A Malicious Program Propagation Model and Optimal Control Method for Cyber-Physical Systems in Distribution Networks
By constructing a PC-PLC dual-layer heterogeneous network model and optimal control model, the problem of difficult to suppress malicious program propagation in the distribution network is solved, and the effect of effectively suppressing malicious program propagation in the distribution network is achieved.
Patent Information
- Application Number
- CN202210948976.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-09
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2042-08-09
AI Technical Summary
The existing distribution network information physics system lacks effective malicious program dissemination models and control methods, making it difficult to effectively curb the spread of malicious programs.
A PC-PLC double-layer heterogeneous network model is constructed, a differential equation system is established through the node state transition diagram, and a malicious program propagation situation is simulated, and a kill rate and immunity rate are used as control variables to build an optimal control model to suppress the spread of malicious programs.
It realizes the suppression of malicious programs in the distribution network at the minimum cost, and effectively simulates and controls the propagation of malicious programs in the PC-PLC dual-layer network.
Smart Images

Figure CN115514655B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of power system networks, and particularly relates to a malicious program propagation model and an optimal control method for a distribution network cyber-physical system. Background Art
[0002] Since the 1980s, with the continuous growth of ecological damage problems caused by the widespread application of fossil fuels globally, coupled with the rapid rise of populous developed countries, non-renewable energy cannot guarantee the high-speed growth of industry and the national economy. The third industrial revolution centered around the energy Internet and smart grid has enabled the widespread use of renewable energy, effectively alleviating problems such as the shortage of world fossil energy, the tension of energy resources, and climate change caused by the use of fossil energy. The power grid has improved its intelligence by introducing advanced sensing technologies, control technologies, data processing technologies, and new-generation information communication technologies to address previous power quality and dynamic adjustment problems. With the realization of the two major strategies and the development of the power grid's intelligent informatization level, the power grid has evolved into a cyber-physical system (CPS) with a high degree of integration at the communication, control, and physical levels, featuring a high degree of cyber-physical coupling, capable of real-time sensing of the distribution system, providing instant intelligent strategies, and performing dynamic control.
[0003] Malicious code is a program that embeds code into another program without being detected, thereby achieving the purpose of destroying the data of the infected computer, running invasive or destructive programs, and destroying the security and integrity of the data of the infected computer. Malicious code has a wide range, including procedural computer security threats that use various network, operating system, software, and physical security vulnerabilities to spread malicious payloads to computer systems. Summary of the Invention
[0004] In view of the existing problems, the purpose of the present invention is to provide a malicious program propagation model and an optimal control method for a distribution network cyber-physical system to solve the above problems.
[0005] The present invention provides the following technical solutions:
[0006] A modeling method for a malicious program propagation model of a distribution network cyber-physical system includes the following steps:
[0007] A1: Based on the propagation principle of PC-PLC worm viruses, a PC-PLC double-layer heterogeneous network model is constructed for the distribution network CPS;
[0008] A2: Construct a node state transition diagram;
[0009] A3: Divide the nodes into susceptible nodes, infected nodes, isolated nodes, and immune nodes;
[0010] A4: Establish a system of differential equations based on the node state transition diagram, that is, obtain the malicious program propagation model in the CPS of the distribution network.
[0011] The system of differential equations established by the node state transition diagram is as follows:
[0012]
[0013]
[0014]
[0015]
[0016]
[0017]
[0018]
[0019] In the system of differential equations, S A (t), I A (t), Q A (t), R A (t), S B (t), I B (t), R B (t) are the numbers of susceptible PC nodes, infected PC nodes, isolated PC nodes, immune PC nodes, susceptible PLC nodes, infected PLC nodes, and immune PLC nodes at time t, respectively; in the system of differential equations, β 11 , β 22 , β 12 represent the transmission coefficient of the virus in the PC network, the transmission coefficient of the virus in the PLC network, and the transmission coefficient of the virus across networks, respectively. The proportion of infected nodes in the PC network that are isolated is η, and the recovery rate and immunity rate of infected PC nodes by running patch programs and / or installing antivirus software are γ 1 , the recovery rate of PC nodes taking isolation measures is ω, the recovery probability of PLC nodes by adopting the security protocol of industrial control systems is γ 2 . When nodes die due to hardware damage or environmental factors, the death rates of PC nodes and PLC nodes are d 1 , d 2 , respectively. The time delay for the virus in the PC network to infect nodes in the PLC network is τ; and S A (t), I A (t), Q A (t), R A (t), SB (t), I B (t), R B (t) satisfies: N A (t) = S A (t) + I A (t) + R A (t) + Q A (t) and N B (t) = S B (t) + I B (t) + R B (t).
[0020] An optimal control method for suppressing the spread of malicious programs in a cyber - physical power distribution system, comprising the following steps:
[0021] S1: Based on the propagation principle of PC - PLC worm viruses, construct a PC - PLC double - layer heterogeneous network model for the power distribution system CPS;
[0022] S2: Construct a node state transition diagram;
[0023] S3: Divide the nodes into susceptible nodes, infected nodes, isolated nodes, and immune nodes;
[0024] S4: Establish a system of differential equations according to the node state transition diagram, that is, obtain the malicious program propagation model in the power distribution system CPS;
[0025] S5: Take the detection rates of infected nodes in the PC and PLC networks and the immunity rate of newly deployed nodes as control variables, and construct the objective function of the optimal control model;
[0026] S6: Obtain the Hamiltonian function according to the objective function, and solve the optimal control pair according to the Pontryagin maximum principle to minimize the number of infected nodes in the power distribution network and the cost of suppressing the spread of malicious programs.
[0027] Preferably, in step S1, the PC - PLC double - layer heterogeneous network model is constructed through the following operations: Connect the PC network and the PLC network. The PC network is the upper - layer network, and the PLC network is the lower - layer network to form a double - layer coupled network; in the double - layer coupled network, the PC sends control information to the PLC, and the PLC feeds back status information to the PC.
[0028] Preferably, in step S3, the susceptible nodes are: nodes in the normal working state, the initial state of all nodes; the infected nodes are: nodes infected by the virus or selected as the attack target by the virus, which will spread the virus to other susceptible nodes; the isolated nodes are nodes infected by the virus but isolated, which will not spread the virus to other susceptible nodes; the immune nodes are: nodes that can resist virus attacks and cannot be spread by the virus.
[0029] Preferably, in step S5, the following method is used to construct the objective function:
[0030] S51: During [0, t f , apply the control strategy in the system. Use the Lebesgue square-integrable function u(t) as the control function. The system disinfects the infected nodes and injects immune patches, and increases the proportion of immune nodes among the newly deployed nodes. Let γ 1 = u 1 (t), γ 2 = u 2 (t), (1 - b 1 ) = u 3 (t);
[0031] S52: Calculate the set of control functions: {u i (t) ∈ L 2 [0, t f : 0 ≤ t ≤ t f , 0 ≤ u i (t) ≤ 1, i = 1, 2, 3};
[0032] S53: Let m, n, and p be the weight coefficients of the three control variables, and calculate the PC immune patch injection cost PLC immune patch injection cost Cost of pre-immunizing patches for newly deployed PCs
[0033] S54: Calculate the objective function:
[0034]
[0035] Preferably, in step S6, the following method is used to solve the optimal control ratio:
[0036] S61: Calculate:
[0037]
[0038] S62: According to the Pontryagin maximum principle, obtain the corresponding Hamiltonian function:
[0039] τ)I A (t - τ) - u 2 (t)I B (t) - d 2 I B (t)} + λ 7 (t){u 2 (t)I B (t) - d 2 R B (t) - l 2 RB (t)}, where λ i (t) (λ = 1, 2, 3…7) is the co-state variable of the system;
[0040] S63: Define that when t ∈ [0, t f -τ], the characteristic equation of the system is:
[0041]
[0042] S64: Define the transversality condition of the system as: λ i (t f ) = 0, i = 1, 2, 3, 4, 5, 6, 7;
[0043] S65: Calculate and obtain the optimization condition:
[0044]
[0045] S66: Calculate and obtain the optimal control pair:
[0046]
[0047] The beneficial technical effects of the present invention are as follows:
[0048] The technical solution provided by the present invention can suppress the spread of malicious programs in the power grid PC-PLC double-layer network model at the minimum cost.
[0049] Based on the propagation mode of PC-PLC worm viruses, the present invention constructs a PC-PLC double-layer coupled network model, considering situations such as isolation, patch injection, and transmission delay, to simulate the spread of malicious programs in the realistic distribution network CPS, and can effectively suppress the spread of malicious programs. Description of the Drawings
[0050] Figure 1 is a schematic flow chart of the malicious program propagation model of the distribution network cyber-physical system and the optimal control method for suppressing the spread of malicious programs provided by the embodiments of the present invention. Detailed Embodiments
[0051] The following details the embodiments of the present invention. The following embodiments are implemented on the premise of the technical solution of the present invention, and detailed implementation manners and specific operation processes are given. However, the protection scope of the present invention is not limited to the following embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without making creative efforts belong to the protection scope of this application.
[0052] References to "embodiments" in this specification mean that the particular features, structures, or characteristics described in connection with the embodiments can be included in at least one embodiment of the present application. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments without conflict.
[0053] Embodiment
[0054] See Figure 1 , the method for modeling the malicious program propagation model of the cyber-physical system of the distribution network provided by this embodiment includes the following steps:
[0055] A1: Based on the propagation principle of the PC-PLC worm virus, construct a PC-PLC two-layer heterogeneous network model for the distribution network CPS;
[0056] A2: Construct a node state transition diagram;
[0057] A3: Divide the nodes into susceptible nodes, infected nodes, isolated nodes, and immune nodes;
[0058] A4: Establish a system of differential equations according to the node state transition diagram, that is, obtain the malicious program propagation model in the distribution network CPS.
[0059] The system of differential equations established by the node state transition diagram is as follows:
[0060]
[0061]
[0062]
[0063]
[0064]
[0065]
[0066]
[0067] In the system of differential equations, S A (t), I A (t), Q A (t), R A (t), S B (t), I B (t), R B(t) are the numbers of susceptible PC nodes, infected PC nodes, quarantined PC nodes, immune PC nodes, susceptible PLC nodes, infected PLC nodes, and immune PLC nodes at time t; in the differential equation system, β 11 , β 22 , β 12 represent the transmission coefficient of the virus in the PC network, the transmission coefficient of the virus in the PLC network, and the transmission coefficient of the virus across networks respectively. The proportion of infected nodes in the PC network that are quarantined is η, and the recovery rate and immunity rate of infected PC nodes by running patch programs and / or installing antivirus software are γ 1 . The recovery rate of quarantined PC nodes by taking quarantine measures is ω, and the recovery probability of PLC nodes by adopting the security protocol of the industrial control system is γ 2 . When nodes die due to hardware damage or environmental factors, the death rates of PC nodes and PLC nodes are d 1 and d 2 respectively. The time delay for the virus in the PC network to infect nodes in the PLC network is τ; and S A (t), I A (t), Q A (t), R A (t), S B (t), I B (t), R B (t) satisfy: N A (t) = S A (t) + I A (t) + R A (t) + Q A (t) and N B (t) = S B (t) + I B (t) + R B (t).
[0068] See Figure 1 , this embodiment also provides an optimal control method for suppressing the spread of malicious programs in the distribution network cyber-physical system, which includes the following steps:
[0069] S1: Based on the PC-PLC worm virus propagation principle, construct a PC-PLC double-layer heterogeneous network model for the distribution network CPS;
[0070] S2: Construct a node state transition diagram;
[0071] S3: Divide the nodes into susceptible nodes, infected nodes, quarantined nodes, and immune nodes;
[0072] S4: Establish a differential equation system according to the node state transition diagram, that is, a malicious program propagation model in the distribution network CPS;
[0073] S5: Use the anti-virus detection rate of the infected nodes in the PC and PLC networks and the immunity rate among the newly deployed nodes as control variables to construct the objective function of the optimal control model.
[0074] S6: Obtain the Hamiltonian function from the objective function, and solve for the optimal control pair according to the Pontryagin maximum principle to minimize the number of infected nodes in the controlled distribution network and the cost of suppressing the spread of malicious programs.
[0075] The differential equation system in step S4 is the differential equation system in claim 3.
[0076] In step S1, construct the PC-PLC double-layer heterogeneous network model through the following operations: Connect the PC network and the PLC network. The PC network is the upper-layer network, and the PLC network is the lower-layer network to form a double-layer coupled network. In the double-layer coupled network, the PC sends control information to the PLC, and the PLC feeds back status information to the PC.
[0077] In step S3, the susceptible nodes are: nodes in the normal working state, the initial state of all nodes; the infected nodes are: nodes infected by the virus or selected as the attack target by the virus, which will spread the virus to other susceptible nodes; the isolated nodes are nodes infected by the virus but isolated, which will not spread the virus to other susceptible nodes; the immune nodes are: nodes that can resist virus attacks and cannot be spread with the virus.
[0078] In step S5, use the following method to construct the objective function:
[0079] S51: Apply the control strategy in the system during the period [0, t f . Use the Lebesgue square-integrable function u(t) as the control function. The system disinfects the infected nodes and injects immune patches, and increases the proportion of immune nodes among the newly deployed nodes. Let γ 1 = u 1 (t), γ 2 = u 2 (t), (1 - b 1 ) = u 3 (t);
[0080] S52: Calculate the set of control functions: {u i (t) ∈ L 2 [0, t f : 0 ≤ t ≤ t f , 0 ≤ u i (t) ≤ 1, i = 1, 2, 3};
[0081] S53: Let m, n, and p be the weight coefficients of the three control variables, and calculate the cost of injecting immune patches for the PC The cost of injecting immune patches for the PLC Cost of newly deployed PC pre-immunization patch
[0082] S54: Calculate the objective function:
[0083]
[0084] Step S46 solves the optimal control ratio through the following method:
[0085] S61: Calculate:
[0086]
[0087] S62: According to the Pontryagin maximum principle, obtain the corresponding Hamiltonian function:
[0088] τ)I A (t - τ) - u 2 (t)I B (t) - d 2 I B (t)} + λ 7 (t){u 2 (t)I B (t) - d 2 R B (t) - l 2 R B (t)}, where λ i (t)(λ = 1, 2, 3…7) is the co-state variable of the system;
[0089] S63: Define the system characteristic equation when t ∈ [0, t f -τ] as:
[0090]
[0091] S64: Define the system transversality condition as: λ i (t f ) = 0, i = 1, 2, 3, 4, 5, 6, 7;
[0092] S65: Calculate and obtain the optimization condition:
[0093]
[0094] S66: Calculate and obtain the optimal control pair:
[0095]
[0096] In the above embodiments of the present invention, the focus is on constructing a PC-PLC double-layer coupling network model based on the propagation mode of PC-PLC worm viruses, considering situations such as isolation, patch injection, and transmission delay, so as to simulate the propagation of malicious programs in the realistic power distribution network CPS, and can effectively inhibit the propagation of malicious programs.
[0097] The preferred specific embodiments of the present invention have been described in detail above. It should be understood that those of ordinary skill in the art can make many modifications and variations based on the concept of the present invention without creative labor. Therefore, all technical solutions that can be obtained by those skilled in the art in the technical field of the present invention through logical analysis, reasoning, or limited experiments based on the concept of the present invention on the basis of the prior art should fall within the protection scope determined by the claims.
Claims
1. A method for modeling a malicious program propagation model in a cyber - physical system of a distribution network, characterized in that, it includes the following steps: A1: Based on the propagation principle of PC - PLC worm viruses, construct a PC - PLC two - layer heterogeneous network model for the distribution network CPS; A2: Construct a node state transition diagram; A3: Divide the nodes into susceptible nodes, infected nodes, isolated nodes, and immune nodes; A4: Establish a system of differential equations according to the node state transition diagram, that is, obtain the malicious program propagation model in the distribution network CPS; Among them, the system of differential equations established in step A4 according to the node state transition diagram is as follows: In the differential equation system, \(l\) 1 , \(l\) 2 , \(b\) 1 , \(\Lambda\) 1 (t), \(\Lambda\) 2 (t) are respectively the rate at which immune PC nodes lose their immunity, the rate at which immune PLC nodes lose their immunity, the non-immunity rate of PC deployment nodes, the number of PC nodes deployed at time \(t\), and the number of PLC nodes deployed at time \(t\); in the differential equation system, \(S\) A (t), \(I\) A (t), \(Q\) A (t), \(R\) A (t), \(S\) B (t), \(I\) B (t), \(R\) B (t) are respectively the numbers of susceptible PC nodes, infected PC nodes, quarantined PC nodes, immune PC nodes, susceptible PLC nodes, infected PLC nodes, and immune PLC nodes at time \(t\); in the differential equation system, \(\beta\) 11 , \(\beta\) 22 , \(\beta\) 12 respectively represent the transmission coefficient of the virus in the PC network, the transmission coefficient of the virus in the PLC network, and the transmission coefficient of the virus across networks. The proportion of infected nodes in the PC network that are quarantined is \(\eta\). The recovery rate and immunity rate of infected PC nodes by running patch programs and / or installing antivirus software are \(\gamma\) 1 , the recovery rate of quarantined PC nodes is \(\omega\), the recovery probability of PLC nodes by adopting the security protocol of industrial control systems is \(\gamma\) 2 . When nodes die due to hardware damage or environmental factors, the death rates of PC nodes and PLC nodes are \(d\) 1 , \(d\) 2 respectively, and the time delay for the virus in the PC network to infect nodes in the PLC network is \(\tau\); and \(S\) A (t), \(I\) A (t), \(Q\) A (t), \(R\) A (t), \(S\) B (t), \(I\) B (t), \(R\) B (t) satisfy: \(N\) A (t)= \(S\) A (t)+ \(I\) A (t)+ \(R\) A (t)+ \(Q\) A (t) and \(N\) B (t)= \(S\) B (t)+ \(I\) B (t)+ \(R\) B (t).
2. An optimal control method for suppressing malicious program propagation in a cyber - physical system of a distribution network, characterized in that, it includes the following steps: S1: Based on the propagation principle of PC - PLC worm viruses, construct a PC - PLC two - layer heterogeneous network model for the distribution network CPS; S2: Construct a node state transition diagram; S3: Divide the nodes into susceptible nodes, infected nodes, isolated nodes, and immune nodes; S4: Establish a system of differential equations according to the node state transition diagram, that is, obtain the malicious program propagation model in the distribution network CPS; S5: Take the detection rates of infected nodes in the PC and PLC networks and the immunity rate of newly deployed nodes as control variables, and construct the objective function of the optimal control model; S6: Obtain the Hamiltonian function according to the objective function, and solve the optimal control pair according to the Pontryagin maximum principle to minimize the number of infected nodes in the controlled distribution network and minimize the cost of suppressing malicious program propagation.
3. The optimal control method for suppressing malicious program propagation in a cyber - physical system of a distribution network according to claim 2, characterized in that, in step S1, the PC - PLC two - layer heterogeneous network model is constructed through the following operations: Connect the PC network and the PLC network, with the PC network as the upper - layer network and the PLC network as the lower - layer network to form a two - layer coupled network; In the two - layer coupled network, the PC sends control information to the PLC, and the PLC feeds back status information to the PC.
4. The optimal control method for suppressing malicious program propagation in a cyber - physical system of a distribution network according to claim 2, characterized in that, the system of differential equations established in step S4 according to the node state transition diagram is as follows: In the differential equations, S A (t), I A (t), Q A (t), R A (t), S B (t), I B (t), R B (t) are the numbers of susceptible PC nodes, infected PC nodes, quarantined PC nodes, immune PC nodes, susceptible PLC nodes, infected PLC nodes, and immune PLC nodes at time t, respectively. In the differential equations, β 11 , β 22 , β 12 represent the transmission coefficient of the virus in the PC network, the transmission coefficient of the virus in the PLC network, and the transmission coefficient of the virus across networks, respectively. The proportion of infected nodes in the PC network that are quarantined is η. The recovery rate and immunity rate of infected PC nodes by running patch programs and / or installing antivirus software are γ 1 . The recovery rate of quarantined PC nodes is ω. The recovery probability of PLC nodes by adopting the security protocol of the industrial control system is γ 2 . When nodes die due to hardware damage or environmental factors, the death rates of PC nodes and PLC nodes are d 1 and d 2 , respectively. The time delay for the virus in the PC network to infect nodes in the PLC network is τ. And S A (t), I A (t), Q A (t), R A (t), S B (t), I B (t), R B (t) satisfy: N A (t) = S A (t) + I A (t) + R A (t) + Q A (t) and N B (t) = S B (t) + I B (t) + R B (t).
5. The optimal control method for suppressing malicious program propagation in a cyber - physical system of a distribution network according to claim 2, characterized in that, in step S3, the susceptible nodes are: nodes in a normal working state, the initial state of all nodes; Infected nodes are: nodes infected by the virus or selected as attack targets by the virus, which will spread the virus to other susceptible nodes; Isolated nodes are nodes infected by the virus but isolated, which will not spread the virus to other susceptible nodes; Immune nodes are: nodes that can resist virus attacks and cannot be spread by the virus.
6. The optimal control method for suppressing malicious program propagation in a cyber - physical system of a distribution network according to claim 2, characterized in that, in step S5, the following method is used to construct the objective function: S51: [0, t f During this period, apply the control strategy in the system. Using the Lebesgue square-integrable function u(t) as the control function, the system disinfects the infected nodes and injects immune patches, and increases the proportion of immune nodes among the newly deployed nodes, making γ 1 = u 1 (t), γ 2 = u 2 (t), (1 - b 1 ) = u 3 (t); S52: Calculate the control function set: {u i (t) ∈ L 2 [0, t f : 0 ≤ t ≤ t f , 0 ≤ u i (t) ≤ 1, i = 1, 2, 3}; S53: m, n, and p are the weight coefficients of three control variables, and the cost of PC immune patch injection is calculated Cost of PLC immune patch injection Cost of newly launched PC pre-immune patch S54: Calculate the objective function:
7. The optimal control method for suppressing the spread of malicious programs in the cyber-physical system of the distribution network according to claim 2, characterized in that, in step S6, the optimal control ratio is solved by the following method: S61: Calculate: S62: According to the Pontryagin maximum principle, obtain the corresponding Hamiltonian function: λ i (t) (λ = 1, 2, 3…7) is the co-state variable of the system; S63: Define that when \(t\in[0,t f -\tau]\), the characteristic equation of the system is: S64: Define the system transverse condition as: λ i (t f ) = 0, i = 1, 2, 3, 4, 5, 6, 7; S65: Calculate to obtain the optimization condition: S66: Calculate and obtain the optimal control pair: