Power internet of things security risk assessment method, system, device and storage medium
By constructing an information network diagram and a power network diagram for the power Internet of Things (IoT), and combining graph computing methods, the problem of failing to fully consider the impact of information-side attacks on the physical side in existing technologies has been solved. This has enabled more accurate and efficient security risk assessment and improved the security and topology design capabilities of the power IoT.
Patent Information
- Application Number
- CN202210720264.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-23
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2042-06-23
AI Technical Summary
Existing technologies in power Internet of Things (IoT) security risk assessment fail to fully consider the impact of information-side attacks on the physical side, resulting in low accuracy of security assessments and an inability to effectively reflect the network layer topology and device connectivity.
Based on interdependent network theory, an information network diagram, a power network diagram, and inter-network dependencies of the power Internet of Things are constructed. Through graph computation methods, the mutual influence between the information side and the physical side is reflected. By combining information-side graph computation and physical-side graph computation, the security risks of the power Internet of Things are assessed.
It improves the accuracy and comprehensiveness of security assessments, can identify devices with high potential risk values, enhances network security, provides guidance for topology design, and improves computational efficiency.
Smart Images

Figure CN115034644B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the field of power automation, and relates to a power Internet of Things security risk assessment method, system, device and storage medium. BACKGROUND
[0002] With the rapid development of power technology and power market, and the continuous coupling of power systems and information systems, a power grid information-physical coupling system is gradually formed. The access of more and more sensing devices, distributed new energy and energy storage elements makes the power network more and more complex, and the multi-source heterogeneous data generated also puts forward higher requirements on the calculation, analysis and complex problem processing of the power grid system. The power Internet of Things is one of the important components of the power information-physical integration. The power Internet of Things is a network that comprehensively perceives the massive information in all links of the power system. It is deeply integrated with the smart grid through modern technologies such as big data processing, cloud computing, 5G mobile communication, smart city and blockchain, opens up information islands, and realizes the wide interconnection of people and things.
[0003] The overall logical architecture of the power Internet of Things can be abstracted as the acquisition, transmission, processing and application of information, i.e. the perception layer, the network layer, the platform layer and the application layer. The network layer is the transmission channel of the data involved in the power information-physical integration using modern communication technologies, and is also an important hub connecting the perception layer and the platform layer. In the network layer, various sensing devices deployed in the power information-physical integration use multiple communication protocols for the transmission and exchange of power measurement data. However, due to the complex and numerous devices, data and network protocols connected in the network layer, there are a large number of security risks, which are extremely vulnerable to denial-of-service attacks, wormhole attacks, flooding attacks and cancellation synchronization attacks, etc. These attacks can easily cause the communication between the sensing devices in the power information-physical integration and the power information-physical integration platform or the sensing devices to be interrupted, causing harm to the safe and stable operation of the power information-physical integration. For example, as a component of the power CPS, the information network of the power Internet of Things is attacked, which will also affect the safe and stable operation of the physical side of the power network. The sensing devices in the power information-physical integration cannot return electrical sensing data or return error data to the SCADA and other power control systems in time due to the attack, which may cause the power control system to make wrong decisions, and further cause the electrical equipment to burn out due to exceeding the rated power, and even may cause large-scale power outages.
[0004] The defense against cyber attacks on power cyber physical systems can be divided into four parts: security protection, attack detection, attack mitigation and recovery after attack. At present, the research work for defense mainly focuses on the first three parts, mainly including artificially assessing the risks of power cyber physical systems based on analytic hierarchy process, and using machine learning technology to analyze the historical operation data of power cyber physical systems to assess the risks of influencing factors of power cyber physical systems, but both of them only assess the security risks of information side statically to further prevent, and do not consider the influence of attacks on the physical side after the information side of power cyber physical systems is attacked, so the accuracy of security assessment is low. SUMMARY
[0005] The purpose of the present application is to overcome the above-mentioned shortcomings of the prior art, and to provide a power Internet of Things security risk assessment method, system, device and storage medium.
[0006] To achieve the above-mentioned purpose, the following technical solutions are adopted:
[0007] The first aspect of the present application is a power Internet of Things security risk assessment method, comprising:
[0008] Based on the interdependent network theory, the information network diagram, the power network diagram and the inter-network dependence relationship of the power Internet of Things are established;
[0009] The attacked node in the information network diagram is obtained and its state value is assigned as a preset attack success probability, and then the state values of each node in the information network diagram are updated according to the information side diagram calculation method;
[0010] According to the updated state values of each node in the information network diagram, the attack success probability of each node in the power network diagram is determined through the inter-network dependence relationship;
[0011] According to the attack success probability of each node in the power network diagram, the state values of each node in the power network diagram are determined through the physical side diagram calculation method;
[0012] According to the state values of each node in the power network diagram, the power Internet of Things security risk assessment value is obtained.
[0013] Optionally, the establishment of the information network diagram, the power network diagram and the inter-network dependence relationship of the power Internet of Things based on the interdependent network theory comprises:
[0014] The physical devices in the primary system of the power Internet of Things are abstracted as physical nodes, and the power lines are abstracted as power edges, so as to construct the power network diagram of the power Internet of Things;
[0015] The secondary devices in the power Internet of Things are abstracted as information nodes, and the communication lines are abstracted as information edges, so as to construct the information network diagram of the power Internet of Things;
[0016] According to the interdependence between the information nodes and the physical nodes, the interdependence between the information network graph and the power network graph is established.
[0017] Optionally, the preset attack success probability is obtained by the following formula:
[0018]
[0019] wherein, is the preset attack success probability of the node u, is the total number of vulnerabilities of the node u, is the exploitability probability of the vulnerability i , is the probability that the attacker can successfully exploit the vulnerability under the condition of knowing the principle of the vulnerability i ; i
[0020] = AV i *w1+ AC i *w2+ AU i *w3+ RL i *w4+ EX i *w5
[0021]
[0022]
[0023] wherein, AV i , AC i and AU i are the index values of the access vector, the complexity and the authentication times of the base attribute group in the CVSS of the vulnerability i , RL i is the index value of the patch repair degree of the temporal attribute group in the CVSS of the vulnerability i ; EX i is the time exposure degree of the vulnerability i ; w1, w2, w3, w4 and w5 are weight coefficients; α and β are the parameters of the Pareto distribution, t i is the publication duration of the vulnerability i ; k∈[0,1] is the knowledge degree of the attacker mastering the vulnerability i , M i is the attack times against the vulnerability i .
[0024] Optionally, updating the state values of each node in the information network graph according to the information side graph calculation method includes:
[0025] Get the state values of all nodes connected to the current node by its incoming edges, and obtain the state value of each incoming edge node;
[0026] When at least one of the state values of each incoming edge node is not 0, the state value of the current node is updated using the following formula:
[0027] , V
[0028] in, For nodes in the information network diagram u The state value; This represents the preset attack success probability for node u. For nodes in the information network diagram The state value; V For nodes u The set of all nodes connected by incoming edges;
[0029] Activate all nodes connected to the outgoing edges of the current node to obtain information about the activated nodes;
[0030] When the state value of each incoming edge node is 0, activate all outgoing edge nodes connected to the current node to obtain the information of the activated node.
[0031] Repeat the above steps with each activated information node as the current node until all nodes in the information network graph have been traversed.
[0032] Optionally, determining the attack success probability of each node in the power grid diagram based on the state values of each node in the updated information network diagram and through inter-network dependencies includes:
[0033] The probability of a successful attack on each node in the power grid diagram is determined by the following formula:
[0034] P v = vector u * E P-C ( u , v )
[0035] in, P v Nodes in the power network diagram v The probability of a successful attack. vector u For nodes in the information network diagram u The state value, E P-C ( u ,v ) is an interdependence value, E P-C ( u , v )=1 indicates that the normal operation of the node v in the power grid diagram depends on the support of the node u in the information network diagram, E P-C ( u , v )=0 indicates that the normal operation of the node v in the power grid diagram does not depend on the support of the node u in the information network diagram.
[0036] Optionally, the state value of each node in the power grid diagram is determined by the physical side diagram calculation method, comprising:
[0037] obtaining the node type of the current node;
[0038] when the node type of the current node is a load node, obtaining the attack success probability of all nodes connected by the incoming edges of the current node, and updating the state value of each node in the power grid diagram to the load loss value considering the user level factor, the switch out-of-control probability of the feeder and the load importance;
[0039] activating all nodes connected by the outgoing edges of the current node to obtain each power activated node;
[0040] when the node type of the current node is not a load node, activating all nodes connected by the outgoing edges of the current node to obtain each power activated node;
[0041] repeating the above steps for each power activated node as the current node until all nodes in the power grid diagram are traversed.
[0042] Optionally, the power Internet of Things security risk assessment value is obtained according to the state value of each node in the power grid diagram, comprising:
[0043] the power Internet of Things security risk assessment value is obtained by the following formula:
[0044]
[0045] wherein, is the power Internet of Things security risk assessment value, is the state value of the node v in the power grid diagram, is the node set of the node type load node in the power grid diagram.
[0046] In the second aspect of the present application, a power Internet of Things security risk assessment system comprises:
[0047] A graph establishment module is configured to establish an information network graph, a power network graph and inter-network dependency relationship of the power Internet of Things based on a dependency network theory.
[0048] An information side updating module is configured to obtain an attacked node in the information network graph and assign a state value of the attacked node as a preset attack success probability, and then update state values of all nodes in the information network graph according to an information side graph calculation method.
[0049] A conversion module is configured to determine attack success probabilities of all nodes in the power network graph through the inter-network dependency relationship according to the state values of all nodes in the updated information network graph.
[0050] A physical side updating module is configured to determine state values of all nodes in the power network graph through a physical side graph calculation method according to the attack success probabilities of all nodes in the power network graph.
[0051] A risk assessment module is configured to obtain a power Internet of Things security risk assessment value according to the state values of all nodes in the power network graph.
[0052] In a third aspect of the present application, a computer device includes a memory, a processor and a computer program stored in the memory and executable on the processor, and the processor implements the steps of the power Internet of Things security risk assessment method when executing the computer program.
[0053] In a fourth aspect of the present application, a computer readable storage medium stores a computer program, and the computer program implements the steps of the power Internet of Things security risk assessment method when executed by a processor.
[0054] Compared with the prior art, the present application has the following beneficial effects:
[0055] The power Internet of Things security risk assessment method has the natural graph structure of the information side and the physical side data in the power Internet of Things, the information network graph, the power network graph and the inter-network dependence relationship are constructed based on the dependence network theory, the different connection relationships of the physical side and the information side device nodes can be reflected, the network topology structure can be directly reflected, the security risk of the power Internet of Things with different topologies can be evaluated, and the application scene of the technology is widened. Meanwhile, the concept of graph calculation is adopted, the calculation solving process is decomposed into super steps in the graph calculation through the information side graph calculation method and the physical side graph calculation method, parallel calculation can be realized by using the graph calculation engine, and the calculation efficiency of the risk assessment is improved. In addition, based on the dependence network theory, the mutual influence of the information side and the physical side is integrated into the evaluation method, the network attack propagation in the information side is considered, and the influence of the information side on the physical side is also considered, so that the accuracy and comprehensiveness of the safety evaluation are greatly improved compared with the traditional method, the potential risk value of the device is identified, the safety protection measures are provided for the device, the safety of the whole network is improved, and the guidance for designing or improving the topology of the power Internet of Things is provided. BRIEF DESCRIPTION OF DRAWINGS
[0056] Figure 1 The power Internet of Things security risk assessment method flow chart of the application;
[0057] Figure 2 The heterogeneous graph model schematic diagram of the power Internet of Things of the application;
[0058] Figure 3 The information side graph calculation method flow chart of the application;
[0059] Figure 4 The feeder network topology graph of the application;
[0060] Figure 5 The physical side graph calculation method flow chart of the application;
[0061] Figure 6 The power Internet of Things security risk assessment system structure block diagram of the application. DETAILED DESCRIPTION
[0062] In order to make the personnel in the technical field better understand the application scheme, the technical solutions in the embodiments of the application will be described clearly and completely in combination with the drawings in the embodiments of the application. Obviously, the described embodiments are only a part of the embodiments of the application, not all the embodiments. Based on the embodiments in the application, all other embodiments obtained by the person skilled in the art without creative labor should belong to the protection scope of the application.
[0063] It is to be understood that the terms "first", "second", and the like used in the description and the claims of the present application as well as the above-described drawings do not necessarily have to connote any ordinal, sequential or priority relationship. It is to be understood that the terms "comprises", "comprising", "includes", "including" and the like are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises, includes, or consists of a list of steps or elements does not necessarily comprise, include, or consist only of those steps or elements specifically identified. It is to be understood that such an embodiment shown in any drawing / figure / illustration is intended to encompass all changes and modifications that can be suggested by the disclosure, and further includes any additional steps or elements that can be inherent to the process, method, article, or apparatus shown.
[0064] The application will be further described in details below with reference to the accompanying drawings:
[0065] As introduced in the background, currently, whether the risk of the power information physical fusion information side is artificially evaluated by the analytic hierarchy process or the influencing factors of the power information physical fusion are evaluated by analyzing the historical operation data of the power information physical fusion through machine learning technology, the purpose is to statically evaluate the security risk of the information side to further prevent, and the influence of the attack on the physical side after the information side of the power information physical fusion is attacked is not considered. In addition, the power information physical fusion security analysis method based on the analytic hierarchy process does not consider the connection relationship and topological structure of various sensing devices in the power information physical fusion, and the influence of the security risk that may be generated on the information side and the physical side of the power information physical fusion.
[0066] As Chinese patent application CN111695754A, a power internet of things security risk assessment method and device are provided, a genetic expression programming algorithm is adopted to calculate the weight of each evaluation index in the pre-constructed risk assessment index system; a comprehensive evaluation matrix is determined based on the membership degree of each evaluation index to each risk level; the power internet of things security risk is evaluated based on the weight and the comprehensive evaluation matrix, the evaluation process is simplified, the weight is calculated by using the genetic expression programming algorithm, the determination of the weight is objective and accurate, the power internet of things information security risk is evaluated based on the weight and the comprehensive evaluation matrix, the relationship between each evaluation index in the risk assessment index system is considered, the accuracy of the evaluation result is greatly improved; considering that the number of factors affecting the stable operation of the power internet of things is large and the factors have strong connection with each other and the non-additivity between the factors, the reliability and stability of the stable operation of the power internet of things are improved.
[0067] However, the risk assessment method of the technical solution has the following limitations: 1. Only the security risks of the information side of the power Internet of Things are evaluated, and the damage that the information side of the power Internet of Things may suffer from attacks on the power physical network is not considered, so the prior art is not comprehensive enough in evaluating security risks. 2. Only the security risks of the power Internet of Things are evaluated by the risk assessment index system, which has more subjective factors, and the influence of the topology connection structure of the information side and the physical side of the power Internet of Things on the security risks of the power Internet of Things is not considered.
[0068] However, the inventors have found in practical work that in order to solve the problem of analyzing and processing massive graph data, graph computing technology has emerged. Graph computing is based on graph theory and directly computes on graph structure data. Graph computing has a node-centered logical framework and computing mode, and compared with traditional matrix computing, graph computing provides a distributed feature for the problem solving process, so it has better adaptability to large-scale graph data. In addition, graph computing is more convenient for the application of sparse technology, which is conducive to improving the computing efficiency. Therefore, the graph data model can provide an effective technical route for solving the above problems. The power system is a natural graph structure, and many data also have the characteristics of a graph. At the same time, the complex correlation between the information side and the physical side in the power information-physical fusion is more suitable for intuitive expression in the form of a graph.
[0069] Based on this, in order to improve the above problems, the embodiment of the application provides a power Internet of Things security risk assessment method, which comprises the following steps: based on the interdependent network theory, establishing an information network graph, a power network graph and an inter-network dependence relationship of the power Internet of Things; obtaining an attacked node in the information network graph and assigning a state value of the attacked node to a preset attack success probability, then updating the state values of the nodes in the information network graph according to an information side graph calculation method; determining the attack success probability of each node in the power network graph through the inter-network dependence relationship according to the state values of the nodes in the updated information network graph; determining the state values of the nodes in the power network graph through a physical side graph calculation method according to the attack success probability of each node in the power network graph; and obtaining a power Internet of Things security risk assessment value according to the state values of the nodes in the power network graph. The security assessment accuracy and comprehensiveness are greatly improved, which provides guidance for designing or improving the topology of the power Internet of Things. The above scheme will be described in detail below.
[0070] Firstly, the related terms involved in the embodiment of the application are introduced:
[0071] Power CPS: cyber-physical system (CPS), the power CPS system can be divided into three layers: decision control layer, communication layer, and perception execution layer.
[0072] Power IOT: Power IOT refers to collecting information such as temperature, voltage, current and other information required by power system through various information sensors in power system, and realizing intelligent perception, identification and management of equipment in power system through various possible network access. Power IOT can be understood as the communication layer and perception execution layer of power CPS system.
[0073] Heterogeneous graph: the number of categories of nodes and edges on a graph is not one. The sum of the number of categories is greater than 2, which can be called a heterogeneous graph. A classic example is citation data: papers, authors, and conference publications are all nodes in the graph.
[0074] Power SCADA: SCADA (Supervisory Control And Data Acquisition) system, that is, data acquisition and monitoring control system. Remote communication technology is applied to monitor and control remote equipment to realize remote signal, remote measurement, remote control and remote adjustment and other functions. It is mainly composed of field terminal equipment, communication system and central monitoring system.
[0075] FTU: FTU (Feeder Terminal Unit) is a switch monitoring device installed beside the feeder switch. These feeder switches refer to outdoor pole-mounted switches, such as circuit breakers, load switches and sectional switches on 10kV lines. Generally speaking, 1 FTU is required to monitor 1 pole-mounted switch, the main reason is that pole-mounted switches are mostly installed in scattered manner.
[0076] RTU: Remote Terminal Unit (RTU), a special computer measurement and control unit with modular structure designed for long communication distance and harsh industrial site environment, which connects the end detection instrument and execution mechanism with the main computer of remote control center, has remote data acquisition, control and communication functions, can receive operation instructions of main computer and control action of end execution mechanism.
[0077] The application will be further described in detail below in combination with the drawings:
[0078] Referring to Figure 1 In an embodiment of the present application, a power IOT security risk assessment method is provided, which effectively improves the accuracy and comprehensiveness of power IOT security assessment. Specifically, the power IOT security risk assessment method comprises the following steps:
[0079] S1: Based on the dependence network theory, the information network graph, power network graph and inter-network dependence relationship of power IOT are established.
[0080] S2: Obtain the attacked node in the information network graph and assign a state value to the node as a preset attack success probability, and then update the state value of each node in the information network graph according to the information side graph calculation method.
[0081] S3: According to the state value of each node in the updated information network graph, the attack success probability of each node in the power network graph is determined through the inter-network dependence relationship.
[0082] S4: According to the attack success probability of each node in the power network graph, the state value of each node in the power network graph is determined through the physical side graph calculation method.
[0083] S5: According to the state value of each node in the power network graph, the power Internet of Things security risk assessment value is obtained.
[0084] The power Internet of Things security risk assessment method of the application, when modeling the power Internet of Things, a heterogeneous graph model based on the dependence network theory is constructed for the power Internet of Things, that is, an information network graph, a power network graph and an inter-network dependence relationship. Since the data on the information side and the physical side of the power Internet of Things has a natural graph structure, this modeling method can not only reflect the differences in the connection relationship between the physical side and the information side device nodes, but also intuitively reflect the network topology, so that the method can assess the security risk of the power Internet of Things with different topologies, and broaden the application scenarios of the technology. At the same time, the concept of graph calculation is adopted, and according to the information side graph calculation method and the physical side graph calculation method, the calculation solving process is decomposed into super steps in graph calculation, and parallel calculation can be realized by using a graph calculation engine, thereby improving the calculation efficiency of risk assessment. In addition, based on the dependence network theory, the mutual influence between the information side and the physical side is integrated into the assessment method, which not only considers the propagation of network attacks on the information side, but also considers the influence of the information side on the physical side, so that the method has greater improvement in the accuracy and comprehensiveness of security assessment compared with traditional methods, and can help operation personnel to identify devices with high potential risk value, so as to provide targeted security protection measures for the devices and improve the security of the entire network. It can also provide guidance for the design or improvement of the topology of the power Internet of Things.
[0085] In one possible implementation, the establishment of the information network graph, the power network graph and the inter-network dependence relationship of the power Internet of Things based on the dependence network theory comprises: abstracting the physical devices in the primary system of the power Internet of Things as physical nodes and the power lines as power edges to construct the power network graph of the power Internet of Things; abstracting the secondary devices in the power Internet of Things as information nodes and the communication lines as information edges to construct the information network graph of the power Internet of Things; and establishing the inter-network dependence relationship between the information network graph and the power network graph according to the mutual dependence relationship between the information nodes and the physical nodes.
[0086] Specifically, according to the complex network theory, a heterogeneous graph model is established for the single-sided physical network and information network in the power internet of things. The power source, transformer and load in the power grid system are abstracted as physical nodes, and the power line is abstracted as an edge. In order to ensure the normal operation of the physical node, the real-time state information of the physical node needs to be collected, monitored and controlled, therefore, the related secondary equipment such as FTU is usually equipped in the vicinity of the physical node, so that the physical node can accept the control command issued by the control master station. The secondary equipment related to the physical node is abstracted as an information node, and the communication line is abstracted as an edge. The informatization function of the secondary equipment is realized by the node, and the information node corresponding to each physical node has at most one. The power grid graph G p and the information network graph G c are constructed, G=(V, E), V is the node set of the network, E is the edge set of the network, G is the power grid graph G p or the information network graph G c .
[0087] According to the interdependence relationship between the information node and the physical node, the interdependence relationship set E is established, E={E C-P , E P-C}. Wherein, E C-P ( v , u ) and E P-C ( u , v ) are the interdependence relationship values, E C-P ( v , u )=1 indicates that the normal operation of the node u in the information network graph depends on the support of the node v in the power grid graph, E C-P ( v , u )=0 indicates that the normal operation of the node u in the information network graph does not depend on the support of the node v in the power grid graph; E P-C ( u , v )=1 indicates that the normal operation of the node v in the power grid graph depends on the support of the node u in the information network graph, E P-C ( u , v )=0 indicates that the normal operation of the node v in the power grid graph does not depend on the support of the node u in the information network graph.
[0088] Referring to Figure 2The heterogeneous graph model of the power Internet of Things can be expressed as a model composed of an information network graph, a power network graph, and inter-network dependency relationships. The node types of the model include different physical device nodes and information nodes, and the edge types include backbone communication lines, access communication lines, power lines, and dependency relationship edges. Different node types can be distinguished by a node attribute, and different edge types can be distinguished by an edge attribute.
[0089] In a possible implementation, when an attacked node in the information network graph is obtained and the state value of the attacked node is assigned as a preset attack success probability, the preset attack success probability is obtained by the following formula:
[0090]
[0091] wherein, is the preset attack success probability of the node u, is the total number of vulnerabilities of the node u, is the exploitability probability of the vulnerability, representing the difficulty of successfully exploiting the vulnerability itself, and the exploitability probability of the vulnerability is evaluated with reference to the Common Vulnerability Scoring System (CVSS), i is the probability that the attacker can successfully exploit the vulnerability under the condition of knowing the principle of the vulnerability i ; wherein, i
[0092] AV i *w1 + AC i *w2 + AU i *w3 + RL i *w4 + AV EX i *w5
[0093]
[0094]
[0095] wherein, AV i , AC i , and AU i are respectively the access vector, the complexity, and the authentication number of the base attribute group of the CVSS of the vulnerability i , RL i is the patch repair degree of the temporal attribute group of the CVSS of the vulnerability i , EX i is the time exposure degree of the vulnerability i , and represents the dynamic scoring value of the vulnerability in the time dimension; w1, w2, w3, w4, and w5 are weight coefficients.α and β is a parameter of the Pareto distribution, t i is the release duration of the vulnerability i ; k ∈ [0, 1] is the degree of knowledge of the attacker about the vulnerability i . M i is the number of attacks on the vulnerability i .
[0096] Specifically, in the power Internet of Things, the power network and the information network have a deep coupling. In the entire network, various types of monitoring terminals, such as FTU and RTU, have an important influence on the cross-space propagation of risks. On the one hand, these terminal devices collect the data and state of power equipment / users, connect with other information nodes through communication lines, and transmit information to other information nodes or control centers for decision-making; on the other hand, they accept the commands of the control center and perform operations on the power equipment. For the power Internet of Things, if the nodes of the information space are attacked and successfully infected, it will also have an impact on the normal operation of the power side primary equipment, resulting in certain consequences. For example, if the RTU on the feeder circuit breaker is attacked, the circuit breaker will malfunction, and the load on the feeder will be lost. From the perspective of network attack threats faced by the power Internet of Things, the power generation system and the power transmission system have the characteristics of closed-loop operation, there are few access points that can be used for attacks in the system, the backbone communication network mostly uses optical fiber transmission network, and the robustness and self-healing ability are strong, the reliability is high, and the intelligent terminals widely distributed in the power distribution network SCADA system often lack physical isolation protection, have limited processing capacity, and communicate through access to communication networks, so they become the target of attackers. Attackers use this as a stepping stone to gradually penetrate other secondary devices connected to the power grid, expand the scope of the attack, and ultimately successfully attack the physical side primary equipment.
[0097] Therefore, the main impact of network attacks on the power Internet of Things is that the information side is attacked, leading to a chain reaction on the physical side. This contains two aspects of content: 1. The impact of network attacks on the information side: attackers invade intelligent terminal devices that lack effective protection, continue to attack other information devices by accessing communication networks, make the network attack spread in the information network, and expand the range of affected devices. 2. The loss of the physical side: power primary equipment is often controlled by its dependent secondary equipment, and after the secondary equipment is attacked by network attacks, power primary equipment such as circuit breakers, switches and loads will face the risk of misoperation. The present application takes the load loss of the power side as a parameter of the security risk assessment value.
[0098] For the vulnerability attack success probability calculation of secondary equipment, firstly, the attack target selection probability, FTU, RTU and DTU (data transmission unit) terminals are often selected as the attack entrance of network attackers, but due to the different geographical environment and different functions, the physical protection measures are also different. When the equipment is "three remote" and "two remote" equipment, the selection probability is 0.3 and 0.7. When the equipment is DTU, RTU and FTU, the selection probability is 0.2, 0.3 and 0.5. Finally, the probability of the terminal being selected as the attack target is obtained. .
[0099] Secondly, the success probability of the attack target is: .
[0100] In a possible implementation, the method for calculating the state value of each node in the information network graph according to the information side graph includes: obtaining the state values of all nodes connected by the incoming edges of the current node to obtain the state values of each incoming edge node; when at least one of the state values of each incoming edge node is not 0, the state value of the current node is updated by the following formula: , V ; wherein, is the state value of the node u in the information network graph; is the state value of the node in the information network graph; V is the set of all nodes connected by the incoming edges of the node u ; all nodes connected by the outgoing edges of the current node are activated to obtain each information activated node; when the state values of each incoming edge node are all 0, all nodes connected by the outgoing edges of the current node are activated to obtain each information activated node; finally, each information activated node is repeated as the current node to repeat the above steps until each node in the information network graph is traversed.
[0101] Specifically, the node update function of the shortest path algorithm of the graph model calculates the minimum distance between the current node and the source node according to the edge weight of the incoming edge and the value of the node, and updates the node value if the calculated minimum distance is less than the saved value of the node. Through continuous iteration until the node is no longer updated, the shortest distance from the source node to the target node is finally obtained. On the basis of the algorithm idea, the calculation method of the attack probability of each node in the network attack is realized by changing the calculation method of the node update function, that is, the information side graph calculation method.
[0102] Referring to Figure 3 , the specific steps of the information side graph calculation method include:
[0103] a, determine the attacked nodes in the information network, allow to attack multiple nodes simultaneously. Set the state value to the probability of attack success, and set the state value of other nodes to 0.
[0104] b, collect the nodes u The state values of all nodes connected by the incoming edges form a set V.
[0105] c, if the state values of all nodes connected by the incoming edges collected are 0, it indicates that the current node has not reached the attacked node, then activate the nodes connected by the outgoing edges to perform step b; otherwise, perform step d.
[0106] d, after the state values of all nodes connected by the incoming edges collected are calculated by the node update function, update the state value of the node to the calculation result, and activate the nodes connected by the outgoing edges to participate in the next round of calculation. The specific calculation formula of the node update function is:
[0107] , V
[0108] wherein, is the state value of the node, and the probability of the network attack propagating from the initial attacked device to the device is sequentially indicated.
[0109] e, determine whether all nodes no longer update, if not, perform step b.
[0110] Wherein, step d can be regarded as a super step in graph calculation, and each node performs its own calculation task in parallel in a super step. This parallel mechanism effectively utilizes the computing resources of the computer and improves the calculation efficiency.
[0111] In a possible implementation, the attack success probability of each node in the power grid graph is determined according to the state value of each node in the updated information network graph and the inter-network dependency relationship, comprising:
[0112] The attack success probability of each node in the power grid graph is determined by the following formula:
[0113] P v = vector u * E P-C ( u , v )
[0114] wherein, P v is the attack success probability of the node v in the power grid graph, vector u is the attack success probability of the node uE (E, E) is a state value of E P-C u v E (E, E) is a network interdependence value P-C u v E (E, E) = 1 indicates that the normal operation of the node E v in the power grid diagram depends on the support of the node E u in the information network diagram, and E P-C u v E (E, E) = 0 indicates that the normal operation of the node E v in the power grid diagram does not depend on the support of the node E u in the information network diagram.
[0115] Specifically, the graph computing process of the information network characterizes the propagation and penetration of the network attack in the information side network with the initial attack node as the starting point. The value of each node after the graph computing process stops represents the probability that the node is successfully attacked in the network attack risk propagation process. Then, according to the dependence relationship, the attack success probability of all circuit breaker devices in the power grid is updated to the attack success probability of the dependent information node, which represents the loss of control probability of the power node under network attack.
[0116] In one possible implementation, the state value of each node in the power grid diagram is determined by the physical side graph computing method, including: obtaining the node type of the current node; when the node type of the current node is a load node, obtaining the attack success probability of all nodes connected by the incoming edges of the current node, and updating the state value of each node in the power grid diagram to a load loss value considering the user level factor, the switch loss probability of the feeder and the importance of the load; activating all nodes connected by the outgoing edges of the current node to obtain each power activated node; when the node type of the current node is not a load node, activating all nodes connected by the outgoing edges of the current node to obtain each power activated node; repeating the above steps with each power activated node as the current node until all nodes in the power grid diagram are traversed.
[0117] Specifically, referring to Figure 4 , a feeder network topology is shown to analyze the influence of network attack on the power side. In the figure, CB, L, F, S and T represent circuit breakers, loads, FRTUs, sectionalizing switches and tie switches, and the numbers are the numbers of the devices. When the power side is normally operated, due to the attack on the FTU and other devices dependent on the power nodes, the attacker causes the misoperation of the circuit breakers, switches and other devices through false message injection and other methods, causing the load to be powered off and causing losses. When the information integrity of the FTU is destroyed due to network attack, the influence on the power side can be represented by the following formula:
[0118]
[0119] wherein, for Load loss caused by the breach of information integrity is used to characterize the impact on the power side; Indicates feeder h On the node i The FTU on which it depends; This indicates the importance of the load, and its value is determined based on the comprehensive impact of the load on personal safety and property safety. Represents a node i The load capacity; Indicates the node i If the controlled load quantity, such as the control information of F4, is tampered with by an attacker, it causes the sectionalizing switch S4 to trip erroneously, ultimately leading to the power outage of load L5; and if an attack on F0 causes circuit breaker CB1 to open, the entire feeder... h All loads on the line were de-energized.
[0120] See Figure 5 The specific steps of the physical side diagram calculation method include:
[0121] 1. Determine if the current node is a load node. If so, proceed to step 2; otherwise, activate all nodes connected to the outgoing edges of the current node and proceed to step 1.
[0122] 2. Collect the success probability of a switch attack from the attributes of all nodes connected to the current node by its incoming edges. P j The probability of a successful attack on a feeder circuit breaker P CB .
[0123] 3. After processing the collected values, update the current node and activate all nodes connected to its outgoing edges to participate in the next round of calculation. The specific operations performed when updating a node are as follows:
[0124] Update the set of attack success probabilities for all nodes connected by the current node's incoming edges. P : P = P +{ P j , P CB}
[0125] Update the current node state value This represents the potential power outage load of the current node, taking into account the user level factor.
[0126] 4. Determine if all nodes are no longer being updated; otherwise, proceed to step 1.
[0127] Similar to step d, step 3 can also be regarded as a super-step of graph computation, in which each node performs its own computation task in parallel, thereby effectively utilizing the computer's computing resources and improving the computing efficiency.
[0128] In the process of node iteration, the feeder breaker attack success probability P CB The switch attack success probability is passed in the edges of the entire feeder network P j Then it is passed in the edges between the load nodes that can be affected. The set of attack success probabilities of the nodes connected by all incoming edges of the current node of the load node P The switch attack success probability P j The feeder breaker attack success probability P CB .
[0129] After the power grid graph computation process is completed, the node value of the load node is updated to the load loss value considering the switch out-of-control probability of the feeder where the load node is located and the importance of the load. At this time, the load loss on a feeder can be calculated by the following formula:
[0130]
[0131] Wherein, N h is the set of load nodes on the feeder h , and is the state value of the node v .
[0132] In one possible implementation, the power Internet of Things security risk assessment value is obtained according to the state values of the nodes in the power grid graph, including: the power Internet of Things security risk assessment value is obtained by the following formula:
[0133]
[0134] Wherein, is the power Internet of Things security risk assessment value, is the state value of the node v in the power grid graph, is the set of nodes whose type is load node in the power grid graph.
[0135] Specifically, the risk value represents the load loss on the power side that may be caused when the information side devices are attacked by attackers, and the risk value can be used to sort the importance of the secondary devices on the information side.
[0136] In summary, the power internet of things contains a large number of intelligent terminal devices, many of which are the same or similar devices, and providing perfect protection for each device will consume a large amount of cost. The present application considers that similar devices may cause different potential impacts due to different positions in the power internet of things topology, designs a method for calculating the network attack risk of causing load loss in the power internet of things based on the shortest path algorithm of a graph, and proposes a risk quantification evaluation method. The method evaluates the potential impact of the secondary devices on the information side, which can help the operation personnel identify the devices with high potential risk value in the network, so as to provide targeted security protection measures for the devices and improve the security of the entire network. Further, the method can also provide guidance for designing or improving the topology of the power internet of things.
[0137] The following is an apparatus embodiment of the present application, which can be used to execute the method embodiment of the present application. For details not disclosed in the apparatus embodiment, please refer to the method embodiment of the present application.
[0138] Referring to Figure 6 In still another embodiment of the present application, a power internet of things security risk evaluation system is provided, which can be used to implement the power internet of things security risk evaluation method described above. Specifically, the power internet of things security risk evaluation system comprises a graph establishing module, an information side updating module, a conversion module, a physical side updating module and a risk evaluation module. The graph establishing module is used to establish the information network graph, the power network graph and the inter-network dependence relationship of the power internet of things based on the dependence network theory. The information side updating module is used to obtain the attacked nodes in the information network graph and assign their state values as preset attack success probabilities, and then update the state values of each node in the information network graph according to the information side graph calculation method. The conversion module is used to determine the attack success probability of each node in the power network graph through the inter-network dependence relationship according to the state values of each node in the updated information network graph. The physical side updating module is used to determine the state values of each node in the power network graph through the physical side graph calculation method according to the attack success probability of each node in the power network graph. The risk evaluation module is used to obtain the power internet of things security risk evaluation value according to the state values of each node in the power network graph.
[0139] In a possible implementation, the establishing of the information network graph, the power network graph and the inter-network dependence relationship of the power internet of things based on the dependence network theory comprises: abstracting the physical devices in the primary system of the power internet of things as physical nodes and the power lines as power edges to construct the power network graph of the power internet of things; abstracting the secondary devices in the power internet of things as information nodes and the communication lines as information edges to construct the information network graph of the power internet of things; and establishing the inter-network dependence relationship between the information network graph and the power network graph according to the mutual dependence relationship between the information nodes and the physical nodes.
[0140] In a possible implementation, the preset attack success probability is obtained by the following formula:
[0141]
[0142] = AV i * w1 + AC i * w2 + AU i * w3 + RL i * w4 + RL EX i * w5
[0143]
[0144] .
[0145] In a possible implementation, the method for calculating the state value of each node in the information network graph according to the information side graph comprises the following steps: obtaining the state values of all nodes connected to the incoming edges of the current node to obtain the state values of the incoming edge nodes; when at least one of the state values of the incoming edge nodes is not 0, updating the state value of the current node by the following formula: , V ; activating all nodes connected to the outgoing edges of the current node to obtain the information activated nodes; when the state values of all the incoming edge nodes are 0, activating all nodes connected to the outgoing edges of the current node to obtain the information activated nodes; repeating the above steps with each information activated node as the current node until all nodes in the information network graph are traversed.
[0146] In a possible implementation, the method for determining the attack success probability of each node in the power network graph according to the state values of all nodes in the updated information network graph and the inter-network dependency relationship comprises the following formula: P v = vector u * E P-C ( u , v ).
[0147] In a possible implementation, the method for determining the state value of each node in the power grid diagram by the physical side diagram calculation method comprises: obtaining the node type of a current node; when the node type of the current node is a load node, obtaining the attack success probability of all nodes connected to the incoming edges of the current node, and updating the state value of each node in the power grid diagram to a load loss value considering the user level factor, the switch out-of-control probability of the feeder where the load is located, and the importance of the load; activating all nodes connected to the outgoing edges of the current node to obtain each power activated node; when the node type of the current node is not a load node, activating all nodes connected to the outgoing edges of the current node to obtain each power activated node; repeating the above steps with each power activated node as the current node until all nodes in the power grid diagram are traversed.
[0148] In a possible implementation, the method for obtaining the power Internet of Things security risk assessment value according to the state value of each node in the power grid diagram comprises: obtaining the power Internet of Things security risk assessment value by the following formula:
[0149] .
[0150] The foregoing embodiments of the power Internet of Things security risk assessment method involve all related contents of each step, which can be cited as the function description of the function modules corresponding to the power Internet of Things security risk assessment system in the embodiments of the present application, and will not be repeated here. The division of the modules in the embodiments of the present application is illustrative, and is only a logical function division. In actual implementation, another division mode can be used. In addition, each function module in each embodiment of the present application can be integrated in one processor, or can be physically separated, or two or more modules can be integrated in one module. The integrated module can be realized in the form of hardware or in the form of a software function module.
[0151] In another embodiment of the present application, a computer device is provided, which comprises a processor and a memory, the memory is configured to store a computer program, the computer program comprises program instructions, and the processor is configured to execute the program instructions stored in the computer storage medium. The processor can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc., which are the computing core and control core of the terminal, and are suitable for implementing one or more instructions, and are particularly suitable for loading and executing one or more instructions in the computer storage medium to implement a corresponding method process or a corresponding function; the processor in the embodiment of the present application can be used for the operation of the power internet of things security risk assessment method.
[0152] In another embodiment of the present application, the present application further provides a storage medium, specifically a computer readable storage medium (Memory), which is a memory device in a computer device, and is configured to store programs and data. It can be understood that the computer readable storage medium herein can include an internal storage medium in the computer device, and of course can also include an expansion storage medium supported by the computer device. The computer readable storage medium provides a storage space, and the storage space stores an operating system of the terminal. In addition, one or more instructions suitable for being loaded and executed by the processor are also stored in the storage space, and the instructions can be one or more computer programs (including program codes). It should be noted that the computer readable storage medium herein can be a high-speed RAM memory, or a non-volatile memory such as at least one disk memory. One or more instructions stored in the computer readable storage medium can be loaded and executed by the processor to implement the corresponding steps of the power internet of things security risk assessment method in the above embodiments.
[0153] Those skilled in the art will appreciate that embodiments of the application can be devised for a method, a system, or a computer program product. Accordingly, the present application can be embodied in the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present application can take the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, etc.) embodying computer readable program code.
[0154] The present application is described in reference to the flowchart and / or block diagrams of the method, apparatus (system) and computer program product according to embodiments of the application. It will be understood that each block of the flowchart and / or block diagrams, and combinations of blocks in the flowchart and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processing device or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks.
[0155] These computer program instructions can also be stored in a computer- readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks.
[0156] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks.
[0157] Finally, it should be noted that the above-mentioned embodiments are merely intended for describing the technical solutions of the present application, but not for limiting it. Although the present application is described in detail with reference to the above embodiments, those skilled in the field should understand that the specific embodiments of the present application can be modified or replaced equivalently without departing from the spirit and scope of the present application, and any modification or equivalent replacement without departing from the spirit and scope of the present application should be covered in the protection scope of the claims of the present application.
Claims
1. A method for assessing security risks in the power Internet of Things, characterized in that, include: Based on interdependent network theory, an information network diagram, a power network diagram, and inter-network dependencies for the power Internet of Things (IoT) are established. This includes: abstracting physical devices in the primary system of the power IoT as physical nodes and power lines as power edges to construct the power network diagram of the power IoT; abstracting secondary devices in the power IoT as information nodes and communication lines as information edges to construct the information network diagram of the power IoT; and establishing inter-network dependencies between the information network diagram and the power network diagram according to the interdependence between information nodes and physical nodes. The attacking node in the information network graph is obtained and its state value is assigned a preset attack success probability. Then, the state value of each node in the information network graph is updated according to the information side graph calculation method. This includes: obtaining the state values of all nodes connected to the current node by its incoming edges, and obtaining the state value of each incoming edge node. When at least one of the state values of each incoming edge node is not 0, the state value of the current node is updated using the following formula: , V in, For nodes in the information network diagram u The state value; This represents the preset attack success probability for node u. For nodes in the information network diagram The state value; V For nodes u The set of all nodes connected by incoming edges; Activate all nodes connected to the outgoing edges of the current node to obtain information about the activated nodes; When the state value of each incoming edge node is 0, activate all outgoing edge nodes connected to the current node to obtain the information of the activated node. Repeat the above steps, treating each activated information node as the current node, until all nodes in the information network graph have been traversed. Based on the status values of each node in the updated information network diagram, the probability of a successful attack on each node in the power network diagram is determined through inter-network dependencies. Based on the attack success probability of each node in the power grid diagram, the state value of each node in the power grid diagram is determined through the physical side diagram calculation method; including: obtaining the node type of the current node; When the current node is a load node, obtain the attack success probability of all nodes connected to the current node by its incoming edges, and update the state value of each node in the power grid diagram to a load loss value that takes into account the user level factor, the probability of switch failure of the feeder and the importance of the load. Activate all nodes connected to the outgoing edges of the current node to obtain the power activation nodes; When the current node's node type is not a load node, activate all nodes connected to the current node's outgoing edges to obtain each power activation node; Repeat the above steps with each power activation node as the current node until all nodes in the power network diagram have been traversed. Based on the state values of each node in the power grid diagram, the security risk assessment value of the power Internet of Things is obtained.
2. The power Internet of Things security risk assessment method according to claim 1, characterized in that, The preset attack success probability is obtained by the following formula: in, This represents the preset attack success probability for node u. Let u be the total number of vulnerabilities in node u. For vulnerabilities i The probability of availability, For attackers to know the vulnerability i Under the premise of principle, the vulnerability can be successfully exploited. i The probability of; =AV i w1+AC i w2+AU i w3+RL i w4+ EX i w5 Among them, AV i AC i and AU i To separate vulnerabilities i In CVSS, the metrics for the access vector, complexity, and authentication count in the base attribute group are assigned values. i For vulnerabilities i Assigning values to the patch fixation index of the temporal attribute group in CVSS; EX i For vulnerabilities i The degree of exposure over time; w1, w2, w3, w4, and w5 are weighting coefficients; α and β For Pareto distribution parameters, t i For vulnerabilities i The duration of the release; k∈[0,1] represents the vulnerability that the attacker has discovered. i The level of knowledge, M i In response to the vulnerability i The number of attacks.
3. The power Internet of Things security risk assessment method according to claim 1, characterized in that, The process of determining the probability of a successful attack on each node in the power grid diagram based on the state values of each node in the updated information network diagram and through inter-network dependencies includes: The probability of a successful attack on each node in the power grid diagram is determined by the following formula: P v = vector u E P-C ( u , v ) in, P v Nodes in the power network diagram v The probability of a successful attack. vector u For nodes in the information network diagram u The state value, E P-C ( u , v E represents the inter-network dependency value. P-C ( u , v )=1 indicates a node in the power network diagram. v Normal operation depends on nodes in the information network graph. u Support, E P-C ( u , v )=0 indicates a node in the power network diagram v Its normal operation does not depend on nodes in the information network graph. u Support.
4. The power Internet of Things security risk assessment method according to claim 1, characterized in that, The process of obtaining the power Internet of Things (IoT) security risk assessment value based on the state values of each node in the power network diagram includes: The security risk assessment value for the power Internet of Things is obtained using the following formula: in, This is a safety risk assessment value for the power Internet of Things. Nodes in the power network diagram v The state value, This is the set of nodes in the power network diagram whose node type is load node.
5. A power Internet of Things (IoT) security risk assessment system based on the power IoT security risk assessment method of claim 1, characterized in that, include: The graph building module is used to build information network graphs, power network graphs, and inter-network dependencies of the power Internet of Things based on the interdependent network theory. The information-side update module is used to obtain the attacked nodes in the information network diagram and assign their status values to the preset attack success probability. Then, according to the information-side diagram calculation method, the status values of each node in the information network diagram are updated. The conversion module is used to determine the probability of a successful attack on each node in the power grid diagram based on the status values of each node in the updated information network diagram and through inter-network dependencies. The physical side update module is used to determine the state value of each node in the power grid diagram based on the attack success probability of each node in the power grid diagram and through the physical side diagram calculation method. The risk assessment module is used to obtain the security risk assessment value of the power Internet of Things based on the status values of each node in the power network diagram.
6. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the power Internet of Things security risk assessment method as described in any one of claims 1 to 4.
7. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the power Internet of Things security risk assessment method as described in any one of claims 1 to 4.
Citation Information
Patent Citations
Electric power Internet-of-things information security risk assessment method and device
CN111695754A