Dynamic modeling method for cyber attacks on advanced measurement systems in smart grids

By analyzing the network attacks on the AMI system through the dynamic SEIR model and complex network theory, the problem that the existing strategies are unable to cope with dynamic attacks is solved, and effective defense and stability improvement of the AMI system are achieved.

CN115801377BActive Publication Date: 2025-10-03HUNAN INSTITUTE OF ENGINEERING +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202211404050.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-10
Publication Date
2025-10-03
Estimated Expiration
2042-11-10

AI Technical Summary

Technical Problem

Existing AMI system defense strategies cannot effectively deal with dynamic network attacks, and existing game models fail to consider time variations and network structure changes, resulting in high defense costs and poor results.

Method used

The dynamic SEIR model is used to describe the state evolution of AMI system nodes. Combined with complex network theory, the propagation trend of network attacks and system stability are analyzed, the future state changes of nodes are predicted, and defense strategy guidance is provided.

Benefits of technology

It realizes dynamic modeling of AMI system network attacks, reveals the propagation patterns, analyzes the system virus propagation dynamics and anti-attack capabilities, provides real-time defense strategies, reduces defense costs, and improves system stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115801377B_ABST
    Figure CN115801377B_ABST
Patent Text Reader

Abstract

This invention discloses a dynamic modeling method for cyberattacks in smart grid advanced measurement systems. The method includes establishing a propagation model for cyberattack viruses within the AMI system, performing dynamic analysis of the virus's propagation within the AMI system, analyzing the system's stability and attack tolerance, and predicting the propagation trends of DDoS attacks within the AMI network. The method can visualize the propagation of cyberattacks within the AMI system, reveal the propagation patterns of cyberattacks, analyze the system's virus propagation dynamics and fault tolerance against attacks, predict future state change trends of system nodes, and analyze the propagation thresholds and vulnerability factors of cyberattacks within the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security protection, and in particular relates to a dynamic modeling method for network attacks on advanced measurement systems of smart grids. Background Art

[0002] In recent years, faced with challenges such as global warming and fossil energy shortages, the power system has undergone a series of profound changes in its organizational structure and operational methods. New power systems, primarily based on renewable energy, have become a trend. The mainstream development direction of these new power systems is smart grid technology. Its fundamental concept is to achieve a close integration of all aspects of electricity generation, transmission, distribution, and utilization through digitalization and informatization, and to use intelligent control technologies to build a future power grid that is "economically efficient, flexible, interactive, user-friendly, open, clean, and environmentally friendly." Advanced Metering Infrastructure (AMI) is considered the first step in building a smart grid. Through the implementation of AMI, a universal communication network and information system capable of realizing the future smart grid will be established, gradually realizing applications such as advanced distribution and transmission operations.

[0003] While the introduction of intelligent terminal devices and open communication systems has improved the operational and management efficiency of smart grid AMI systems, it has also introduced increased cybersecurity risks. Because many intelligent terminal devices in AMI, such as smart meters and concentrators (intelligent converged terminals), lack robust physical protection, cyber attackers can easily compromise these devices and use them as a springboard to attack other AMI devices. Furthermore, because the computing and information processing capabilities of various terminal devices are often very limited, some commonly used information security technologies in computer networks, such as sophisticated encryption, are difficult to directly apply to AMI systems. For these reasons, AMI systems are more vulnerable to cyberattacks.

[0004] Researchers have demonstrated cyberattacks against AMI systems. For example, Mike Davis of "The Hacker Show" demonstrated how smart meters can be rapidly compromised by malware and spread worms. Industry leader McAfee has also highlighted the destructive effects of malware on AMI. Penetration testing of smart meters has identified several potential attacks against them, including meter spoofing, denial of service, and power outages. Once a cyberattack infiltrates an AMI system, it can not only cause physical device failure but also compromise the security and reliability of the communication network, impacting the safe and stable operation of the power system.

[0005] To ensure the reliable operation of AMI systems, many scholars have proposed corresponding defense strategies, such as equipment upgrades, policy engine checks to distinguish normal and malicious attack traffic at the AMI application layer, open firewalls, intelligent tracking firewalls, etc. However, whether these strategies can achieve the defense effect with maximum benefit and minimum cost has not been reflected.

[0006] While some researchers have proposed building game models for attackers and defenders to identify optimal attack and defense strategies, this approach is limited in that, firstly, it only considers a finite number of games between attackers and defenders at discrete time points, ignoring the impact of time-varying and network structure-changing factors. Secondly, it only generates static and fixed equilibrium strategies for attackers and defenders. However, in real-world scenarios, modeling cyberattacks against AMI is a dynamic game process, requiring continuous adjustment of the defense strategies deployed in the AMI system to minimize costs and maximize defense effectiveness.

[0007] With the goal of finding the optimal defense strategy, this paper proposes a dynamic modeling method for node state changes in AMI systems under network attacks. This method analyzes the propagation dynamics of AMI networks under network attacks, drawing on the concept of infectious diseases for cross-disciplinary integration. By combining complex network theory, the paper models the node state evolution process of the AMI network system after a network attack, analyzes the system's stability and attack threshold, and predicts the propagation trend of DDoS attacks in the AMI network. This method can display the propagation process of network attacks in the AMI system, reveal the propagation patterns of network attacks, analyze the system's virus propagation dynamics and anti-attack fault tolerance, predict the future state change trends of system nodes, and analyze the propagation threshold and vulnerability factors of network attacks in the system. This method provides guidance for control domain defense against the propagation of network attack security risks in the AMI system. Summary of the Invention

[0008] The purpose of the embodiments of the present invention is to provide a dynamic modeling method for network attacks on smart grid advanced measurement systems, which can display the propagation process of network attacks in AMI systems, reveal the propagation laws of network attacks, analyze the system's virus propagation dynamics and anti-attack fault tolerance, predict the future state change development trend of system nodes, and analyze the propagation domain value and vulnerability factors of network attacks in the system.

[0009] To solve the above technical problems, the technical solution adopted by the present invention is a dynamic modeling method for network attacks on smart grid advanced measurement systems, which is carried out according to the following steps:

[0010] S1, establish a model for the spread of network attack viruses in the AMI system;

[0011] S2, conducts dynamic analysis on the propagation of AMI system network attack viruses, analyzes the system stability and attack tolerance, and predicts the propagation trend of DDoS attacks in the AMI network.

[0012] Furthermore, the S1 includes:

[0013] The AMI network topology is modeled as a graph G consisting of N nodes and edges connecting the nodes. Each node represents a device in the AMI network, and an edge represents a communication channel connecting two nodes.

[0014] A SEIR dynamic model is established to describe the dynamic transformation state of AMI system nodes due to network attacks.

[0015] Furthermore, the SEIR dynamic model complies with the following assumptions:

[0016] 1),Every node in AMI is vulnerable to network attacks;

[0017] 2), the total number of nodes in the AMI network is constant;

[0018] The SEIR dynamic model is as follows:

[0019]

[0020] In formula (1),

[0021] S k 、E k , I k and R k To represent the state of a node with degree k;

[0022] S k Represents normal but vulnerable nodes that are easily infected by network attack viruses;

[0023] E k Represents a proxy node that is infected by a virus and controlled by an attacker;

[0024] I k The target node that has been successfully attacked is unable to provide services and accurately send normal data to the system center;

[0025] R k Recovered nodes can recover infected and attacked nodes by updating software, firewalls or system upgrades, and installing intrusion prevention mechanisms;

[0026] β is the infection rate, ε is the probability of an infected node attacking, μ is the infection node recovery rate, and γ is the attack node recovery rate; S k (t), E k (t), Ik (t) and R k (t) represents the node S with degree k k 、E k , I k and R k At time t, the proportion of the number in the system, represents the probability of any node connecting to an infected node, where <k>=∑ k kP k is the average degree of the node, k=1,2,···,n is the degree distribution of the node, P k The meaning of is the degree distribution of the network.

[0027] Furthermore, the S2 includes:

[0028] There is a no-attack equilibrium point in the SEIR dynamic model

[0029] E0=(S1,E1,I1,R1,S2,E2,I2,R2,…,S n ,E n ,I n ,R n )=(1,0,0,0,1,0,0,0,…,1,0,0,0);

[0030] The dynamic stability and attack tolerance x of the SEIR dynamic model are defined as:

[0031] x=(E1(t),…,E n (t),I1(t),…,I n (t)) T , T is transpose;

[0032] Convert the SEIR dynamic model into an infection and attack state model, namely:

[0033]

[0034] Formula (2) can be further expressed as:

[0035]

[0036] In formula (3), F is the node infection matrix, V is the node conversion matrix, The meaning is

[0037] in

[0038] V=diag(V1,V2,...,V n ), where i, j = 1, 2, ..., n, S i Indicates that node i is in normal state, P j represents the degree distribution of node j; where,

[0039] The system has a threshold for whether the network attack virus is eliminated. When R0 is less than 1, the system model only has an attack equilibrium point, and the spread of the network attack virus in the system is locally stable; when R0 is greater than 1, the network attack virus will continue to infect the system and always exist.

[0040] The beneficial effect of the present invention is that it is more realistic to model the behavior of the defender as a dynamic process. In this process, the defender's defense costs and benefits are taken into consideration in real time to continuously adjust its countermeasures. In order to seek the optimal strategy for its prevention and control, a dynamic modeling method for network attacks on the advanced measurement system of the smart grid is proposed. A dynamic evolution SEIR model of the AMI system nodes when they are attacked by the network is established. Through qualitative and quantitative analysis and numerical simulation of the dynamic properties of the model, the propagation process of network attacks (malicious code, DDoS attacks, worm viruses) in the AMI system is accurately displayed in real time, the propagation law of network attacks is revealed, the stability of the system, the dynamic behavior of virus propagation and the fault tolerance against attacks are analyzed, the future state change trend of the system nodes is predicted, the causes and key factors of the propagation of network attacks in the system are analyzed, and a theoretical basis and numerical basis are provided for defenders to formulate defense strategies. The model can be extended to other areas of the power grid, laying a solid theoretical foundation for building a complete defense system for the power grid against the network. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0042] Figure 1 This is a schematic diagram of the propagation process of network attacks in the AMI system.

[0043] Figure 2 It is a schematic diagram of node state transition.

[0044] Figure 3 Schematic diagram of the AMI system with scale-free network structure.

[0045] Figure 4 This is the evolution trend diagram of infected nodes and attack nodes in the AMI system when R0 < 1.

[0046] Figure 5 is β and R o relationship diagram.

[0047] Figure 6 This is the development trend diagram of E(t) and I(t) as β changes. DETAILED DESCRIPTION

[0048] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0049] An accurate attack virus propagation model helps defenders predict virus spread trends, identify weaknesses in the virus transmission process, and develop effective mitigation methods. This paper draws on infectious disease models to study the propagation model of network attack viruses in AMI systems. Incorporating complex network theory, a dynamic SEIR model is constructed to describe the state evolution of each node when AMI is under DDoS attack. Based on this model, the paper studies the propagation trends of AMI under DDoS attacks, system stability, and system attack tolerance.

[0050] The dynamic modeling method for network attacks on smart grid advanced measurement systems includes the following steps:

[0051] S1, network attack virus propagation modeling in AMI system:

[0052] The topology of an AMI network can be modeled as a graph G consisting of N nodes and edges connecting the nodes. Each node represents a device in the AMI network, and an edge represents a communication channel connecting two nodes.

[0053] Dynamic SEIR model establishment

[0054] The state of each node in AMI will change as the worm virus spreads due to network attacks. Figure 1 The attack virus propagation path shown in the figure proposes to establish a SEIR epidemic dynamic model to describe the dynamic transformation state of AMI system nodes due to network attacks.

[0055] The node state transition diagram of the dynamic SEIR model is as follows: Figure 2 As shown, it is assumed that at any time, each node of AMI has four possible states. k 、E k , I k and R k To represent the state of a node with degree k.

[0056] S k Represents normal but vulnerable nodes that are easily infected by network attack viruses.

[0057] E k Represents a proxy node (such as a smart meter) that is infected by a virus and controlled by an attacker.

[0058] I k The target node (such as a data concentrator) that has been successfully attacked is unable to provide services and accurately send normal data to the system center.

[0059] R k Recovered nodes can recover infected and attacked nodes by updating software, upgrading firewalls or systems, and installing intrusion prevention mechanisms.

[0060] The SEIR dynamic model conforms to the following assumptions:

[0061] (1) Every node in AMI is vulnerable to network attacks.

[0062] (2) The total number of nodes in the AMI network remains unchanged.

[0063] The mathematical model of the SEIR dynamic model of system node state evolution is as follows:

[0064]

[0065] In formula (1), β is the infection rate (the node state is represented by S k Convert to E k ), ε is the probability of infection node attack (the node state is represented by E k Convert to I k ), μ is the recovery rate of infected nodes (the node state is determined by E k Transform to recovery state R k ), γ is the attack node recovery rate (the node state is determined by I k Transform to recovery state R k );S k (t), E k (t), I k (t) and R k (t) represents the node S with degree k k 、E k , I k and R k At time t, the proportion of the number in the system, represents the probability of any node connecting to an infected node, where <k>=∑ k kP k is the average degree of the node, where k=1,2,···,n is the degree distribution of the node, P k The meaning of is the degree distribution of the network;

[0066] The initial conditions of formula (1) are:

[0067]

[0068] S2, AMI system network attack virus propagation dynamics analysis

[0069] The SEIR dynamic model of system node state evolution (i.e., Equation (1)) is regarded as a system dynamics problem to analyze the system stability and attack tolerance, and predict the propagation trend of DDoS attacks in AMI networks.

[0070] Theorem 1: System (1) (i.e., Equation (1)) has a non-attack equilibrium point

[0071] E0=(S1,E1,I1,R1,S2,E2,I2,R2,…,S n ,E n ,I n ,R n )=(1,0,0,0,1,0,0,0,…,1,0,0,0)

[0072] Proof: Convert formula (1) into infection and attack state model, that is:

[0073]

[0074] When E k =0,I k = 0, the system can be obtained without attack equilibrium point

[0075] E0=(S1,E1,I1,R1,S2,E2,I2,R2,…,S n ,E n ,I n ,R n )=(1,0,0,0,1,0,0,0,…,1,0,0,0)

[0076] In order to analyze the dynamic stability and attack tolerance x of the research system (1), we define

[0077] x=(E1(t),…,E n (t),I1(t),…,I n (t)) T ,

[0078] Here T is the transpose;

[0079] Formula (2) can be expressed as the following mathematical model:

[0080]

[0081] In formula (3), F is the node infection matrix, V is the node conversion matrix, The meaning is

[0082] in

[0083] V=diag(V1,V2,...,V n ), where i, j = 1, 2, ..., n, S i Indicates that node i is in normal state, P j represents the degree distribution of node j; where,

[0084] The system has a threshold R0 for whether the network attack virus is eliminated. According to the next generation matrix method, the system attack threshold It is used to analyze system stability and attack tolerance, as well as predict the propagation trend of cyberattack viruses in AMI systems. When R0 < 1, the system model only has an attack equilibrium point, and the propagation of the cyberattack virus in the system is locally stable. When R0 > 1, the cyberattack virus will continuously infect the system and remain present.

[0085] Theorem: When R0 < 1, there exists a non-attack equilibrium point in equation (1) which will be locally asymptotically stable.

[0086] Proof: The Jacobian matrix of formula (2) at the no-attack equilibrium point E0 is:

[0087]

[0088] In formula (4), i,j=1,2,…,n, is the element in the Jacobian matrix C; I n×n is an n×n unit matrix, 0 n×n is an n×n zero matrix; represent The partial derivatives of E(t) and I(t), E(t) and I(t) are the infected nodes E k , attacked node I k The matrix consisting of the proportion of the number in the system at time t.

[0089] The characteristic equation of the Jacob matrix (4) can be derived, namely:

[0090]

[0091] Obviously, formula (5) has 2n roots, and they are all negative, of which n roots have the value of -γ, and the other n roots have the value of when Available That is, the other n roots are also negative, so we can get the non-attack equilibrium point lim t→∞ E k =0,lim t→∞ I k =0, k = 1, 2, ..., n, R0 < 1, the system has attack tolerance and tends to be stable. From another perspective, when R0 < 1, the spread of network attack viruses will tend to disappear.

[0092] Experiments have shown that:

[0093] The Barabasi-Albert method is used to simulate an AMI network with 300 nodes and a scale-free network structure, as shown in Figure 3 As shown in the figure, three nodes are set as data collectors and the rest are set as smart meter nodes. Data collector nodes have a high probability of being selected as targets by attackers, while the probability of being selected as infected nodes is very small. That is, the total number of nodes in the BA network is N = 300, the initial number of network nodes is m0 = 3, and the number of edges generated each time a new node is introduced is m = 3. The degree distribution of nodes in a scale-free network follows a power law distribution, that is, P k =ck -r ,c=2m 2 , where m = 3, k is the degree of the network, n=N=300,r=3, <k>=1.38,

[0094] k 2 >=4.55, β=0.02, ε=0.16, γ=0.1, μ=0.2, we can get R0=0.55<1

[0095] The density (number) of infected meters (unsuccessful attacks, in the incubation period) is a weighted average based on the degree distribution: Set the initial global density to: S(0) = S k (0) = 0.9, E(0) = E k (0) = 0.1, I(0) = I k (0) = 0, R(0) = R k (0)=0.

[0096] The probability density trend of infected and attacked meter nodes over time is as follows: Figure 4 shown.

[0097] Figure 4 It shows that as time goes by, when R0 is less than 1, the number of infected meters and successfully attacked meters will continue to decrease until it reaches 0, which means that the trend of network attack nodes in the AMI system being infected with viruses will decrease until it disappears.

[0098] Experimental setup: The impact of different infection β on the infected node ratio E(t) and I(t), β is proportional to R0 (e.g. Figure 5 As shown), that is, as β increases, E(t) and I(t) will also increase (as shown Figure 6 As shown in Figure 2, when it increases to make R0>1, the system will continue to be infected so that the infected nodes and attack nodes always exist in the AMI system.

[0099] This paper studies the security risk propagation threshold R0 caused by network attacks in AMI, analyzes the key factors affecting the security risk propagation of AMI information systems, and plays a guiding role in controlling the risk propagation of network attack viruses in AMI systems.

[0100] Each embodiment in this specification is described in a related manner. Similar parts between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences between the other embodiments. In particular, the system embodiment is generally similar to the method embodiment, so the description is relatively simple. For related parts, refer to the description of the method embodiment.

[0101] The above description is only a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention are included in the scope of protection of the present invention.< / k> < / k> < / k>

Claims

1. A dynamic modeling method for network attacks on smart grid advanced measurement systems, characterized by: Follow these steps: S1, establish a model for the spread of network attack viruses in the AMI system; S2, conducts dynamic analysis of the propagation of virus attacks on the AMI system network, analyzes the system's stability and attack tolerance, and predicts the propagation trend of DDoS attacks in the AMI network; Said S1 comprises: The AMI network topology is modeled as a graph G consisting of N nodes and edges connecting the nodes. Each node represents a device in the AMI network, and an edge represents a communication channel connecting two nodes. Establish a SEIR dynamic model to describe the dynamic transformation state of AMI system nodes due to network attacks; The SEIR dynamic model is consistent with the following assumptions: 1),Every node in AMI is vulnerable to network attacks; 2), the total number of nodes in the AMI network is constant; The SEIR dynamic model is as follows: In formula (1), S k 、E k , I k and R k To represent the state of a node with degree k; S k Represents normal but vulnerable nodes that are easily infected by network attack viruses; E k Represents a proxy node that is infected by a virus and controlled by an attacker; I k The target node that has been successfully attacked is unable to provide services and accurately send normal data to the system center; R k Recovered nodes can recover infected and attacked nodes by updating software, firewalls or system upgrades, and installing intrusion prevention mechanisms; β is the infection rate, ε is the probability of an infected node attacking, μ is the infection node recovery rate, and γ is the attack node recovery rate; S k (t), E k (t), I k (t) and R k (t) represents the node S with degree k k 、E k , I k and R k At time t, the proportion of the number in the system, represents the probability of any node connecting to an infected node, where k>=∑ k kP k is the average degree of the node, k=1,2,···,n is the degree distribution of the node, P k The meaning of is the degree distribution of the network.

2. The dynamic modeling method for network attacks on smart grid advanced measurement systems according to claim 1 is characterized in that: The S2 includes: There is a no-attack equilibrium point in the SEIR dynamic model E0=(S1,E1,I1,R1,S2,E2,I2,R2,…,S n ,E n ,I n ,R n )=(1,0,0,0,1,0,0,0,…,1,0,0,0); The dynamic stability and attack tolerance x of the SEIR dynamic model are defined as: x=(E1(t),…,E n (t),I1(t),…,I n (t)) T , T is transpose; Convert the SEIR dynamic model into an infection and attack state model, namely: Formula (2) can be further expressed as: In formula (3), F is the node infection matrix, V is the node conversion matrix, The meaning is in V=diag(V1,V2,...,V n ), where i, j = 1, 2, ..., n, S i Indicates that node i is in normal state, P j represents the degree distribution of node j; where, The system has a threshold for whether the network attack virus is eliminated. When R0 is less than 1, the system model only has an attack equilibrium point, and the spread of the network attack virus in the system is locally stable; when R0 is greater than 1, the network attack virus will continue to infect the system and always exist.