A system for constructing a cybersecurity behavior model of a power infrastructure

By introducing the power entity model and the power network action model into the power network security behavior model, the problem of insufficient reusability of the existing models is solved, more efficient network security assessment and response are achieved, and the security of the power infrastructure is improved.

CN116208505BActive Publication Date: 2025-06-24JOINT WARFARE COLLEGE NAT DEFENSE UNIV OF THE CHINESE PEOPLES LIBERATION ARMY
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211677123.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-26
Publication Date
2025-06-24
Estimated Expiration
2042-12-26

AI Technical Summary

Technical Problem

The existing power network security behavior model is highly targeted to existing entity domains, but is not very reusable, and lacks a network security behavior model built from the perspective of system modeling.

Method used

A network security behavior model for power infrastructure is proposed, including power entity model and power network action model. The power physical model simulates the characteristics of the power physical domain and information domain, while the power network action model is used to evaluate and simulate the impact of network security behavior on the physical model and conducts detection, protection and repair.

Benefits of technology

Through the system modeling method, the reusability and scalability of the power network security behavior model is improved, and network security threats can be more effectively evaluated and responded to, and the security of power infrastructure can be ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116208505B_ABST
    Figure CN116208505B_ABST
Patent Text Reader

Abstract

The present invention provides a power infrastructure network security behavior model, including a power entity model and a power network operation model; the power entity model includes a power physical domain entity model and a power information domain entity model, the power physical domain entity model is used to simulate the topological relationship and power function of transmission lines in a region, and the power information domain entity model is used to simulate the network characteristics and power dispatching function of power information control facilities; the power network operation model includes a power network security behavior model, which is used to evaluate the impact of network security behaviors on the power entity model, detect, protect and repair the power entity model, ensuring that the established power infrastructure network security behavior model has high reusability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security, and more particularly, to a power infrastructure network security behavior model. Background Art

[0002] Power infrastructure refers to a framework based on power CPS (Cyber-Physical System), which is composed of the integration of the power physical domain and the power information domain, and is compatible with electrical technologies such as intelligent power distribution, renewable energy grid connection, and smart grid restoration. The power information domain is the main target of network security protection actions. Network security behaviors occurring in the power information domain may cause greater-scale networked effects in the power grid system and even other combat domains. Network security behavior refers to personal (collective) behaviors such as malicious (accidental) destruction, modification, leakage, and protection of the hardware, software, and data in the network system, including network intrusion behaviors, network protection behaviors, etc.

[0003] Currently, power network security behavior models generally construct power network security behavior strategy optimization problems through complex network theory, or use petri network modeling methods to establish a network protection strategy under the fault types of the pre-conceived power grid system.

[0004] However, the above power network security behavior models have strong pertinence to the existing entity domain, weak reusability, and lack of network security behavior models constructed from the perspective of system modeling. Summary of the Invention

[0005] The problem solved by the present invention is how to establish a power network security behavior model with strong reusability.

[0006] To solve the above problem, the present invention provides a power infrastructure network security behavior model, including a power entity model and a power network action model;

[0007] The power entity model includes a power physical domain entity model and a power information domain entity model. The power physical domain entity model is used to simulate the topological relationship and power function of the transmission lines in the region, and the power information domain entity model is used to simulate the network characteristics and power dispatching function of the power information control facilities.

[0008] The power network action model includes a power network security behavior model, which is used to evaluate the impact of network security behaviors on the power entity model, detect, protect, and repair the power entity model.

[0009] Optionally, the power physical domain entity model includes a power generation station node model, a substation node model, a distribution station node model, and a load center model.

[0010] Optionally, the power information domain entity model includes a power generation station monitoring model, a substation monitoring model, and a power dispatching center model.

[0011] Optionally, the information in the power generation station node model, the substation node model, the distribution station node model, and the load center model includes node name, unit number, node number, administrative region to which it belongs, grid region to which it belongs, heterogeneous node name, repair time, voltage, power, node status, node type, equipment type, and location coordinates.

[0012] Optionally, the information in the power generation station monitoring model, the substation monitoring model, and the power dispatching center model includes node name, unit number, node number, heterogeneous node, repair time, defense method, node status, node type, location, administrative region, grid region, controlled enemy unit, initial controlled party, and visible party.

[0013] Optionally, the power network security behavior model includes a virus attack model, a malicious code attack model, an intrusion detection model, and a power grid repair model;

[0014] The virus attack model is used to simulate the impact of virus attacks on the power entity model;

[0015] The malicious code attack model is used to simulate the impact of malicious code attacks on the power entity model;

[0016] The intrusion detection model is used to simulate the impact of network attacks on the power entity model;

[0017] The power grid repair model is used to simulate the overall repair behavior of the power entity model after damage.

[0018] Optionally, the virus attack model is constructed by a virus attack simulation method, and the virus attack simulation method includes:

[0019] According to the source node, target node, virus propagation hop count, and virus attack intensity array of the virus attack, determine whether the virus attack on the power information domain source node is successful through a network attack and defense dynamic game algorithm. The network attack and defense dynamic game algorithm includes an external exposure probability judgment and a comprehensive defense intensity judgment. When the external exposure probability is greater than the exposure threshold, the target node is in an externally visible state; when the attack intensity is greater than the comprehensive defense intensity, it is determined that the virus attack is successful; when the attack intensity is less than or equal to the comprehensive defense intensity, it is determined that the virus attack fails;

[0020] After determining that the virus attack is successful, change the electrical properties of the physical power domain entity model controlled by the power information domain entity model, shut down the power information domain entity, and set the power of the control node of the power information domain entity to zero;

[0021] Traverse the power information domain entities directly associated with the information of the power information domain entity attacked by the virus, and return to the step of determining whether the virus attack on the source node of the power information domain is successful through the network attack and defense dynamic game algorithm;

[0022] Determine whether the virus propagation hop count reaches the maximum propagation hop count;

[0023] If the maximum propagation hop count is not reached, return to the step of changing the electrical properties of the physical power domain entity model controlled by the power information domain entity model, shutting down the power information domain entity, and setting the power of the control node of the power information domain entity to zero until the maximum propagation hop count is reached.

[0024] Optionally, the malicious code attack model is constructed by a malicious code attack method, and the malicious code attack method includes:

[0025] At the first moment, traverse the information network characteristics of the nodes of the power information domain entity model in the attack path of the malicious code, and determine whether the power information domain entity model is attacked by the malicious code;

[0026] If it is attacked by the malicious code, update the power grid system topology and electrical parameters after the attack;

[0027] At the second moment, check whether the communication link of the local physical power domain entity model is attacked by the malicious code;

[0028] If it is attacked by the malicious code, update the power grid system topology and electrical parameters after the attack;

[0029] At the third moment, determine whether the path between the attacked node of the power information domain entity model and the next attacked node is normal according to the attack path;

[0030] If it is not normal, update the power grid system topology and electrical parameters after the attack;

[0031] At the fourth moment, check whether the first path that requires power flow adjustment for electrical local monitoring from the attack entity to the power dispatching center is normal;

[0032] At the fifth moment, check whether the information path between the attacked power information domain entity model and the power dispatching center entity is normal;

[0033] If both the first path and the information path are normal, cut off the corresponding load or backup circuit;

[0034] Traverse the fault conditions of all links and calculate the ratio of the remaining largest connected node clusters after fault propagation.

[0035] Optionally, the intrusion detection model is constructed by an intrusion detection method, and the intrusion detection method includes:

[0036] According to the virus attack simulation method, start detecting the intrusion of the virus at a preset detection time.

[0037] Optionally, the power grid repair model is constructed by a power grid repair method, and the power grid repair method includes:

[0038] Judge the repair conditions of the nodes in the power entity model to be repaired;

[0039] When the node is a power physical domain entity, judge whether it meets the preset physical domain entity repair conditions. When the power physical domain entity node meets the physical domain entity repair conditions, start the repair. Among them, the preset physical domain entity repair conditions include that the node is in a fault state, the repair probability is greater than the preset probability, and there is at least one normal electric circuit for the node;

[0040] When the node is a power information domain entity, find the heterogeneous node of the node, judge whether the heterogeneous node is down. If it is down, judge whether the heterogeneous node meets the physical domain entity repair conditions. If it meets, start repairing the heterogeneous node;

[0041] When all the nodes associated with the power information domain entity are repaired, end the power repair operation.

[0042] Compared with the prior art, the present invention establishes a physical domain entity model to depict the physical entities of electrical facilities; establishes an information domain entity model to depict the electrical control rules and information scheduling characteristics of electrical facilities, ensuring the establishment of a model of electrical facilities from the perspective of system modeling; and based on the power network action model, simulates the network security behavior of the established entity model, simulates the impact of network security behavior on the entity model, and then conducts detection, protection and repair according to the impact situation, ensuring the construction of a simulation at the technical level of power network behavior starting from the impact rules and effects of power information propagation, and ensuring that the model has high reusability. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] Figure 1 It is a system block diagram of the power infrastructure network security behavior model according to an embodiment of the present invention;

[0044] Figure 2 It is a flowchart of the virus attack model of the power infrastructure network security behavior model according to an embodiment of the present invention;

[0045] Figure 3 Flowchart of the malicious code attack model of the power infrastructure network security behavior model according to an embodiment of the present invention;

[0046] Figure 4 Flowchart of the intrusion detection model of the power infrastructure network security behavior model according to an embodiment of the present invention;

[0047] Figure 5 Flowchart of the power grid repair model of the power infrastructure network security behavior model according to an embodiment of the present invention. Detailed implementation manners

[0048] To make the above objects, features and advantages of the present invention more obvious and understandable, the following will describe the specific embodiments of the present invention in detail with reference to the accompanying drawings. Although some embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be construed as limited to the embodiments described herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present invention. It should be understood that the drawings and embodiments of the present invention are only for exemplary purposes and are not used to limit the protection scope of the present invention.

[0049] It should be understood that the various steps recorded in the method embodiments of the present invention can be executed in different orders and / or executed in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present invention is not limited in this regard.

[0050] As used herein, the term "including" and its variants are open-ended, that is, "including but not limited to". The term "based on" is "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments"; the term "optionally" means "optional embodiments". The relevant definitions of other terms will be given in the following description. It should be noted that the concepts such as "first" and "second" mentioned in the present invention are only used to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependent relationships.

[0051] It should be noted that the modifications of "one" and "multiple" mentioned in the present invention are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly stated in the context, it should be understood as "one or more".

[0052] As Figure 1 shown, a power infrastructure network security behavior model provided by an embodiment of the present invention includes a power entity model and a power network action model;

[0053] The power entity model includes a power physical domain entity model and a power information domain entity model. The power physical domain entity model is used to simulate the topological relationship and power function of the transmission lines in the region, and the power information domain entity model is used to simulate the network characteristics and power dispatching function of the power information control facilities;

[0054] The power network action model includes a power network security behavior model, which is used to evaluate the impact of network security behaviors on the power entity model, detect, protect, and repair the power entity model.

[0055] The present invention aims to design a power network security protection action model for large-scale critical infrastructure network security deduction. This model overcomes the characteristics of poor model reusability and scalability in the power professional technology field. From the perspective of system modeling, it draws on the EBNI modeling framework, starting from the rules and effects of network security games on power information dissemination, aggregates and improves existing professional models such as power infrastructure and power network security, and mainly constructs models such as power entities and power network monitoring entities that carry power network security services; starting from reflecting the effects of power network security actions, it constructs a simulation at the technical level of power network action equipment.

[0056] The power infrastructure network security behavior model is different from the power and network technology level models. From the perspective of system modeling, it analyzes and extracts the rules and effect models of the impact on power information dissemination in scenarios such as virus attacks and malicious code attacks. This model focuses on supporting the simulation and research of power network security protection effects. From a security perspective, it adds and studies the impact of power infrastructure network security attacks and defenses on transportation, economy, etc.

[0057] Optionally, the power physical domain entity model includes a power generation station node model, a substation node model, a distribution station node model, and a load center model.

[0058] Optionally, the power information domain entity model includes a power generation station monitoring model, a substation monitoring model, and a power dispatching center model.

[0059] Specifically, the physical power domain entity model simulates the topological relationships and power functions of electrical facilities and transmission lines for power generation, transmission, distribution, and use in a regional power grid. To support the deduction requirements of prototype systems with multi-resolution and different scales, the physical power domain entities are divided into four types of entity models: power generation stations, substations, distribution stations, and various types of loads. This model is different from the power technology model and only depicts the dynamic evolution law of the key attributes of electrical facilities affected by network security protection actions. The power information domain entity simulates the network characteristics and power dispatching functions of power information control facilities. According to the impact of network security behaviors on the dissemination of power dispatching information, the power information domain entities are divided into local power monitoring models and power dispatching center models, which mainly describe the electrical control rules and information dispatching characteristics for the regional power grid and local electrical facilities. The local power monitoring entity model includes models such as power generation station monitoring, substation monitoring, and distribution monitoring. The local monitoring entity coincides geographically with the corresponding local electrical facilities and realizes the electrical attribute monitoring and dispatching functions for local electrical facilities. The power dispatching center entity simulates the comprehensive power dispatching and emergency control rules for power dispatching centers at different levels, including power dispatching center entities such as large regions and regions.

[0060] The power infrastructure network security behavior model provided by the embodiment can support the deduction requirements of large-scale joint network security command, and can also independently support the deduction of power infrastructure network security protection, improving the joint command ability for power network security protection.

[0061] Optionally, the information in the power generation station node model, the substation node model, the distribution station node model, and the load center model includes node name, unit number, node number, administrative region to which it belongs, power grid region to which it belongs, heterogeneous node name, repair time, voltage, power, node status, node type, equipment type, and location coordinates.

[0062] Specifically, the power generation station node model simulates the power generation and electrical attributes of various power generation station entities in different regions, including entities such as nuclear power stations, hydropower stations, thermal power stations, and wind power generation stations, and supports the development of other types of power generation station entities. The main parameter list of the power generation station node model is shown in the following table:

[0063]

[0064]

[0065] Specifically, the substation node model simulates the step-up (step-down) electrical performance of substations of various voltage levels within the simulation area. Taking the high voltage as the voltage attribute of this entity, substation models of different voltage levels are divided. Substations of different voltage levels perform different functions of electric energy conversion within different scopes. For example: extra-high voltage substations are responsible for the electric energy conversion tasks in areas above the city level, medium-high voltage substations are responsible for the electric energy conversion tasks in cities, counties, and community areas. The main parameters of the substation node model are shown in the following table:

[0066]

[0067]

[0068] Specifically, the distribution substation node model simulates the electric energy distribution function of the county (community) low-voltage distribution substations within each region, including the entity of the county (community) low-voltage distribution substation. This entity describes the distribution attributes and functions of the county (community) electric energy to various types of electrical loads. The main parameters of the distribution substation node model are shown in the following table:

[0069]

[0070]

[0071] Specifically, the load center model simulates the electric energy attributes of the electric energy consumption center nodes within the county (community), including: convergence points of industrial, commercial, and residential electrical loads, etc. If there is an electric energy fault in this model, numerous electrical facilities with a power supply relationship with it will have power failures. The main parameters of the load center model are shown in the following table:

[0072]

[0073]

[0074] Optionally, the information in the power plant monitoring model, the substation monitoring model, and the power dispatching center model includes node name, unit number, node number, heterogeneous node, repair time, defense method, node status, node type, location, administrative region, power grid region, controlled enemy units, initial controlled party, visible party.

[0075] Specifically, the power plant monitoring model simulates the local normal monitoring of the power plant or the power generation power and excitation control performance within the controllable over-limit range, including: hydropower plant monitoring entity, thermal power plant monitoring entity, etc., supports the extension of monitoring of other types of power plants, and also simulates the network protection of the power plant monitoring and the dispatching and repair behavior of the power plant. The main parameters of the power plant monitoring model are shown in the following table:

[0076]

[0077]

[0078] Specifically, the substation monitoring model simulates the computer monitoring to execute the control performance of the excitation voltage and active power within the normal state or controllable over-limit range of local step-up (step-down). It includes: substation monitoring entities of different voltage levels. The main parameters of the substation monitoring model are shown in the following table:

[0079]

[0080]

[0081] Specifically, the power dispatching center model establishes a network connection with the local monitoring model, executes power dispatching behaviors such as power grid energy balance dispatching and power grid fault repair, and has related services for network defense and network repair. It includes: large-area and regional dispatching center models, etc. The main parameters of the power dispatching center model are shown in the following table:

[0082]

[0083]

[0084] Optionally, the power network security behavior model includes a virus attack model, a malicious code attack model, an intrusion detection model, and a power grid repair model;

[0085] The virus attack model is used to simulate the impact of virus attacks on the power entity model;

[0086] The malicious code attack model is used to simulate the impact of malicious code attacks on the power entity model;

[0087] The intrusion detection model is used to simulate the impact of network attacks on the power entity model;

[0088] The power grid repair model is used to simulate the overall repair behavior after the damage of the power entity model.

[0089] Optionally, as Figure 2 shown, the virus attack model is constructed by a virus attack simulation method, and the virus attack simulation method includes:

[0090] According to the source node, target node, virus propagation hop count, and virus attack intensity array of the virus attack, determine whether the virus attack on the source node of the power information domain is successful through a network attack and defense dynamic game algorithm. Among them, the network attack and defense dynamic game algorithm includes an external exposure probability judgment and a comprehensive defense intensity judgment. When the external exposure probability is greater than the exposure threshold, the target node is in an externally visible state; when the attack intensity is greater than the comprehensive defense intensity, it is determined that the virus attack is successful; when the attack intensity is less than or equal to the comprehensive defense intensity, it is determined that the virus attack fails;

[0091] When it is determined that the virus attack is successful, change the electrical properties of the physical power domain entity controlled by the entity model of the power information domain, shut down the entity of the power information domain, and set the power of the control node of the power information domain entity to zero.

[0092] Traverse the power information domain entities directly associated with the information of the virus attack on the power information domain entity, and return to the step of determining whether the virus attack on the source node of the power information domain is successful through the network attack and defense dynamic game algorithm.

[0093] Judge whether the virus propagation hop count reaches the maximum propagation hop count.

[0094] If the maximum propagation hop count is not reached, return to the step of changing the electrical properties of the physical power domain entity controlled by the entity model of the power information domain, shutting down the entity of the power information domain, and setting the power of the control node of the power information domain entity to zero, until the maximum propagation hop count is reached.

[0095] Specifically, the network virus attack behavior against the power information domain entity uses methods such as phishing emails and USB flash drive propagation to achieve network monitoring and privilege stealing of the power data scheduling network, and causes misoperations in the power information domain and large-scale cascading failures of the regional power grid system by destroying the availability and authenticity of power scheduling information. The model mainly simulates the cross-domain influence rules of network virus attacks on power scheduling behavior under the established network defense resource allocation.

[0096] In an embodiment, parameters such as the source node, target node, virus propagation hop count, and virus attack intensity array of the virus attack are set. At the start time of the virus attack initiation action, use the network attack and defense dynamic game algorithm to determine whether the virus attack on the source node of the power information domain is successful. If the external exposure probability of the target node is greater than the exposure threshold, the target is exposed and is in an externally visible state; if the attack intensity is greater than the comprehensive defense intensity, the virus successfully attacks the power information domain entity; if the attack intensity is not greater than the comprehensive defense intensity, the network defense facility of the power information domain entity successfully resists the virus attack.

[0097] When the virus is successful, change the electrical properties of the physical power domain entity controlled by the power information domain entity, shut down the power information domain entity, and set the power of the node controlled by the power information domain entity to zero.

[0098] Traverse the power information domain entities directly associated with the information of the virus attack on the power information domain entity, and return to the step of "using the network attack and defense dynamic game algorithm at the start time of the virus attack initiation action to determine whether the virus attack on the source node of the power information domain is successful".

[0099] Determine whether the virus transmission hop count has reached the maximum transmission hop count. If it has not reached the maximum transmission hop count, return to the step of "changing the electrical attributes of the power physical domain entity that controls the power information domain entity".

[0100] When the maximum transmission hop count is reached, the virus attack operation ends.

[0101] The main parameters of the virus attack model are shown in the following table:

[0102]

[0103] Optionally, as Figure 3 shown, the malicious code attack model is constructed by a malicious code attack method, and the malicious code attack method includes:

[0104] At the first moment, traverse the information network characteristics of the nodes of the power information domain entity model in the attack path of the malicious code, and determine whether the power information domain entity model is attacked by the malicious code;

[0105] If it is attacked by the malicious code, update the power grid system topology and electrical parameters after the attack;

[0106] At the second moment, check whether the communication link of the local power physical domain entity model is attacked by the malicious code;

[0107] If it is attacked by the malicious code, update the power grid system topology and electrical parameters after the attack;

[0108] At the third moment, determine whether the path between the attacked node of the power information domain entity model and the next attacked node is normal according to the attack path;

[0109] If it is not normal, update the power grid system topology and electrical parameters after the attack;

[0110] At the fourth moment, check whether the first path that requires power flow adjustment for electrical local monitoring from the attack entity to the power dispatching center is normal;

[0111] At the fifth moment, check whether the information path between the attacked power information domain entity model and the power dispatching center entity is normal;

[0112] If both the first path and the information path are normal, cut off the corresponding load or backup circuit;

[0113] Traverse the fault conditions of all links, and calculate the remaining maximum connected node cluster ratio after the fault propagation.

[0114] Specifically, malicious code attacks on the power information domain are carried out through network intrusion and network monitoring methods, causing malicious regulation and misoperation of power information domain entities on the power grid system, resulting in local or even large-scale failures of the power grid. Focus on simulating multi-point collaborative malicious code attacks on power information domain entities, triggering malicious and faulty operations in power dispatching, and causing local or even large-scale paralysis of the power grid system.

[0115] In one embodiment, at the first moment, i.e., the initial moment, traverse the information network characteristics of the power information domain nodes in the malicious code attack path to determine whether the power information domain entity is attacked by malicious code; if the malicious code attack on this power information domain node is successful and the original communication link is normal, then update the power grid system topology and electrical parameters; if the malicious code attack on this power information domain node fails and the original communication link is abnormal, then update the power grid system topology and electrical parameters;

[0116] At the second moment, check whether the communication link of the local power physical domain entity (for example: local low-voltage distribution monitoring to the circuit breaker) is normal; if the original communication link is abnormal, then update the power grid system topology and electrical parameters; if the original communication link is normal, update the power grid system topology and electrical parameters;

[0117] At the third moment, adopt the network attack path to check whether it is normal from the currently attacked power information domain node to the next attacked power information domain node; if it is normal and the original communication link is abnormal, update the power grid system topology and electrical parameters; if it is abnormal and the original communication link is normal, update the power grid system topology and electrical parameters;

[0118] At the fourth moment, check whether the path from the attacking entity to the power dispatching center that requires power flow adjustment for electrical local monitoring is normal; at the fifth moment, check whether the information path from the attacked power information domain entity to the power dispatching center entity is normal; if both are normal, then cut off the corresponding load or backup circuit; if at least one is abnormal, do not perform the load shedding operation.

[0119] Traverse all links through the above method to determine whether there is a fault, and calculate the proportion of the remaining largest connected node cluster after the fault propagation, as the result of the malicious code attack simulation.

[0120] The main parameters of the malicious code attack model are shown in the following table:

[0121]

[0122] Optionally, as Figure 4 shown, the intrusion detection model is constructed by an intrusion detection method, and the intrusion detection method includes:

[0123] According to the virus attack simulation method, start detecting the intrusion of the virus at a preset detection time.

[0124] Specifically, the intrusion detection model simulates that entities in the power information domain are under cyber attacks, and takes intrusion detection actions for network protection. According to different intrusion detection methods, it includes execution at a specified time and automatic execution.

[0125] The main parameters of the intrusion detection model are shown in the following table:

[0126]

[0127] Optionally, as Figure 5 shown, the power grid restoration model is constructed by a power grid restoration method, and the power grid restoration method includes:

[0128] Judging the repair conditions of the nodes in the power entity model to be repaired;

[0129] When the node is a power physical domain entity, judge whether it meets the preset physical domain entity repair conditions. When the power physical domain entity node meets the physical domain entity repair conditions, start the repair. Among them, the preset physical domain entity repair conditions include that the node is in a fault state, the repair probability is greater than the preset probability, and there is at least one normal power line for the node;

[0130] When the node is a power information domain entity, find the heterogeneous node of the node, judge whether the heterogeneous node is down. If it is down, judge whether the heterogeneous node meets the physical domain entity repair conditions. If it meets, start to repair the heterogeneous node;

[0131] When all the nodes associated with the power information domain entities are repaired, end the power repair operation.

[0132] Specifically, the power grid restoration model simulates the overall restoration behavior of the regional power grid damage, and the power information domain regulates the power grid restoration prior to the power information domain repair, supporting the behavior strategies and process simulations for the repair and restoration of power grid system failures under the dispatching of the power information domain such as overload load shedding, relay protection, and low-frequency generator tripping; supporting the simulation and verification of power physical domain repair optimization strategies such as black start, power grid reconstruction, and load restoration.

[0133] In an embodiment, when the start time of the network repair operation is reached, judge the repair conditions of the nodes in the power information domain (physical domain) to be repaired;

[0134] If the node is an entity in the power physical domain, the judgment criteria include: the node to be repaired is currently in a fault state; the repair probability meets the strength for the node to be repairable; there is at least one normal outgoing power line for the repaired node; that is, the repair probability meets the strength for the node to be repairable. When the judgment conditions are met, change the node state to the repaired state, traverse all the outgoing node lists of the node. If the node is a physical domain node, directly perform the repair; if the node is an information domain node, check whether the state of the heterogeneous node physical domain node of the information domain machine node is normal. If the heterogeneous node is down, repair the heterogeneous physical domain node. If the repair probability of the information domain node is met and the state of its heterogeneous node is normal, the repair condition of the information domain node is met and the information domain node is repaired successfully.

[0135] If the repair of all associated information domain nodes and heterogeneous nodes is completed, end the power repair operation.

[0136] The main parameters of the power grid repair model are shown in the following table:

[0137]

[0138] An electronic device provided by another embodiment of the present invention includes a memory and a processor; the memory is used to store a computer program; the processor is used to implement the power infrastructure network security behavior model as described above when executing the computer program.

[0139] A computer-readable storage medium provided by another embodiment of the present invention stores a computer program, and when the computer program is executed by a processor, it implements the power infrastructure network security behavior model as described above.

[0140] Now, an electronic device that can be used as the server or client of the present invention will be described. It is an example of a hardware device that can be applied to various aspects of the present invention. The electronic device is intended to represent various forms of digital electronic computer devices, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are only examples and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0141] An electronic device includes a computing unit that can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) or a computer program loaded from a storage unit into a random access memory (RAM). In the RAM, various programs and data required for device operation can also be stored. The computing unit, ROM, and RAM are connected to each other via a bus. An input / output (I / O) interface is also connected to the bus.

[0142] A computer system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The client-server relationship is generated by computer programs running on the respective computers and having a client-server relationship with each other.

[0143] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it may include the processes of the embodiments of the above methods. Among them, the storage medium can be a magnetic disk, an optical disc, a read-only memory (ROM), or a random access memory (RAM), etc. In this application, the units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units. They can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of the embodiments of the present invention. In addition, the functional units in each embodiment of the present invention can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0144] Although the present disclosure is disclosed as above, the protection scope of the present disclosure is not limited thereto. Those skilled in the art can make various changes and modifications without departing from the spirit and scope of the present disclosure, and these changes and modifications will all fall within the protection scope of the present invention.

Claims

1. A system for constructing a cyber security behavior model of a power infrastructure, characterized in that It includes a power entity model and a power network action model; The power entity model includes a power physical domain entity model and a power information domain entity model. The power physical domain entity model is used to simulate the topological relationship and power function of the transmission lines in the region, and the power information domain entity model is used to simulate the network characteristics and power dispatching function of the power information control facilities; The power network action model includes a power network security behavior model, which is used to evaluate the impact of network security behaviors on the power entity model, detect, protect, and repair the power entity model; the power network security behavior model includes a virus attack model, a malicious code attack model, an intrusion detection model, and a power grid repair model; the virus attack model is used to simulate the impact of virus attacks on the power entity model; the malicious code attack model is used to simulate the impact of malicious code attacks on the power entity model; The intrusion detection model is used to simulate the impact of network attacks on the power entity model; The power grid repair model is used to simulate the overall repair behavior after the power entity model is damaged; The virus attack model is constructed by a virus attack simulation method, and the virus attack simulation method includes: according to the source node, target node, virus propagation hop count, and virus attack intensity array of the virus attack, determining whether the virus attack on the source node of the power information domain is successful through a network attack and defense dynamic game algorithm. Among them, the network attack and defense dynamic game algorithm includes an external exposure probability judgment and a comprehensive defense intensity judgment. When the external exposure probability is greater than the exposure threshold, the target node is in an externally visible state; when the attack intensity is greater than the comprehensive defense intensity, it is determined that the virus attack is successful; when the attack intensity is less than or equal to the comprehensive defense intensity, it is determined that the virus attack fails; when it is determined that the virus attack is successful, change the electrical attributes of the power physical domain entity model controlled by the power information domain entity model, the power information domain entity shuts down, and set the power of the control node of the power information domain entity to zero; traverse the power information domain entities directly associated with the information of the power information domain entity attacked by the virus, and return to the step of determining whether the virus attack on the source node of the power information domain is successful through the network attack and defense dynamic game algorithm; judge whether the virus propagation hop count reaches the maximum propagation hop count; if it does not reach the maximum propagation hop count, then return to the step of changing the electrical attributes of the power physical domain entity model controlled by the power information domain entity model, the power information domain entity shuts down, and set the power of the control node of the power information domain entity to zero, until the maximum propagation hop count is reached; The power grid repair model is constructed by a power grid repair method, and the power grid repair method includes: judging the repair conditions of nodes in the power entity model to be repaired; when the node is a power physical domain entity, judging whether the preset physical domain entity repair conditions are met, and when the power physical domain entity node meets the physical domain entity repair conditions, starting the repair, wherein the preset physical domain entity repair conditions include that the node is in a fault state, the repair probability is greater than the preset probability, and there is at least one normal electric circuit for the node; when the node is a power information domain entity, searching for heterogeneous nodes of the node, judging whether the heterogeneous nodes are down, if they are down, judging whether the heterogeneous nodes meet the physical domain entity repair conditions, and if they meet, starting to repair the heterogeneous nodes; when all the nodes associated with the power information domain entity are repaired, ending the power repair operation.

2. The system for constructing a cybersecurity behavior model of a power infrastructure network according to claim 1, characterized in that The power physical domain entity model includes a power generation station node model, a substation node model, a distribution station node model, and a load center model.

3. The system for constructing a cybersecurity behavior model of a power infrastructure network according to claim 1, characterized in that, The power information domain entity model includes a power generation station monitoring model, a substation monitoring model, and a power dispatching center model.

4. The system for constructing a cyber security behavior model of a power infrastructure network according to claim 2, wherein The information in the power generation station node model, the substation node model, the distribution station node model, and the load center model includes node name, unit number, node number, administrative region to which it belongs, power grid region to which it belongs, heterogeneous node name, repair time, voltage, power, node status, node type, equipment type, and location coordinates.

5. The system for constructing a cybersecurity behavior model of a power infrastructure network according to claim 3, characterized in that, The information in the power generation station monitoring model, the substation monitoring model, and the power dispatching center model includes node name, unit number, node number, heterogeneous node, repair time, defense method, node status, node type, location where it is located, administrative region, power grid region, controlled enemy unit, initial controlling party, and visible party.

6. The system for constructing a cybersecurity behavior model of a power infrastructure network according to claim 1, characterized in that, The malicious code attack model is constructed by a malicious code attack method, and the malicious code attack method includes: At the first moment, traversing the information network characteristics of the nodes in the power information domain entity model in the attack path of the malicious code, and judging whether the power information domain entity model is attacked by the malicious code; If it is attacked by the malicious code, updating the power grid system topology and electrical parameters after the attack; At the second moment, checking whether the communication link of the local power physical domain entity model is attacked by the malicious code; If it is attacked by the malicious code, updating the power grid system topology and electrical parameters after the attack; At the third moment, determining whether the path between the attacked node in the power information domain entity model and the next attacked node is normal according to the attack path; If it is not normal, updating the power grid system topology and electrical parameters after the attack; At the fourth moment, checking whether the first path for power flow adjustment electrical local monitoring from the attack entity to the power dispatching center is normal; At the fifth moment, checking whether the information path from the attacked power information domain entity model to the power dispatching center entity is normal; If both the first path and the information path are normal, cutting off the corresponding load or backup circuit; Traverse the fault conditions of all links and calculate the proportion of the remaining largest connected node clusters after fault propagation.

7. The system for constructing a cyber security behavior model of a power infrastructure network according to claim 1, characterized in that, The intrusion detection model is constructed by an intrusion detection method, and the intrusion detection method includes: According to the virus attack simulation method, start detecting the intrusion of the virus at a preset detection time.

Citation Information

Patent Citations

  • Active power distribution network dynamic defensive performance optimization method based on game theory

    CN115102166A