A method for detecting false data injection in industrial control systems based on bispectral analysis

By using a bispectral analysis method, third-order spectrum transformation and Parzen window function to remove Gaussian noise and calculate the credibility p, the real-time and accuracy problems of false data injection detection are solved, and efficient false data injection detection is achieved.

CN115454028BActive Publication Date: 2025-09-30XIAN THERMAL POWER RES INST CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211122774.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-15
Publication Date
2025-09-30
Estimated Expiration
2042-09-15

AI Technical Summary

Technical Problem

Existing technologies have problems with poor real-time performance, low detection efficiency, low accuracy and high false alarm rate when detecting false data injection attacks, especially in industrial control systems that are greatly affected by noisy data.

Method used

A method based on bispectrum analysis is adopted. The real-time data of the industrial control system is subjected to discrete time series construction, bispectral transformation and credibility calculation. The influence of Gaussian noise is removed by using third-order spectrum transformation and Parzen window function. The credibility p is calculated to determine whether there is false data injection.

Benefits of technology

It improves the accuracy and real-time performance of false data injection detection, simplifies the detection process, improves detection efficiency, and reduces the false alarm rate.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115454028B_ABST
    Figure CN115454028B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for detecting false data injection in industrial control systems based on bispectral analysis, comprising the following steps: acquiring real-time data of an industrial control system and constructing a discrete time series based on the data; performing bispectral transformation on the data in the discrete time series to obtain a result of the bispectral transformation; calculating a credibility p based on the result of the bispectral transformation; and judging whether false data injection exists in the industrial control system based on the calculated credibility p. The method can accurately detect whether a false data injection attack exists in the industrial control system and has the characteristics of good real-time performance and high detection efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of industrial control safety and network security, and relates to an industrial control false data injection detection method based on bispectral analysis. Background Art

[0002] With the rapid development of industrial control systems, information and communication technologies are increasingly being used in these systems. Physical equipment systems are facing increasingly complex operating environments, and the protection of physical equipment has become an extremely important aspect of industrial control security. False data injection attacks involve directly tampering with sensor measurement data, invading the communication system between sensors and SCADA systems, or entering SCADA systems through the control center's local area network. This allows the state estimation to produce erroneous values ​​for state variables while satisfying residual detection requirements, leading to incorrect decisions by the dispatch center. Attacks targeting the operating variables of industrial control systems, by tampering with measurement values, pose a threat to industrial production and disrupt the normal operation of production activities. However, current detection of false data injection attacks faces numerous challenges, including poor real-time performance, low detection efficiency, low detection accuracy due to noise data, and high false alarm rates. Summary of the Invention

[0003] The purpose of the present invention is to overcome the shortcomings of the above-mentioned prior art and provide an industrial control false data injection detection method based on bispectral analysis. The method can accurately detect whether there is a false data injection attack in the industrial control system, and has the characteristics of good real-time performance and high detection efficiency.

[0004] To achieve the above objectives, the industrial control false data injection detection method based on bispectral analysis described in the present invention includes:

[0005] Obtain real-time data from industrial control systems and use it to construct discrete time series;

[0006] Perform bispectral transformation on the data in discrete time series to obtain the result of bispectral transformation;

[0007] Calculate the credibility p based on the result of bispectral transformation;

[0008] According to the calculated credibility p, it is determined whether there is false data injection in the industrial control system.

[0009] The specific process of performing bispectral transformation on the data in the discrete time series to obtain the result of bispectral transformation is as follows:

[0010] Quantify data in discrete time series;

[0011] Perform third-order spectrum transformation on the quantized result to obtain the result of bispectral transformation.

[0012] Quantize the data y(k) in discrete time series as:

[0013] y(k)=x(k)+e(k)

[0014] Wherein, x(k) is the state value, e(k) is Gaussian additive noise, and y(k) = [y(1), y(2), ..., y(n)].

[0015] The result of bispectral transformation for:

[0016]

[0017] Among them, ω1≤π, ω2≤π, |ω1+ω2|≤π, is the third-order cumulant of sequence y, τ is called the integral variable or cumulative variable in discrete Fourier transform, j is a negative number, and ω is the angular frequency.

[0018] The credibility p is:

[0019]

[0020]

[0021] Where M is an indefinite value, and

[0022] The specific operation of judging whether there is false data injection in the industrial control system according to the calculated credibility p is as follows:

[0023] When the credibility p is greater than or equal to the threshold value 0.9, it is considered that there is no false data injection attack on the industrial control system. When the credibility p is less than 0.9, it is considered that there is a false data injection attack on the industrial control system.

[0024] When the industrial control system is attacked by false data injection, the potential information of the attack is sent to the output end, and the output end forms an attack event report.

[0025] The present invention has the following beneficial effects:

[0026] In the specific operation of the industrial control false data injection detection method based on bispectral analysis described in the present invention, bispectral transformation is performed on the data in the discrete time series to obtain the result of the bispectral transformation, remove the influence of Gaussian noise, and improve the accuracy and real-time performance of the detection result. In addition, the credibility p is calculated based on the result of the bispectral transformation, and then the industrial control system is judged based on the calculated credibility p to detect whether the industrial control system has false data injection attacks. The calculation process is relatively simple and the detection efficiency is high. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] Figure 1 Flow chart of the method of the present invention. DETAILED DESCRIPTION

[0028] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only embodiments of a part of the present invention, not all embodiments, and are not intended to limit the scope of the present invention. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessary confusion of the concepts disclosed in the present invention. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work should fall within the scope of protection of the present invention.

[0029] The accompanying drawings illustrate schematic diagrams of the structures of the disclosed embodiments of the present invention. These figures are not drawn to scale; for the purpose of clarity, some details are exaggerated and some details may be omitted. The shapes of the various regions and layers shown in the figures, as well as their relative sizes and positional relationships, are merely exemplary and may deviate in practice due to manufacturing tolerances or technical limitations. Those skilled in the art may design regions / layers with different shapes, sizes, and relative positions as needed.

[0030] Example 1

[0031] The method for detecting false data injection in industrial control based on bispectral analysis of the present invention comprises the following steps:

[0032] 1) Data Collection

[0033] refer to Figure 1 , acquiring real-time data from the industrial control host computer to form a discrete time series of the operation values ​​of each device and point. When sampling the operation data, it is necessary to set the initial number of sampling points N, the sampling interval t, and the number of repetition points n. The number of sampling points is the number of values ​​in a unit discrete time series, the sampling interval is the sampling frequency, and the number of repetition points is the number of identical values ​​in two discrete time series adjacent in time. In this embodiment, the initial number of sampling points is set to 500, the sampling interval is set to 1 second, and the number of repetition points is set to 400.

[0034] 2) Bispectral transform

[0035] Quantize the measurements in discrete time series as:

[0036] y(k)=x(k)+e(k)

[0037] Where y(k) is the measured value, x(k) is the state value, e(k) is the Gaussian additive noise, and y(k) = [y(1), y(2), ..., y(n)];

[0038] Performing third-order spectrum transformation on y(k) yields:

[0039]

[0040] Among them, ω1≤π, ω2≤π, |ω1+ω2|≤π, is the third-order cumulant of sequence y. At any moment, the state value of the device is independent of the noise, then:

[0041]

[0042] The third-order and above cumulative amount of the Gaussian stationary sequence is 0, so:

[0043]

[0044]

[0045] Therefore, bispectral analysis removes the influence of additive Gaussian noise on the analysis results.

[0046] 3) Credibility calculation

[0047] Add Parzen window function to y series bispectrum Then we have:

[0048]

[0049] Where M is an indefinite value, and

[0050] Let the credibility p be the ratio of the spectrum intercepted by the window function to the total spectrum, that is:

[0051]

[0052] 4) Optimize the engine

[0053] The optimization engine is a machine learning model based on the logistic regression algorithm. By optimizing the number of sampling points N, the sampling interval t, the repetition value n, and the parameter M in the window function, it minimizes the time spent on bispectral calculations for multiple discrete sequences and continuously optimizes the window function so that the trust parameter p is greater than 0.9.

[0054] 5) Deviation detection

[0055] The analysis engine first detects bad data in real-time data and removes any bad data if any. It then processes the data according to the set number of sampling points, sampling time interval, and number of repetition points to form a discrete time series of real-time data. The generated discrete series is subjected to bispectral transformation and its credibility is calculated. When the credibility p is higher than the set threshold of 0.9, it is considered that the data deviation is within a reasonable range and the industrial control system does not have a false data injection attack. When the credibility p is less than 0.9, it is considered that a false data injection attack has occurred in the industrial control system.

[0056] 6) Alarm

[0057] When a false injection attack occurs in an industrial control system, the information of the attack point will be sent to the output terminal and an attack event report will be generated, which will be confirmed and tracked by the administrator.

[0058] Example 2

[0059] The industrial control false data injection detection system based on bispectral analysis of the present invention includes:

[0060] Data acquisition module, used to obtain real-time data from industrial control systems and construct discrete time series based on it;

[0061] An analysis module is used to perform bispectral transformation on the data in the discrete time series to obtain the result of bispectral transformation;

[0062] A credibility calculation module, used to calculate the credibility p according to the result of bispectral transformation;

[0063] The judgment module is used to judge whether there is false data injection into the industrial control system based on the calculated credibility p.

[0064] From the perspective of architecture, the system described in the present invention is divided into a client and a server, wherein the client includes a probe and a data source, and the server includes a receiving end, an industrial control database, an analysis engine and an alarm module.

[0065] The client includes a probe and a data sending source program. The probe is a data monitoring program that can run on 32-bit / 64-bit Windows and Linux hosts. It obtains real-time data collected on the industrial control host by hooking the underlying system process. To ensure the smooth and continuous operation of the industrial control host and not affect normal production activities during the data collection process, the probe only has read permissions; the probe runs automatically when the industrial control host is turned on, and the real-time collected data is pushed to the data sending source through the API.

[0066] The data sending source is connected to the industrial history database and the probe through two independent APIs respectively. Each API measurement point has an identifier in the format of ip:port / id, where id is a non-repeating string randomly assigned by the sending source program. It should be noted that in other application scenarios, APIs can be expanded and added according to the data source; the data sending source can be configured with multiple receiving ends, support distributed deployment, and provide load balancing; after the data sending source configures the receiving end, an encrypted transmission channel is established through a handshake when the connection is established. The encryption algorithm uses 192-bit Blowfish encryption and fully implements 16 rounds of Fei Stel encryption operations; during data transmission, the encrypted channel is maintained through heartbeat packets. When no heartbeat signal is detected, the transmission channel is closed.

[0067] The receiving end receives data by establishing an encrypted channel with the sending source. The identifier of the receiving end is ip:port / id, where id is the receiving end sequence number. In this embodiment, id is 1. The receiving end obtains the measurement point identifier information from the handshake information and allocates a separate data transmission channel for each measurement point.

[0068] The industrial control database is used to store the data obtained by the receiving end. Multiple sub-tables are established in the database according to the ID, and the data with the same ID is stored in the same sub-table.

[0069] Example 3

[0070] A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the industrial control false data injection detection method based on bispectral analysis are implemented. The memory may include internal memory, such as high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device. The processor, network interface, and memory are interconnected via an internal bus. The internal bus may be an industrial standard architecture bus, a peripheral component interconnect standard bus, an extended industrial standard architecture bus, etc. The bus may be divided into an address bus, a data bus, a control bus, etc. The memory is used to store programs. Specifically, the programs may include program code, and the program code includes computer operating instructions. The memory may include internal memory and non-volatile memory, and provides instructions and data to the processor.

[0071] Example 4

[0072] A computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the method for detecting false data injection in industrial control systems based on bispectral analysis. Specifically, the computer-readable storage medium includes, but is not limited to, volatile memory and / or non-volatile memory. The volatile memory may include random access memory (RAM) and / or cache memory. The non-volatile memory may include read-only memory (ROM), a hard disk, flash memory, an optical disk, a magnetic disk, etc.

[0073] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0074] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0075] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0076] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1A step that specifies a function in one or more boxes.

[0077] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered by the scope of protection of the claims of the present invention.

Claims

1. A method for detecting false data injection in industrial control based on bispectral analysis, characterized in that: include: Obtain real-time data from industrial control systems and use it to construct discrete time series; Perform bispectral transformation on the data in discrete time series to obtain the result of bispectral transformation; Calculate the credibility p based on the result of bispectral transformation; Determine whether there is false data injection in the industrial control system based on the calculated credibility p; The specific process of performing bispectral transformation on the data in the discrete time series to obtain the result of bispectral transformation is as follows: Quantify data in discrete time series; Perform third-order spectrum transformation on the quantized result to obtain the result of bispectral transformation; The data y(k) in the discrete time series is quantized as: y(k)=x(k)+e(k) Where x(k) is the state value, e(k) is the Gaussian additive noise, and y(k) = [y(1), y(2), …, y(n)]; The result of bispectral transformation for: Among them, ω1≤π, ω2≤π, |ω1+ω2|≤π, is the third-order cumulant of sequence y, τ is called the integral variable or cumulative variable in discrete Fourier transform, j is a negative number, and ω is the angular frequency; The credibility p is: Where M is an indefinite value, and N is the number of sampling points.

2. The method for detecting false data injection in industrial control based on bispectral analysis according to claim 1, characterized in that: The specific operation of judging whether there is false data injection in the industrial control system according to the calculated credibility p is as follows: When the credibility p is greater than or equal to the threshold value 0.9, it is considered that there is no false data injection attack on the industrial control system. When the credibility p is less than 0.9, it is considered that there is a false data injection attack on the industrial control system.

3. The method for detecting false data injection in industrial control based on bispectral analysis according to claim 1, characterized in that: When the industrial control system is attacked by false data injection, the potential information of the attack is sent to the output end, and the output end forms an attack event report.

Citation Information

Patent Citations

  • False data injection attack detection method suitable for power system load frequency control

    CN111988303A