Knowledge Graph Generation Method, System and Medium for Threat Analysis of Power Monitoring System
Through the knowledge graph generation method, an intelligent dynamic knowledge graph is generated, which solves the comprehensive consideration of threat analysis in the power monitoring system, and realizes efficient and intelligent analysis of the safety risks of the power system.
Patent Information
- Application Number
- CN202210888684.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-27
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2042-07-27
AI Technical Summary
The existing power monitoring system lacks comprehensive consideration of threats in threat analysis, cannot effectively utilize the entity relationships of the data itself, and cannot conduct intelligent and efficient threat analysis.
The knowledge graph generation method is adopted to obtain the actual data of threat analysis, preprocess and generate a single-dimensional vector graph, cluster and model, extract the correlation relationship, and generate an intelligent dynamic knowledge graph.
It realizes accurate and efficient analysis of data characteristics in power system safety risk assessment, can comprehensively analyze threat association relationships, and improves the intelligence level of threat analysis.
Smart Images

Figure CN115329092B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a knowledge graph generation method, system and medium for threat analysis of an electric power monitoring system, and belongs to the technical field of electric power trading. Background Art
[0002] Ensuring the safety of the power system is an important part of the country's economic development. At present, the power monitoring system has a preliminary network situation awareness capability in terms of security protection. At the same time, it has also begun to have the ability to discover, analyze and deal with the vulnerabilities of the system's internal security. However, when facing known or unknown risks, there is a lack of comprehensive consideration of threats. There are only single threat alerts without any relationship between them, and there is no comprehensive analysis or discussion of in-depth system threat analysis.
[0003] Knowledge graph technology is essentially the use of graph databases, which are non-relational databases. Although they do not collect data as quickly as relational databases and process data, they can use their essential graph theory principles to sort out the relationship problems between many complex data that cannot be processed manually or by relational databases. At present, the threat analysis related needs in the power monitoring system already have a large amount of existing data and knowledge bases, and do not require data collection from multiple relational databases. However, the need to sort out the relationship between complex data is of utmost importance. First, the connection between the data itself can be clarified, and then based on its connection, further reasonable and effective threat analysis can be carried out.
[0004] In existing technical applications, only knowledge graph technology is used alone in power monitoring systems, or only artificial intelligence technology is used alone. Therefore, it is not enough to meet the current power industry's demand for intelligent implementation. At the same time, it is also impossible to utilize the entity relationship of the data itself to achieve accurate and efficient intelligent threat analysis in complex data. Summary of the invention
[0005] The purpose of the present invention is to overcome the shortcomings of the prior art and to provide a knowledge graph generation method, system and medium for threat analysis of power monitoring systems, which can analyze the data characteristics based on the data of security risk assessment of monitoring systems such as power system security and meet actual needs.
[0006] To achieve the above object, the present invention is implemented by adopting the following technical solutions:
[0007] In a first aspect, the present invention provides a method for generating a knowledge graph for threat analysis of an electric power monitoring system, comprising the following steps:
[0008] S1: Obtain actual data for threat analysis;
[0009] S2: Preprocess the actual threat analysis data to generate a single - dimensional vector graph; the data of the single - dimensional vector graph includes features and key scores.
[0010] S3: Perform clustering and modeling on the single - dimensional vector graph to obtain the clustering categories of the single - dimensional vector graph, and then obtain the relevant data that can comprehensively analyze all threats; the relevant data that can comprehensively analyze all threats includes the clustering categories, features, and key scores of the single - dimensional vector graph.
[0011] S4: According to the relevant data that can comprehensively analyze all threats, extract the association relationships between the relevant data that can comprehensively analyze all threats, and generate an intelligent dynamic knowledge graph based on the relevant data that can comprehensively analyze all threats and their association relationships.
[0012] Further, in step S1, the method for obtaining the actual threat analysis data includes:
[0013] Obtain the raw monitoring and acquisition data related to security from the sources of each station in the power system. The raw data is pre - allocated into three major parts: high - risk abnormal data, non - threat data, and actual daily data.
[0014] The high - risk abnormal data refers to all data that has repeatedly caused risks in the historical security event data.
[0015] The non - threat data refers to all data in the purest situation without threats and completely without data.
[0016] The actual daily data refers to the actual data daily monitored by a dispatching center in the past three years, including most of the security data and occasionally discovered threat data.
[0017] Set the key score of the high - risk abnormal data as the upper limit value, set the key score of the non - threat data as the lower limit value, and determine the key score of the actual daily data according to the specific threat level.
[0018] Sort out the raw data and the corresponding key scores to obtain the actual threat analysis data.
[0019] Further, in step S2, the method for preprocessing the actual threat analysis data includes:
[0020] S21: Extract the correctly associated features of the actual threat analysis data in multiple dimensions to obtain associated feature data.
[0021] S22: Filter out the interference data from the associated feature data to obtain the actual data.
[0022] S23: Based on the text data of the obtained actual data, perform text digitization, convert the text information of the actual data into numbers, and obtain multi-dimensional digital data;
[0023] S24: Perform multi-dimensional data fusion, map the multi-dimensional digital data onto one level, and generate a single-dimensional vector graph; the data of the single-dimensional vector graph includes features and key scores; the features are formed by directly arranging and expanding the digitized multi-dimensional data in a single dimension.
[0024] Further, in step S21, perform correct feature extraction for association, including performing correct feature extraction for association on the threat analysis actual data in four dimensions;
[0025] The four dimensions include:
[0026] IP address dimension: specific risks, warning levels, clustering categories, number of warnings in the morning, number of warnings in the afternoon, specific open services, specific device names, specific protocols, specific verification times, risk levels, whether abnormal, verification times and device names of specific vulnerabilities on different IP addresses;
[0027] Open service dimension: specific IP addresses, device names, verification times, specific protocols on different open services;
[0028] Specific risk dimension: specific IP addresses, warning levels on different specific risks;
[0029] Specific vulnerability dimension: specific IP addresses, device names, verification times on different specific vulnerabilities.
[0030] Further, in step S22, filter out interference data from the associated feature data, including:
[0031] Filter out irregular data, null data, dirty data, damaged data, or incorrect logic data that will affect the construction of the knowledge graph from the associated feature data.
[0032] Further, in step S24, the method for generating the single-dimensional vector graph includes:
[0033] Convert the digital data of each specific threat data in multiple dimensions into grayscale values with a limit of 0 - 255 pixels. The grayscale value corresponding to the maximum converted number is determined to be 255, and the grayscale value corresponding to the minimum converted number is determined to be 0. Other numbers are converted proportionally to obtain the grayscale values of each specific threat data; among the grayscale values, 0 is pure white, 255 is pure black, and the intermediate values are grayscale colors with a gradient increasing from 0 to 255.
[0034] Construct a single - dimensional vector graph with the converted digital data. The abscissa is the name of the specific threat data, the ordinate is a spatial unit, and the color at each abscissa is the color corresponding to the gray - scale value of the corresponding specific threat data. A single - dimensional vector graph with different colors in a row represents different threat levels is constructed.
[0035] Further, in step S3, the method for clustering and modeling the data in the single - dimensional vector graph includes applying unsupervised learning Kmeans for clustering and modeling, including the following steps:
[0036] Establish a Kmeans unsupervised learning model. The input of the model is the data from the single - dimensional vector graph, including features and key scores, and the output is labeled clustering data.
[0037] Obtain the feature and key - score data of the single - dimensional vector graph, and randomly select a part of the data as the training set and another part of the data as the test set.
[0038] Input the training set and the test set into the Kmeans unsupervised learning model. Among them, use the gray - scale value of the single - dimensional vector graph as the weight data in the input data and conduct machine - learning training to obtain a trained Kmeans unsupervised learning model.
[0039] According to the trained Kmeans unsupervised learning model, obtain the clustering labels of the single - dimensional vector graph.
[0040] Further, in step S4, the method for generating an intelligent dynamic knowledge graph based on the relevant data and their association relationships that can comprehensively analyze all threats includes:
[0041] Use software programming methods to generate a visual dynamic knowledge graph from the relevant data and their association relationships that can comprehensively analyze all threats.
[0042] The association relationships include use, authorization, parsing, inclusion, belonging to, attack, exploitation, sending, and receiving.
[0043] In a second aspect, the present invention provides a knowledge - graph generation system for threat analysis of a power monitoring system, including:
[0044] A data acquisition module: used to acquire actual threat - analysis data.
[0045] A pre - processing module: used to pre - process the actual threat - analysis data to generate a single - dimensional vector graph.
[0046] Clustering module: It is used to cluster and model the data in the single-dimensional vector diagram, obtain the clustering categories of the single-dimensional vector diagram, and further obtain the relevant data that can comprehensively analyze all threats; the relevant data that can comprehensively analyze all threats includes the clustering categories, features, and key scores of the single-dimensional vector diagram.
[0047] Atlas generation module: It is used to extract the association relationships of the relevant data that can comprehensively analyze all threats according to the relevant data that can comprehensively analyze all threats, and generate an intelligent dynamic knowledge atlas based on the relevant data that can comprehensively analyze all threats and their association relationships.
[0048] In a third aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the steps of the method described in the first aspect are implemented.
[0049] Compared with the prior art, the beneficial effects achieved by the present invention:
[0050] 1. The present invention respectively generates features, clustering categories, and key scores, combines the features, clustering categories, and key scores to obtain the association relationships of the relevant data that can comprehensively analyze all threats, and generates an intelligent dynamic knowledge atlas based on the relevant data that can comprehensively analyze all threats and their association relationships. It can analyze the data characteristics on the basis of the data of the security risk assessment of monitoring systems such as power system security, and can utilize the entity relationships of the data itself to achieve accurate and efficient intelligent threat analysis in complex data.
[0051] 2. The present invention uses artificial intelligence technology to comprehensively analyze and model more features and threat impacts. Therefore, it can start from the key data in the existing knowledge bases in four dimensions of IP address, open services, specific risks, and specific vulnerabilities, and each dimension can be further subdivided into threat assessments, such as abnormal threat assessment, defect level threat assessment, and risk level threat assessment, etc. It uses knowledge graph technology to realize the knowledge representation between data and the association relationships between data, and then uses machine learning to fuse the above threat assessment data for modeling, clustering, and outputting comprehensive scores, so as to realize the intelligent analysis of system threats.
[0052] 3. The present invention obtains the actual data of threat analysis; in accordance with the actual power system threat analysis and evaluation rules, the present invention analyzes the data characteristics on the basis of the data of the security risk assessment of monitoring systems such as power system security, meeting the actual needs.
[0053] 4. In the data preprocessing process, the present invention is convenient for computer processing and subsequent analysis, solves the problem of multi-dimensional data fusion, and designs a method of mapping multi-dimensional data to a single-dimensional vector diagram on one level.
[0054] 5. Based on the existing public technical methods, the present invention realizes text digitization, and through design, comprehensively analyzes threat data, uses unsupervised learning for machine learning modeling and clustering, and outputs a score of threat analysis correlation with strong association, ensuring that the clustering results of the data model simultaneously satisfy the high intra-cluster similarity and inter-cluster difference in clustering.
[0055] 6. The present invention utilizes the advantages of the knowledge graph itself to associate the above analysis process with the important features extracted, and realizes convenient visual display to improve the retrieval efficiency for monitoring personnel;
[0056] 7. The present invention can apply the knowledge graph to intelligently analyze actual data, combine machine learning clustering modeling, construct a dynamic knowledge graph, can effectively evaluate threat events, can extract threat events that need to be monitored key points, and can reduce the possibility of detection omissions. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] Figure 1 FIG. is a knowledge graph of intelligent threat analysis of a power monitoring system provided by Embodiment 1 of the present invention, and this figure is an expansion diagram of root nodes in four dimensions.
[0058] Figure 2 FIG. is a knowledge graph of intelligent threat analysis of a power monitoring system provided by Embodiment 1 of the present invention, and this figure is a knowledge graph expanded in the IP address dimension among the four dimensions.
[0059] Figure 3 FIG. is a knowledge graph of intelligent threat analysis of a power monitoring system provided by Embodiment 1 of the present invention, and this figure is a knowledge graph expanded in the open service dimension among the four dimensions.
[0060] Figure 4 FIG. is a knowledge graph of intelligent threat analysis of a power monitoring system provided by Embodiment 1 of the present invention, and this figure is a knowledge graph expanded in the specific risk dimension among the four dimensions.
[0061] Figure 5 FIG. is a knowledge graph of intelligent threat analysis of a power monitoring system provided by Embodiment 1 of the present invention, and this figure is a knowledge graph expanded in the specific vulnerability dimension among the four dimensions.
[0062] Figure 6 FIG. is a flowchart of the method of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0063] The present invention will be further described below with reference to the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solutions of the present invention and should not be used to limit the protection scope of the present invention.
[0064] Embodiment 1:
[0065] An embodiment of the present invention provides a method for generating a knowledge graph for threat analysis of a power monitoring system, as Figure 6 shown, including:
[0066] Step 1: Obtain raw monitoring and acquisition data related to security from the sources of each power station in the power system, and perform pre-data processing methods such as feature extraction, data filtering, digitalization of text data, multi-dimensional big data fusion, and single-dimensional vector graph to obtain a single-dimensional data vector graph.
[0067] Step 1.1: Extract features from the raw data to obtain associated feature data in four dimensions.
[0068] Step 1.2: Filter out the interfering data in the feature data through data filtering.
[0069] Step 1.3: Based on the text data of the actual data obtained, apply the One-Hot encoding technology for text digitalization to convert the text information of the actual data into numbers, and obtain multi-dimensional digital data.
[0070] Step 1.4: Perform multi-dimensional data fusion, map the multi-dimensional digital data onto one level, and generate a single-dimensional vector graph. Its feature is that the digitized multi-dimensional data is directly arranged and expanded in a single dimension. The data in the single-dimensional vector graph is used as the input of the subsequent machine learning model.
[0071] Step 2: According to the single-dimensional vector graph, apply unsupervised learning Kmeans for clustering to obtain relevant data that can comprehensively analyze all threats.
[0072] Step 3: According to the relevant data that comprehensively analyze all threats, perform feature, clustering, and key scoring processing to obtain the associated information of the relevant data that can comprehensively analyze all threats, and generate an intelligent dynamic knowledge graph according to the obtained associated information. Features and key scores all come from the single-dimensional vector graph, and are also generated step by step from the original data to the single-dimensional vector graph. Finally, clustering comes from the unsupervised learning Kmeans algorithm in the previous step.
[0073] The associated information at least includes the association relationship between the relevant data that can comprehensively analyze all threats, and can also be directly extracted as entity-relationship triples. Both the association relationship and the entity-relationship triples are terms in the knowledge graph system, and those skilled in the art can clearly know their concepts and principles.
[0074] The specific method for generating the knowledge graph is to generate a visual dynamic knowledge graph through programming methods such as programs and Neo4j software for all the associated information of comprehensive threat analysis data.
[0075] Specifically, the actual data for threat analysis is directly collected from various power stations, provincial dispatching centers, local dispatching centers, etc. in the power system.
[0076] Specifically, correct feature extraction for association is performed, including:
[0077] IP address dimension: specific risks, alarm levels, clustering categories, number of alarms in the morning, number of alarms in the afternoon, specific open services, specific device names, specific protocols, specific verification times, risk levels, whether abnormal, verification times and device names of specific vulnerabilities on different IP addresses;
[0078] Open service dimension: specific IP addresses, device names, verification times, specific protocols on different open services;
[0079] Specific risk dimension: specific IP addresses, alarm levels on different specific risks;
[0080] Specific vulnerability dimension: specific IP addresses, device names, verification times on different specific vulnerabilities.
[0081] Specifically, interference data filtering is performed, including:
[0082] Irregular data, empty data, dirty data, damaged data, or incorrect logical data that may affect the construction of the knowledge graph in the above-mentioned required data.
[0083] Specifically, text digitization is performed, including:
[0084] Using the publicly available One-Hot encoding method, all text data is converted into numbers.
[0085] This embodiment provides a method, system and medium for generating a knowledge graph for threat analysis of a power monitoring system, which can construct a knowledge graph through four dimensions (IP address, open service, specific risk, specific vulnerability), and use specific key data volumes, data relationships, data scores, etc. related to security and threats in each dimension to provide the rationality and accuracy of threat analysis. Finally, machine learning modeling and clustering are used to output the total score.
[0086] Perform multi-dimensional data fusion. Specifically, the data that has been converted into numbers is mapped onto a single layer and represented using a one-dimensional vector graph. The one-dimensional vector graph is specifically limited to pixels from 0 to 255. The original maximum value of the converted numbers is set to 255, and the minimum value is set to 0. Other numbers are proportionally converted. After that, a one-dimensional vector graph is constructed using the converted numbers. The horizontal axis represents the specific threat data names (for example: alert level, risk level, whether it is abnormal, etc. The specific threat data for each dimension may be used as the horizontal axis), and the vertical axis represents a spatial unit with no meaning. In this way, a one-dimensional vector graph with different colors (representing different threat levels) is constructed. Among them, the specific color of the one-dimensional vector graph means that for the one-dimensional vector graph, the above-mentioned pixels from 0 to 255 are displayed as specific grayscale colors. 0 is pure white, 255 is pure black, and the intermediate values are grayscale colors that gradually increase from 0 to 255 according to the gradient, which plays a more intuitive role. Generally, the closer it is to the bright white color, the lower the threat level. On the contrary, the closer it is to the dark black color, the higher the threat level. However, the one-dimensional vector graph cannot accurately display the corresponding threat level based on the color depth by 100%. Therefore, in a few extremely special cases, there will be situations different from the above rules, and thus the intervention analysis and clustering input of the following artificial intelligence are required.
[0087] Use the one-dimensional vector graph as data preprocessing and input, and enter the knowledge graph modeling for the next aspect of intelligent threat analysis. Use the Kmean basic algorithm of unsupervised learning in publicly available machine learning for clustering and modeling.
[0088] Specifically, apply unsupervised learning Kmeans to cluster and model the data in the preprocessed one-dimensional vector graph, so as to comprehensively analyze all threat data. Apply Kmeans unsupervised learning. The input is all the feature data in the single vector graph, and the output is the category calculated and processed by the algorithm based on the spatial distance between data points and the K value set according to experience itself. Because clustering can effectively analyze the association between data points through algorithms and computers, generate new reference features, and thus analyze threat data more comprehensively, which belongs to adding an intelligent method. This step (clustering and modeling) obtains clustering categories, specifically A-E clustering and X clustering. It is equivalent to expanding the feature data. These clusters, as new feature data, are combined with the data of the single vector graph and output to the next step, combined to generate an intelligent dynamic knowledge graph.
[0089] Among them, the model establishment is divided into three parts: model training, model generation, and model output.
[0090] Model training specifically refers to the step of inputting the corresponding digital information contained in the pre - processed single - dimensional vector graph into the model and performing machine learning training. Unsupervised learning Kmeans is applied to cluster and model the data in the pre - processed single - dimensional vector graph, so as to comprehensively analyze all threat data.
[0091] According to the actual data and the above - mentioned method, there are six clustering results: defined as "Cluster A", "Cluster B", "Cluster C", "Cluster D", "Cluster E", and "Cluster X". Among them, in alphabetical order, "Cluster A" has no threat at all, to "Cluster E" with high - risk anomalies. In addition, "Cluster X" is the scatter points outside most of the other clusters. Most of them are noise, but it also contains the existence of unknown threat information. Because this part of the data does not conform to the training model of the historical data set, it is the data that is most worthy of the monitoring personnel's observation.
[0092] Among them, taking the single - dimensional vector graph with different colors (representing different threat levels) as the weight data in the input data, there are three reasons why the present invention selects the Kmean unsupervised learning method.
[0093] Reason 1: This algorithm is already a very common and general method in unsupervised learning. After being applied in many projects for a long time, it has been relatively mature and stable.
[0094] Reason 2: Clustering is carried out through the principle of digital vector distance of Kmean itself, which is more beneficial to the processing of the currently vectorized data.
[0095] Reason 3: There are public methods to detect the accuracy and precision of the results obtained by it, and its credibility is higher.
[0096] Applying unsupervised learning Kmeans to cluster and model the data in the pre - processed single - dimensional vector graph includes:
[0097] The model training set is the pre - processed data from the single - dimensional vector graph, that is, data such as features and key scores. These data are the most complete set. Then, 80% of the data is randomly selected as the training set, and 20% of the data is used as the test set. This is the main step in the publicly known kmeans unsupervised learning.
[0098] Input the model training set into the model for training to obtain a trained model.
[0099] The input of the model is the pre - processed data from the single - dimensional vector graph, including data such as features and key scores, and the output is the labeled clustering data. The labels are the above - mentioned Cluster A, B, C, D, E clusters and Cluster X.
[0100] Specifically, model training specifically refers to inputting the corresponding digital information contained in the preprocessed single-dimensional vector diagram into the model and performing the training steps of machine learning.
[0101] Among them, a single-dimensional vector diagram with different colors (representing different threat levels) is used as the weight data in the input data.
[0102] The method for obtaining the model training set includes data from a single-dimensional vector diagram.
[0103] In addition, in step 1, the specific method for obtaining the actual threat analysis data includes:
[0104] Input more than ten thousand historical security data of the power monitoring system, where the data is pre-allocated into three major parts: high-risk abnormal data, non-threat data, and actual daily data.
[0105] Among them, high-risk abnormal data specifically refers to all data that has repeatedly caused risks in the historical security event data.
[0106] Among them, non-threat data specifically refers to the purest situation, non-threat data, and the situation of completely no data.
[0107] Among them, actual daily data specifically refers to the actual data daily monitored by a dispatching center in the past three years, including most security data and occasionally discovered threat data.
[0108] In the historical data, the numbers trained and output from high-risk abnormal data are used as 100 for scoring, and the purest and non-threat data and the situation of completely no data are used as 0 for scoring.
[0109] It should be noted that the generation process of the single-dimensional vector diagram also includes preprocessing the threat data, including: performing data fusion, entity extraction, and entity disambiguation on the structured data that has been digitized in the actual threat data.
[0110] Finally, all the above feature data and analysis scores are used to form a reasonable knowledge graph to achieve intelligence.
[0111] Among them, the visualization part of the knowledge graph applies the open-source Neo4j community version.
[0112] The generation process of the single-dimensional vector diagram includes preprocessing the threat data, including: performing data fusion, entity extraction, and entity disambiguation on the structured data that has been digitized in the actual threat data.
[0113] The knowledge graph in this embodiment can be specifically applied as follows: The knowledge graph will display several root nodes on the starting interface, such as Figure 1, including four dimensions: IP address, open services, risks, and vulnerabilities. These four dimensions can be further classified as follows: IP address is classified as the analysis result, while open services, risks, and vulnerabilities are classified as the manifestations in the cyberspace.
[0114] The knowledge graph presents this root node to the operators, and then the operators can conduct detailed inquiries according to their different needs. The specific usage method is to start from the root node and go to each branch, as well as the actual requirements of power system monitoring operations, etc., to conduct specific inquiries on the branch details. The knowledge graph mainly plays the role of facilitating the operators to conduct inquiries based on logical relationships and quickly and accurately perform indexing.
[0115] Detect / monitor the power system monitoring system data according to the generated knowledge graph to determine whether there are threats in the power system monitoring system.
[0116] As Figure 2 shown, the IP address dimension of the actual threat analysis data includes: specific risks on different IP addresses, alarm levels, clustering categories, number of morning alarms, number of afternoon alarms, specific open services, specific device names, specific protocols, specific verification times, risk levels, whether abnormal, verification times and device names of specific vulnerabilities.
[0117] As Figure 3 shown, the open services dimension of the actual threat analysis data includes: specific IP addresses, device names, verification times, and specific protocols on different open services.
[0118] As Figure 4 shown, the risk dimension of the actual threat analysis data includes: specific IP addresses and alarm levels on different specific risks.
[0119] As Figure 5 shown, the vulnerability dimension of the actual threat analysis data includes: specific IP addresses, device names, and verification times on different specific vulnerabilities.
[0120] According to the data obtained by relevant operating units of the State Grid Corporation in the past three years and in accordance with the above description, finally use the open-source Neo4j to output a visualized dynamic knowledge graph. Thus, it can clearly present the results of each threat analysis to the monitoring personnel, facilitating quick retrieval and traceability.
[0121] Generating an intelligent dynamic knowledge graph includes: According to the requirements of the power system, power monitoring personnel divide the threat data into four dimensions from the perspective of easy viewing, thus constituting the "entity" data and "relationship" data of the knowledge graph. According to the data obtained by relevant operating units of the State Grid Corporation in the past three years, process and draw the knowledge graph, where circles represent "entity" times, and the connecting lines between each "entity" represent "relationship" data.
[0122] The present invention uses artificial intelligence technology to comprehensively analyze and model more features and threat impacts. Based on this, it can start the analysis from the key data in the existing knowledge base in four dimensions: IP address, open services, specific risks, and specific vulnerabilities. Each dimension can be further subdivided into threat assessments, such as abnormal threat assessment, defect level threat assessment, and risk level threat assessment, etc. The knowledge graph technology is used to realize the knowledge representation between data and the association relationship between data. Then, machine learning is used to fuse the above threat assessment data for modeling, clustering, and outputting a comprehensive score, so as to realize the intelligent analysis of system threats.
[0123] The present invention obtains the actual data of threat analysis; in accordance with the actual power system threat analysis and evaluation rules, based on the data of the security risk assessment of the power system security monitoring system, the present invention analyzes the data characteristics and meets the actual requirements.
[0124] In the data preprocessing process of the present invention, it is convenient for computer processing and subsequent analysis, solves the problem of multi-dimensional data fusion, and designs a method of mapping multi-dimensional data to a single-dimensional vector graph on one level.
[0125] Based on the publicly available existing technical methods, the present invention realizes text digitization, and through design, comprehensively analyzes threat data, uses unsupervised learning for machine learning modeling and clustering, and outputs a score with strong correlation of threat analysis. The existing methods for determining the accuracy of unsupervised learning and the Kmeans model itself are to apply the commonly used similarity analysis in the academic community, specifically referring to the relationship between the distance and density of the projection of data on a two-dimensional graph during the experimental clustering process, ensuring that the clustering results of the data model simultaneously meet the higher intra-cluster similarity and inter-cluster difference in clustering.
[0126] The present invention uses the advantages of the knowledge graph itself to associate the above analysis process with the important features extracted, and realizes convenient visual display to improve the retrieval efficiency for monitoring personnel;
[0127] The knowledge graph described in the present invention is used for intelligent threat analysis and evaluation of power monitoring systems; through the analysis of the knowledge graph, these analyses can all see the "analysis" lines in the graph. For example, in the graph of the IP address, in the "analysis" of the defect level, whether it is abnormal "analysis" is yes. The specific analysis method is the above steps, from the initial feature extraction, data filtering, to the subsequent single-dimensional vector graph, plus clustering and other processes, to obtain the analysis and evaluation data. These data are the "high", "medium", "low"; "yes", "no", etc. in the above examples.
[0128] The present invention can use a knowledge graph to perform intelligent analysis on actual data, combine machine learning clustering modeling to construct a dynamic knowledge graph, effectively evaluate threat events, extract threat events that need to be monitored key points, and reduce the possibility of detection omissions. Intelligent analysis means adding the clustering analysis results of Kmeans on the basis of the above analysis. Applying unsupervised learning makes the "analysis" intelligent. The result obtained from the analysis is the associated information that can comprehensively analyze the relevant data of all threats. Finally, the associated information is used to generate a knowledge graph
[0129] Embodiment 2:
[0130] This embodiment provides a knowledge graph generation system for threat analysis of a power monitoring system, including:
[0131] Data acquisition module: used to acquire actual data for threat analysis;
[0132] Feature extraction module: used to extract relevant correct features from the actual data for threat analysis in multiple dimensions to obtain associated feature data;
[0133] Filtering module: used to filter out interference data from the associated feature data to obtain actual data;
[0134] Digitization module: used to perform text digitization on the text data of the obtained actual data, convert the text information of the actual data into numbers, and obtain multi-dimensional digital data;
[0135] Data fusion module: used to perform multi-dimensional data fusion, map the multi-dimensional digital data onto one level, and generate a single-dimensional vector diagram;
[0136] Clustering module: used to cluster and model the data in the single-dimensional vector diagram to obtain the clustering categories of the single-dimensional vector diagram, and further obtain the relevant data that can comprehensively analyze all threats; the relevant data that can comprehensively analyze all threats includes the clustering categories, features, and key scores of the single-dimensional vector diagram;
[0137] Graph generation module: used to combine features, clustering categories, and key scores to obtain the associated information of the relevant data that can comprehensively analyze all threats, and generate an intelligent dynamic knowledge graph according to the relevant data that can comprehensively analyze all threats and their association relationships.
[0138] The system of this embodiment can be used to implement the method described in Embodiment 1.
[0139] Embodiment 3:
[0140] In this embodiment, a third aspect is provided. The present invention provides a computer-readable storage medium having a computer program stored thereon, and when the program is executed by a processor, the steps of the method described in Embodiment 1 are implemented.
[0141] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0142] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the flows and / or blocks in the flowchart and / or block diagram can also be implemented. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the specified functions in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0143] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the specified functions in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0144] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the specified functions in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0145] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the technical principle of the present invention, several improvements and deformations can be made, and these improvements and deformations should also be regarded as the protection scope of the present invention.
Claims
1. A method for generating a knowledge graph for threat analysis of a power monitoring system, characterized in that, It includes the following steps: S1: Obtain the actual data for threat analysis; S2: Preprocess the actual data for threat analysis to generate a single-dimensional vector diagram; S3: Cluster and model the single-dimensional vector diagram to obtain the clustering categories of the single-dimensional vector diagram, and then obtain the relevant data that can comprehensively analyze all threats; the relevant data that can comprehensively analyze all threats includes the clustering categories, features, and key scores of the single-dimensional vector diagram; S4: According to the relevant data that can comprehensively analyze all threats, extract the association relationships between the relevant data that can comprehensively analyze all threats, and generate an intelligent dynamic knowledge graph based on the relevant data that can comprehensively analyze all threats and the association relationships between them; In step S2, the method for preprocessing the actual data for threat analysis includes: S21: Extract the correctly associated features of the actual data for threat analysis in multiple dimensions to obtain associated feature data; S22: Filter out the interference data from the associated feature data to obtain the actual data; S23: Based on the text data of the obtained actual data, perform text digitization, convert the text information of the actual data into numbers, and obtain multi-dimensional digital data; S24: Perform multi-dimensional data fusion, map the multi-dimensional digital data to one level, and generate a single-dimensional vector diagram; the data of the single-dimensional vector diagram includes features and key scores; the features are formed by directly arranging and expanding the digitized multi-dimensional data in a single dimension; In step S24, the method for generating the single-dimensional vector diagram includes: Convert the digital data of each specific threat data in multiple dimensions into grayscale values with a limit of 0-255 pixels. The grayscale value of the maximum converted number is determined to be 255, and the grayscale value of the minimum converted number is determined to be 0. Other numbers are proportionally converted to obtain the grayscale values of each specific threat data; among the grayscale values, 0 is pure white, 255 is pure black, and the intermediate values are grayscale colors that gradually increase from 0 to 255 according to the gradient; Construct a single-dimensional vector diagram with the converted digital data. The abscissa is the name of the specific threat data, the ordinate is a spatial unit, and the color at each abscissa is the color corresponding to the grayscale value of the corresponding specific threat data, constructing a single-dimensional vector diagram with a row of different colors representing different threat levels.
2. The method for generating a knowledge graph for threat analysis of a power monitoring system according to claim 1, wherein In step S1, the method for obtaining the actual data for threat analysis includes: Obtain the raw monitoring and collection data related to security from the sources of each power system substation. The raw data is pre-allocated into three major parts: high-risk abnormal data, threat-free data, and actual daily data; The high-risk abnormal data refers to all data that has repeatedly caused risks in the historical security event data; The threat-free data refers to all data in the purest, threat-free, and completely data-free situations; The actual daily data refers to the actual data daily monitored by a dispatching center in the past three years, including most of the security data and occasionally discovered threat data; Set the critical score of high-risk abnormal data as the upper limit value, and set the critical score of non-threatening data as the lower limit value. The critical score of actual daily data is determined according to the specific threat level; Sort out the rough data and the corresponding critical scores to obtain the actual data for threat analysis.
3. The method for generating a knowledge graph for threat analysis of a power monitoring system according to claim 1, wherein In step S21, perform correct feature extraction, including performing correct feature extraction on the actual threat analysis data in four dimensions; The four dimensions include: IP address dimension: including specific risks, alarm levels, clustering categories, morning alarm times, afternoon alarm times, specific open services, specific device names, specific protocols, specific verification times, risk levels, whether abnormal, verification times and device names of specific vulnerabilities on different IP addresses; Open service dimension: including specific IP addresses, device names, verification times, and specific protocols on different open services; Specific risk dimension: including specific IP addresses and alarm levels on different specific risks; Specific vulnerability dimension: including specific IP addresses, device names, and verification times on different specific vulnerabilities.
4. The method for generating a knowledge graph for threat analysis of a power monitoring system according to claim 1, wherein In step S22, filter out interference data from the associated feature data, including: Filter out irregular data, null data, dirty data, damaged data, or incorrect logic data that may affect the construction of the knowledge graph from the associated feature data.
5. The method for generating a knowledge graph for threat analysis of a power monitoring system according to claim 1, wherein In step S3, the method of clustering and modeling within a single-dimensional vector graph includes applying unsupervised learning Kmeans for clustering and modeling, including the following steps: Establish a Kmeans unsupervised learning model. The input of the Kmeans unsupervised learning model is data from a single-dimensional vector graph, including features and critical scores, and the output is labeled clustering data; Obtain the feature and critical score data of the single-dimensional vector graph, and randomly select a part of the data as the training set and another part of the data as the test set; Input the training set and the test set into the Kmeans unsupervised learning model. Among them, use the gray value of the single-dimensional vector graph as the weight data in the input data and perform machine learning training to obtain a trained Kmeans unsupervised learning model; According to the trained Kmeans unsupervised learning model, obtain the clustering labels of the single-dimensional vector graph.
6. The method for generating a knowledge graph for threat analysis of a power monitoring system according to claim 1, characterized in that In step S4, the method of generating an intelligent dynamic knowledge graph based on the relevant data that can comprehensively analyze all threats and the association relationships between them includes: Generate a visual dynamic knowledge graph through software programming methods for the relevant data that can comprehensively analyze all threats and their association relationships; The association relationships include use, authorization, parsing, inclusion, belonging to, attack, exploitation, sending, and receiving.
7. A knowledge graph generation system for power monitoring system threat analysis for performing the method according to claim 1, characterized in that, Include: Data acquisition module: used to acquire the actual data for threat analysis; Preprocessing module: used to preprocess the actual threat analysis data to generate a single-dimensional vector graph; Clustering module: used to cluster and model the data within the single-dimensional vector graph to obtain the clustering categories of the single-dimensional vector graph, and further obtain the relevant data that can comprehensively analyze all threats; the relevant data that can comprehensively analyze all threats includes the clustering categories, features, and critical scores of the single-dimensional vector graph; Graph Generation Module: It is used to extract the correlation relationships between the relevant data that can comprehensively analyze all threats based on the relevant data that can comprehensively analyze all threats, and generate an intelligent dynamic knowledge graph based on the relevant data that can comprehensively analyze all threats and their correlation relationships.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, it implements the steps of the method according to any one of claims 1-6.
Citation Information
Patent Citations
Monitoring system for power grid event response
CN113570474A
Air combat threat target identification method based on convolutional neural network
CN113902974A