A defense method against dynamic cyber attacks on power systems

By constructing static and dynamic network attack and defense models for power systems, identifying critical substations and their components, and formulating priority protection strategies, the challenges of identifying and defending against coordinated attacks in power systems are solved, thereby improving the system's resistance to attacks and resilience.

CN115065499BActive Publication Date: 2026-03-24ELECTRIC POWER RES INST OF GUANGXI POWER GRID CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-04-15
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

Existing technologies are insufficient to effectively identify and defend against coordinated attacks in power systems, leading to uncontrollable system damage.

Method used

We employ game theory to construct static and dynamic network attack and defense models. By identifying critical substations and their components, we formulate prioritization and protection strategies to maximize or minimize system damage.

Benefits of technology

It improves the resilience and attack resistance of the power system, significantly reduces system damage, and is more efficient than exhaustive search.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115065499B_ABST
    Figure CN115065499B_ABST
Patent Text Reader

Abstract

The application provides a defense method against power system dynamic network attacks, comprising the following steps: constructing a static attack model, determining the key substations and their components to be attacked at different times, and maximizing the system damage; constructing a static defense model, determining the most critical substations for prioritization and protection, and minimizing the damage of the whole system; constructing a dynamic attack model, determining the key substations and their components to be attacked at different times, and maximizing the system damage; constructing a dynamic defense model, determining the most critical substations for prioritization and protection, and minimizing the damage of the whole system. The application can determine the key substations to be protected, so as to minimize the damage of the whole system. Under the budget constraint, the prioritization and protection of the intelligently selected substations can significantly improve the flexibility of the power system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power system network attack defense technology, and in particular to a defense method against dynamic network attacks on power systems. Background Technology

[0002] Power companies, power users, power generation companies, suppliers, and their respective equipment are widely interconnected, forming the Power Internet of Things (IoT). Information and communication technologies and security technologies play a crucial role in this, achieving a close integration of cyberspace and the physical power grid. Newly added social factors have also transformed the Power IoT from a single-function terminal to a comprehensive service terminal, significantly altering the physical form and operating mode of the power system. With the shift in business models where various services are provided through open platforms, the ubiquitous Power IoT faces more complex security threats. Analyzing the interaction mechanisms and security protection systems among various entities in the Power IoT is the primary task in ensuring its security. The Ubiquitous Electric Internet of Things (UEIOT) is a smart service system that fully utilizes modern information technologies such as mobile internet and artificial intelligence, as well as advanced communication technologies, to achieve ubiquitous connectivity and human-machine interaction across all aspects of the power system. It features comprehensive state perception, efficient information processing, and convenient and flexible applications. When the power system is subjected to disturbances or attacks, the ability to quickly and effectively develop defense strategies against various attacks is of paramount importance.

[0003] Currently, there is a lack of effective technical means to identify abnormal events caused by various coordinated attacks and to perform system optimization control. The widespread interconnection of numerous heterogeneous devices has drastically altered the physical form and operating mode of power systems. Attack methods have also evolved from simple network attacks to various coordinated attacks. Previous techniques for identifying single network attacks have gradually become ineffective, and various optimization control schemes are unable to operate effectively. To effectively address these issues, it is necessary not only to analyze the reliability of the power system topology but also to analyze the impact of dynamic network attacks. This will help reveal the inherent laws governing the operation of the power Internet of Things (IoT) and strengthen its security. Summary of the Invention

[0004] The purpose of this invention is to provide a defense method against dynamic network attacks on power systems, which can solve the problem that existing technologies for single network attacks cannot effectively identify coordinated attacks.

[0005] The objective of this invention is achieved through the following technical solution:

[0006] A defense method against dynamic network attacks on power systems includes the following steps:

[0007] Step S1: Construct a static attack model to identify the key substations and their components to be attacked at different times, maximizing system damage;

[0008] Step S2: Construct a static defense model to identify the most critical substations for priority and protection, minimizing damage to the entire system.

[0009] Step S3: Construct a dynamic attack model to identify the key substations and their components to be attacked at different times, maximizing system damage;

[0010] Step S4: Construct a dynamic defense model to identify the most critical substations for priority ranking and protection, and identify the key substations to be protected to minimize damage to the entire system.

[0011] Furthermore, step S1 includes:

[0012] Step S101: Based on the static attack model of the static power system network, find the worst-case static attack.

[0013] Step S102: Determine the algorithm for the worst-case static attack.

[0014] Furthermore, step S101 includes:

[0015] The attacker gained access to a subset of the substation. The attacker gained access to the substation budget B. s Launch an attack;

[0016] Given a power system network G P A protection component budget B P Find a worst-case static attack A P This maximizes damage within the power system network.

[0017]

[0018] B S ≤B P ;

[0019] Where S' and S" represent the substations selected for attack, P' represents the protection component of substation S', and P" represents the protection component of substation S".

[0020] Furthermore, step S2 includes:

[0021] Step S201: Confirm the formula of the defender model to improve the resilience of the power system by minimizing load loss;

[0022] Step S202: Determine the algorithm for the critical substations that need to be protected.

[0023] Furthermore, step S201 includes:

[0024] Given a power system network Gp and a defense budget B D A substation budget B s A protection component budget B p Find a defense strategy that minimizes system load loss, in the following form:

[0025]

[0026] |D S |≤B D ;

[0027]

[0028] B S ≤B P ;

[0029] Among them, D s This represents a subset of substations. S represents the set of substations; S' and S" represent the substations selected for attack; P' represents the protection component of substation S'; and P" represents the protection component of substation S".

[0030] Furthermore, step S3 includes:

[0031] Step S301: Develop a dynamic attack model and formulate a dynamic attack under the worst-case scenario;

[0032] Step S302: Determine the worst-case dynamic attack algorithm.

[0033] Furthermore, step S301 includes:

[0034] Given a power system network G p, a substation budget B s and a protection component budget B p Find a worst-case dynamic attack A p' (k) maximizes system damage, in form:

[0035]

[0036] B S ≤B P ;

[0037] Where x(k) represents the system state at time step k, H(k) represents the system's attack history, G(H(k)) represents the function that returns the system state given the attack history H(k), and g(H(k)) represents the function that returns the normal system state without an attack history; S'(k) and S'(k') represent the substations selected as targets for attack; and P'(k) represents the protection components operating within the selected substations.

[0038] Furthermore, step S4 includes:

[0039] Step S401: Construct a dynamic defense model;

[0040] Step S402: Determine the algorithm for the critical substations that need to be protected.

[0041] Furthermore, step S401 includes:

[0042] Given a power system network G p, a defense budget B D A substation budget B s A protection component budget B p Find a defense strategy that minimizes load loss when attackers launch dynamic attacks at different times:

[0043]

[0044] |D S |≤B D ;

[0045]

[0046] B S ≤B P ;

[0047] Where x(k) represents the state of the system at time step k, and k' represents any time step other than k; H(k) represents the attack history of the system; D s This represents a subset of substations. S represents the set of substations; S'(k) and S'(k') represent the substations selected as targets for attack, and P'(k) represents the protection components operating within the selected substations.

[0048] This invention presents a defense method against dynamic network attacks on power systems, employing game theory to describe both static and dynamic network attack and defense models. From the attacker's perspective, it provides an efficient and effective algorithm that strategically identifies dynamic attacks by considering both random and worst-case static attacks, thereby maximizing system disruption. From the defender's perspective, it provides an effective algorithm that identifies critical substations to protect, minimizing damage to the entire system. Results show that, under budget constraints, prioritizing and protecting intelligently selected substations can significantly improve the resilience of the power system. Furthermore, even with complex dynamic attack and defense models, the game theory algorithm is more efficient and significantly outperforms exhaustive search. Attached Figure Description

[0049] Figure 1 This is a flowchart of the defense method against dynamic network attacks on power systems according to the present invention;

[0050] Figure 2 The load loss due to static and dynamic attacks on the 39 nodes of the IEEE system;

[0051] Figure 3 Load loss for dynamic defense of the 39 nodes of the IEEE system;

[0052] Figure 4 A comparative chart showing the execution time of attacks and defenses on different standard IEEE systems. Detailed Implementation

[0053] The embodiments of this disclosure will now be described in detail with reference to the accompanying drawings.

[0054] The following specific examples illustrate the implementation of this disclosure. Those skilled in the art can easily understand other advantages and effects of this disclosure from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of this disclosure, and not all of them. This disclosure can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of this disclosure. It should be noted that, in the absence of conflict, the following embodiments and features in the embodiments can be combined with each other. Based on the embodiments in this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.

[0055] The present invention provides a defense method against dynamic network attacks on power systems, comprising the following steps:

[0056] Step S1: Construct a static attack model to identify the key substations and their components to be attacked at different times in order to maximize system damage.

[0057] Further, step S1 includes:

[0058] Step S101: Based on the static attack model of the static power system network, find the worst-case static attack.

[0059] The goal of a malicious attacker is to maximize load loss and disrupt power grid stability. To achieve this, the attacker first gains access to a subset of the substation. Access rights, where the attacker is resource-constrained, meaning the attacker can access most substations within budget B. s The attack is carried out. Now, the adversary can identify and manipulate the protection components to isolate the transmission line from the power grid belonging to the selected substation S'. The attacker is again limited by resources and can only attack the protection components up to budget B. P Please note that the budget for protection components may be advantageous to attackers in the following ways:

[0060] (1) An inexperienced attacker may choose a large business process point and may attack all the protection components in the damaged substation, while a strategic attacker may choose a small business process point because this will allow the attacker to remain undetected for a considerable period of time, which may provide the attacker with the opportunity to potentially cause more system damage.

[0061] (2) The rated power of the transmission line is capable of carrying maximum power and is isolated from the rest of the system in the event of a limit violation. This operation typically results in a cascading failure, leading to significant load losses. Manipulating all protection components in the substation to disconnect the power line reduces the load on the entire system. Therefore, this may not lead to a severe cascading failure resulting in higher load losses.

[0062] Next, the attack on a set of substations S' and protection components P' is carried out by A. P It means. Let Z j Indicates the power grid G j The j-th load in the process. Each load Z that flows through... j From current I j Given, where j = (1, n). Power system damage, i.e., load loss, is defined as the ratio of the sum of all loads disconnected due to attacker manipulation in the entire power system model to the total power system load under standard conditions. A similar definition applies to dynamic attack scenarios with added time parameters. The loss function is calculated as follows:

[0063]

[0064] ZT This represents the total system load. Therefore, an attacker will attempt to maximize this damage capability, which is formally defined as follows.

[0065] Problem 1 (Worst-case static attack). Given a power system network G... P A substation budget B S A protection component budget B P Find a worst-case static attack A P This maximizes damage within the power system network. In form,

[0066]

[0067] B S ≤B P (5)

[0068] Here, S' and S" represent the substations selected for attack, but no substation is attacked twice. A similar assumption applies to the protection components. P' represents the protection component for substation S', and P" represents the protection component for substation S".

[0069] Step S102: Determine the algorithm for the worst-case static attack.

[0070] This invention employs Algorithm 1, namely Get_WSA(Gp,B P Algorithm 1 (S) details the calculation of worst-case static attacks, based on iterative identification of attacks on substations and protection components that maximize system damage according to budget constraints. Budget constraints also help determine combinations of substations and protection components that cause the greatest system damage but would not cause such damage if attacked individually. Algorithm 1 takes this into account and utilizes budget constraints to efficiently identify such combinations.

[0071] The algorithm uses the power system model G P Budget B for protection components P The system uses substation information S as input. Furthermore, it identifies a set of threats to critical substations S', manipulation of protection components P', and attacks L. W The model identifies the worst-case static attack based on the damage caused. In the model, the substation causing the highest system damage, whether attacked alone or along with other substations, is identified as the critical substation using our proposed algorithm, based on the attacker's budget.

[0072] Furthermore, the algorithm Get_WSA(Gp,B) is used to determine the worst-case static attack. P ,S) includes:

[0073] Usage: Get_Static_Attack(Gp,P) t Identify the manipulated elements from the entire set of protection components that could cause the greatest damage to the protection components.

[0074] The set of all protection components can be obtained using the function F(S). Based on the attacker's budget B... P For each iteration, use Obtain a new set of protection components that need to be attacked to isolate power lines. For example, if an attacker has already compromised the protection components in the substation set S. Then in the next iteration, Use this protection component Returns a new set of protection components that can be attacked, such that an attacker can only choose a new protection component from the total number of previously unattacked protection components P in S.

[0075] Similarly, in each iteration, the algorithm selects the protection component P' to be operated from the set of attackable protection components that are part of the selected S', in order to isolate the transmission line from the power grid. Here, the function Get_Static_Attack(Gp,P) t Identify the protective component that causes the greatest damage; if the selected protective component causes L... p Greater than the worst-case static damage L w Then update the solution, where This represents the set of protection components that can be used for attacks. The function Get_Static_Attack(Gp, P) t Similar to Algorithm 4, but it does not consider the time required to schedule the attack. The algorithm terminates if no further improvement in system damage is observed. Finally, to maximize the system damage corresponding to the attacked protected component, the compromised substation S' is identified using a direct mapping of the method Obtain_subs(S,P'). The worst-case running time of Algorithm 1 is non-exponential, consisting of O(|P|×|B). p |) is given.

[0076] Step S2: Construct a static defense model to enable the defender to strategically identify the most critical substations for priority and protection, given a defense budget, thereby minimizing damage to the entire system.

[0077] Furthermore, step S2 includes:

[0078] Step S201: For the defender problem, first confirm the formula of the defender model, and improve the resilience of the power system by minimizing load loss.

[0079] The primary objective of defenders is to enhance the resilience of the power system by protecting critical substations, thereby minimizing potential load losses in the event of an attack. Figure 2 As shown. To achieve this, the protector can protect a subset D of the total number of substations. s , Protectors are constrained by the resources available to protect critical substations, and the budget for substation protection can benefit protectors in two ways:

[0080] (1) Due to budgetary constraints, the defender can target B. D Substations are prioritized and protected because it is impossible to protect and upgrade all substations simultaneously.

[0081] (2) The goal of a strategic attacker is to maximize system damage by attacking the most critical substations. This model can identify substations that can be prioritized for upgrades and protect them from malicious attacks first.

[0082] Next, the defender strategically utilizes the defense budget to minimize the destruction function J(A). p' The problem is formally described as follows.

[0083] Problem 2 (The Defender's Problem). Given a power system network Gp, and a defense budget B... D A substation budget B s A protection component budget B p Find a defense strategy that minimizes system load loss. It should take the following form:

[0084]

[0085] |D S |≤B D (7)

[0086]

[0087] B S ≤B P (10)

[0088] Step S202: Determine the algorithm for the critical substations that need protection: Get_Static_Denfense(Gp,B) p B D ,S).

[0089] Algorithm 2 identifies defense strategies against worst-case static attacks. Starting with an empty set, it strategically identifies key subsites to be protected one by one, minimizing damage to the entire system when an attacker launches an attack. This algorithm uses the same input as Algorithm 1, with a defense budget of B. DAs an additional input, identify the key substation D. s This allows for prioritization and protection when static attacks are launched, thereby minimizing system damage.

[0090] Algorithm 2 is an algorithm for finding critical substations that need protection: Get_Static_Denfense(Gp,B p B D ,S).

[0091] First, use Get_Static_Denfense(Gp,B) p S) Identify the worst-case static attack, as shown in Algorithm 1. Next, in the first iteration, when When there are no critical substations in the protection, the first substation to be protected is identified using the critical substation S' identified from the worst-case attack. We provide an intermediate set of solutions for the substations to be protected in order to obtain a better solution. We iteratively protect each substation in S' and use... Assess the overall system damage after a static attack. The system damage calculated in each iteration is used to select the substation to be protected, i.e., D. S ←D S ∪D' S , Where s' is the substation to be protected, obtained during iteration. Function Similar to Algorithm 1, however, the worst-case static attack here is to remove the protected substation from the list of attackable substations. It is calculated based on the substation s, that is, Furthermore, if the calculated damage L' S Less than the maximum damage Then update the solution.

[0092] Furthermore, for each subsequent iteration, if the set of protected substations... If it is not empty, then the worst-case static attack function is used, i.e. To identify a new set of critical substations. This function is the same as Algorithm 1, however, when performing a worst-case static attack on the power system model Gp, the protected substations... The substation is removed from the list of attackable substations. This ensures that once a substation is protected, attackers can only launch static attacks on the remaining substations according to their attack budget. Considering the defense budget constraint, the obtained attack can be further used to identify substations to be protected. In the algorithm, L HBy tracking all previous load losses obtained after protecting all substations and updating the final solution based on a comparison of the obtained damage with previous system damage, a better protection mechanism is ensured to provide an effective solution. The worst-case running time of Algorithm 2 is non-exponential, consisting of O(|S|×|B). D |×|P|×|B p |) is given.

[0093] Step S3: Construct a dynamic attack model to identify the key substations and their components to be attacked at different times in order to maximize system damage.

[0094] Step S301: Develop a dynamic attack model and formulate a dynamic attack under the worst-case scenario.

[0095] A malicious attacker's goal is to disrupt the stability of the power system by maximizing load losses. To achieve this, the attacker can first gain access to the substation at different times k. Access rights to a subset of , where k∈{1,...,T}. An attacker is resource-constrained and can compromise the substation budget B at most. s Next, the adversary can identify the protection components to be operated within the selected substation. This allows the attacker to disconnect transmission lines from the power system network at different times. Here, the attacker is again limited by resources, meaning it can only operate on a maximum of B. p The protection components' budget is favorable to the attacker. Finally, a dynamic attack on a set of substations S' and protection components P' at time step k is performed using A. p' (k) represents the dynamic attack loss function, which is calculated as follows:

[0096]

[0097] Where k∈{1,...,T}, x(k) and A p' (k) represents the time step, the system state, and the attack at time step k, respectively. Therefore, the attacker will attempt to maximize this damage capability, which is formally defined as follows.

[0098] Problem 3 (Worst-case dynamic attack). Given a power system network Gp, and a substation budget B... s and a protection component budget B p Find a worst-case dynamic attack A p' (k) maximizes system damage. Formally:

[0099]

[0100] B S ≤B P (16)

[0101] Where x(k) represents the system state at time step k, H(k) represents the system's attack history, G(H(k)) is a function that returns the system state given the attack history H(k), and g(H(k)) is a function that returns the normal system state without an attack history. Note that S'(k) and S'(k') represent the substations selected as targets for attack; however, once a substation is attacked at time step k, it does not need to be attacked again at time step k.

[0102] Step S302: Determine the worst-case dynamic attack algorithm.

[0103] In this application, the worst-case dynamic attack algorithm, namely Get_WDA(Gp,B p ,S,a k As shown in Algorithm 3, its basis is the budget constraint, namely B. s and B p Iteratively identifies attacks that maximize system damage at specific times. Here, S represents the power system substation configuration, and a k This represents a potential attack time vector. This indicates dynamic damage in the worst-case scenario. This represents the identification time vector for which an attack needs to be executed.

[0104] Algorithm 3: Algorithm for finding the worst-case dynamic attack: Get_WDA(Gp,B) p ,S,a k )

[0105] First, use Get_WSA(Gp,S,B) p This is used to identify the worst-case static attack. Here, the maximum damage caused by the attack, jeopardizing the safety of substation S', is determined, and the protection component P' within the substation is manipulated to isolate the transmission line from the grid, assuming the attack occurs simultaneously. Gen_Contin(P', P) is used. d Iteratively using the set P' to generate a new emergency set C. The emergency set C is composed of... This algorithm is used to return the maximum damage I(A) that caused the attack. p' (k)), the attack was carried out by the substation and associated protection components P * and attack time vector a * Composition. In each iteration, an attack and its instantaneous temporal vector are intelligently identified. And add it to the solution. Note that during the generation of sporadic events, P *The way this is used makes the search space much smaller than exhaustive search, but it is still efficient. Furthermore, in each iteration, if from... The maximum damage obtained J(A) p' (k) is greater than the worst-case dynamic damage. Then update the solution. Finally, the Obtain_subs(S',P'(k)) method is used to obtain the direct mapping of the attacked substation. Since the corresponding protection components belong to their respective substations, this process reduces the algorithm's running time and provides an effective solution.

[0106] Step S4: Construct a dynamic defense model so that, given a defense budget, the defender can strategically identify the most critical substations for priority and protection, identify the key substations to be protected, and thus minimize damage to the entire system.

[0107] Furthermore, step S4 includes:

[0108] Step S401: Construct a dynamic defense model.

[0109] The goal of a defender is to improve the resilience of the power system by minimizing potential load losses. To achieve this, a protector can protect a subset D of the total number of substations S in the power system network. S Furthermore, due to budgetary constraints, protectors are limited by resources and can only prioritize and protect substation B at most. D Next, the defender strategically utilizes the defense budget to minimize the destruction function J(A). p' The problem is formally described as follows: (k),x(k)).

[0110] Problem 4 (The Defender's Problem): Given a power system network Gp, and a defense budget B... D A substation budget B s A protection component budget B p The goal is to find a defense strategy that minimizes load loss when attackers launch dynamic attacks at different times.

[0111]

[0112] |D S |≤B D (19)

[0113]

[0114] B S ≤B P (twenty two)

[0115] Where x(k) represents the state of the system at time step k, k' represents any time step other than k; H(k) represents the attack history of the system.

[0116] Step S402: Determine the algorithm for the critical substations that need to be protected.

[0117] Algorithm 4 identifies defense strategies against worst-case dynamic attacks. Starting with an empty set, Algorithm 4 intelligently identifies critical substations to be protected one by one, thus minimizing damage to the entire system when an attack occurs. This algorithm uses the same input as Algorithm 3, with a defense budget of B. D As an additional input, it identifies the critical substation D to be protected. S Comparison of execution times for attacks and defenses in different standard IEEE systems, for example Figure 4 As shown.

[0118] Algorithm 4 is an algorithm for finding critical substations that need protection: Get_Dynamic_Defense(Gp,B p ,S D ,S,a k ).

[0119] First, by using Get_WDA(Gp,B) p ,S,a k To identify dynamic attacks in the worst-case scenario, as shown in Algorithm 3. Next, if D... S There are no critical substations in the system. The first substation to be protected is identified using the critical substation S'(k) identified from the worst-case dynamic attack. This is achieved by iteratively protecting each substation in S'(k) and using... The overall system damage following a dynamic attack is assessed. The system damage calculated in each iteration is used to select the substation to be protected, i.e., D. S ←D S ∪s'. To obtain a better solution, retain the intermediate solution D. S ←D S The locus of ∪s'. Function Similar to Algorithm 3, however, the worst-case dynamic attack here involves removing protected substations from the list of attackable substations. It is calculated based on the substation s, that is... Furthermore, if the calculated damage L' S Less than the maximum damage Then update the solution.

[0120] Furthermore, for each subsequent iteration, if the set of protected substations... If it is not empty, then the worst-case dynamic attack function is used, i.e. To identify a new set of critical substations. This function is the same as Algorithm 3; however, when performing a worst-case dynamic attack on the power system model, protected substations have been removed from the attacked substation set Gp. This ensures that once a substation is protected, attackers can only launch dynamic attacks on the remaining substations based on their attack budget. Considering defense budget constraints, the obtained attacks can be further used to identify substations to be protected. Furthermore, internally within the algorithm, L... H Tracking in protection The final solution D is updated based on all previous load losses obtained after the substation is damaged, and the damage obtained is compared with the previous system damage. S This ensures a better protection mechanism for providing effective solutions.

[0121] In this invention, unless otherwise explicitly specified and limited, the terms "installation," "connection," "linking," and "fixing," etc., should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral part; they can refer to a mechanical connection, an electrical connection, or a connection that allows communication between them; they can refer to a direct connection or an indirect connection through an intermediate medium; they can refer to the internal communication of two components or the interaction between two components, unless otherwise explicitly limited. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.

[0122] The above description is merely illustrative of the embodiments of the present invention and is not intended to limit the present invention. For those skilled in the art, any modifications, equivalent substitutions, improvements, etc., made without creative effort within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A defense method against dynamic network attacks on power systems, characterized in that, Includes the following steps: Step S1: Construct a static attack model to identify the key substations and their components to be attacked at different times, maximizing system damage; Step S2: Construct a static defense model to identify the most critical substations for priority and protection, minimizing damage to the entire system. Step S3: Construct a dynamic attack model to identify the key substations and their components to be attacked at different times, maximizing system damage; Step S4: Construct a dynamic defense model to identify the most critical substations for priority ranking and protection, identify the key substations to be protected, and minimize damage to the entire system. Step S1 includes: Step S101: Based on the static attack model of the static power system network, find the worst-case static attack. Step S102: Determine the algorithm for the worst-case static attack; Step S101 includes: The attacker gained access to a subset of the substation. The attacker gained access to the substation budget B. s Launch an attack; Given a power system network G P A protection component budget B P Find a worst-case static attack A P This maximizes damage within the power system network. B S ≤B P ; Where S' and S" represent the substations selected for attack, P' represents the protection component of substation S', and P" represents the protection component of substation S".

2. The defense method against dynamic network attacks on power systems according to claim 1, characterized in that, Step S2 includes: Step S201: Confirm the formula of the defender model to improve the resilience of the power system by minimizing load loss; Step S202: Determine the algorithm for the critical substations that need to be protected.

3. The defense method against dynamic network attacks on power systems according to claim 2, characterized in that, Step S201 includes: Given a power system network Gp and a defense budget B D A substation budget B s A protection component budget B p Find a defense strategy that minimizes system load loss, in the following form: |D S |≤B D ; B S ≤B P ; Among them, D s This represents a subset of substations. S represents the set of substations; S' and S" represent the substations selected for attack; P' represents the protection component of substation S'; and P" represents the protection component of substation S".

4. The defense method against dynamic network attacks on power systems according to claim 1, characterized in that, Step S3 includes: Step S301: Develop a dynamic attack model and formulate a dynamic attack under the worst-case scenario; Step S302: Determine the worst-case dynamic attack algorithm.

5. The defense method against dynamic network attacks on power systems according to claim 4, characterized in that, Step S301 includes: Given a power system network G p, a substation budget B s and a protection component budget B p Find a worst-case dynamic attack A p' (k) maximizes system damage, in form: B S ≤B P ; Where x(k) represents the system state at time step k, H(k) represents the system's attack history, G(H(k)) represents the function that returns the system state given the attack history H(k), and g(H(k)) represents the function that returns the normal system state without an attack history; S'(k) and S'(k') represent the substations selected as targets for attack; and P'(k) represents the protection components operating within the selected substations.

6. The defense method against dynamic network attacks on power systems according to claim 1, characterized in that, Step S4 includes: Step S401: Construct a dynamic defense model; Step S402: Determine the algorithm for the critical substations that need to be protected.

7. The defense method against dynamic network attacks on power systems according to claim 6, characterized in that, Step S401 includes: Given a power system network G p, a defense budget B D A substation budget B s A protection component budget B p Find a defense strategy that minimizes load loss when attackers launch dynamic attacks at different times: B S ≤B P ; Where x(k) represents the state of the system at time step k, and k' represents any time step other than k; H(k) represents the system's attack history; D s This represents a subset of substations. S represents the set of substations; S'(k) and S'(k') represent the substations selected as targets for attack, and P'(k) represents the protection components operating within the selected substations.

Citation Information

Patent Citations

  • Power information physical cooperative attack analysis method considering false injection of load data

    CN108234492A