A substation network security threat detection rule establishment method
By analyzing substation communication information, separating event response from background communication, establishing communication response rules, identifying and blocking covert network attacks, the problems of highly covert attacks and false alarms in smart substations are solved, improving the accuracy of the monitoring system and the safety and stability of the power grid.
Patent Information
- Application Number
- CN202211712678.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-29
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2042-12-29
AI Technical Summary
Existing technologies are insufficient to effectively identify and protect against highly covert network attacks in smart substations, and the monitoring system contains a large number of false alarm signals, making it difficult for monitoring personnel to handle and affecting the safe and stable operation of the power grid.
By analyzing substation communication information, separating event response communication from background communication, establishing communication response rules for emergencies, identifying and blocking covert network behavior anomalies, and using emergency event communication rules for intrusion detection.
It improves the ability to detect highly covert attacks, reduces false alarms, enhances the accuracy and efficiency of the monitoring system, and ensures the safe and stable operation of the power grid.
Smart Images

Figure CN116015911B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of power monitoring system network security protection, and particularly relates to a substation network security threat detection rule establishment method. BACKGROUND
[0002] In the existing power monitoring system network security protection system, security threats are mainly identified based on misuse detection and anomaly detection. The former detects anomalies according to determined rules, and can only cover part of the known attack mode security threats. The latter relies on the setting of an anomaly threshold, and has the defects of threshold setting difficulty and false positives and false negatives. The existing security situation awareness model only fuses secondary device information as an element to construct a situation index, but high concealment attacks do not necessarily cause obvious traffic anomalies and high-risk alarms. If the situation index cannot effectively represent the behavior characteristics of high concealment attacks, it is difficult to accurately perceive high concealment attacks through algorithm optimization. Therefore, it is necessary to strengthen the research on detection methods for high concealment attacks with prior knowledge.
[0003] The patent document with the authorization announcement number CN105245001B discloses an event-driven substation accident intelligent alarm processing method and device. The method first establishes a substation accident type and accident symptom correlation model according to the characteristics of the substation accident, adds the accident analysis and processing strategies of each accident type in the accident type table to the expert knowledge base, then establishes an event-driven model, and monitors the changes of each data signal in real time and triggers the input event when the signal changes to a specific condition to start the event-driven model for accident analysis. Finally, according to the accident analysis result, the corresponding accident analysis and processing strategy is called from the expert knowledge base to form and display the accident analysis report and processing strategy. This method can reduce the work burden of monitoring personnel to a certain extent, improve the processing efficiency and accuracy of substation accidents, and reduce the loss caused by accidents. However, in actual use, it cannot automatically identify repeated alarm signals, which makes it difficult for monitoring personnel to directly obtain the current fault point, causing inconvenience in actual work.
[0004] The patent document with the authorization announcement number CN104578426B discloses a detection method for information comprehensive analysis and intelligent alarm application, including the following steps: detecting whether the modular design of the advanced application function module of the substation meets the requirements; determining the classification of alarm signal information and completing the detection of intelligent alarm and analysis decision; detecting information comprehensive analysis decision; detecting distributed state estimation and data identification. Although this patent solves the data sharing and function interaction between different functional modules, it still cannot solve the problem of quickly and accurately positioning the fault point of the intelligent substation, and cannot solve the problem of the large amount of data transmitted to the monitoring server personnel correctly handling the substation alarm signal. SUMMARY
[0005] The embodiment of the present application aims to provide a substation network security threat detection rule establishment method, which utilizes emergency response communication to analyze and establish emergency communication response rules, and proposes a rule-based network abnormal behavior detection method with explainability based on the rules.
[0006] To solve the above technical problems, the technical solution adopted by the present application is:
[0007] The embodiment of the present application provides a substation network security threat detection rule establishment method, which comprises the following steps: collecting communication information related to the substation, retaining only the message data except the IED device heartbeat message and SV message in the substation, and performing certain preprocessing on the collected communication information; collecting communication information data related to the data transmission process in real time, and performing certain preprocessing on the collected communication information data; analyzing the preprocessed communication information data, completing the deconstruction of background communication and event response communication, discarding the periodic reporting of measurement value data as background communication, and separately analyzing the interactive communication process triggered by the event; summarizing the same event response communication to obtain an event response specification process with verifiability; and judging whether the specific network communication behavior of the secondary system is reasonable and safe according to the above event response specification process, and identifying the hidden network behavior abnormality.
[0008] In some embodiments, in the S1 step, the collected communication information includes: the time of information sending or receiving, the source address, the destination address, and the port number.
[0009] In some embodiments, in the S2 step, the communication information data includes: system, protocol, and IP address information data.
[0010] In some embodiments, in the S3 step, the emergency is found from the substation SoE record and the corresponding time is recorded, and the substation communication data of the substation 1s before the emergency to 30s after the emergency is taken as the communication response of the emergency.
[0011] In some embodiments, in the S4 step, the rules of the communication responses of all recorded emergencies are established according to the method in the above step S3 from the multiple emergencies recorded in the substation SoE.
[0012] In some embodiments, in the S5 step, the intelligent substation performs intrusion detection on the substation automation system according to the rules established based on the historical emergency communication responses in step S4, and identifies the hidden network behavior abnormality.
[0013] With the gradual popularization of smart substation technology, the monitoring system based on data information network transmission is gradually replacing the traditional mode based on secondary cable hard connection. At present, the smart substation network is logically composed of station control layer network, interval layer network and process layer network, and physically configured in two layers, i.e. station control layer and process layer. The automation equipment in the station is uniformly modeled according to IEC61850 standard, and the unified data interface model defined based on IEC61850 is applied to exchange equipment through station control layer MMS (Manufacturing Message Specification) network and process layer GOOSE (Generic Object Oriented Substation Event) and SV (Sampled Value) network to realize information sharing and interaction. However, the current smart substation business message is in clear text transmission, and the station communication does not have network attack and attack protection deployment.
[0014] With the emergence of the serious situation of network security, the important position of substation in power grid safety needs to monitor and protect the security of data communication in the substation.
[0015] In the prior art, there are some methods and systems for monitoring the security of substation communication data.
[0016] For example, the patent document with the application publication number CN114513342A discloses a smart substation communication data security monitoring method and system, which comprises: generating data security monitoring rule configuration file, security monitoring strategy configuration file and switch forwarding configuration file based on the full-station SCD configuration file of the substation and the security requirements; issuing the data security monitoring rule configuration file and the security monitoring strategy configuration file to the security monitoring equipment, and issuing the security monitoring strategy configuration file and the switch forwarding configuration file to the substation network switch; in response to receiving the security event information sent from the security monitoring equipment and the substation network switch, performing alarm display, information recording processing and control. The patent document generates security monitoring basis based on the full-station SCD configuration information, conducts real-time security monitoring and inspection on the communication data, and performs security event control and alarm, thereby improving the security of the smart substation communication network and ensuring the reliable and stable operation of the protection control and automatic monitoring system of the smart substation.
[0017] Meanwhile, with the development of smart substation technology, while information within the substation is highly integrated, the amount of information has also increased exponentially. Especially when an interlocking fault occurs in the power grid, the monitoring server receives a massive influx of information, making it difficult for monitoring personnel to quickly locate the cause of the fault and take countermeasures. On the other hand, due to equipment stability issues, transmission channel interference, and improper setting parameters, the dispatch master station monitoring system is also filled with a large number of false alarm signals. This greatly hinders the correct handling of substation alarm signals by monitoring server personnel, leading to frequent equipment damage and substation tripping accidents caused by improper responses to substation alarm information by monitoring personnel. This adversely affects the safe, stable, economical, and reliable operation of the power grid.
[0018] To ensure efficient integration of information within intelligent substations, improve information quality, and facilitate monitoring personnel's better understanding of the operation of intelligent substations, the intelligent substation technology system proposes intelligent alarm as an advanced application function of the monitoring system. This function aims to extract key information from various alarm messages in the substation through automatic analysis of the monitoring system, analyze and synthesize the information, provide alarm information and processing suggestions, and assist monitoring and operation personnel in quickly handling various abnormal alarm events occurring in the substation.
[0019] For example, patent document CN105245001B discloses an event-driven intelligent alarm processing method and device for substation accidents. This method first establishes a correlation model between substation accident types and accident symptoms based on the characteristics of substation accidents, and adds the accident analysis and processing strategies for each accident type to an expert knowledge base. Then, it establishes an event-driven model, monitors changes in various data signals in real time, and triggers input events when signals change to specific conditions, thereby activating the event-driven model for further accident analysis. Finally, based on the accident analysis results, it retrieves the corresponding accident analysis and processing strategies from the expert knowledge base, generating and displaying an accident analysis report and processing strategies. While this method can alleviate the workload of monitoring personnel to some extent, improve the efficiency and accuracy of substation accident handling, and reduce losses caused by accidents, in actual use, it cannot automatically identify repeated alarm signals. This prevents monitoring personnel from directly obtaining the current fault point, causing inconvenience in practical work.
[0020] For example, patent document CN104578426B discloses a detection method for information integration analysis and intelligent alarm applications, including the following steps: detecting whether the modular design of advanced application functions in substations meets the requirements; determining the classification of alarm information and completing the detection of intelligent alarm and analysis decision-making; detecting information integration analysis decision-making; and detecting distributed state estimation and data identification. Although this patent solves the problem of data sharing and functional interaction between different functional modules, it still cannot solve the problem of quickly and accurately locating fault points in intelligent substations, nor can it solve the problem of the large amount of data transmitted to the monitoring server causing difficulties for monitoring server personnel in correctly processing substation alarm signals.
[0021] Compared with the prior art, the beneficial effects of the present invention are:
[0022] This invention provides a method for establishing network security threat detection rules for substations. First, the communication behavior of the substation monitoring system is decomposed into background traffic of periodically reported SV measurement value messages and heartbeat messages, and event-driven emergency response communication. Then, the background traffic of SV measurement value messages and heartbeat messages is removed, and only emergency response communication is used to parse and establish communication response rules for emergencies. Based on this, a rule-based, interpretable method for detecting abnormal network behavior is proposed.
[0023] The difficulty in misuse detection lies in summarizing and refining a sufficiently rich set of intrusion detection rules. This is because substation automation systems operate according to defined rules and respond to specific emergencies through predetermined processes and patterns.
[0024] This invention provides a method for establishing network security threat detection rules for substations. Based on the parsing of communication triggered by emergencies, response rules for various emergencies are established. Then, these rules, established based on the corresponding communication of actual emergencies, are used to detect intrusion behaviors that violate the rules. This method enriches and improves the rule specifications for event response on the basis of the original misuse detection, and can properly solve the problems existing in misuse detection.
[0025] This invention provides a method for establishing network security threat detection rules for substations. The method includes collecting substation communication data, including real-time data acquisition, parsing the communication data, deconstructing background communication and event response communication, removing SV message communication and heartbeat message communication, analyzing the event-triggered interactive communication process separately, and summarizing corresponding communication response rules based on the communication responses to sudden events. The method also includes summarizing and organizing identical event response communications to obtain verifiable event response standard procedures. Smart substations can use these standard event response procedures to determine whether the specific network communication behavior of secondary systems is reasonable and secure, thereby identifying hidden network behavior anomalies. Attached Figure Description
[0026] To more clearly illustrate the technical solutions in this disclosure, the accompanying drawings used in some embodiments of this disclosure will be briefly described below. Obviously, the drawings described below are only drawings of some embodiments of this disclosure, and those skilled in the art can obtain other drawings based on these drawings. In addition, the drawings described below can be regarded as schematic diagrams and are not intended to limit the actual size of the product, the actual process of the method, etc. involved in the embodiments of this disclosure.
[0027] Figure 1 This is a flowchart of a method for establishing network security threat detection rules for substations according to some embodiments of this disclosure. Detailed Implementation
[0028] The technical solutions in some embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, and not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments provided in this disclosure are within the scope of protection of this disclosure.
[0029] Unless the context otherwise requires, throughout the specification and claims, the term "comprising" is interpreted as open-ended and encompassing, meaning "including, but not limited to." In the description of the specification, terms such as "one embodiment," "some embodiments," "exemplary embodiment," "example," or "some examples" are intended to indicate that a particular feature, structure, material, or characteristic associated with that embodiment or example is included in at least one embodiment or example of this disclosure. The illustrative representations of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics mentioned may be included in any suitable manner in any one or more embodiments or examples.
[0030] This invention provides a method for establishing network security threat detection rules for substations, such as... Figure 1 As shown, the basic process is as follows: Event response data is retained in the substation communication data; then, the event response data is parsed, correlated, and coupled to ultimately improve the existing detection rules. Specifically, this includes steps S1 to S5.
[0031] S1 collects communication information related to the substation, retaining only message data other than heartbeat messages and SV (Sampled Value) messages from IED devices within the substation, and performs certain preprocessing on the collected communication information.
[0032] For example, in step S1, only information related to GOOSE (Generic Object Oriented SubstationEvent) messages is retained.
[0033] S2 collects communication information data involved in the data transmission process in real time and performs certain preprocessing on the collected communication information data.
[0034] S3 parses the preprocessed communication information data, deconstructs the background communication and event response communication, discards the periodically reported measurement data as background communication, and analyzes the event-triggered interactive communication process separately.
[0035] S4 summarizes and organizes the same event response communications to obtain a verifiable event response specification process.
[0036] S5, the intelligent substation judges whether the specific network communication behavior of the secondary system is reasonable and safe according to the above-mentioned event response standard procedure, and identifies hidden network behavior anomalies.
[0037] Here, the collected communication information is for event response communication, while the regularly reported measurement data, such as SV messages and heartbeat messages, can mask highly covert attacks such as bypass control attacks, so background communication data needs to be removed.
[0038] This invention provides a method for establishing network security threat detection rules for substations. The method includes collecting substation communication data, including real-time data acquisition, parsing the communication data, deconstructing background communication and event response communication, removing SV message communication and heartbeat message communication, analyzing the event-triggered interactive communication process separately, and summarizing corresponding communication response rules based on the communication responses to sudden events. The method also includes summarizing and organizing identical event response communications to obtain verifiable event response standard procedures. Smart substations can use these standard event response procedures to determine whether the specific network communication behavior of secondary systems is reasonable and secure, thereby identifying hidden network behavior anomalies.
[0039] In some embodiments, the communication information collected in step S1 includes: the time of information transmission or reception, the source address of the information, the destination address of the information, and the port number.
[0040] For example, the collected communication information may also include the specific content of the information sent or received, the operating status of the primary side when the information is sent or received, and other such information.
[0041] In some embodiments, in step S2, the communication information data includes: information data about the system, protocol, and IP address.
[0042] In some embodiments, in step S3, specifically, an emergency event is found from the substation SoE record and the corresponding time is recorded. The substation communication data from 1 second before the emergency event to 30 seconds after the emergency event is used as the communication response to the emergency event. The protocol, source address, destination address, and timing characteristics of the communication data packets of each IED device during this time period are analyzed. Based on the source, destination, and timing of the communication data packets sent by each IED device during the emergency event communication response process, the rules for the corresponding communication response to the emergency event are established.
[0043] In some examples, in step S3, it is also necessary to combine the event-triggered interactive communication information obtained from the secondary side of the substation with the operating status of the primary system of the substation to perform data parsing, correlation and coupling analysis.
[0044] In some embodiments, in step S4, multiple incidents recorded in the substation SoE are sequentially collected, and rules for communication responses corresponding to all recorded incidents are established according to the method in step S3 above.
[0045] In some examples, specifically in step S4, a fully accurate event response protocol is obtained by long-term monitoring of communication data and SoE event analysis to detect sudden events.
[0046] For example, corresponding emergency communication response rules can be generated for various emergencies that have occurred, such as common capacitor switching and circuit breaker opening and closing.
[0047] For example, for responses to infrequent emergencies, real communication records are generated through simulation exercises, and based on these records, emergency communication response rules for infrequent events are formulated, thereby forming emergency communication response rules for infrequent events, which are used for corresponding security threat detection.
[0048] In some embodiments, in step S5, the smart substation performs intrusion detection of the substation automation system according to the rules established in step S4 based on historical emergency communication responses, and identifies covert network behavior anomalies.
[0049] In some examples, smart substations accurately identify abnormal event responses and issue alarms based on standardized event response procedures, and can promptly block unknown high-risk operations.
[0050] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Any other modifications or equivalent substitutions made by those skilled in the art to the technical solutions of the present invention, as long as they do not depart from the spirit and scope of the technical solutions of the present invention, should be covered within the scope of the claims of the present invention.
Claims
1. A method for establishing network security threat detection rules for substations, characterized in that, Includes the following steps: S1 collects communication information related to the substation, retains only message data other than heartbeat messages and SV messages from IED devices within the substation, and performs certain preprocessing on the collected communication information. S2, collects communication information data involved in the data transmission process in real time, and performs certain preprocessing on the collected communication information data; S3 parses the preprocessed communication information data, deconstructs the background communication and event response communication, discards the periodically reported measurement data as background communication, and analyzes the event-triggered interactive communication process separately. In step S3, the sudden event is found from the substation SoE record and the corresponding time is recorded. The substation communication data from 1 second before the sudden event to 30 seconds after the sudden event is used as the communication response of the sudden event. The protocol, source address, destination address and timing characteristics of the communication data packets of each IED device during this time period are analyzed. Based on the source and destination and timing of the communication data packets sent by each IED device during the communication response process of the sudden event, the rules for the corresponding communication response of the sudden event are established. In step S3, it is also necessary to combine the event-triggered interactive communication information obtained from the secondary side of the substation with the operating status of the primary system of the substation to perform data parsing, correlation and coupling analysis. S4, summarize and organize the same event response communications to obtain a verifiable event response specification process; In step S4, multiple sudden events recorded in the substation SoE are sequentially collected, and rules for communication responses corresponding to all recorded sudden events are established according to the method in step S3 above. In step S4, through long-term communication data monitoring and SoE event analysis, a fully accurate event response protocol for the detected emergencies is obtained. S5, the intelligent substation judges whether the specific network communication behavior of the secondary system is reasonable and safe according to the above-mentioned event response standard procedure, and identifies hidden network behavior anomalies. In step S5, the smart substation performs intrusion detection on the substation automation system based on the rules established in step S4 based on historical emergency communication responses, and identifies covert network behavior anomalies.
2. The method for establishing network security threat detection rules for substations as described in claim 1, characterized in that: In step S1, the collected communication information includes: the time of information transmission or reception, the source address of the information, the destination address of the information, and the port number.
3. The method for establishing network security threat detection rules for substations as described in claim 1, characterized in that: In step S2, the communication information data includes: system, protocol, and IP address information data.
Citation Information
Patent Citations
A detection method for information comprehensive analysis and intelligent alarm application
CN104578426B
An event-driven substation accident intelligent alarm processing method and device
CN105245001B
Intelligent substation communication data safety monitoring method and system
CN114513342A
Intelligent substation secondary network device data holographic analysis display method
CN107644304A
Intelligent substation risk early warning system and method based on security situation awareness
CN113037745A