A Malicious Program Control Method for a Cyber-Physical System of a PC-PLC Distribution Network

By building a malicious program propagation model for the information physics system of the PC-PLC distribution network, and using the optimal control strategy, the security problems caused by the propagation of malicious programs in the power system are solved, effective control of malicious programs is achieved, and the stability and security of the system are improved.

CN115643579BActive Publication Date: 2025-08-05GUANGZHOU UNIVERSITY
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210896796.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-28
Publication Date
2025-08-05
Estimated Expiration
2042-07-28

AI Technical Summary

Technical Problem

Modern power information physics systems may be subject to malicious program network attacks at all links, resulting in damage to system availability, integrity and confidentiality. In severe cases, it may lead to paralysis of the power network, and it is difficult for existing technology to effectively defend and control the spread of malicious programs.

Method used

A malicious program propagation model for the information physics system of PC-PLC distribution network based on nonlinear time-delay heterogeneous model is constructed. By dividing network nodes, building state transfer graphs, constructing differential equation systems, proposing control strategies, constructing Lagrangian functions and Hamiltonian functions, the optimal control pair is finally solved to achieve optimal control of malicious programs.

Benefits of technology

It provides a solution to effectively control the propagation of malicious programs at the minimum cost, improves the network security and stability of the power system and prevents the power network from being paralyzed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115643579B_ABST
    Figure CN115643579B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for controlling malicious programs in a cyber-physical system based on a PC-PLC distribution network. The method comprises the following steps: S1: dividing PC and PLC network nodes based on real-world problem analysis; S2: constructing a network node state transition diagram; S3: constructing a set of differential equations for the malicious program propagation model; S4: proposing a control strategy; S5: constructing a cost function; S6: constructing a Lagrangian function and introducing Lagrangian multipliers; S7: constructing a Hamiltonian function; S8: constructing a set of covariate equations and a transversality condition; and S9: solving an optimal control pair. The present invention achieves optimal control effects at minimal cost by constructing a cost function for controlling malicious programs, constructing Hamiltonian equations based on the model's differential equations and the cost function, and solving the set of covariate equations and the optimal control pair.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of wireless rechargeable sensor networks, and in particular to a method for controlling malicious programs in a cyber-physical system of a PC-PLC power distribution network, which performs modeling and optimal control of the spread of malicious programs in a wireless rechargeable sensor network of an electric power system. Background Art

[0002] In recent years, with the rapid development of wireless rechargeable sensor network technology, its application has become increasingly widespread, and can be found in military, agriculture, industry, transportation, information equipment and other fields. As the foundation of national economic development, the power industry needs to rapidly respond to social electricity demand while ensuring real-time, secure and flexible information exchange, and achieving rational resource optimization and efficient scheduling. Traditional power grids are no longer able to meet the needs of power development. Modern power systems have evolved into power cyber-physical systems that deeply integrate power and information networks.

[0003] Modern power cyber-physical systems (CPSs) integrate a cyber layer with the physical layer of traditional power grids. These systems, through interconnected communication via a large number of sensors, enable real-time perception, detection, and processing of information within their target areas. However, while power grids benefit from CPSs—making modern grid operations more economical and efficient—they also face potential security risks posed by intelligent interconnection. Modern power cyber-physical systems are vulnerable to cyberattacks from malicious programs at every stage of power generation, transmission, distribution, and consumption. These attacks could compromise system availability, integrity, and confidentiality to varying degrees, and in severe cases, could even paralyze the entire power grid. Therefore, the security of modern power networks cannot be ignored.

[0004] Based on the potential information security threats of modern power grids, taking into full consideration the propagation and infection mechanisms of malicious programs, it is an important topic today to establish a practical network model to analyze and study the optimal control strategy to inhibit the spread of malicious programs and ensure the security of network information. Summary of the Invention

[0005] In order to prevent and deal with the adverse effects of malicious programs on the information of the power cyber-physical system, the present invention provides a PC-PLC distribution network cyber-physical system malicious program propagation model based on a nonlinear time-delay heterogeneous model to solve the above problems.

[0006] The present invention provides the following technical solutions:

[0007] A method for controlling malicious programs in a PC-PLC distribution network cyber-physical system, comprising the following steps:

[0008] S1: Divide PC and PLC network nodes based on real-world problem analysis;

[0009] S2: Construct network node state transition graph;

[0010] S3: Constructing a set of differential equations for the malware propagation model;

[0011] S4: Propose control strategies;

[0012] S5: Construct cost function;

[0013] S6: Construct Lagrangian function and introduce Lagrangian multiplier;

[0014] S7: Construct Hamiltonian function;

[0015] S8: Constructing the system of equations of covariates and transversality conditions;

[0016] S9: Solve for the optimal control pair.

[0017] Preferably, in step S1, the computer PC network and the programmable controller PLC network are respectively denoted as network A and network B. Each device in network A and network B corresponds to a node, and the nodes are classified into infected nodes, susceptible nodes, immune nodes, and isolated nodes according to the degree of infection. Preferably, in step S2, the most important k words are selected from all texts x in T, including adversarial samples and clean samples, and are sorted, denoted as C(x).

[0018] Preferably, in step S3, a differential equation group is constructed based on the network node state transition diagram, specifically as follows:

[0019]

[0020] Where θ xy (t) is defined as the probability that a susceptible node has an adjacent infected node, x = 1, 2; y = 1, 2, where "1" represents a PC network and "2" represents a PLC network, that is:

[0021] θ 11 (t) represents the probability that a PC susceptible node is adjacent to a PC infected node, θ 12 (t) represents the probability that a PC susceptible node is adjacent to a PLC infected node, θ 21 (t) represents the probability that a PLC susceptible node is adjacent to a PC infected node, θ 22 (t) represents the probability that a PLC-susceptible node is adjacent to a PLC-infected node, as follows:

[0022]

[0023]

[0024] are the number of susceptible nodes (S), infected nodes (I), isolated nodes (Q), and immune nodes (R) with PC network degree (i, j) at time t, are the number of susceptible nodes, infected nodes, and immune nodes with PLC network degree (k, l) at time t, is the total number of nodes with degree (i, j) in the PC network, is the total number of nodes in the PLC network with degree (k, l); the degree of a PC node is represented by (i, j), which means that a node in the PC network is connected to i other PC nodes and j PLC nodes; the degree of a PLC node is represented by (k, l), which means that a node in the PLC network is connected to k other PLC nodes and l PC nodes. At the same time, the following relationship is satisfied at any time:

[0025]

[0026] γ1 and γ2 are the virus detection rates of infected nodes in PC and PLC networks respectively; μ1 is the birth rate and death rate of PC network nodes, and μ2 is the birth rate and death rate of PLC network nodes; b is the birth ratio of immune nodes in PC network; 1-b is the birth ratio of susceptible nodes in PC network; θ1 is the infection rate of susceptible nodes in PC network caused by PLC network; θ2 is the infection rate of susceptible nodes in PLC network caused by PC network; δ1 is the isolation rate of infected nodes in PC network; ω1 is the recovery rate of isolated nodes in PC network; η1 and η2 are the immunity loss rates of immune nodes in PC and PLC networks; τ1 is the delay for immune nodes in PC network to lose immunity, and τ2 is the delay for immune nodes in PLC network to lose immunity; β1, β2, β3, β4, c, d, g, and h are all normal numbers.

[0027] More preferably, in step S4, the control strategy includes detecting and killing infected nodes and injecting immune patches, increasing the removal and isolation of infected nodes, detecting and killing isolated nodes and injecting immune patches, and increasing the proportion of immune nodes in newly deployed nodes;

[0028] Select γ1, γ2, b, δ1, ω1 as the optimization control variables, and the feasible domain of the optimization control variables is U = {u = (γ1, γ2, b, δ1, ω1)|, 0≤γ1≤1, 0≤γ2≤1, 0≤b≤1, 0≤δ1≤1, 0≤ω1≤1, t∈[0,t f ]}, t f Indicates the terminal time of this optimal control.

[0029] More preferably, in step S5, the cost function is represented by J(γ1,γ2,b,δ1,ω1) and is determined by the following formula:

[0030]

[0031] Among them u1(t)=γ1, u2(t)=γ2, u3(t)=b, u4(t)=δ1, u5(t)=ω1.

[0032] More preferably, in S6, the constructed Lagrangian function is as follows:

[0033]

[0034] More preferably, in S7, the constructed Hamiltonian function is as follows:

[0035]

[0036]

[0037] Among them, λ i (t), (i=1,2,3,4,5,6,7) are the co-state variables of optimal control.

[0038] More preferably, in step S8, the cross-section condition is constructed as follows:

[0039] λ i (t f )=0,i=1,2,3,4,5,6,7.

[0040] More preferably, in S8, the co-state equation is:

[0041]

[0042] Among them, x1, x2, x3, x4, x5, x4, x7 correspond to Seven variables. More preferably, in S9, the final optimal control pair of the system is:

[0043]

[0044] The beneficial effects of the present invention are:

[0045] This paper takes current realities into account to simulate the spread of malware in wireless rechargeable sensor networks within the cyber-physical systems of PC-PLC power distribution networks. The paper considers the nonlinear infection rate, emphasizing that the ability of malware to infect sensor nodes is not fixed. The bilinear and standard incidence rates assumed in earlier studies were both extreme ideals. It also considers heterogeneity, emphasizing that the rechargeable sensors used in current power grids are often heterogeneous. Heterogeneous rechargeable sensors, due to their excellent network stability, reliability, and survivability, have been widely used in complex scenarios. It also considers time lag, emphasizing that in reality, malware infection of immune sensor nodes does not immediately render them invulnerable; rather, it often involves a delay, which varies across networks. This paper proposes an optimal control scheme for controlling malware propagation in a PC-PLC power distribution network cyber-physical system. This scheme constructs a cost function for controlling malware, constructs the Hamiltonian equations based on the model's differential equations and the cost function, and solves a set of co-state equations and an optimal control pair to achieve optimal control results at minimal cost. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] The present invention is further described with reference to the accompanying drawings. However, the embodiments in the accompanying drawings do not constitute any limitation to the present invention. A person skilled in the art can obtain other drawings based on the following drawings without creative effort.

[0047] Figure 1 This is a flow chart of a method for controlling malicious programs in a PC-PLC power distribution network cyber-physical system according to the present invention;

[0048] Figure 2 It is a state transition diagram of the PC and PLC wireless rechargeable sensor network of the present invention. DETAILED DESCRIPTION

[0049] The following is a further detailed description of the method for controlling malicious programs in the PC-PLC distribution network cyber-physical system in conjunction with specific embodiments. These embodiments are only used for comparison and explanation purposes, and the present invention is not limited to these embodiments.

[0050] Example

[0051] In order to prevent and respond to the adverse effects of malicious programs on the information of the power cyber-physical system, an embodiment of the present invention provides a PC-PLC distribution network cyber-physical system malicious program propagation model based on a nonlinear time-delay heterogeneous model, and provides a corresponding optimal control method.

[0052] like Figure 1 As shown, the method for controlling malicious programs in the PC-PLC distribution network cyber-physical system includes the following steps:

[0053] S1: Divide PC and PLC network nodes based on real-world problem analysis;

[0054] A malicious program propagation model for the PC-PLC distribution network cyber-physical system is constructed. The computer network (PC network) and the programmable controller network (PLC network) are recorded as network A and network B. Each device in network A and network B corresponds to a node, and according to the degree of infection of the node, it is classified into infected nodes, susceptible nodes, immune nodes and isolated nodes.

[0055] S2: Construct network node state transition graph;

[0056] Build as Figure 2 The state transition diagram of a PC and PLC wireless rechargeable sensor network is shown. Assume that the PC network (A) includes susceptible nodes (S), infected nodes (I), isolated nodes (Q), and immune nodes (R), and the PLC network (B) includes susceptible nodes (S), infected nodes (I), and immune nodes (R), with a total number of network nodes N. Assume that the state node birth rate of the PC network is μ1, and newly born state nodes are both susceptible and immune nodes, where the proportion of susceptible nodes is 1-b and the proportion of immune nodes is b. Assume that the state node birth rate of the PLC network is μ2, and all newly born nodes are susceptible nodes.

[0057] Define γ1 and γ2 as the virus detection rates of infected nodes in PC and PLC networks, respectively; μ1 is the birth rate and death rate of nodes in PC network, and μ2 is the birth rate and death rate of nodes in PLC network; b is the birth ratio of immune nodes in PC network; 1-b is the birth ratio of susceptible nodes in PC network; θ1 is the infection rate of susceptible nodes in PC network caused by PLC network; θ2 is the infection rate of susceptible nodes in PLC network caused by PC network; δ1 is the isolation rate of infected nodes in PC network; ω1 is the recovery rate of isolated nodes in PC network; η1 and η2 are the immunity loss rates of immune nodes in PC and PLC networks, respectively; τ1 is the delay for immune nodes in PC network to lose immunity, and τ2 is the delay for immune nodes in PLC network to lose immunity; β1, β2, β3, β4, c, d, g, and h are all normal numbers.

[0058] For susceptible nodes on the PC network, as new nodes are added, some may become infected by infected nodes on the PC network, becoming infected nodes. They may also become infected by infected nodes on the PLC network, becoming infected nodes. Some may even die and be removed. For infected nodes on the PC network, some will be isolated, some will be made immune through virus detection and patching, and some may even be removed due to death. For isolated nodes on the PC network, some will recover through treatment and become immune, while others may be removed due to death. For immune nodes on the PC network, as new nodes are added, some may lose their immunity and become susceptible, while others may even be removed due to death.

[0059] As new nodes are added to the PLC network, some susceptible nodes may become infected by infected nodes on the PLC network, or infected by infected nodes on the PC network. Some may even die and be removed. Some infected nodes on the PLC network will be rendered immune through virus detection and patching, while others may be removed due to death. Some immune nodes on the PLC network may lose their immunity and become susceptible, while others may even be removed due to death.

[0060] Define θ xy (t) is the probability that a susceptible node has an adjacent infected node, x = 1, 2; y = 1, 2, where "1" represents a PC network and "2" represents a PLC network, that is:

[0061] θ 11 (t) represents the probability that a PC susceptible state node is adjacent to a PC infected state node, θ 12 (t) represents the probability that a PC susceptible state node is adjacent to a PLC infected state node, θ 21 (t) represents the probability that a PLC susceptible state node is adjacent to a PC infected state node, θ 22 (t) represents the probability that a PLC susceptible state node is adjacent to a PLC infected state node, as follows:

[0062]

[0063] The degree of a state node in a PC network is defined as (i, j), which means that a state node in the PC network is connected to i state nodes in other PC networks and j state nodes in the PLC network. The degree of a state node in a PLC network is defined as (k, l), which means that a state node in the PLC network is connected to k state nodes in other PLC networks and l state nodes in the PC network. At the same time, the following relationship is satisfied at any time:

[0064]

[0065] S3: Constructing a set of differential equations for the malware propagation model;

[0066] The differential equation for the state transition of a PC-PLC network node is as follows:

[0067]

[0068]

[0069] are the number of susceptible nodes (S), infected nodes (I), isolated nodes (Q), and immune nodes (R) with PC network degree (i, j) at time t, are the number of susceptible nodes, infected nodes, and immune nodes with PLC network degree (k, l) at time t, is the total number of nodes with degree (i, j) in the PC network, is the total number of nodes with degree (k, l) in the PLC network.

[0070] S4: Propose control strategies;

[0071] In order to effectively resist attacks from malicious programs, several measures have been adopted, including detecting and killing infected nodes and injecting immune patches, increasing the removal and isolation of infected nodes, detecting and killing isolated nodes and injecting immune patches, and increasing the proportion of immune nodes in newly deployed nodes.

[0072] In order to achieve the optimization goal, the Pontryagin maximum principle is used to select γ1, γ2, b, δ1, and ω1 as optimization control variables. The feasible domain of the optimization control variables is U = {u = (γ1, γ2, b, δ1, ω1)|, 0≤γ1≤1, 0≤γ2≤1, 0≤b≤1, 0≤δ1≤1, 0≤ω1≤1, t∈[0,t f ]}, t f Indicates the terminal time of this optimal control.

[0073] S5: Construct cost function;

[0074] The cost function is represented by J(γ1,γ2,b,δ1,ω1) and is determined by the following formula:

[0075]

[0076] Where u1(t) = γ1, u2(t) = γ2, u3(t) = b, u4(t) = δ1, u5(t) = ω1. S6: Construct Lagrangian function and introduce Lagrangian multiplier;

[0077] The constructed Lagrangian function is as follows:

[0078]

[0079] S7: Construct Hamiltonian function;

[0080] The constructed Hamiltonian function is as follows:

[0081]

[0082]

[0083] Among them, λ i (t), (i=1,2,3,4,5,6,7) are the co-state variables of optimal control.

[0084] S8: Constructing the system of equations of covariates and transversality conditions;

[0085] The co-state equation is:

[0086]

[0087] In the above formula, x1, x2, x3, x4, x5, x4, x7 correspond to Seven variables.

[0088] The constructed transversality conditions are as follows:

[0089] λ i (t f )=0,i=1,2,3,4,5,6,7.

[0090] Among them, the optimization conditions are:

[0091]

[0092] Right now:

[0093]

[0094] S9: solve the optimal control pair;

[0095] The final optimal control pair of the system is obtained as follows:

[0096]

[0097] The above-mentioned embodiment of the present invention focuses on establishing a malware propagation model for the cyber-physical system of the PC-PLC power distribution network. This model fully considers the current reality and is used to simulate the spread of malware in the wireless rechargeable sensor network of the cyber-physical system of the PC-PLC power distribution network. The model takes into account factors such as nonlinear infection rate, heterogeneity, and time lag. The present invention controls the established malware propagation model for the cyber-physical system of the PC-PLC power distribution network and provides an optimal control scheme. It constructs a cost function for controlling malware, constructs Hamiltonian equations based on the differential equations of the model and the cost function, solves the co-state equations and the optimal control pair, and achieves a better control effect at the lowest cost.

[0098] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the scope of protection of the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the essence and scope of the technical solutions of the present invention.

Claims

1. A method for controlling malicious programs in a PC-PLC distribution network cyber-physical system, characterized in that: The following steps are involved: S1: Divide PC and PLC network nodes based on real-world problem analysis; S2: Construct network node state transition graph; S3: Constructing a set of differential equations for the malware propagation model; S4: Propose control strategies; S5: Construct cost function; S6: Construct Lagrangian function and introduce Lagrangian multiplier; S7: Construct Hamiltonian function; S8: Constructing the system of equations of covariates and transversality conditions; S9: solve the optimal control pair; In step S5, the cost function is represented by J(γ1,γ2,b,δ1,ω1) and is determined by the following formula: Among them, u1(t)=γ1,u2(t)=γ2,u3(t=b,u4(t=δ1,u5(t=ω1),γ1,γ2 are the virus detection and killing rates of infected nodes in PC and PLC networks respectively, b is the birth rate of immune nodes in PC network,δ1 is the isolation rate of infected nodes in PC network,ω1 is the recovery rate of isolated nodes in PC network; is the number of infected nodes (I) with PC network degree (i, j) at time t, is the number of infected nodes with degree (k, l) in the PLC network at time t, where c1, c2, c3, c4, and c5 are all positive numbers; f represents the terminal time of this optimal control; In S9, the final optimal control pair of the system is: Among them, λ i (t), (i=1,2,3,4,5,6,7) are the optimal control co-state variables, μ1 is the state node birth rate of the PC network, is the total number of nodes with degree (i, j) in the PC network; is the number of isolated nodes with degree (i, j) in the PC network at time t.

2. The method for controlling malicious programs in a PC-PLC distribution network cyber-physical system according to claim 1, characterized in that: In step S1, the computer PC network and the programmable controller PLC network are respectively recorded as network A and network B. Each device in network A and network B corresponds to a node, and according to the degree of infection of the node, it is classified into infected node, susceptible node, immune node and isolated node.

3. The method for controlling malicious programs in a PC-PLC distribution network cyber-physical system according to claim 1, characterized in that: In step S3, a differential equation group is constructed based on the network node state transition diagram, specifically as follows: Where θ xy (t) is defined as the probability that a susceptible node has an adjacent infected node, x = 1, 2; y = 1, 2, where "1" represents a PC network and "2" represents a PLC network, that is: θ 11 (t) represents the probability that a PC susceptible node is adjacent to a PC infected node, θ 12 (t) represents the probability that a PC susceptible node is adjacent to a PLC infected node, θ 21 (t) represents the probability that a PLC susceptible node is adjacent to a PC infected node, θ 22 (t) represents the probability that a PLC-susceptible node is adjacent to a PLC-infected node, as follows: are the number of susceptible nodes (S), infected nodes (I), isolated nodes (Q), and immune nodes (R) with PC network degree (i, j) at time t, are the number of susceptible nodes, infected nodes, and immune nodes with PLC network degree (k, l) at time t, is the total number of nodes with degree (i, j) in the PC network, is the total number of nodes in the PLC network with degree (k, l); the degree of a PC node is represented by (i, j), which means that a node in the PC network is connected to i other PC nodes and j PLC nodes; the degree of a PLC node is represented by (k, l), which means that a node in the PLC network is connected to k other PLC nodes and l PC nodes. At the same time, the following relationship is satisfied at any time: γ1 and γ2 are the virus detection rates of infected nodes in PC and PLC networks, respectively; μ1 is the birth rate and death rate of nodes in PC network, and μ2 is the birth rate and death rate of nodes in PLC network; b is the birth rate of immune nodes in PC network; 1-b is the birth rate of susceptible nodes in the PC network; θ1 is the infection rate of susceptible nodes in the PC network caused by the PLC network; θ2 is the infection rate of susceptible nodes in the PLC network caused by the PC network; δ1 is the isolation rate of infected nodes in the PC network; ω1 is the recovery rate of isolated nodes in the PC network; η1 and η2 are the loss of immunity rates of immune nodes in the PC and PLC networks; τ1 is the delay for immune nodes in the PC network to lose their immunity, and τ2 is the delay for immune nodes in the PLC network to lose their immunity; β1, β2, β3, β4, c, d, g, and h are all normal numbers.

4. The method for controlling malicious programs in a PC-PLC distribution network cyber-physical system according to claim 3, characterized in that: In step S4, the control strategy includes detecting and killing infected nodes and injecting immune patches, increasing the removal and isolation of infected nodes, detecting and killing isolated nodes and injecting immune patches, and increasing the proportion of immune nodes in newly deployed nodes; Select γ1, γ2, b, δ1, ω1 as the optimization control variables, and the feasible domain of the optimization control variables is U = {u = (γ1, γ2, b, δ1, ω1)|, 0≤γ1≤1, 0≤γ2≤1, 0≤b≤1, 0≤δ1≤1, 0≤ω1≤1, t∈[0,t f ]}, t f Indicates the terminal time of this optimal control.

5. The method for controlling malicious programs in a PC-PLC distribution network cyber-physical system according to claim 4, characterized in that: In S6, the constructed Lagrangian function is as follows:

6. The method for controlling malicious programs in a PC-PLC distribution network cyber-physical system according to claim 5, characterized in that: In step S7, the constructed Hamiltonian function is as follows: Among them, λ i (t), (i=1,2,3,4,5,6,7) are the co-state variables of optimal control.

7. The method for controlling malicious programs in a PC-PLC distribution network cyber-physical system according to claim 4, characterized in that: In step S8, the cross-section conditions are as follows: λ i (t f )=0,i=1,2,3,4,5,6,7。 8. The method for controlling malicious programs in a PC-PLC distribution network cyber-physical system according to claim 7, characterized in that: In step S8, the co-state equation is: Among them, x1, x2, x3, x4, x5, x6, x7 correspond to Seven variables.

Citation Information

Patent Citations

  • Malicious program propagation modeling and optimal control method for charging wireless sensor network

    CN113015169A