, S R T is a quantitative summary of the real-time offensive and defensive situation of the power network; Attack Intensity It refers to the attacker's attack strength; Defense Coverage It is the defensive team's coverage rate.
[0167] This embodiment can also dynamically generate exposure strategies (used to manage the exposure range, exposure method, and decoy deployment rules of elements in the simulated power network, etc.). That is, it generates an overall set of adaptive vulnerability exposure strategies based on the overall quantitative set of the training objectives and the real-time offensive and defensive situation of the power network, and the overall set of adaptive vulnerability exposure strategies can be represented as follows:
[0168] Policy=Expose V Expose Mode Decoy Strategy
[0169] Among them, Policy is the overall set of adaptive vulnerability exposure strategies; Expose V It is a set of vulnerability exposures; Expose Mode It is a vulnerability exposure pattern; Decoy Strategy It is a decoy camouflage strategy.
[0170] Optionally, adaptive configuration of strategies can be implemented for different training objectives: when the training objective is to verify deep detection rules, the Expose mode can be configured. Mode By concealing the core exploit characteristics of vulnerabilities, we can simulate variant vulnerabilities; when the training objective is to verify defense-in-depth capabilities, we configure the vulnerability exposure set Expose. V This is a collection of low-risk vulnerabilities designed to guide attackers to initiate lateral movement.
[0171] Simultaneously adjust strategies based on real-time offensive and defensive situations: when the attacker's attack intensity reaches Attack Intensity When the value is greater than 0.7 (using 0-1 interval quantization), the vulnerability exposure set Expose will be used. V Set as a decoy vulnerability set; when the defender's protection coverage is Defense Coverage When the value is less than 0.5, the vulnerability exposure set Expose V It is set as a high-risk vulnerability set to increase the verification pressure on the protection system.
[0172] Optionally, in terms of decoy asset deployment, highly realistic decoy assets are dynamically generated, including fake PLC devices, scheduling databases that store trapping data, etc. The similarity of the attributes of the decoy assets to real assets is not less than 98%, and they support IEC60870-5-104 protocol interaction.
[0173] Regarding the decoy touch response, when an attacker touches the decoy asset (such as accessing the decoy database), event E4 is triggered. Based on this event, the system automatically adjusts the exposure level of the real asset, such as closing unnecessary ports of the real SCADA server and generating alarm logs simultaneously.
[0174] In this embodiment, by first transforming the abstract attack and defense state into quantifiable current attack strength and current protection coverage based on the current state of each element in the attack surface model, the threat level of the simulated attack and the protection coverage effect are accurately characterized. Then, by combining the preset protection verification target, the target elements to be attacked are selected from the attack surface model, so that the subsequent simulated attacks are no longer carried out blindly, but focus on the key points of verification and the weak links of protection, thereby improving the pertinence and efficiency of protection verification.
[0175] In an exemplary embodiment, taking a 110kV substation power network target training exercise as an example, the dynamic attack surface evolution and protection effectiveness are verified. The specific process is as follows:
[0176] Attack Surface Modeling: Constructing the attack surface AS=(A,V,P,B): Asset A includes 30 PLC devices, 10 SCADA servers, and 5 firewalls; Vulnerability V includes 15 vulnerabilities such as Modbus TCP function code abuse vulnerability (CVSS=8.5) and IEC60870-5-104 message tampering vulnerability (CVSS=9.0); Access Path P includes IP port mapping (PLC device port 502 is open) and access control link (operator → PLC control access); Business Dependency B constructs a dependency graph of "scheduling instructions → PLC execution → telemetry data reporting". Standardized Vulnerability Elements: V1=[V001, protocol defects, 8.5, PLC003, Modbus TCP].
[0177] Attack Surface Evolution: Initial State: All vulnerabilities are at S0 (undiscovered), attack surface AS(0) contains 30 active elements; Evolution Process: t=100s, the attacker scans and discovers PLC003 (Event E1), V1 moves from S0 to S1 (exposed); t=300s, the defender deploys the IDS signature database (Event E2), V1 moves from S1 to S2 (protected); t=500s, the attacker uses a variant function code to bypass the protection (Event E1), V1 moves from S2 to S4 (bypassed); t=700s, the defender patches the vulnerability (Event E2), V1 moves from S4 to S3 (patched). After evolution, attack surface AS(700) contains 25 active elements, with a state distribution of S0:8, S1:5, S2:7, S3:3, S4:2.
[0178] Adaptive Exposure Control: Training Objective T = Verifying the generalization capability of defense, real-time attack and defense situation. Intensity =0.6、Defense Coverage =0.7. Exposure strategy engine generates strategy: Expose V ={V001 variant, V005}、Expose Mode =Hidden core exploit features, DecoyStrategy =Deploy two fake PLC devices (PLC003-1 and PLC003-2). When the attacker touches the fake PLC003-1 (event E4), the system automatically shuts down port 502 of the real PLC003, and V1 changes from S3 to S0 (not detected).
[0179] Protection effectiveness verification: After the attack surface evolves, micro-subsequent test cases are automatically generated.
[0180] Case Mini =[Genuine PLC004, forged IEC60870-5-104 message, blocked by protection rules]
[0181] Quantitative calculation of protection coverage, protection response lag time, and protection capability assessment value: Protection Coverage D The initial value of Coverage is 7 / 25 = 0.28. D =20 / 22=0.91; Protection response delay time (Delay) R The initial value of Delay is 45s, and after optimization... R The time limit is 22 seconds; the protection capability assessment value (Generalization) is 18 / 20 = 0.9. Verification result: When all three indicators after optimization meet the threshold requirements, the protection system is deemed effective.
[0182] Feedback Optimization: Based on feedback data, the evolution rules were optimized: the migration weight from S2 to S4 was adjusted to increase the probability of variant attack triggering; the exposure strategy was optimized: the exposure ratio of variant vulnerabilities was increased from 30% to 50%. Post-Optimization Training: the attack surface evolution is closer to real confrontation, the attacker's attack success rate decreased from 45% to 28%, and the defender's protection adjustment efficiency increased by 40%.
[0183] To demonstrate this solution more comprehensively, this embodiment presents a verification method for power grid attack protection, specifically including:
[0184] 1. Determine the attack dimensions for the simulated power network; where the attack dimensions include at least one of the following: device dimension, security vulnerability dimension, attack path dimension, and business dependency dimension.
[0185] 2. Based on the target data of the actual power equipment corresponding to the simulated power network under the attack dimension, construct the attack surface model of the simulated power network under the attack dimension;
[0186] 3. Simulate an attack on the attack surface model to obtain the current attack events occurring in the simulated power network during the simulated attack process; wherein, the current attack events include at least one of the following: attack behavior events, defense action events, state update events, and spoofing device trigger events;
[0187] 4. Based on the state transition rules corresponding to the current attack event, the state of each element in the attack surface model is transitioned to obtain the current state of each element in response to the simulated attack update; where each element corresponds to a target data.
[0188] 5. Based on the current state of each element, determine the current attack strength and current protection coverage corresponding to the simulated attack;
[0189] 6. Based on the current attack intensity, current protection coverage, and the protection verification target corresponding to the simulated attack, determine the target element to be attacked;
[0190] 7. Perform a simulated attack on the target element again to obtain the target element's updated target state in response to the simulated attack.
[0191] 8. Generate protection test cases based on the target state of the target element;
[0192] 9. Based on protection test cases, verify the protection effectiveness of the simulated power network and obtain the verification results; the verification results include at least one of the following: protection coverage, protection response lag time, and protection capability evaluation value;
[0193] 10. If the verification results meet the preset verification conditions, the protection verification result of the power network is determined to be effective.
[0194] The specific process of the above steps can be found in the description of the above method embodiments. The implementation principle and technical effect are similar, and will not be repeated here.
[0195] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages in other steps. It is understood that the steps in different embodiments can be freely combined as needed, and all non-contradictory solutions formed by such combinations are within the scope of protection of this application.
[0196] Based on the same inventive concept, this application also provides a power network attack protection verification device for implementing the power network attack protection verification method described above. The solution provided by this device is similar to the implementation described in the above method; therefore, the specific limitations of one or more power network attack protection verification device embodiments provided below can be found in the limitations of the power network attack protection verification method described above, and will not be repeated here.
[0197] In one exemplary embodiment, such as Figure 7 As shown, a verification device for power network attack protection is provided, comprising: a determination module 71, a construction module 72, an attack module 73, and a verification module 74, wherein:
[0198] The determination module 71 is used to determine the attack dimensions against the simulated power network; wherein the attack dimensions include at least one of the following: device dimension, security vulnerability dimension, attack path dimension, and service dependency dimension.
[0199] Module 72 is used to construct an attack surface model of the simulated power network in the attack dimension based on the target data of the actual power equipment corresponding to the simulated power network in the attack dimension.
[0200] Attack module 73 is used to simulate an attack on the attack surface model to obtain the current state of each element in the attack surface model in response to the simulated attack; wherein each element corresponds to a target data.
[0201] The determination module 71 is also used to determine the target element to be attacked based on the protection verification target corresponding to the simulated attack and the current state of each element.
[0202] The attack module 73 is also used to perform a second simulated attack on the target element in order to obtain the target element's updated target state in response to the second simulated attack.
[0203] The verification module 74 is used to verify the protection effectiveness of the simulated power network based on the target state of the target element, and obtain the protection verification result of the power network.
[0204] In one embodiment, the verification module 74 is further configured to:
[0205] Generate protection test cases based on the target state of the target element;
[0206] Based on protection test cases, the protection effectiveness of the simulated power network is verified, and the verification results are obtained. The verification results include at least one of the following: protection coverage, protection response lag time, and protection capability evaluation value.
[0207] If the verification results meet the preset verification conditions, the protection verification result of the power network is determined to be effective.
[0208] In one embodiment, the attack module 73 is further configured to:
[0209] A simulated attack is performed on the attack surface model to obtain the current attack events occurring in the simulated power network during the simulated attack; wherein, the current attack events include at least one of attack behavior events, defense action events, state update events, and spoofing device trigger events;
[0210] Based on the state transition rules corresponding to the current attack event, the states of each element in the attack surface model are transitioned to obtain the current state of each element in response to the simulated attack update.
[0211] In one embodiment, the attack module 73 is further configured to:
[0212] The states of each element are transitioned according to the state transition weights of each element in the attack surface model and the state transition rules corresponding to the current attack event.
[0213] In one embodiment, the attack module 73 is further configured to:
[0214] Determine the verification feedback data; wherein, the verification feedback data includes the protection verification result, and at least one of the attack surface evolution log, attack behavior data and defense behavior data corresponding to the power network during this verification process;
[0215] Based on the verification feedback data, update the state transition weights of each element in the attack surface model and / or the device parameters of the spoofing devices in the simulated power network; wherein the device parameters include deployment location and / or simulation accuracy.
[0216] In one embodiment, the attack module 73 is further configured to:
[0217] In the case that the current attack event includes an attack behavior event or a state update event, for each element, if the element's state before migration is an undiscovered state, then the element's state is migrated to an exposed state; if the element's state before migration is a first state, then the element's state is kept in the first state; wherein, the first state includes other states besides the undiscovered state.
[0218] In the case where the current attack event includes a defensive action event, for each element, if the element's state before migration is an exposed state, then the element's state is migrated to a protected state or a repaired state; if the element's state before migration is a second state, then the element's state is maintained in the second state; wherein, the second state includes other states besides the exposed state.
[0219] In the case where the current attack event includes an attack behavior event, for each element, if the element's state before migration is a protected state, then the element's state is migrated to an attacked state; if the element's state before migration is a third state, then the element's state is maintained as the third state; wherein, the third state includes other states besides the protected state.
[0220] In the case where the current attack event includes a defensive action event or a decoy action event, for each element, if the element's state before migration is an exposed state, then the element's state is migrated to an undiscovered state; if the element's state before migration is a second state, then the element's state is maintained in the second state; wherein, the second state includes other states besides the protected state.
[0221] In one embodiment, the determining module 71 is further configured to:
[0222] Based on the current state of each element, determine the current attack strength and current protection coverage corresponding to the simulated attack;
[0223] The target element to be attacked is determined based on the current attack intensity, the current protection coverage, and the protection verification target corresponding to the simulated attack.
[0224] Each module in the aforementioned power grid attack protection verification device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the computer device's memory as software, so that the processor can call and execute the corresponding operations of each module.
[0225] In one exemplary embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 8As shown, this computer device includes a processor, memory, input / output (I / O) interfaces, and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor provides computational and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides the environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The database stores the verification results of power network protection. The I / O interfaces are used for information exchange between the processor and external devices. The communication interface is used for communication with external terminals via a network connection. When the computer program is executed by the processor, it implements a verification method for power network attack protection.
[0226] Those skilled in the art will understand that Figure 8 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0227] In one embodiment, a computer device is also provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above method embodiments.
[0228] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the steps in the above method embodiments.
[0229] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.
[0230] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.
[0231] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.
[0232] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0233] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A verification method for power grid attack protection, characterized in that, The method includes: Determine the attack dimensions for the simulated power network; wherein the attack dimensions include at least one of the following: device dimension, security vulnerability dimension, attack path dimension, and service dependency dimension. Based on the target data of the actual power equipment corresponding to the simulated power network under the attack dimension, an attack surface model of the simulated power network under the attack dimension is constructed. A simulated attack is performed on the attack surface model to obtain the current state of each element in the attack surface model in response to the simulated attack; wherein each element corresponds to a target data. Based on the protection verification target corresponding to the simulated attack and the current state of each element, determine the target element to be attacked; The target element is subjected to a second simulated attack to obtain the target element's updated target state in response to the second simulated attack. Based on the target state of the target element, the protection effectiveness of the simulated power network is verified, and the protection verification result of the power network is obtained.
2. The method according to claim 1, characterized in that, The step of verifying the protection effectiveness of the simulated power network based on the target state of the target element, and obtaining the protection verification result of the power network, includes: Based on the target state of the target element, generate protection test cases; Based on the protection test cases, the protection effectiveness of the simulated power network is verified, and the verification results are obtained; wherein, the verification results include at least one of protection coverage, protection response lag time, and protection capability evaluation value; If the verification result meets the preset verification conditions, the protection verification result of the power network is determined to be effective.
3. The method according to claim 1, characterized in that, The step of simulating an attack on the attack surface model to obtain the current state of each element in the attack surface model in response to the updated state of the simulated attack includes: A simulated attack is performed on the attack surface model to obtain the current attack events occurring in the simulated power network during the simulated attack; wherein, the current attack events include at least one of attack behavior events, defense action events, state update events, and spoofing device trigger events; Based on the state transition rules corresponding to the current attack event, the states of each element in the attack surface model are transitioned to obtain the current state of each element in response to the simulated attack update.
4. The method according to claim 3, characterized in that, The step of transitioning the state of each element in the attack surface model according to the state transition rule corresponding to the current attack event includes: The states of each element are transitioned according to the state transition weights of each element in the attack surface model and the state transition rules corresponding to the current attack event.
5. The method according to claim 4, characterized in that, After obtaining the protection verification result, the method further includes: Determine the verification feedback data; wherein, the verification feedback data includes the protection verification result, and at least one of the attack surface evolution log, attack behavior data and defense behavior data corresponding to the power network during this verification process; Based on the verification feedback data, update the state transition weights of each element in the attack surface model and / or the device parameters of the spoofing devices in the simulated power network; wherein the device parameters include deployment location and / or simulation accuracy.
6. The method according to claim 3, characterized in that, The state transition rules include: In the case that the current attack event includes an attack behavior event or a state update event, for each element, if the element's state before migration is an undiscovered state, then the element's state is migrated to an exposed state; if the element's state before migration is a first state, then the element's state is kept in the first state; wherein, the first state includes other states besides the undiscovered state. In the case where the current attack event includes a defensive action event, for each element, if the element's state before migration is an exposed state, then the element's state is migrated to a protected state or a repaired state; if the element's state before migration is a second state, then the element's state is maintained in the second state; wherein, the second state includes other states besides the exposed state. In the case where the current attack event includes an attack behavior event, for each element, if the element's state before migration is a protected state, then the element's state is migrated to an attacked state; if the element's state before migration is a third state, then the element's state is maintained as the third state; wherein, the third state includes other states besides the protected state. In the case where the current attack event includes a defensive action event or a decoy action event, for each element, if the element's state before migration is an exposed state, then the element's state is migrated to an undiscovered state; if the element's state before migration is a second state, then the element's state is maintained in the second state; wherein, the second state includes other states besides the protected state.
7. The method according to any one of claims 1-6, characterized in that, The step of determining the target element to be attacked based on the protection verification target corresponding to the simulated attack and the current state of each element includes: Based on the current state of each element, determine the current attack strength and current protection coverage corresponding to the simulated attack; The target element to be attacked is determined based on the current attack intensity, the current protection coverage, and the protection verification target corresponding to the simulated attack.
8. A power network target protection verification device, characterized in that, The device includes: The determination module is used to determine the attack dimensions against the simulated power network; wherein the attack dimensions include at least one of the following: device dimension, security vulnerability dimension, attack path dimension, and service dependency dimension. The construction module is used to construct the attack surface model of the simulated power network in the attack dimension based on the target data of the actual power equipment corresponding to the simulated power network in the attack dimension. An attack module is used to simulate an attack on the attack surface model to obtain the current state of each element in the attack surface model in response to the simulated attack; wherein each element corresponds to a target data. The determining module is further configured to determine the target element to be attacked based on the protection verification target corresponding to the simulated attack and the current state of each element. The attack module is also used to perform a second simulated attack on the target element to obtain the target element's updated target state in response to the second simulated attack. The verification module is used to verify the protection effectiveness of the simulated power network based on the target state of the target element, and obtain the protection verification result of the power network.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7.