Method and system for constructing a security protection early warning model based on multiple data perception
By constructing a security protection and early warning model based on multiple data perceptions, and combining deep neural networks and spatial information clustering analysis, the problem of monitoring intrusion behavior in power grid energy systems in complex network environments has been solved. This has enabled scientific assessment of power grid user energy systems and accurate identification of abnormal energy consumption, thereby improving monitoring and early warning capabilities.
Patent Information
- Application Number
- CN202111459596.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-01
- Publication Date
- 2025-12-19
- Estimated Expiration
- 2041-12-01
AI Technical Summary
Existing power grid systems struggle to effectively monitor new security attacks when faced with a large number of IoT terminal devices and complex network environments. Traditional intrusion detection methods cannot meet the monitoring needs of high-dimensional, non-linear traffic data, leading to increased difficulty in intrusion detection.
A security protection and early warning model based on multiple data perceptions is constructed. By collecting real-time energy consumption monitoring data of power grid users and combining deep neural networks and spatial information clustering analysis, a health status level assessment and early warning model are constructed. Multiple datasets and time matrices are used to monitor and warn of abnormal intrusion behavior.
It enables scientific assessment of power grid users' energy consumption systems and accurate identification of abnormal energy consumption, improves the monitoring and early warning capabilities of power grid users' energy consumption systems, and reduces the complexity and error of intrusion behavior monitoring.
Smart Images

Figure CN114398820B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the technical field of user energy use, intrusion monitoring, and particularly relates to a security protection early warning model construction method and system based on multiple data perception. BACKGROUND
[0002] The statements in this section merely provide background information related to the present application and do not necessarily constitute the prior art.
[0003] Due to the expansion of power grid energy use system data types and collection channels, it is difficult to effectively monitor new security attack behaviors. How to improve the perception of user energy use state of power grid enterprises, improve the quality of user services, and establish an effective power grid user energy use system monitoring and early warning method based on multiple data perception is an urgent problem to be solved.
[0004] At present, the most commonly used method is to apply feature-based intrusion detection technology and intrusion detection algorithm improvement, to monitor and warn intrusion behaviors by detecting the feature differences between normal traffic and abnormal traffic in a local area network.
[0005] However, with the large number of Internet of Things terminal devices accessing and the continuous expansion of energy use, the network environment becomes more complex, and more high-latitude and nonlinear traffic data are generated in the communication process. The power grid enterprise has constructed a signal monitoring and management system that spans the collection front-end and marketing business system, and based on the service bus and message center, the process message collection and distribution driving collection is carried out. The current monitoring data dimension and data volume increase the difficulty of intrusion detection, and the traditional method cannot meet the requirements. SUMMARY
[0006] To overcome the above-mentioned deficiencies of the prior art, the present application provides a security protection early warning model construction method based on multiple data perception, which combines various working condition characteristics of power energy use equipment and multiple intrusion behavior data to perform energy use safety early warning monitoring and ensure the stability of power grid user energy use.
[0007] To achieve the above-mentioned purpose, one or more embodiments of the present application provide the following technical solutions:
[0008] In a first aspect, a security protection early warning model construction method based on multiple data perception is disclosed, comprising:
[0009] Real-time collection of power grid user energy use monitoring data to construct multiple data sets;
[0010] Construction of a multiple data perception model based on multiple data sets and deep neural networks;
[0011] The multiple data perception model perceives intrusion behavior data, performs health state level evaluation, obtains health state level evaluation results, and constructs an early warning model.
[0012] Further technical solutions, using early warning model to judge the intrusion behavior, if there is intrusion behavior, give early warning, protection, otherwise, no warning.
[0013] Further technical solutions, for real-time acquisition of power grid user energy monitoring data, extract the reflection of running system operation condition data between each level of energy center and each energy user, power network, including normal operation data, normal energy data, abnormal energy data, abnormal intrusion data, various interference information, as a sample feature set for constructing multiple data acquisition model.
[0014] Further technical solutions, also include: based on the sample feature set of the running system operation condition data, using spatial information clustering analysis method, the running system operation condition data is divided into N cluster head nodes, which is used for classification of abnormal data feature recognition processing of power grid user energy system.
[0015] Further technical solutions, also include: based on N cluster head nodes, in the intrusion behavior identification, through time matrix and multi attribute data monitoring matrix, get user energy system abnormal energy consumption diffusion matrix;
[0016] Input different clustering data of running system operation condition, through user energy system abnormal energy consumption diffusion matrix, output abnormal feature data of power grid user energy system, realize the abnormal data feature recognition processing of power grid user energy system.
[0017] Further technical solutions, the multi attribute data monitoring matrix calculation process is as follows:
[0018] Based on the sample feature data of the running system operation condition data, the running state data of the same cluster energy line acquisition is extracted by setting the user energy system abnormal energy consumption diffusion matrix threshold, based on the feature data of the running state sample set of the same cluster energy line acquisition, the normal distribution is used for automatic scheduling of power grid user energy system monitoring warning range, that is, based on sample feature data to obtain its mathematical expectation, standard deviation, and based on the collection time period to set the automatic scheduling confidence threshold, based on time dynamic change power grid user energy system monitoring warning range, the multi attribute data monitoring matrix is composed of multi attribute data monitoring threshold range
[0019] Further technical solutions, the multiple data set combined with deep neural network to construct multiple data perception model, including using deep learning theory to classify the time load of monitoring collection data, the specific process is:
[0020] Based on the monitoring collection data in the running process of power grid user energy system, construct monitoring collection data sample library;
[0021] The relevant monitoring characteristic data is called from the power utilization information collection system, and the set samples of the monitoring and collection data sample library are used as the time load classification model training samples;
[0022] The time load classification model structure and each parameter definition are determined;
[0023] The training sample data is transmitted to the input neurons, and the parameters are adjusted in the negative gradient direction of the target based on the gradient descent strategy;
[0024] The error between the expected output value and the sample output value of the current parameters obtained in the training process is calculated;
[0025] According to the chain rule, the gradient items of the neurons are calculated, the connection weights and threshold values of each layer are corrected by calculating the correction amount of the connection weights and threshold values, and the globally optimal parameters are obtained.
[0026] In a further technical solution, the multiple data perception model perceives the intrusion behavior data, and specifically includes:
[0027] Based on the constructed multiple data collection model, the data overflow monitoring of abnormal intrusion behavior based on multiple data perception is performed by combining the quantitative representation and the fuzzy monitoring method.
[0028] In a further technical solution, based on the sample feature set of the multiple data collection model, the joint probability density feature of the multiple data is calculated for the multiple collection characteristic data, and the statistical characteristic quantity is obtained.
[0029] Based on the feature quantity and the overflow conversion modulation component of the multiple data perception, the distribution of the intrusion behavior data of different partitions is described, and the normal distribution of the user energy system monitoring and early warning load data meeting the standard is obtained.
[0030] In a further technical solution, the early warning model takes the multiple collection data and the multiple perception data as input data, and corrects the monitoring abnormal intrusion behavior signal feature curve based on the early warning result feedback.
[0031] In a second aspect, the purpose of the embodiment is to provide a security protection early warning model construction system based on multiple data perception, which includes:
[0032] The multiple data set construction module is configured to collect power grid user energy monitoring data in real time and construct a multiple data set;
[0033] The multiple data perception model construction module is configured to construct a multiple data perception model based on the multiple data set and a deep neural network;
[0034] The early warning model construction module is configured to: the multiple data perception model perceives the intrusion behavior data, performs health state level assessment, obtains a health state level assessment result, and constructs an early warning model.
[0035] The above one or more technical solutions have the following beneficial effects:
[0036] The application constructs a multiple data acquisition model, a multiple data perception control method, a monitoring and early warning model, a power grid user energy system monitoring and early warning method based on multiple data perception, adopts a quantitative characterization and fuzzy monitoring method to perform multiple data perception control on the power grid user energy system, sets a power grid user energy system monitoring and early warning level by determining a permission threshold, and adopts a combination of a multi-head attention and a GRU to construct a power grid user energy system monitoring and early warning model, so as to realize scientific assessment of the health state of the user energy system, improve system diagnosis capability, analyze user energy system characteristics, complete probability speculation and early warning on the user energy state, and accurately identify abnormal energy consumption.
[0037] In the application, multiple data perception is introduced, single-dimensional intrusion anomaly acquisition data and multi-dimensional related feature intrusion anomaly acquisition data are used to realize power grid energy intrusion behavior monitoring.
[0038] The application proposes a multiple data acquisition model, uses a time matrix and a multi-attribute data monitoring matrix to construct an abnormal energy consumption diffusion matrix of the user energy system, adjusts a monitoring data threshold based on time dynamics, realizes data overflow monitoring of abnormal intrusion behavior based on multiple data perception, and solves the problem of incomplete intrusion behavior monitoring.
[0039] Advantages of additional aspects of the application will be partially given in the following description, partially become obvious from the following description, or be understood through practice of the application. BRIEF DESCRIPTION OF DRAWINGS
[0040] The accompanying drawings, which form a part of the specification, are included to provide a further understanding of the application and are incorporated herein by reference. The embodiments illustrated in the drawings are intended to explain the present application and are not intended to limit the present application.
[0041] Figure 1 is a frequency monitoring result graph of the original data signal and the intrusion behavior data signal according to the embodiment one of the application;
[0042] Figure 2 is a monitoring intrusion behavior signal characteristic curve graph according to the embodiment one of the application;
[0043] Figure 3 is a corrected monitoring intrusion behavior signal characteristic curve graph according to the embodiment one of the application;
[0044] Figure 4 This is a flowchart illustrating the method described in Embodiment 1 of the present invention. Detailed Implementation
[0045] It should be noted that the following detailed descriptions are exemplary and intended to provide further illustration of the invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.
[0046] It should be noted that the terminology used herein is for the purpose of describing particular implementations only and is not intended to limit the exemplary implementations of the present invention.
[0047] Where there is no conflict, the embodiments and features in the embodiments of the present invention can be combined with each other.
[0048] Example 1
[0049] See appendix Figure 4 As shown, this embodiment discloses a method for constructing a multi-data acquisition model (dataset), including:
[0050] Real-time energy consumption monitoring data of power grid users is collected through dedicated power channels. Data reflecting the operating conditions of the system are extracted from the data transmitted between energy consumption centers at all levels, energy users, and the power network. This includes normal operation data, normal energy consumption data, abnormal energy consumption data, abnormal intrusion data, and various interference information, which serve as the sample feature set for constructing a multi-data acquisition model.
[0051] Based on the sample feature set of operating system data, a spatial information clustering analysis method is used. Based on monitoring sensor nodes, the operating system data is divided into N cluster head nodes for classification and identification of abnormal data features in the power grid user energy consumption system. Based on these N cluster head nodes, in intrusion behavior identification, the abnormal energy consumption diffusion matrix B of the user energy consumption system is obtained through the time matrix and multi-attribute data monitoring matrix. N×1 Its expression is: B N×1 =S N×L ·T L×1
[0052] In the formula, T L×1 S is a space matrix; N×L For multi-attribute data monitoring matrix, L is the number of attribute categories, representing the feature values of samples of operating condition data of the system in operation.
[0053] Input different clusters of data on the operating conditions of the system, and output abnormal characteristic data of the power grid user energy system through the abnormal energy consumption diffusion matrix of the user energy system, so as to realize the identification and processing of abnormal data features of the power grid user energy system.
[0054] The multi-attribute data monitoring matrix S N×L , the calculation process is as follows: based on the operation condition of the running system, the sample characteristic data of the data, the running state data of the energy consumption line collected by setting the user energy consumption system abnormal energy consumption diffusion matrix threshold value is extracted, based on the characteristic data of the running state sample set collected by the energy consumption line in the same cluster, the normal distribution is used for automatic scheduling of the power grid user energy consumption system monitoring and early warning range, that is, based on the sample characteristic data, the mathematical expectation is μ, and the standard deviation is σ 2 , denoted as X~N(μ,σ 2 ), and based on the collection time period, the automatic scheduling confidence threshold is set, the power grid user energy consumption system monitoring and early warning range is dynamically changed based on time, and the multi-attribute data monitoring threshold range constitutes a multi-attribute data monitoring matrix S N×L ;
[0055] The time matrix T L×1 The calculation process is as follows: based on the monitoring and collection data amount of the power grid user energy consumption system during operation, the deep learning theory is used for time load classification of the monitoring and collection data amount, time period division is carried out based on the classified time period, and the time matrix T L×1 is formed.
[0056] The deep learning theory is used for time load classification of the monitoring and collection data amount, and the specific process is as follows:
[0057] (1) Based on the monitoring and collection data of the power grid user energy consumption system during operation, a monitoring and collection data amount sample library is constructed, and relevant monitoring characteristic data is called from the power consumption information collection system. 80% of the samples in the monitoring and collection data amount sample library are used as time load classification model training samples (x k ,y k ), k∈(1,2,…,K), y k ∈(c1,c2,…,c8), wherein x is a sample, the training sample is K, c is a time load classification, and the remaining 20% is a test sample. The iteration number is initialized τ OI =τ sI =1.
[0058] (2) The time load classification model structure and each parameter are defined, and the first iteration number threshold OI and the second iteration number threshold SI are initialized and assigned. The learning rate η is initialized and randomly assigned, η∈(0,1). The hidden layer error back propagation neural network is initialized, and the initial neural network hidden layer node number calculation formula is:
[0059]
[0060]
[0061]
[0062] wherein s is the initialized simulation single hidden layer node number, I is the input neuron number, each input neuron is as an input end for monitoring the amount of collected data, J is the output neuron number, representing the time load classification number; is a random variable; R is the initialized second hidden layer neuron number; H is the initialized first hidden layer neuron number;
[0063] (3) transmitting the K training sample data to the input neurons, adjusting the parameters in the negative gradient direction of the target based on the gradient descent strategy, and the sample output value of the current parameter
[0064]
[0065] wherein, is the training stage output value of the output layer jth neuron of the training sample x k ; and J output layer neuron threshold value θ j ;
[0066] (4) calculating the error E between the expected output value and the k acquired in the current training process as follows:
[0067]
[0068] wherein, is the actual output value of the output layer jth neuron of the training sample x k ; and the cumulative error E
[0069]
[0070] (5) if iteration number τ OI = OI && τ SI = SI, it is indicated that the time load classification model training is completed, and step (9) is entered; if not, step (6) is entered;
[0071] (6) if iteration number τ = SI, it is indicated that the time load classification model of the current set of initialized parameter values is locally solved, the current secondary iteration process is stopped, the BP neural network data constructed this time is transmitted to the database for storage, τ OI = τ OI + 1, and step (2) is returned; if not, τ SI = τ SI + 1, and step (7) is entered;
[0072] (7) Calculate the gradient term of each neuron according to the chain rule, as follows:
[0073] Gradient term g of output layer neuron j :
[0074]
[0075] Gradient term q of second hidden layer neuron r :
[0076]
[0077] Gradient term e of first hidden layer neuron h :
[0078]
[0079] (8) Modify the connection weights and thresholds of each layer by calculating the correction amount of the connection weights and thresholds, and the calculation formula is as follows:
[0080] Connection weight update ω of second hidden layer and output layer neuron rj :
[0081]
[0082] Update threshold θ of output layer j :
[0083] θ j ← θ j + Δθ j = θ j - Δηg j (5-15)
[0084] Connection weight update u of first hidden layer and second hidden layer neuron hr
[0085]
[0086] Update threshold γ of second hidden layer r
[0087] γ r ← γ r + Δγ r = γ r - Δηq r (5-17)
[0088] Connection weight update v of input layer and first hidden layer neuron ih
[0089] v ih ← v ih + Δvih = v ih + ηe h x i (5-18)
[0090] update threshold of the first hidden layer κ h
[0091] κ h ← κ h + Δκ h = κ h - Δηe h (5-19)
[0092] wherein the adjustment parameters are totally H(I+1)+R(J+1)+J(R+1), including IxH weight values v from the input layer to the first hidden layer ih , HxR weight values u from the first hidden layer to the second hidden layer hr , RxJ weight values ω from the second hidden layer to the output layer rj , H threshold values κ of the first hidden layer neurons h , R threshold values γ of the second hidden layer neurons r , J threshold values θ of the output layer neurons j , and then returning to step (3);
[0093] (9) obtaining the BP neural network constructed by the different initialization parameter values of the OI groups from the database, taking the test sample set as the input data, testing the OI BP neural networks, and obtaining the cumulative error according to formulas (5-8)-(5-10) , calculating the minimum error objective function E min ,
[0094]
[0095] (10) taking the BP neural network parameters of the group where E min is located as the approximate global optimal parameters, specifically including R, H, v ih , u hr , ω rj , κ h , γ r and θ j , and outputting the time load classification model based on the deep learning algorithm.
[0096] In another embodiment, a multi-data perception control method is disclosed, comprising:
[0097] On the basis of the constructed multi-data acquisition model, data overflow monitoring of abnormal intrusion behavior based on multi-data perception is carried out by combining quantitative representation and fuzzy monitoring method, and the specific process is as follows:
[0098] Based on the sample feature set of multiple data acquisition model, the joint probability density feature of multiple data is calculated for multiple acquisition feature data, and the statistical feature quantity μ(n) is obtained, n is the feature dimension of multiple data, and the feature quantity of multiple data perception is obtained by using quantization representation method
[0099] In the above formula, x(n) is the correlation feature value of the power grid user energy use, and is obtained by setting the correlation threshold for screening; is the data feature value of the abnormal intrusion behavior sample j, is the covariance matrix of the correlation feature;
[0100] Based on the feature quantity of multiple data perception and the overflow conversion modulation component, the distribution of intrusion behavior data in different partitions is described, and the user energy system monitoring and early warning load data X that meets the standard normal distribution is obtained, denoted as X ~ S α (μ,σ,β), wherein μ,σ,β are the mean, standard deviation and noise parameter of the feature quantity of multiple data perception respectively, and the overflow conversion modulation component is used as the confidence parameter;
[0101] The calculation process of the overflow conversion modulation component is as follows:
[0102] The abnormal intrusion behavior overflow data component of multiple data perception is modulated to obtain the modulation component:
[0103]
[0104] In the above formula, D m (0) represents the health state feature set of the power grid user energy system, and is composed of the value difference d m (0) of each sample data at different times, X m+1 (i) represents the data load balancing degree of the power grid user energy system monitoring, μ VSS-MCMA (n) is the working condition state feature distribution function of the energy-using equipment, X k+1 (i) represents the number of intrusion behavior samples.
[0105] Among them, X m is the sample feature value center point, X k is each sample feature value at time k, and the sample data distribution calculation d m (0) of the power grid user energy system is carried out m ; k
[0106] Among them, the sample data processing is carried out in combination with the working condition running time dimension feature of the energy-using equipment, and the working condition state feature distribution function of the energy-using equipment at time m is obtained as:
[0107] μVSS-MCMA (n) = β [1 - exp (-α|d m (0)|)C′ D (n i )]
[0108] Wherein, alpha and beta represent the center vector of abnormal intrusion behavior data; C′ D (n i ) represents the overflow parameter of power grid user energy multiple data perception abnormal intrusion behavior data.
[0109] According to the overflow conversion modulation component, the multiple data perception fusion feature abnormality discrimination control is performed on the overflow of the power grid user energy multiple data perception abnormal intrusion behavior data.
[0110] In another embodiment, a monitoring and early warning model is disclosed, which uses multiple attention and GRU combination to construct the early warning model based on multiple collection data and multiple perception data as input data, so as to realize state safety monitoring and early warning, and based on the early warning result, the monitoring abnormal intrusion behavior signal feature curve is corrected, and the abnormal intrusion behavior data multiple perception control ability is improved.
[0111] The application constructs a multiple data collection model, collects power grid user energy monitoring data in real time through a power special channel, and uses a spatial information clustering analysis method to process abnormal data feature identification of the power grid user energy system.
[0112] In the multiple data perception control method, based on the constructed multiple data collection model, the abnormal intrusion behavior data overflow monitoring based on multiple data perception is performed by combining the quantitative representation and fuzzy monitoring method.
[0113] Based on the abnormal intrusion behavior data overflow control of the power grid user energy system by using the quantitative representation and fuzzy monitoring method, the abnormal intrusion behavior data control method of multiple data perception is used for balanced control of the power grid user energy system, so as to correct the monitoring abnormal intrusion behavior signal feature curve and improve the abnormal intrusion behavior data multiple perception control ability.
[0114] The embodiment provides a power grid user energy system monitoring and early warning method based on multiple data perception. In the application performance in the realization of the power grid user energy system monitoring and early warning, MatlabR2017 is used for simulation test analysis. On the PSS / E power system simulation platform, a power grid user energy system network structure model with 11 servers and 1 switch is built.
[0115] The physical network topology of the power grid user energy positioning is set, the user energy load is about 2000 kW, of which 1600 kW is received, the intrusion behavior occurs concentratedly on the 1000 kV energy user line, the sample number of abnormal intrusion behavior overflow data sampling is 2000, the information fusion of the power grid user energy system monitoring and early warning is set in the API interface, the running time of the power grid user energy system is set to 0.15 s, the intrusion behavior is added after the power grid user energy system maintains the normal running state for 0.01 s, and the system monitoring is performed. The frequency of the power grid user energy system monitoring original data signal and the intrusion behavior data signal is as shown in Figure 1 .
[0116] The feature curve is generated after the monitoring intrusion behavior signal collected is normalized, as shown in Figure 2 . The distance between the feature curve of the power grid user energy system monitoring intrusion behavior signal and the frequency center is very small, and there is obvious burr in the figure, indicating that there is abnormal intrusion behavior data. The method is used for abnormal intrusion behavior control of multiple data, and the feature curve of the monitoring intrusion behavior signal is further corrected based on the feedback data, and the correction result is as shown in Figure 3 .
[0117] The method corrects the data curve containing bad burr, and well collects and senses the multiple data of the intrusion behavior, and realizes the safety protection of the power grid user energy system.
[0118] In order to further verify the effectiveness of the method, the power grid user energy system monitoring and early warning results obtained by using the method are compared with the actual test results of the power grid user energy system monitoring and early warning, and the comparison results are as shown in Table 1.
[0119] Table 1: Error comparison of power grid user energy system monitoring and early warning
[0120]
[0121] According to Table 1, the error of the power grid user energy system monitoring and early warning result obtained by using the method is controlled within 0.002%, which indicates that the power grid user energy system monitoring and early warning accuracy realized by the method is high, and the multiple data sensing control ability is good.
[0122] Example two
[0123] The purpose of this embodiment is to provide a computing device, including a memory, a processor and a computer program stored on the memory and executable on the processor, wherein the processor implements the steps of the above method when executing the program.
[0124] Example three
[0125] The embodiment aims to provide a computer readable storage medium.
[0126] A computer readable storage medium, having stored thereon a computer program, which is executed by a processor to perform the steps of the above method.
[0127] Embodiment four
[0128] The embodiment aims to provide a security protection early warning model construction system based on multiple data perception, comprising:
[0129] A multiple data set construction module is configured to collect power grid user energy monitoring data in real time and construct a multiple data set.
[0130] A multiple data perception model construction module is configured to construct a multiple data perception model based on the multiple data set and a deep neural network.
[0131] An early warning model construction module is configured to perform perception on intrusion behavior data by using the multiple data perception model, perform health state level assessment, obtain a health state level assessment result, and construct an early warning model.
[0132] The steps and methods involved in the devices of embodiments two, three and four correspond to embodiment one, and the specific implementation can be seen from the related description of embodiment one. The term "computer readable storage medium" should be understood as including a single medium or multiple media of one or more instruction sets; it should also be understood as including any medium capable of storing, encoding or carrying instruction sets for execution by a processor and causing the processor to perform any method in the present application.
[0133] Those skilled in the art should understand that the above modules or steps of the present application can be realized by a general computer device, and alternatively, they can be realized by program codes executable by a computing device, so that they can be stored in a storage device and executed by a computing device, or they can be respectively manufactured into individual integrated circuit modules, or a plurality of modules or steps can be manufactured into a single integrated circuit module. The present application is not limited to any specific combination of hardware and software.
[0134] The above describes the specific embodiments of the present application in combination with the accompanying drawings, but is not a limitation on the protection scope of the present application. Those skilled in the art should understand that various modifications or variations made by those skilled in the art on the basis of the technical solutions of the present application without creative labor are still within the protection scope of the present application.
Claims
1. A method for constructing a security protection early warning model based on multiple data perception, characterized in that, The method comprises the following steps: Real-time acquisition of power grid user energy consumption monitoring data, construction of multiple data sets; For the real-time acquisition of power grid user energy consumption monitoring data, extract the operating condition data of the in-operation system, including normal operation data, normal energy consumption data, abnormal energy consumption data, abnormal intrusion data, and various interference information, which are transmitted between each level of energy consumption center and each energy user and power network, as the sample feature set for constructing the multiple data acquisition model; Further comprising: based on the sample feature set of the operating condition data of the in-operation system, using spatial information clustering analysis method, the operating condition data of the in-operation system is divided into N cluster head nodes, which are used for classification and abnormal data feature recognition processing of the power grid user energy system; Further comprising: based on the N cluster head nodes, in the intrusion behavior recognition, through the time matrix and the multi-attribute data monitoring matrix, the abnormal energy consumption diffusion matrix of the user energy system is obtained; Input different clustering data of the operating condition of the in-operation system, through the abnormal energy consumption diffusion matrix of the user energy system, output the abnormal feature data of the power grid user energy system, realize the abnormal data feature recognition processing of the power grid user energy system; The calculation process of the multi-attribute data monitoring matrix is as follows: Based on the sample feature data of the operating condition data of the in-operation system, the operating state data of the energy consumption line collected in the same cluster is extracted by setting the user energy system abnormal energy consumption diffusion matrix threshold, based on the feature data of the operating state sample set collected in the same cluster energy consumption line, the normal distribution is used for automatic scheduling of the monitoring and early warning range of the power grid user energy system, the automatic scheduling confidence threshold is set based on the collection time period, the monitoring and early warning range of the power grid user energy system is dynamically changed based on time, and the multi-attribute data monitoring matrix is composed of the multi-attribute data monitoring threshold range; Based on the multiple data sets, a multiple data perception model is constructed by combining a deep neural network; The multiple data perception model perceives the intrusion behavior data, performs health state level evaluation, obtains health state level evaluation results, and constructs a warning model.
2. The method for constructing a security protection and early warning model based on multiple data perception as described in claim 1, characterized in that, The warning model is used to judge the intrusion behavior, and if there is intrusion behavior, a warning is given for protection, otherwise, no warning.
3. The method of claim 1, wherein the method further comprises: determining a security protection early warning model based on the multi-data perception. The multiple data perception model constructed based on the multiple data sets and the deep neural network comprises time load classification of monitoring and collection data volume by using deep learning theory, and the specific process is as follows: Based on the monitoring and collection data in the operation process of the power grid user energy system, a monitoring and collection data volume sample library is constructed; The relevant monitoring feature data is called from the power consumption information collection system, and the set samples of the monitoring and collection data volume sample library are used as time load classification model training samples; The time load classification model structure and each parameter are defined; The training sample data is transmitted to the input neurons, and the parameters are adjusted in the negative gradient direction of the target based on the gradient descent strategy; The error between the expected output value and the sample output value of the current parameters obtained in the training process is calculated; According to the chain rule, the gradient items of neurons are calculated, the connection weights and thresholds of each layer are modified by calculating the correction amount of the connection weights and thresholds, and the global optimal parameters are obtained.
4. The method for constructing a security protection and early warning model based on multiple data perception as described in claim 1, characterized in that, The multiple data perception model perceives the intrusion behavior data, and specifically comprises: Based on the constructed multiple data acquisition model, combined with quantitative characterization and fuzzy monitoring method, data overflow monitoring of abnormal intrusion behavior based on multiple data perception is carried out.
5. The method of claim 1, wherein the method further comprises: determining a security level of the target object based on the security level of the target object and the security level of the object; and determining a security level of the target object based on the security level of the target object and the security level of the object. Based on the sample feature set of the multiple data acquisition model, the joint probability density feature of the multiple data is calculated for the multiple acquisition feature data, and the statistical feature quantity is obtained. Based on the feature quantity and overflow conversion modulation component of the multiple data perception, the distribution of the intrusion behavior data of different partitions is described, and the normal distribution of the user energy system monitoring and early warning load data meeting the standard is obtained. The early warning model takes the multiple acquisition data and the multiple perception data as input data, and corrects the monitoring abnormal intrusion behavior signal feature curve based on the early warning result feedback.
6. A security protection early warning model construction system based on multiple data perception, characterized in that, It comprises: A multiple data set construction module configured to acquire real-time power grid user energy monitoring data and construct a multiple data set; For the real-time acquired power grid user energy monitoring data, the reflection in the operating system operating condition data between each level of energy center and each energy user and power network is extracted, including normal operation data, normal energy data, abnormal energy data, abnormal intrusion data and various interference information, which are used as a sample feature set for constructing a multiple data acquisition model; It also includes: based on the sample feature set of the operating system operating condition data, the spatial information clustering analysis method is used to divide the operating system operating condition data into N cluster head nodes for classification and abnormal data feature recognition processing of the power grid user energy system; It also includes: based on the N cluster head nodes, through the time matrix and the multiple attribute data monitoring matrix, the user energy system abnormal energy consumption diffusion matrix is obtained in the intrusion behavior identification; Different clustering data of the operating system operating condition are input, the abnormal feature data of the power grid user energy system is output through the user energy system abnormal energy consumption diffusion matrix, and the abnormal data feature recognition processing of the power grid user energy system is realized; The multiple attribute data monitoring matrix calculation process is as follows: Based on the sample feature data of the operating system operating condition data, the operating state data of the energy line collected in the same cluster is extracted by setting the user energy system abnormal energy consumption diffusion matrix threshold, the normal distribution is used for automatic scheduling of the power grid user energy system monitoring and early warning range based on the feature data of the operating state sample set collected by the energy line in the same cluster, the automatic scheduling confidence threshold is set based on the collection time period, and the power grid user energy system monitoring and early warning range is dynamically changed based on time, and the multiple attribute data monitoring matrix is composed of the multiple attribute data monitoring threshold range; A multiple data perception model construction module configured to construct a multiple data perception model based on the multiple data set and a deep neural network; An early warning model construction module configured to perform perception on the intrusion behavior data based on the multiple data perception model, perform health state level evaluation, obtain health state level evaluation results, and construct an early warning model.
7. A computing device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, The processor executes the program to realize the steps of the method of any one of claims 1-5.
8. A computer-readable storage medium having stored thereon a computer program, characterized in that, The program is executed by the processor to perform the steps of the method of any one of claims 1-5.
Citation Information
Patent Citations
Electricity larceny prevention early warning method based on multi-source data fusion
CN109615004A