A data attack adaptive system applied to power networks

By building a power grid immune neural model and dynamic configuration immune strategy, the problem of insufficient data protection capabilities under the basic power grid communication architecture is solved, efficient and dynamic computer virus identification and response are achieved, and the security and efficiency of power grid data transmission are improved.

CN115952499BActive Publication Date: 2025-07-04STATE GRID FUJIAN ELECTRIC POWER CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202211657756.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-22
Publication Date
2025-07-04
Estimated Expiration
2042-12-22

AI Technical Summary

Technical Problem

The existing data protection technology cannot adapt to the basic power grid communication architecture, resulting in low protection capabilities on the device side, and it is difficult for the host to identify and respond to malicious attacks, affecting the data transmission efficiency.

Method used

Build a power grid immune neural model, and generate channel parameter groups and identification and disinfection ability groups through the architecture management module, association feature management module and immune ability management module. Combined with the computer virus information database and the immune strategy database, immunity strategies are dynamically configured to realize the identification and detection of computer viruses.

Benefits of technology

It improves the data protection capabilities of power grid equipment under limited processing capabilities, dynamically responds to computer viruses and data attacks, reduces the use of equipment resources, and improves data transmission efficiency and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115952499B_ABST
    Figure CN115952499B_ABST
Patent Text Reader

Abstract

The present invention discloses a data attack adaptive system applied to a power network, including a power grid model construction subsystem and an immune configuration subsystem; the power grid model construction subsystem is used to construct a power grid immune neural model, and the power grid model construction subsystem includes an architecture management module, an associated feature management module, and an immune ability management module, simulating the training and tolerance process of immune cells in the human body, researching the generation and tolerance training methods of power system network attack detectors; researching the life cycle evolution strategy of detectors, forming an adaptive immune feedback process, and then adapting to the evolution and progression of network attacks in the real power system network environment, computer viruses, researching the real-time and quantitative calculation method of power system network dynamic risks; thereby achieving the effect of targeted identification and elimination of all computer viruses or data attacks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of power grid data, and particularly relates to a data attack adaptive system applied to a power network. Background Art

[0002] With the upgrade and iteration of intelligent devices and communication technologies, the information technology of the power grid has developed to the stage of intelligent big data. By collecting, storing, and analyzing power grid and power data through a service platform, it aims to achieve more accurate prediction of power consumption information, timely detection of power grid anomalies, and convenient scheduling of power consumption resources. With the increasing requirements for accuracy, analysis dimensions, and timeliness under the demand for data analysis, new requirements have been continuously put forward for data communication nodes and data collection methods. On the other hand, as the information granularity of the entire power grid platform becomes finer, the power grid platform's dependence on data is also increasing, mainly reflected in the realization of intelligent power distribution and intelligent control technologies. If the data is abnormal, the corresponding functions will also be abnormal. Moreover, power grid information includes power consumption data of individuals, enterprises, administrative organs, etc., and its information also requires higher confidentiality requirements. The losses caused by information leakage are also inestimable. Therefore, the patent number CN202011360530.9 proposed a power grid data protection method and system based on blockchain and data security sandbox, which authorizes and verifies the identity information of the user side through blockchain technology to ensure the security of power grid data. Additionally, the patent number CN201410355049.9 proposed a power grid object access control device that can achieve secure configuration and access of power grid model data, and also manages the security of power grid data by controlling the access rights of the power grid model through security configuration. Combining with firewall technology and computer virus killing technology applicable to the network itself, power grid data can apply a variety of computer virus, data attack security protection software, strategies, or algorithms that have become relatively mature and are widely used in other fields. For example, the patent number CN202010332037.X proposed a power grid data secure communication transmission system and method, which ensures the security of power grid data through an information internal network server and a security protection wall. However, since power grid data still has significant differences from network data in other fields, part of the power grid data is transmitted using HPLC, and the power grid data is directly forwarded on the device side and may not pass through the data terminal. Due to the limited processing capacity of basic power grid devices, they do not have the function of data attack recognition and killing, which will result in relatively low protection ability of power grid data on the device side. Moreover, due to different types, models, and applicable communication protocols of different basic power grid devices, data attacks are relatively simple, but it is very difficult to identify data attacks. Currently, the adopted method is through CN201210191144.A related method for the network security architecture of a power information collection system. By directly matching the host through a firewall in the front-end collection, the host coordinates local data protection and data transmission. In this way, a host needs to be set up for each layer and each area. Although the data security is improved, the data transmission and communication efficiency are reduced. Moreover, the host needs to have the ability to identify all malicious attacks, which is obviously difficult. At the same time, adopting the above architecture requires a relatively large change to the current basic power grid communication architecture. For most basic power grid devices, a shielding communication method needs to be adopted to ensure that the power grid devices cannot send and receive data through other communication interfaces, so that the firewall can play its due role. Summary of the Invention

[0003] The present invention provides a data attack adaptive system applied to a power network, aiming to solve the problem that the existing data protection technology cannot adapt to the existing basic power grid communication architecture.

[0004] To solve the above technical problems, the present invention adopts the following technical solutions:

[0005] A data attack adaptive system applied to a power network includes a power grid model construction subsystem and an immunity configuration subsystem;

[0006] The power grid model construction subsystem is used to construct a power grid immune neural model. The power grid model construction subsystem includes an architecture management module, a correlation feature management module, and an immunity ability management module;

[0007] The architecture management module generates and updates a basic communication model according to the power grid communication architecture. The nodes of the basic communication model correspond to communication devices, and the connections of the basic communication model correspond to communication channels;

[0008] The correlation feature management module is configured with a channel matching database. The channel matching database stores a number of channel identification indexes and corresponding channel identification data. The correlation feature management module obtains the channel information of each communication channel and retrieves the corresponding channel identification data according to the channel identification index in the channel information to generate a channel parameter group for each communication channel. Each channel parameter group includes several different types of channel parameters, and the type items in the channel parameter groups of different communication channels are the same;

[0009] The immune capacity management module is configured with an identification matching database and a disinfection matching database. The identification matching database stores a number of identification items, each identification item corresponding to a number of identification conditions. The disinfection matching database corresponds to disinfection items, each disinfection item corresponding to a number of disinfection conditions. The immune capacity management module obtains the device information of each communication node. When the device information meets the identification conditions corresponding to the identification item, the corresponding identification item is added to the identification capacity group of the communication node until all the identification items are traversed. When the device information meets the disinfection conditions of the corresponding disinfection item, the corresponding disinfection item is added to the disinfection capacity group of the communication node until all the disinfection items are traversed.

[0010] The immune configuration subsystem is configured with a computer virus information library and an immune strategy library. The computer virus information library stores a number of computer virus information, each computer virus information including computer virus data characteristics and computer virus critical values. The immune configuration subsystem includes a computer virus analysis module and an immune configuration module. The computer virus analysis module generates corresponding immune numbers according to the computer virus critical values, and retrieves corresponding immune strategies from the immune strategy library according to the computer virus characteristic information. The immune configuration module is used to generate immune configuration instructions with the number of immune numbers according to the immune strategies, and use the immune configuration instructions to configure the immune strategies in the communication nodes of the power grid immune neural model.

[0011] Further, it further includes a dynamic response subsystem, which includes a response trigger module and an immune response module. The response trigger module is used to receive the trigger identification information of the communication node, and determine the corresponding computer virus information according to the computer virus data characteristics of the trigger identification information. The immune response module is configured with a critical value identification algorithm for updating the computer virus critical value, and the critical value identification algorithm is configured as where, S A is the computer virus critical value, S C is the preset reference critical value, α1 is the preset static critical value weight, α2 is the preset dynamic critical value weight, and α1 + α2 = 1. H a is the computer virus historical impact value, t0 is the current time, t k is the time when the kth computer virus is identified, k is the total number of times the computer virus is identified, M k is the security level corresponding to the communication node when the kth computer virus is identified, H k is the actual impact value of the computer virus corresponding to when the kth computer virus is identified, t a is the preset reference time parameter.

[0012] The described immunity configuration instruction includes a dynamic forwarding request, and the dynamic forwarding request includes a dynamic forwarding condition. When the communication node's configured immunity policy meets the dynamic forwarding condition, the communication node sends the dynamic forwarding request to other communication nodes according to the power grid immunity neural model to configure the immunity policy to other communication nodes.

[0013] Further, the steps for the immunity configuration instruction to configure the immunity policy are as follows:

[0014] Step A1: Generate a configuration value range based on the channel information of the communication channel corresponding to the current communication node, so that different communication channels have different configuration value ranges;

[0015] Step A2: Generate a random number, and determine the next communication node corresponding to the communication channel according to the configuration value range into which the random number falls;

[0016] Step A3: Retrieve the recognition ability group and the disinfection ability group of the corresponding communication node, and determine whether the immunity policy matches the recognition ability group and the disinfection ability group. If it matches, go to Step A4; if it does not match, return to Step A1;

[0017] Step A4: Generate a load value range according to the immunity load value of the current communication node, and the immunity load value reflects the working load situation of this communication node;

[0018] Step A5: Generate a random number. If the random number falls within the load value range, return to Step A1; if the random number does not fall within the load value range, configure the immunity policy to the current communication node.

[0019] Further, the configuration value range is generated according to the configuration trust value of the communication channel. The size of the configuration value range is proportional to the configuration trust value, and there is where G a is the configuration trust value, T d is the interval time for the immunity configuration instruction to pass through this communication channel, T x is the preset reference interval time, is the preset anti-information attenuation factor, G d is the channel correlation value, and there is G d =β1D j +β2U(u1 + u2)+β3Q j , where β1 is the preset distance weight, β2 is the preset communication efficiency weight, β3 is the preset area weight, and β1 + β2 + β3 = 1. D j is the communication distance value of this communication channel, U is the transmission speed value of this communication channel, u1 is the communication protocol efficiency number, u2 is the communication type efficiency number, and the communication protocol efficiency number and the communication type efficiency number are obtained by looking up the table through the channel information, Qj is the area association value of the communication channel, and the area association value is obtained by looking up a table according to the communication channel information;

[0020] When an immune configuration instruction passes through the communication channel, an anti-information attenuation factor corresponding to the communication channel mark is marked.

[0021] Furthermore, each disinfection item corresponds to a disinfection ability sub-value, and each corresponding identification item corresponds to an identification ability sub-value. The immune ability management module also includes marking the disinfection ability value and the identification ability value of each communication node. The disinfection ability value is the sum of the disinfection ability sub-values, and the identification ability value is the sum of the identification ability sub-values;

[0022] The power grid model construction subsystem further includes a node marking module, and the node marking module is configured with a model calculation algorithm. The model calculation algorithm is used to calculate the total model channel value and the total model ability value, where LS is the total model ability value, LK is the total model channel value, z j is the identification ability value corresponding to the jth communication node, G jd is the channel association value corresponding to the jth communication channel, l is the total number of communication nodes, v j is the disinfection ability value corresponding to the jth communication node, R i is the layer ratio weight, and there is R i = 1 / (p1...p i )), p i is the number of communication nodes in the ith layer of the power grid immune neural model, and i is the layer number of the communication node in the power grid immune neural model;

[0023] The node marking module is configured with a hierarchical feature index table. The hierarchical feature index table uses the total model ability value and the total model channel value as indexes to retrieve hierarchical feature conditions, and marks the node security level for each communication node according to the hierarchical feature conditions.

[0024] Furthermore, the immune configuration subsystem configures an instruction splitting strategy for communication nodes with a node security level lower than the preset level benchmark. When a communication node is configured with an immune configuration instruction, the instruction splitting strategy splits a new immune configuration instruction according to the immune configuration instruction and configures it on other communication nodes.

[0025] Furthermore, each immune strategy includes several immune sub-strategies, and different immune sub-strategies have different concentration execution thresholds. When the number of times an immune strategy is repeatedly configured exceeds the concentration execution threshold, the corresponding immune sub-strategy is executed.

[0026] Furthermore, the immune configuration subsystem configures corresponding immune configuration instructions in the order of computer virus critical values.

[0027] Further, the recognition conditions include encryption method, communication type, communication efficiency, and maximum transmission unit, and the disinfection conditions include verification method, memory size, and processor type.

[0028] Compared with the prior art, the present invention has the following technical effects:

[0029] By setting it like this, first, a power grid immune neural model is established based on full-architecture recognition, and the nodes and connections of the power grid immune neural model are feature-labeled. The channels mainly analyze the channel information related to computer virus recognition and computer virus killing and checking. The communication device analyzes whether the corresponding recognition program or disinfection program can be edited by establishing a database. In this way, it can be edited in the form of a power grid immune neural model through the entire power grid architecture. In this way, corresponding immune strategies can be configured specifically for computer viruses, data attacks, etc. And directly by issuing corresponding immune configuration instructions according to the routing relationship corresponding to the model, the number of immune instructions and the location where the immune strategy is sent can be dynamically determined, without repeated confirmation through the platform. At the same time, the number of immune strategies is determined according to the computer virus critical value, so that computer viruses or data attacks with higher critical values can be uniformly judged on the platform, improving the dynamic response ability of the immune strategy, and at the same time ensuring that the device can identify and respond to corresponding data computer viruses under the condition of limited processing power. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] Figure 1 is the system architecture schematic diagram of a data attack adaptive system applied to a power network according to the present invention;

[0031] Figure 2 is the flowchart of immune strategy configuration of the power grid immune neural model of a data attack adaptive system applied to a power network according to the present invention.

[0032] In the figure: 100, power grid construction subsystem; 110, architecture management module; 120, associated feature management module; 130, immune ability management module; 140, node marking module; 200, immune configuration subsystem; 201, computer virus information library; 202, immune strategy library; 210, computer virus analysis module; 220, immune configuration module; 300, dynamic response subsystem; 310, response trigger module; 320, immune response module. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0033] To make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be clearly and completely described below in conjunction with specific embodiments of the present application and with reference to the accompanying drawings.

[0034] A data attack adaptive system applied to a power network, comprising a power grid model construction subsystem 100 and an immune configuration subsystem 200;

[0035] The power grid model construction subsystem is used to construct a power grid immune neural model. The power grid model construction subsystem includes an architecture management module 110, a correlation feature management module 120, and an immune capacity management module 130. The power grid model construction subsystem not only constructs a power grid immune neural model. When the protocols, communication methods, locations, and communication relationships between power grid devices or devices change, the power grid model construction subsystem updates the information to ensure that the power grid immune neural model is the same as the actual power grid architecture. By collecting all communication-related information of the entire power grid architecture through the platform, it can also be effective for the platform to analyze or dispatch other resources. On the other hand, if the immune strategy is configured through node devices or terminals, all intelligent terminals need to configure all immune strategies, which occupies a large amount of resources. At the same time, all intelligent terminals need to identify all computer viruses, which will also cause a relatively large load on data communication. However, constructing a power grid immune neural model can be uniformly managed by the background. The background has the advantages of complete data and strong computing power. The update rate of new computer viruses or data attacks in the background is relatively fast, and it can ensure that each recognition and disinfection program exists in the entire power grid system, but not every device must be configured with the corresponding program. Specifically as follows:

[0036] The architecture management module 110 generates and updates a basic communication model according to the power grid communication architecture. The nodes of the basic communication model correspond to communication devices, and the connections of the basic communication model correspond to communication channels. The basic communication model is a power grid immune neural model without feature marking, which can be obtained by retrieving the power grid architecture from an external database or by issuing communication test data. The communication relationship is updated in real time, and the position of each communication node in the entire model can be determined by the space tree method.

[0037] The associated feature management module 120 is configured with a channel matching database, which stores a number of channel identification indexes and corresponding channel identification data. The associated feature management module 120 obtains the channel information of each communication channel, and retrieves the corresponding channel identification data according to the channel identification index in the channel information to generate a channel parameter group for each communication channel. Each channel parameter group includes several different types of channel parameters, and the type items in the channel parameter groups of different communication channels are the same. First, it is the channel-related information. The type items of the channel information at least include communication type, communication protocol, communication interface, communication physical distance, and communication method. The communication type is the communication means used, such as specific communication methods like optical fiber, HPLC, wireless communication, etc. The communication protocol is sent with the name or number of the protocol as the content. The communication interface is also sent with the name or number of the communication interface as the content. The communication physical distance is sent in the form of a value. The communication method is simplex, duplex communication, or whether there is a situation where multiple interfaces compete, and is sent with a preset number. In this way, the situations of all channels are obtained. The main purpose is to judge the information related to the data signal transmission efficiency. And according to the detailed situation, the above information is converted into corresponding information parameters, and then the communication ability of the channel can be calculated. The communication ability is recorded in numerical form. Through the channel matching database, the content truly reflected by the channel information is determined for the names of different expression methods and different contents through the channel identification index, and the actual content of the information is uniformly standardized, and at the same time, the useless data in the channel information is filtered out. In this way, the channel parameter group can be obtained, and the communication ability of the channel can be judged from different dimensions.

[0038] The immunity management module 130 is configured with an identification matching database and a disinfection matching database. The identification matching database stores a number of identification items, and each identification item corresponds to a number of identification conditions. The disinfection matching database corresponds to disinfection items, and each disinfection item corresponds to a number of disinfection conditions. The immunity management module 130 obtains the device information of each communication node. When the device information meets the identification conditions corresponding to the identification item, the corresponding identification item is added to the identification ability group of the communication node until all the identification items are traversed. When the device information meets the disinfection conditions of the corresponding disinfection item, the corresponding disinfection item is added to the disinfection ability group of the communication node until all the disinfection items are traversed. The identification conditions include encryption method, communication type, communication efficiency, and maximum transmission unit. The disinfection conditions include verification method, memory size, and processor type. Since different types of communication devices have different communication methods and different control contents involved, for example, devices such as repeaters do not have information processing capabilities, or some devices only provide a small amount of space for external programs, all of which will result in great differences in the ability of different communication devices to configure corresponding immunity strategies. Therefore, first, the immunity management module 130 determines the identification conditions according to the identified content, and similarly determines the disinfection conditions according to the disinfected content. That is to say, the cloud platform records and stores in advance the implementation of corresponding immunity strategies according to the characteristics of computer viruses or data attacks, and then judges whether the communication node meets these conditions through analysis. If it meets the conditions, it means that it has the ability to configure the corresponding strategy. If it does not meet the conditions, it means that the node cannot configure the corresponding strategy. Therefore, when configuring the immunity strategy, it will also judge whether it has the disinfection ability or identification ability according to the content of the immunity strategy. The advantage of such a setting is that the data platform only needs to obtain the information related to identification and disinfection of each device node, without obtaining irrelevant information. Then, the disinfection ability and identification ability of each corresponding device are marked through the disinfection ability group and the identification ability group.

[0039] The immune configuration subsystem 200 is configured with a computer virus information database 201 and an immune strategy database 202. The computer virus information database 201 stores a number of computer virus information. The computer virus information can be obtained from an external database or input manually. The computer virus data feature is to analyze the computer virus data and extract the corresponding features. If the computer virus data feature is not extracted, it cannot be used as computer virus information. Each computer virus information includes the computer virus data feature and the computer virus risk value. The computer virus risk value reflects the degree of danger of the computer virus. The immune configuration subsystem 200 includes a computer virus analysis module 210 and an immune configuration module 220. The computer virus analysis module 210 generates corresponding immune numbers according to the computer virus risk value and retrieves the corresponding immune strategy from the immune strategy database 202 according to the computer virus feature information. The immune configuration module 220 is used to generate immune configuration instructions with the number of immune numbers according to the immune strategy and use the immune configuration instructions to configure the immune strategy in the communication nodes of the power grid immune neural model. It can be seen that the immune risk value is an important feature. Since the method of the present invention is to send the immune strategy of each computer virus to multiple nodes, the number of nodes sent for storage reflects the degree of attention of the system to the computer virus. Therefore, the present invention calculates the computer virus risk value for each computer virus, determines the immune number according to the computer virus risk value, and thus configures the immune strategy. Moreover, the corresponding immune configuration instructions are configured in the order of the computer virus risk value according to the immune configuration subsystem 200. In this way, under limited processing resources, the immune strategy with a higher risk value can be configured first. Each immune strategy includes a number of immune sub-strategies, and different immune sub-strategies have different concentration execution thresholds. When the number of times the immune strategy is repeatedly configured exceeds the concentration execution threshold, the corresponding immune sub-strategy is executed. In the configuration logic, there is also a strategy to adjust the immune degree according to the concentration. For the same computer virus, there may be different recognition methods and disinfection methods. However, the higher the immune degree, the greater the burden on the device or communication will be. For example, multiple confirmations in recognition, or adding verification algorithms. For example, in disinfection, further refined features are screened out, a full-scale multi-node screening is carried out, or the screening fineness of data packets is improved. Since the corresponding immune configuration instructions are stored in the system of the present invention, there may also be multiple immune configuration instructions sent to the same node. At this time, the node records the number of simultaneously existing immune configuration instructions and upgrades the situation according to the number. Because when the actual computer virus concentration increases, the situation where a single device receives multiple immune configuration instructions will occur, indicating that the computer virus risk value is very high at this time. Therefore, sacrificing efficiency is necessary at this time. By imitating the immune method of real organisms against computer viruses, it is ensured that the power grid data with limited resources can dynamically configure immune responses according to the actual external computer virus danger degree.And here it comes to the issue of how to configure the immune strategy: The steps for the immune configuration instruction to configure the immune strategy are as follows:

[0040] Step A1: Generate a configuration value range according to the channel information of the communication channel corresponding to the current communication node, so that different communication channels have different configuration value ranges; the configuration value range is generated according to the configured trust value of the communication channel, and the size of the configuration value range is proportional to the configured trust value. There is where G a is the configured trust value, T d is the interval time for the immune configuration instruction to pass through this communication channel, T x is the preset reference interval time, is the preset anti-information attenuation factor, G d is the channel correlation value, and there is G d =β1D j +β2U(u1 + u2)+β3Q j , where β1 is the preset distance weight, β2 is the preset communication efficiency weight, β3 is the preset area weight, and β1 + β2 + β3 = 1. D j is the communication distance value of this communication channel, U is the transmission speed value of this communication channel, u1 is the communication protocol efficiency number, u2 is the communication type efficiency number, and the communication protocol efficiency number and the communication type efficiency number are obtained by looking up the table through the channel information. Q jis the regional association value of the communication channel, and the regional association value is obtained by looking up a table based on the communication channel information; each configured numerical range is determined by the proportion of the sum of the configured trust values. The range for generating random numbers is the same as the sum of the configured numerical ranges. Therefore, the configured trust value reflects the probability of this node being selected. Since the random numbers are randomly generated, the immune configuration instructions flow with the selected node positions. There is a logic in this flow. First, the configured trust value marks the channel during the flow, and then it is reduced by the anti-information attenuation factor. This can ensure that, for example, when any immune configuration instruction flows from A to B, it is not easy for the immune configuration instruction to flow back from B to A because at this time, the configured trust value corresponding to this channel decreases under the influence of the anti-information attenuation factor, so the probability of flow also decreases. However, the influence of the anti-information attenuation factor on the configured trust value will gradually decrease over time, causing the configured trust value at this position to return to the original standard. The reference interval time can adjust the attenuation efficiency of the anti-information attenuation factor. When the reference interval time is equal to the actual interval time, that is, when the influence of the anti-information attenuation factor is 0, the anti-information attenuation factor is deleted. On the other hand, the numerical value of the anti-information attenuation factor determines the circulation return rate of the immune configuration instructions. The larger the value, the smaller the return rate. The channel association value is calculated based on the basic situation of the channel, comprehensively considering factors such as its communication efficiency, the region it is in, and the actual transmission distance, and comprehensively judging the comprehensive impact of data attacks on this channel and its ability to respond to data attacks. Since the model is known and each communication channel has communication parameters, the communication parameters are converted into corresponding numerical values through a table lookup method, and then the channel association value is calculated. The channel association value reflects the possibility of a channel being selected in a static situation. Devices that are farther away, have a faster transmission speed, and a higher density of devices in the region are more likely to be selected as the transmission channel, and the corresponding channel association value is also larger.

[0041] Step A2: Generate random numbers and determine the next communication node of the corresponding communication channel according to the configured numerical range into which the random numbers fall; the random numbers are generated within the corresponding total configured numerical range. The advantage of generating random numbers is that, first, the pattern of the positions where different immune strategies are sent cannot be judged, which can improve the security of the system. On the other hand, by adjusting the probabilities of different randomly sent positions, the sending trend of the immune strategies can be macroscopically controlled, making the immune strategies sent to positions with greater influence.

[0042] When an immune configuration instruction passes through this communication channel, mark the corresponding anti-information attenuation factor on the communication channel.

[0043] Step A3: Retrieve the recognition ability group and disinfection ability group of the corresponding communication node, and determine whether the immunity strategy matches the recognition ability group and disinfection ability group. If they match, proceed to Step A4; if not, return to Step A1. If the communication node corresponding to this location does not have the disinfection ability and recognition ability to execute the corresponding immunity strategy, return to Step A1 so that the corresponding configuration instruction can continue to flow. It should be noted that the current communication node at this time is the next node selected in Step A2. If they match, proceed to Step A4.

[0044] Step A4: Generate a load value range based on the immunity load value of the current communication node. The immunity load value reflects the working load situation of this communication node. The purpose of this step is not to directly and preferably configure it on the current communication node. Because the communication nodes are tree - shaped distributed, if the capabilities match and it is directly configured, it is easy for the upper - level nodes to match too many immunity strategies, resulting in an increasing burden on the upper - level nodes. Therefore, by calculating the immunity load value, which takes into account factors such as storage space and processing power and reflects the usage status of the data resources of this communication node, and generating the corresponding load value range in a numerical way. For example, the immunity load value can be directly obtained as the CPU usage rate of the node - corresponding terminal, and the node load situation. The corresponding load value range is directly generated through the load value ratio, that is, the greater the load, the less likely it is to be configured with the corresponding immunity strategy.

[0045] Step A5: Generate a random number. If the random number falls within the load value range, return to Step A1; if the random number does not fall within the load value range, configure the immunity strategy on the current communication node. If it falls within the load value range, it means the load is large, so it continues to flow. If it does not fall within the load value range, the immunity strategy is configured on the current communication node.

[0046] On the other hand, the present invention further includes a dynamic response subsystem 300. The dynamic response subsystem 300 includes a response trigger module 310 and an immunity response module 320. The response trigger module 310 is used to receive the trigger recognition information of the communication node and determine the corresponding computer virus information according to the computer virus data characteristics of the trigger recognition information. The immunity response module 320 is configured with a critical value recognition algorithm for updating the computer virus critical value. The critical value recognition algorithm is configured as, where, S A is the computer virus critical value, S C is the preset reference critical value, α1 is the preset static critical value weight, α2 is the preset dynamic critical value weight, and α1 + α2 = 1. H a is the computer virus historical impact value, t0 is the current moment, t kis the time when the k-th computer virus is recognized, where k is the total number of times the computer virus is recognized, and M k is the security level corresponding to the communication node when the k-th computer virus is recognized, and H k is the actual impact value of the computer virus corresponding to when the k-th computer virus is recognized, and t a is a preset reference time parameter. The dynamic response subsystem 300 is to adjust the corresponding computer virus critical value according to the actual situation. Its principle is to judge in real time according to the actual supply situation of the computer virus through the response trigger module 310, identify the characteristic type of the computer virus, and adjust the corresponding computer virus critical value by matching the computer virus information library 201. The critical value recognition algorithm calculates the computer virus critical value through two dimensions. One is the static dimension, that is, by analyzing the impact degree judged by the computer virus, and the other is the dynamic dimension, which is judged according to the actual number and frequency of computer virus intrusions. If the number of computer virus intrusions is large, the computer virus critical value is updated in real time through the supply analysis of the computer virus. In this way, a new immune strategy can be generated to increase the concentration of the corresponding immune strategy of the system. On the other hand, it can trigger the upgrade of the immune sub-strategy.

[0047] The described immune configuration instruction includes a dynamic forwarding request, and the dynamic forwarding request includes a dynamic forwarding condition. When the communication node configures the immune strategy to meet the dynamic forwarding condition, the communication node sends the dynamic forwarding request to other communication nodes according to the power grid immune neural model to configure the immune strategy to other communication nodes. Through the dynamic forwarding request, the dynamic configuration of the immune strategy is realized. The dynamic forwarding condition can be the time when the immune strategy is configured. If the configured duration exceeds the preset time, it is regarded as meeting the corresponding dynamic forwarding condition. At this time, the immune strategy can be reconfigured. In this way, while ensuring the basic concentration of the immune strategy corresponding to each computer virus, the fluidity of the immune strategy can be ensured, and the immune rule can be avoided from being discovered, resulting in system vulnerabilities.

[0048] Each disinfection item corresponds to a disinfection ability sub-value, and each corresponding recognition item corresponds to a recognition ability sub-value. The immune ability management module 130 also includes marking the disinfection ability value and recognition ability value of each communication node. The disinfection ability value is the sum of the disinfection ability sub-values, and the recognition ability value is the sum of the recognition ability sub-values;

[0049] The power grid model construction subsystem also includes a node marking module, and the node marking module is configured with a model calculation algorithm. The model calculation algorithm is used to calculate the total model channel value and the total model ability value, where LS is the total model ability value, LK is the total model channel value, and z jis the recognition ability value corresponding to the j-th communication node, G jd is the channel association value corresponding to the j-th communication channel, l is the total number of communication nodes, v j is the disinfection ability value corresponding to the j-th communication node, R i is the layer ratio weight, there is R i = 1 / (p1...p i ), p i is the number of communication nodes in the i-th layer of the power grid immune neural model, i is the layer number of the communication node in the power grid immune neural model; by calculating the total model ability and the total model channel value, the immunity of the entire system can be calculated, and based on this immunity, the execution method of the corresponding immunity strategy can be formulated for different situations.

[0050] Specifically as follows: The node marking module 140 is configured with a hierarchical feature index table. The hierarchical feature index table uses the total model ability and the total model channel value as indexes to retrieve hierarchical feature conditions, and marks the node security level for each communication node according to the hierarchical feature conditions. The immunity configuration subsystem 200 configures the communication nodes with a node security level lower than the preset level benchmark with an instruction splitting strategy. When a communication node is configured with an immunity configuration instruction, the instruction splitting strategy splits a new immunity configuration instruction according to the immunity configuration instruction and configures it on other communication nodes. The division basis of the node security level is retrieved according to the immunity of the entire system. For example, the division basis can be the number of nodes spaced from the platform, or the number of collection points as terminal nodes, or the number of connected peer nodes, or the disinfection ability and recognition ability of the node itself can all be used as the division basis. Different division bases correspond to different node security levels. Thus, for example, new immunity strategies can be split at nodes with a higher security level, which can ensure that nodes with higher security requirements improve their immunity and ensure that computer virus attacks can be detected in the first place.

[0051] Refer to Figure 2As shown, the immunity of computer virus A with a computer virus number is described in combination with the grid immune neural model. First, according to the computer virus critical value of this computer virus, the immunity number is calculated to be 4. In the figure, the immunity strategies of computer virus A are shown by A1 - A4, and the immunity strategies are configured outward from the data platform through the immunity configuration instructions. The configuration process of immunity strategy A1 is as follows: After passing through the first node (A1 - 1), since it cannot be configured at step A5, it enters the next node, denoted as A5 - A1; after determining the direction of the next node (A1 - 2) through a random number, since step A3 is not configured yet, it enters the next node, denoted as A3 - A1; after determining the third node (A1 - 3) through a random number, the configuration is completed, denoted as A5 end. After completion, it is found that the node security level of this node is higher than the preset value, so the instruction splitting strategy is executed to generate a new A1 and send it to the next node (A1 - 4). Thus, the configuration of the first immunity strategy A1 is completed. Since the channel corresponding to the A1 - 1 node already has an anti - information attenuation factor, the probability of this channel being selected again is reduced. The configuration of immunity strategy A2 also passes through A2 - 1\A2 - 2 and ends at node A2 - 3. At this time, if the characteristics of this computer virus are exactly recognized at A2 - 3, the dynamic response will affect the computer virus critical value, so the corresponding immunity number rises to 6, and new immunity strategies A5 and A6 are added; although the immunity strategy A6 is affected by the attenuation factor, the random number still falls into the node corresponding to A3 - 1, so A3 - 1 receives two immunity strategies, and the corresponding executed immune sub - strategy is upgraded. The immunity strategy A5 passes through the A5 - 1 node and ends at A5 - 2. The immunity strategy A4 passes through nodes A4 - 1\A4 - 2\A4 - 3 and reaches A4 - 4 to end the configuration. After meeting the corresponding forwarding conditions, it then passes through A4 - 5 to reach the A4 - 6 node.

[0052] The above - mentioned are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the creative concept of the present invention, several modifications and improvements can still be made, and these all belong to the protection scope of the present invention.

Claims

1. An adaptive data attack system applied to a power network, characterized in that, Including: A power grid model construction subsystem and an immune configuration subsystem; The power grid model construction subsystem is used to construct a power grid immune neural model, and the power grid model construction subsystem includes an architecture management module, an associated feature management module, and an immune capacity management module; The architecture management module generates and updates a basic communication model according to the power grid communication architecture, the nodes of the basic communication model correspond to communication devices, and the connections of the basic communication model correspond to communication channels; The associated feature management module is configured with a channel matching database, the channel matching database stores a number of channel identification indexes and corresponding channel identification data, the associated feature management module obtains the channel information of each communication channel, and retrieves the corresponding channel identification data according to the channel identification index in the channel information to generate a channel parameter group for each communication channel, each channel parameter group includes a number of different types of channel parameters, and the type items in the channel parameter groups of different communication channels are the same; The immune capacity management module is configured with an identification matching database and a disinfection matching database, the identification matching database stores a number of identification items, each identification item corresponds to a number of identification conditions, and the disinfection matching database corresponds to disinfection items, each disinfection item corresponds to a number of disinfection conditions; the immune capacity management module obtains the device information of each communication node, and when the device information meets the identification conditions corresponding to the identification item, adds the corresponding identification item to the identification capacity group of the communication node until all identification items are traversed, and when the device information meets the disinfection conditions corresponding to the corresponding disinfection item, adds the corresponding disinfection item to the disinfection capacity group of the communication node until all disinfection items are traversed; The immune configuration subsystem is configured with a computer virus information library and an immune strategy library, the computer virus information library stores a number of computer virus information, each computer virus information includes computer virus data characteristics and computer virus critical values, the immune configuration subsystem includes a computer virus analysis module and an immune configuration module, the computer virus analysis module generates corresponding immune numbers according to the computer virus critical values, and retrieves the corresponding immune strategies from the immune strategy library according to the computer virus characteristic information, and the immune configuration module is used to generate immune configuration instructions with the number of immune numbers according to the immune strategies, and use the immune configuration instructions to configure the immune strategies in the communication nodes of the power grid immune neural model.

2. The data attack adaptive system applied to a power network according to claim 1, wherein, It further includes a dynamic response subsystem, and the dynamic response subsystem includes a response trigger module and an immune response module; the response trigger module is used to receive the trigger recognition information of the communication node, and determine the corresponding computer virus information according to the computer virus data characteristics of the trigger recognition information, and the immune response module is configured with a critical value recognition algorithm for updating the computer virus critical value, and the critical value recognition algorithm is configured as wherein, S A is the computer virus critical value, S C is the preset reference critical value, α1 is the preset static critical value weight, α2 is the preset dynamic critical value weight, and α1 + α2 = 1, H a is the computer virus historical impact value, t0 is the current time, t k is the time when the k-th computer virus is recognized, k is the total number of times the computer virus is recognized, M k is the security level corresponding to the communication node where the k-th computer virus is recognized, H k is the actual impact value of the computer virus corresponding to when the k-th computer virus is recognized, t a is the preset reference time parameter.

3. The data attack adaptive system applied to the power grid according to claim 1, wherein The immune configuration instruction includes a dynamic forwarding request, the dynamic forwarding request includes a dynamic forwarding condition, and when the communication node configures the immune strategy to meet the dynamic forwarding condition, the communication node sends the dynamic forwarding request to other communication nodes according to the power grid immune neural model to configure the immune strategy in other communication nodes.

4. The data attack adaptive system applied to a power network according to claim 3, wherein The steps of configuring the immune strategy by the immune configuration instruction are as follows: Step A1: Generate a configuration value range according to the channel information of the communication channel corresponding to the current communication node so that different communication channels have different configuration value ranges; Step A2: Generate a random number, and determine the next communication node of the corresponding communication channel according to the configuration value range into which the random number falls; Step A3: Retrieve the recognition ability group and disinfection ability group corresponding to the communication node, and determine whether the immunity strategy matches the recognition ability group and disinfection ability group. If they match, proceed to Step A4; if not, return to Step A1; Step A4: Generate a load value range based on the immunity load value of the current communication node, where the immunity load value reflects the working load of the communication node; Step A5: Generate a random number. If the random number falls within the load value range, return to Step A1; if the random number does not fall within the load value range, configure the immunity strategy for the current communication node.

5. The data attack adaptive system applied to the power network according to claim 4, characterized in that, The configured numerical range is generated based on the configured trust value of the communication channel, and the size of the configured numerical range is proportional to the configured trust value. There is where G a is the configured trust value, T d is the interval time for the immunity configuration instruction to pass through this communication channel, T x is the preset reference interval time, is the preset anti-information attenuation factor, G d is the channel correlation value. There is G d =β1D j +β2U(u1 + u2)+β3Q j , where β1 is the preset distance weight, β2 is the preset communication efficiency weight, β3 is the preset area weight, and β1 + β2 + β3 = 1. D j is the communication distance value of this communication channel, U is the transmission speed value of this communication channel, u1 is the communication protocol efficiency number, u2 is the communication type efficiency number. The communication protocol efficiency number and the communication type efficiency number are obtained by looking up a table based on the channel information. Q j is the area correlation value of this communication channel, and the area correlation value is obtained by looking up a table based on the communication channel information; When an immunity configuration instruction passes through the communication channel, mark the corresponding anti-information attenuation factor on the communication channel.

6. The data attack adaptive system applied to a power network according to claim 5, wherein, Each disinfection item corresponds to a disinfection ability sub-value, and each corresponding recognition item corresponds to a recognition ability sub-value. The immunity ability management module also includes marking the disinfection ability value and recognition ability value of each communication node. The disinfection ability value is the sum of the disinfection ability sub-values, and the recognition ability value is the sum of the recognition ability sub-values; The power grid model construction subsystem further includes a node marking module, and the node marking module is configured with a model calculation algorithm, which is used to calculate the total model channel value and the total model capacity value. There is LS where is the total model capacity value, LK is the total model channel value, z j is the recognition ability value corresponding to the jth communication node, G jd is the channel association value corresponding to the jth communication channel, l is the total number of communication nodes, v j is the disinfection ability value corresponding to the jth communication node, R i is the layer ratio weight, and there is R i = 1 / (p1...p i ), p i is the number of communication nodes in the ith layer of the power grid immune neural model, and i is the layer number of the communication node in the power grid immune neural model; The node marking module is configured with a hierarchical feature index table. The hierarchical feature index table uses the total model ability value and the total model channel value as indexes to retrieve the hierarchical feature conditions, and marks the node security level for each communication node according to the hierarchical feature conditions.

7. An adaptive data attack system applied to a power grid according to claim 5, characterized in that, The immunity configuration subsystem configures the instruction splitting strategy for communication nodes with a node security level lower than the preset level benchmark. When a communication node is configured with an immunity configuration instruction, the instruction splitting strategy splits the immunity configuration instruction into a new immunity configuration instruction and configures it on another communication node.

8. The data attack adaptive system applied to a power network according to claim 3, wherein, Each immunity strategy includes several immunity sub-strategies, and different immunity sub-strategies have different concentration execution thresholds. When the number of times an immunity strategy is repeatedly configured exceeds the concentration execution threshold, execute the corresponding immunity sub-strategy.

9. An adaptive data attack system applied to a power network according to claim 1, characterized in that, The immunity configuration subsystem configures the corresponding immunity configuration instructions in the order of the computer virus critical value.

10. The data attack adaptive system applied to the power grid according to claim 1, wherein, The recognition conditions include encryption method, communication type, communication efficiency, and maximum transmission unit. The disinfection conditions include verification method, memory size, and processor type.

Citation Information

Patent Citations

  • Network security architecture for power information acquiring system

    CN102710649A

  • A power grid object access control device capable of realizing secure configuration and access to power grid model data

    CN104168268B

  • Power grid data safety communication transmission system and method

    CN111683042A

  • Power grid data protection method and system based on block chain and data security sandbox

    CN112347470A

  • Safety immune system for intelligent power distribution terminal

    CN114564717A