A data flow-oriented traceability method for power monitoring data
By dividing the device end and partitioning on the power monitoring big data cloud, and using cloud databases to identify and analyze attack data, the traceability difficulties caused by address tampering in power monitoring data flow are solved, and rapid traceability and security management are achieved.
Patent Information
- Application Number
- CN202211418861.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-14
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2042-11-14
AI Technical Summary
In the prior art, the power monitoring data is tampered with during the data flow, making it difficult to accurately trace the origin of the attack data.
By dividing the device end into blocks and partitions on the power monitoring big data cloud, using cloud databases to identify attack data, extract public network IP addresses, merge and analyze data similarity and residence time, generate comparison signals, mark abnormal blocks and device ends, and perform real-time monitoring and traffic management.
It effectively improves the traceability speed and security of power monitoring data, can quickly find attack data sources, and ensures the security of the power platform.
Smart Images

Figure CN115733679B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of attack data tracing, and in particular is a method for tracing the source of power monitoring data oriented to data flow. Background Art
[0002] Tracing the source refers to looking upstream for the source of the data, which is a metaphor for seeking the historical roots.
[0003] The invention with publication number CN112822213A provides a method for collecting evidence and tracing the source of an attack on an electric power monitoring system, the method comprising: collecting network flow data in the electric power monitoring system; performing feature analysis on the network flow data to obtain feature parameters of the network flow data; if the feature parameters match abnormal feature parameters in a preset database, it is determined that a network attack exists, and the network data flow is traced. The embodiment of the present application can perform feature analysis on the network flow data to obtain feature parameters, and when the feature parameters match abnormal feature parameters in a preset database, it is determined that a network attack exists, and the source can be traced, thereby simply and effectively ensuring the security of the electric power monitoring system.
[0004] During the data flow process, a large amount of data will be generated. The data is too messy and the capacity is too large. In the power monitoring data process, a large amount of attack data will be generated. However, because the data is too messy, it is difficult to find the source of the corresponding attack data. The existing traceability method only traces the source based on the address information of the corresponding data, but some criminals will tamper with the address information within the attack data, making it difficult to find the source of the corresponding attack data. Summary of the Invention
[0005] The present invention aims to solve at least one of the technical problems existing in the prior art; to this end, the present invention proposes a traceability method for power monitoring data oriented to data flow, which is used to solve the technical problem that when tracing is only based on the address information of the corresponding data, some criminals will tamper with the address information within the attack data, making it difficult to find the traceability source of the corresponding attack.
[0006] To achieve the above-mentioned purpose, according to an embodiment of the first aspect of the present invention, a method for tracing the source of power monitoring data for data flow is proposed, comprising the following steps:
[0007] S1. Based on the power monitoring big data cloud, multiple groups of different devices are divided into blocks. Multiple groups of devices belonging to the same network broadband are divided into a block. Multiple blocks belonging to the same power monitoring area are divided into the same partition. Different partitions, blocks, and devices are marked in sequence.
[0008] S2. Identify attack data during data flow through the cloud database and find the corresponding sending partition by extracting the public IP address of the attack data;
[0009] S3. Merge and analyze the data sent by different blocks within the partition, merge and analyze the sent data with the attack data, obtain the similarity of the sent data, compare the similarity with a preset value, and generate a corresponding comparison signal. Process the data based on the number of times the comparison signal exists and the residence time of the sent data, and mark the corresponding block as an abnormal block based on the processing result;
[0010] S4. Monitor different device terminals within the abnormal block, check the monitoring data sent by different device terminals during the monitoring period, and compare this monitoring data with the attack data. According to the comparison results, mark different device terminals differently. If there is no comparison result, monitor the traffic of different device terminals, and manage the specified device terminals according to the monitoring results.
[0011] Preferably, in step S2, the specific method of identifying the attack data is:
[0012] S21. Compare each set of input data, extract the corresponding virus partition from the cloud database, and compare each set of data with the virus data within the virus partition to obtain the overlap degree CH. When CH>X1, where H1 is a preset value (the specific value is determined by the operator), the data is marked as data to be monitored. Otherwise, no processing is performed;
[0013] S22. Perform real-time monitoring on the data stream that has been marked as data to be monitored to check whether the data stream has any attack behaviors such as code tampering, node attack, network monitoring, and password intrusion. If the above behaviors exist, mark the data stream as attack data; otherwise, do not mark it.
[0014] Preferably, in step S3, the specific method of combining the sent data with the attack data for analysis is:
[0015] S31, limit the monitoring period T1, obtain the data sent by all blocks in this monitoring period T, and compare the sent data with the attack data to obtain the similarity XS i-k , where i represents different data, k represents different blocks, and the similarity XS i-k Compare with the preset parameter Y1, when XS i-k When >Y1, the data is marked as abnormal data and an abnormal similarity signal is generated. Otherwise, no signal is generated.
[0016] S32. Obtain the number of times abnormal similar signals appear within the monitoring period T and mark it as CSk , and then mark the total length of time that several groups of abnormal data stay as SS k , where k represents different blocks, using Get block determination parameter PD k , where C1 and C2 are preset fixed coefficient factors;
[0017] S33, PD k Compare with the preset parameter Y2, Y2 is the preset parameter, the specific value is determined by the operator based on experience, when PD k When Y2 is higher than Y2, the block is determined to be an abnormal block; otherwise, the block is determined to be a normal block.
[0018] Preferably, in step S4, the specific method of comparing the monitoring data with the attack data is:
[0019] S41, determine the monitoring time period T2, T2 is 5h, extract the attack data, and mark this attack data as the data to be compared, and compare all the monitoring data that appear in the monitoring time period T2 with the data to be compared in turn to obtain the comparison parameter BDC e , where e represents the monitoring data sent by different devices, and the comparison parameter BDC e Compare with the preset parameter Y3, where Y3 takes a value of 98%, and check whether to ban the corresponding device or mark it as a device to be monitored based on the comparison result;
[0020] S42. The data sent by the monitored equipment is transmitted through a special network channel, and the corresponding monitoring software is used to monitor the special network channel in real time. If corresponding virus data or attack data appears, the device end transmitting the data is directly blocked using the method of step S411, thereby fully improving the traceability effect of the power monitoring data and being able to quickly find the corresponding attack data from the transmitted big data.
[0021] Preferably, in step S41, the comparison parameter BDC e The specific method of comparing with the preset parameter Y3 is:
[0022] S411, when BDC e When the value is ≥Y3, the device sending the corresponding monitoring data will be directly marked as an abnormal device, and the MAC address of the abnormal device will be obtained and added to the blacklist. The data sent by this MAC address will no longer be received. At the same time, this MAC address will be compared with the MAC parameters stored in the cloud. If there is no comparison result, it means that this MAC address has been modified. Then the network node number of the corresponding device will be obtained and this network node number will be disabled.
[0023] S412, when BDCe When LLx is less than Y3, the flow rate of different equipment ends is monitored, and the monitoring time period T3 is selected, T3 takes a value of 2h, and the flow parameters generated by different equipment ends are marked as LLx, where x represents different equipment ends. The flow parameter LLx is compared with the preset parameter Y4, where the specific value of Y4 is determined by the operator. When LLx is greater than Y4, this equipment end is marked as a device to be monitored, otherwise, it is not marked.
[0024] Compared with the prior art, the present invention has the following beneficial effects: based on the power monitoring big data cloud, multiple groups of different device terminals are sequentially divided, multiple groups of devices belonging to the same network broadband are divided into a block, and different partitions, different blocks, and different device terminals are sequentially marked. Attack data in the data flow process is identified through the cloud database, the corresponding sending partition is found, and the data sent by different blocks in the partition are merged, processed and analyzed to obtain the similarity of the sent data. The similarity is then compared with a preset value, and a corresponding comparison signal is generated. Processing is performed based on the number of times the comparison signal exists and the residence time of the sent data. According to the processing result, the corresponding block is marked as an abnormal block, and different device terminals within the abnormal block are monitored. The monitoring data sent by different device terminals during the monitoring period is checked and compared with the attack data. The traffic of different device terminals is monitored. According to the monitoring results, the designated device terminals are managed, and the traceability effect of the power monitoring data is fully improved. The corresponding attack data can be quickly found from the transmitted big data, which not only effectively improves the traceability speed of the corresponding attack speed data, but also fully ensures the security of the power platform. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 Schematic diagram of the process of the present invention. DETAILED DESCRIPTION
[0026] The technical solutions of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0027] Example 1
[0028] See also Figure 1 , this application provides a method for tracing the source of power monitoring data for data flow, including the following steps:
[0029] S1. Based on the power monitoring big data cloud, multiple groups of different devices are divided into blocks. Multiple groups of devices belonging to the same network broadband are divided into a block. Multiple blocks belonging to the same power monitoring area are divided into the same partition. Different partitions, blocks, and devices are marked in sequence.
[0030] S2. Identify attack data during data flow through the cloud database, extract the public IP address of the attack data, and find the corresponding sending partition. The specific method for identifying attack data is as follows:
[0031] S21. Compare each set of input data, extract the corresponding virus partition from the cloud database, and compare each set of data with the virus data within the virus partition to obtain the overlap degree CH. When CH>X1, where H1 is a preset value (the specific value is determined by the operator), the data is marked as data to be monitored. Otherwise, no processing is performed;
[0032] S22. Monitor the data stream marked as data to be monitored in real time to check whether the data stream contains any attack behaviors such as code tampering, node attack, network eavesdropping, and password intrusion. If any of the above behaviors are found, mark the data stream as attack data; otherwise, do not mark it.
[0033] S3. Merge and analyze the data sent by different blocks within the partition, merge and analyze the sent data with the attack data, obtain the similarity of the sent data, compare the similarity with the preset value, and generate a corresponding comparison signal. Process the data based on the number of times the comparison signal exists and the residence time of the sent data. Mark the corresponding block as an abnormal block based on the processing result. The specific method of merging and analyzing the sent data with the attack data is as follows:
[0034] S31, limit the monitoring period T1, T1 takes a value of 1h, obtain the data sent by all blocks in this monitoring period T, and compare the sent data with the attack data to obtain the similarity XS i-k , where i represents different data, k represents different blocks, and the similarity XS i-k Compare with the preset parameter Y1. The specific value of Y1 is determined by the operator based on experience. i-k When >Y1, the data is marked as abnormal data and an abnormal similarity signal is generated. Otherwise, no signal is generated.
[0035] S32. Obtain the number of times abnormal similar signals appear within the monitoring period T and mark it as CS k , and then mark the total length of time that several groups of abnormal data stay as SS k , where k represents different blocks, using Get block determination parameter PD k , where C1 and C2 are preset fixed coefficient factors;
[0036] S33, PD k Compare with the preset parameter Y2, Y2 is the preset parameter, the specific value is determined by the operator based on experience, when PD k When Y2 is higher than Y2, the block is judged as an abnormal block, otherwise, the block is judged as a normal block;
[0037] S4. Monitor different device terminals within the abnormal block, check the monitoring data sent by different device terminals during the monitoring period, and compare the monitoring data with the attack data. Different device terminals are marked differently based on the comparison results. If no comparison results exist, traffic monitoring is performed on different device terminals. Based on the monitoring results, the designated device terminals are managed. The specific method for comparing the monitoring data with the attack data is as follows:
[0038] S41, determine the monitoring time period T2, T2 is 5h, extract the attack data, and mark this attack data as the data to be compared, and compare all the monitoring data that appear in the monitoring time period T2 with the data to be compared in turn to obtain the comparison parameter BDC e , where e represents the monitoring data sent by different devices, and the comparison parameter BDC e Compare with the preset parameter Y3, where Y3 takes a value of 98%, and check whether to ban the corresponding device or mark it as a device to be monitored based on the comparison result;
[0039] S411, when BDC e When the value is ≥Y3, the device sending the corresponding monitoring data will be directly marked as an abnormal device, and the MAC address of the abnormal device will be obtained and added to the blacklist. Data sent by this MAC address will no longer be received. At the same time, this MAC address will be compared with the MAC parameters stored in the cloud. If there is no comparison result, it means that this MAC address has been modified. Then the network node number of the corresponding device will be obtained and this network node number will be disabled.
[0040] S412, when BDC eWhen LLx is less than Y3, traffic flow is monitored on different device terminals. A monitoring period T3 is selected, which is 2 hours. The traffic parameters generated by different device terminals are marked as LLx, where x represents different device terminals. The traffic parameter LLx is compared with the preset parameter Y4, where the specific value of Y4 is determined by the operator. When LLx is greater than Y4, the device terminal is marked as a device to be monitored; otherwise, it is not marked. (Specifically, when a device terminal sends virus software, it will also be affected by the virus software. During the affected process, the virus software will automatically download a large amount of bundled software to the device terminal during the computer's idle period, causing the traffic parameters inside the device terminal to continue to increase.)
[0041] S42. The data sent by the monitored equipment is transmitted through a special network channel, and the special network channel is monitored in real time using corresponding monitoring software. If corresponding virus data or attack data appears, the device end transmitting the data is directly blocked using the method of step S411, thereby fully improving the traceability effect of the power monitoring data and being able to quickly find the corresponding attack data from the transmitted big data (specifically, the corresponding monitoring software is programmed or selected by external operators, and the special network channel is also constructed by external operators).
[0042] Example 2
[0043] During the specific implementation process, the specific difference between this embodiment and the first embodiment is that T1 is set to 0.6h, T2 is set to 4h, and T3 is set to 1.5h.
[0044] experiment
[0045] Some people used Example 1 and Example 2 in experiments to experience them, and obtained their experience parameters, which are shown in the following table:
[0046] Example 1 Example 2 Experience parameters 89.5 88.6
[0047] It can be seen from the data in the table that the data of Example 1 is better than that of Example 2. Some operators can choose the corresponding embodiment according to their personal needs.
[0048] Some of the data in the above formula are calculated by removing the dimensions and taking their numerical values. The formula is a formula that is closest to the actual situation obtained by software simulation of a large amount of collected data; the preset parameters and preset thresholds in the formula are set by technical personnel in this field according to actual conditions or obtained through simulation of a large amount of data.
[0049] The working principle of the present invention is as follows: Based on the power monitoring big data cloud, multiple groups of different device ends are divided in sequence, multiple groups of devices belonging to the same network broadband are divided into a block, and multiple blocks belonging to the same power monitoring area are divided into the same partition, and different partitions, different blocks and different device ends are marked in sequence, and the attack data in the data flow process is identified through the cloud database, and the public network IP address of the attack data is extracted to find the corresponding sending partition, and the data sent by different blocks in the partition are merged and analyzed, and the sent data is merged and analyzed with the attack data to obtain the similarity of the sent data, and then the similarity is compared with the preset value. For, and generate corresponding comparison signals, process according to the number of times the comparison signal exists and the residence time of the sent data, mark the corresponding block as an abnormal block according to the processing result, monitor the different device ends inside the abnormal block, check the monitoring data sent by different device ends during the monitoring period, and compare this monitoring data with the attack data. According to the comparison results, different device ends are marked differently. If there is no comparison result, the flow of different device ends is monitored. According to the monitoring results, the specified device end is managed, which fully improves the traceability effect of the power monitoring data and can quickly find the corresponding attack data from the transmitted big data.
[0050] The above embodiments are only used to illustrate the technical method of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical method of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical method of the present invention.
Claims
1. A data flow-oriented power monitoring data traceability method, characterized in that: The following steps are involved: S1. Based on the power monitoring big data cloud, multiple groups of different devices are divided into blocks. Multiple groups of devices belonging to the same network broadband are divided into a block. Multiple blocks belonging to the same power monitoring area are divided into the same partition. Different partitions, blocks, and devices are marked in sequence. S2. Identify attack data during data flow through the cloud database and find the corresponding sending partition by extracting the public IP address of the attack data; S3. Merge and analyze the data sent by different blocks within the partition, merge and analyze the sent data with the attack data, obtain the similarity of the sent data, compare the similarity with a preset value, and generate a corresponding comparison signal. Process the data based on the number of times the comparison signal exists and the residence time of the sent data, and mark the corresponding block as an abnormal block based on the processing result; S4. Monitor different devices within the abnormal block, check the monitoring data sent by different devices during the monitoring period, and compare the monitoring data with the attack data: S41, determine the monitoring time period T2, T2 is 5h, extract the attack data, and mark this attack data as the data to be compared, and compare all the monitoring data that appear in the monitoring time period T2 with the data to be compared in turn to obtain the comparison parameter BDC e , where e represents the monitoring data sent by different devices, and the comparison parameter BDC e Compare with the preset parameter Y3, where Y3 takes a value of 98%, and check whether to ban the corresponding device or mark it as a device to be monitored based on the comparison result; S42. The data sent by the monitored equipment is transmitted through a special network channel, and the corresponding monitoring software is used to monitor the special network channel in real time. If corresponding virus data or attack data appears, the device end transmitting the data is directly blocked using the method of step S411, thereby fully improving the traceability effect of the power monitoring data and being able to quickly find the corresponding attack data from the transmitted big data.
2. A method for tracing power monitoring data for data flow according to claim 1, characterized in that: In step S2, the specific method of identifying attack data is: S21. Compare each set of input data, extract the corresponding virus partition from the cloud database, and compare each set of data with the virus data within the virus partition to obtain the overlap degree CH. When CH>X1, where H1 is a preset value (the specific value is determined by the operator), the data is marked as data to be monitored. Otherwise, no processing is performed; S22. Perform real-time monitoring on the data stream that has been marked as data to be monitored to check whether the data stream has any attack behaviors such as code tampering, node attack, network monitoring, and password intrusion. If the above behaviors exist, mark the data stream as attack data; otherwise, do not mark it.
3. The method for tracing the source of power monitoring data for data flow according to claim 2 is characterized in that: In step S3, the specific method of combining the sent data with the attack data for analysis is as follows: S31, limit the monitoring period T1, obtain the data sent by all blocks in this monitoring period T, and compare the sent data with the attack data to obtain the similarity XS i-k , where i represents different data, k represents different blocks, and the similarity XS i-k Compare with the preset parameter Y1, when XS i-k When >Y1, the data is marked as abnormal data and an abnormal similarity signal is generated. Otherwise, no signal is generated. S32. Obtain the number of times abnormal similar signals appear within the monitoring period T and mark it as CS k , and then mark the total length of time that several groups of abnormal data stay as SS k , where k represents different blocks, using Get block determination parameter PD k , where C1 and C2 are preset fixed coefficient factors; S33, PD k Compare with the preset parameter Y2, Y2 is the preset parameter, the specific value is determined by the operator based on experience, when PD k When Y2 is higher than Y2, the block is determined to be an abnormal block; otherwise, the block is determined to be a normal block.
4. The method for tracing the source of power monitoring data for data flow according to claim 1 is characterized in that: In step S41, the comparison parameter BDC e The specific method of comparing with the preset parameter Y3 is: S411, when BDC e When the value is ≥Y3, the device sending the corresponding monitoring data will be directly marked as an abnormal device, and the MAC address of the abnormal device will be obtained and added to the blacklist. The data sent by this MAC address will no longer be received. At the same time, this MAC address will be compared with the MAC parameters stored in the cloud. If there is no comparison result, it means that this MAC address has been modified. Then the network node number of the corresponding device will be obtained and this network node number will be disabled. S412, when BDC e When LLx is less than Y3, the flow rate of different equipment ends is monitored, and the monitoring time period T3 is selected, T3 takes a value of 2h, and the flow parameters generated by different equipment ends are marked as LLx, where x represents different equipment ends. The flow parameter LLx is compared with the preset parameter Y4, where the specific value of Y4 is determined by the operator. When LLx is greater than Y4, this equipment end is marked as a device to be monitored, otherwise, it is not marked.
Citation Information
Patent Citations
Attack evidence obtaining and tracing method for power monitoring system
CN112822213A
Network attack tracing method and system based on data analysis
CN111669370A
Attack monitoring system
CN114500060A