Power node network attack threat degree calculation method and terminal equipment
Through an improved method for calculating the threat level of power node network attacks, the threat level of plant-level nodes is calculated using the threat level of device-level nodes, which solves the problems of single evaluation indicators and strong dependence on training samples in existing technologies, and achieves more accurate and more mobile threat level calculation.
Patent Information
- Application Number
- CN202310157799.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-23
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2043-02-23
AI Technical Summary
The evaluation index system of the existing power node threat degree calculation method is imperfect and relies on training samples. It fails to fully consider the spatiotemporal relationship between attackers and the power system and the historical characteristics of alarm logs, resulting in inaccurate calculation results and poor portability.
A method for calculating the threat level of power node network attacks is adopted. The formula NZ=N′za+N′zb+N′zc+N′zd is used. The threat level of the equipment and substation is combined with the threat level of the equipment, substation, dispatching level and load importance. The spatiotemporal relationship between the attacker and the power system and the historical characteristics of the alarm log are considered. The threat level of the plant-level node is calculated based on the threat level of the device-level node.
The accuracy and portability of the calculation of the threat degree of network attacks on power nodes are improved, and an objective and accurate evaluation index system is provided.
Smart Images

Figure CN116318894B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power system network security, and in particular to a method for calculating the threat degree of network attack on a power node and a terminal device. Background Art
[0002] With the rapid development of new power systems in recent years, the number and severity of cyberattacks targeting these systems have been on the rise. Improving the accuracy of threat calculations for power nodes is a crucial component of building a defense-in-depth cybersecurity framework for power information systems.
[0003] The current methods for calculating the threat level of power nodes have the disadvantages of an imperfect evaluation index system and a high degree of dependence on training samples. They fail to fully consider the spatiotemporal relationship between attackers and the power system, as well as the historical characteristics of alarm logs, which easily leads to problems such as poor portability and objectivity of the calculation methods. Summary of the Invention
[0004] The technical problem to be solved by the present invention is to provide a method and terminal device for calculating the threat level of network attacks on power nodes in response to the shortcomings of the existing technology, so as to solve the problem of inaccurate threat level calculation caused by the single evaluation index and strong dependence on training samples.
[0005] In order to solve the above technical problems, the technical solution adopted by the present invention is: a method for calculating the threat level of network attack on power nodes, using the following formula to calculate the threat level of network attack on dispatch center N Z :
[0006] N Z =N′ za +N′ zb +N′ zc +N′ zd ;
[0007] Among them, N′ za , N′ zb , N′ zc , N′ zd Represents the equipment threat level N of the dispatch center za Normalized value, substation threat degree N of the dispatching center zb Normalized value, dispatching level assignment normalized value of dispatching center, load importance N of dispatching center zd Normalized value;
[0008] Equipment threat level N of the dispatch center za The calculation formula is:
[0009] l z 、m z 、n z 、oz Respectively represent the number of server devices, database devices, network devices and security protection devices in the dispatch center; α, β, γ and δ represent the threat coefficient of server devices, database devices, network devices and security protection devices respectively; I x (t z ), I y (t z ), I z (t z ), I w (t z ) represent the server equipment, database, network equipment, and security equipment in the dispatch center. z The network attack threat level of each device-level node; z The number of devices in the dispatch center.
[0010] Substation threat level N zb The calculation formula is: n and m represent the number of power plants and substations within the dispatching center’s dispatching range, respectively; N B (i) represents the substation network attack threat level of the i-th substation; N p (j) represents the power plant cyber attack threat level of the j-th power plant;
[0011] Load importance N zd The calculation formula is: Respectively represent the 0th z The load of the first-level load node, the z The load of the secondary load node, Respectively represent the total primary load and the total secondary load in the system, ρ a , ρ b Represents the primary load weight and the secondary load weight, x z 、y z They respectively represent the number of first-level load nodes and second-level load nodes within the control range of the dispatching center.
[0012] The evaluation index of the present invention is perfect, does not rely on training samples, and fully considers the temporal and spatial relationship between the attacker and the power system, as well as the historical characteristics of the alarm log. Therefore, the calculation result of the network attack threat degree is accurate and the calculation precision is high.
[0013] The dispatch level is scored as follows:
[0014] For national dispatch, the dispatch level is assigned a score of 10;
[0015] For national dispatch, the dispatch level score is 8;
[0016] For provincial dispatch, the dispatch level is assigned a score of 6;
[0017] For provincial reserve dispatch, the dispatch level score is 4;
[0018] For local dispatch, the dispatch level score is 2;
[0019] For county dispatch, the dispatch level is assigned a score of 1.
[0020] Substation network attack threat level N B The calculation formula is: N B =γ1N′ Ba +γ2N′ Bb +γ3N′ Bc +γ4N′ Bd ; Among them, γ1, γ2, γ3, and γ4 represent the equipment threat weight of the substation, the attribute score weight of the substation, the rated capacity weight of the substation, and the load importance weight of the substation respectively; N′ Ba , N′ Bb , N′ Bc , N′ Bd Represents the equipment threat degree N of the substation Ba Normalized value, attribute assignment normalized value of substation, rated capacity N of substation Bc Normalized value, load importance of substation N Bd Normalized value.
[0021] Substation equipment threat level N Ba The calculation formula is: l b 、m b 、n b 、o b Respectively represent the number of server equipment, database equipment, network equipment and security protection equipment in the substation; I x (t b ), I y (t b ), I z (t b ), I w (t b ) represent the server equipment, database, network equipment, and safety protection equipment in the substation. b The network attack threat level of each device-level node; b The number of devices in the dispatch center.
[0022] The attributes of the substation are assigned as follows:
[0023] For hub substations, the attribute score is 10;
[0024] For the intermediate substation, the attribute score is 7;
[0025] For regional substations, the attribute is assigned a score of 5;
[0026] For the terminal substation, the attribute is assigned as 2.
[0027] Rated capacity of substation N Bc The calculation formula is: in, Indicates the i-th b The rated capacity of the main transformer, s represents the number of main transformers in the substation, Q max Indicates the maximum capacity of the substation in the system.
[0028] Substation load importance N Bd The calculation formula is: Respectively represent the oth b The load of the first-level load node, the b The load of the second-level load node and the mth b The load of the three-level load nodes, Indicates the total amount of three-level load in the system. Respectively represent the substation associated with the o b The first level load energy supply ratio, the first b Secondary load energy supply ratio, mth b The three-level load energy supply ratio, x b 、y b 、z b They respectively represent the number of primary load nodes, secondary load nodes, and tertiary load nodes associated with the substation.
[0029] Power plant cyber attack threat level N p The calculation formula is: N P =N′ Pa +N′ Pb +N′ Pc ; N′ Pa , N′ Pb , N′ Pc Represents the equipment threat level N of the power plant pa Normalized value, rated capacity attribute degree N of power plant Pb Normalized value, annual power generation attribute degree N of power plant Pc Normalized value; Where w represents the number of power generation equipment in the power plant, T irepresents the rated capacity of the i-th power generation equipment, T max Indicates the rated capacity of the largest power plant in the system, W j represents the actual annual power generation of the jth power plant, and N represents the number of power plants in the system.
[0030] The calculation formula of the network attack threat level I of the device-level node is: I=θ1I′ α +θ2I′ β +θ3I′ γ +θ4I′ δ +θ5I′ ε ; I′ α , I′ β , I′ γ , I′ δ , I′ ε I are the alarm level values of the equipment α Normalized value, device alarm attack process value I β Normalized value, device attack type score I γ Normalized value, device alarm history characteristic value I δ Normalized value, attribute importance of equipment I ε Normalized value; θ1, θ2, θ3, θ4, θ5 are the coefficients of each indicator;
[0031] r is the number of the rth attack, f r Indicates the number of times the device suffers the rth attack, h r represents the attack type score of the rth attack, and v represents the number of network attack types suffered by the device;
[0032] The attack types and corresponding scores are: denial of service, 7 points; ransomware attack, 8 points; scanning attack, 4 points; time synchronization attack, 5 points; virus attack, 10 points;
[0033] I δ =Q q +F q +E q , Q q 、F q 、E q are the normalized values of the alarm quantity ratio, threat alarm ratio, and time characteristic value of the qth device respectively;
[0034] I ε =G′(q)+L′(q), where G′(q) and L′(q) represent the normalized value of the energy level and the normalized value of the associated safety zone assignment of the qth device respectively.
[0035] The present invention also provides a terminal device, comprising a memory, a processor, and a computer program stored in the memory; the processor executes the computer program to implement the steps of the above method of the present invention.
[0036] Compared with existing technologies, the present invention has the following advantages: it solves the problem of inaccurate threat calculation caused by a single evaluation indicator and strong dependence on training samples, greatly improving the accuracy of threat calculation for power node network attacks. The method of the present invention is highly transferable and the calculation is objective and accurate. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] Figure 1 This is a flow chart of the method of Example 1 of the present invention;
[0038] Figure 2 This is a flowchart for determining a denial of service attack;
[0039] Figure 3 It is a three-stage alarm content and logic sequence diagram;
[0040] Figure 4 Logic diagram for scanning attack judgment;
[0041] Figure 5 This is the logic diagram for judging time synchronization attacks. DETAILED DESCRIPTION
[0042] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0043] In this document, the terms "include," "comprising," and similar expressions are intended to indicate a logical relationship and should not be construed as indicating a spatial relationship. For example, "A includes B" is intended to indicate that B logically belongs to A, not that B is spatially located within A. Furthermore, the terms "include," "comprising," and similar expressions should be considered open-ended, not closed-ended. For example, "A includes B" is intended to indicate that B belongs to A, but B does not necessarily constitute the entirety of A; A may also include other elements such as C, D, and E.
[0044] Example 1
[0045] In Example 1 of the present invention, the alarm logs of various types of equipment in a power plant are used as input. The network attack threat level of device-level nodes is then calculated based on the alarm logs. Finally, the network attack threat level of power plant-level nodes is calculated based on the network attack threat level of the device-level nodes. Power plant-level nodes include three categories: power plants, substations, and dispatch centers. Equipment-level nodes include four categories: hosts (servers), databases, network equipment, and security equipment.
[0046] Figure 1 The following is a flowchart of the implementation method of the method for calculating the threat level of network attack on plant-level nodes based on alarm logs provided in an embodiment of the present invention. The specific implementation steps are as follows:
[0047] Step S1: Calculate the alarm level value of the device according to the number of alarm logs generated by the device and the alarm level coefficient corresponding to a single alarm. α .
[0048] Step S2: Determine the attack process using the corresponding relationship between a single alarm event and the attack step, and calculate the alarm attack process value I of the device. β .
[0049] Step S3: Consider the temporal logic between multiple alarm events, determine the type of attack suffered by the device, and calculate the attack type score of the device. γ .
[0050] Step S4: Calculate the device's alarm history characteristic value I using the alarm quantity ratio, high-level alarm ratio, and historical alarm time series characteristics. δ .
[0051] Step S5: First, calculate the attribute energy level of the device according to the energy level of the plant to which the device belongs, then obtain the associated safety zone of the device according to the topological structure of the plant, and finally use the attribute energy level and associated safety zone of the device to solve the attribute importance I of the device. ε .
[0052] Step S6: Calculate the device-level node network attack threat level I using the device's alarm level value, alarm attack process value, attack type score, alarm history feature value, and attribute importance obtained in steps S1-S5.
[0053] Step S7: Considering the rated capacity and annual power generation of the power plant, and combining the network attack threat level I of the device-level node corresponding to the power plant in step S6, calculate the network attack threat level N of the power plant. P .
[0054] Step S8: Considering the rated capacity, type, voltage level and load importance of the substation, and combining the backup node network attack threat level I of the corresponding equipment of the substation in step S6, calculate the substation network attack threat level NB .
[0055] Step S9: Using the power plant network attack threat level N calculated in steps S7 and S8 P and the threat level of substation cyberattack N B , calculate the dispatch center network attack threat level N Z .
[0056] Furthermore, the specific execution method of step S1 is as follows:
[0057] S1-1: First, according to the content of the "Device Type" field in the alarm log, determine the type of network security monitoring device that sent the alarm. Then, parse the content of the "Alarm Log Type" field in the alarm log, classify the alarm generating device, and construct the device classification set Q. a .
[0058] S1-2: First extract the content of the "alarm log subtype" field in the alarm log, and classify the device into a set Q a Reclassify and construct the alarm classification set Q for a single device b Then, according to the "Technical Specifications for Network Security Detection Devices of Power Monitoring Systems", the "Network Security Monitoring Device Upload Information Requirements" is used to determine the alarm classification set Q. b Various alarm levels.
[0059] S1-3: Based on the alarm level determination result in step S1-2, the alarm level coefficient A corresponding to each alarm is calculated, and the scores are shown in Table 1 below:
[0060] Table 1 Alarm severity assignment table
[0061] Alarm level urgent important secondary generally Alarm level coefficient (A) 10 8 5 3
[0062] S1-4: Take 24 hours as the time window, count the number of 4 types of alarms in the alarm severity assignment table within the time window, and use the following formula to calculate the alarm level value of the device: α Perform the calculation:
[0063]
[0064]
[0065] Where: T s Indicates the alarm level coefficient of the sth alarm, S s represents the number of alarms of the sth level, W represents the average alarm level value of all similar devices corresponding to the device in the same time window, and n represents the number of similar devices in the system.
[0066] Furthermore, the specific execution method of step S2 is as follows:
[0067] S2-1: By classifying the alarms of a single device into a set Q b The four fields of the alarm log, "alarm log subtype", "alarm log content", "alarm start time", and "alarm end time", are parsed and the same alarm logs are merged to form an alarm event set Q. c .
[0068] S2-2: Use k-means clustering method to classify the alarm event set Q c Clustering is performed to form an alarm event cluster set Q with attack steps as cluster classification number and log subtype as cluster member d , where the number of cluster centers is 7, and the corresponding relationship between the center number and the attack step is shown in Table 2 below:
[0069] Table 2 Correspondence between center point numbers and attack steps
[0070] Center point number 1 2 3 4 5 6 7 Attack steps Reconnaissance and tracking Weapon Build Payload delivery Exploitation Install implant Command and Control Goal achieved
[0071] When clustering, the following formula is used to calculate the attribute similarity S(x, y) between alarm events:
[0072]
[0073] Where: S(x, y) is the attribute similarity between alarm events x and y; x and y are the alarm event sets Q c There are two different alarm events; n is the number of attribute types of each alarm event; i s is the i-th alarm event s attribute number; For the i s The weight of each attribute; is the i-th event between alarm event x and alarm event y s Similarity of attributes; is the i-th alarm event x s properties, is the i-th alarm event y s Attributes;
[0074] Furthermore, the specific execution method of step S2-3 is as follows:
[0075] S2-3-1: Using the clustering results in step S2-2, a database of correspondence between alarm events and attack steps is formed. The corresponding form of the relationship in the database is shown in Table 3 below:
[0076] Table 3 Corresponding forms of relations in the database
[0077]
[0078] In the table, m is the number of alarm event types, and the value range of n is 1≤n≤7.
[0079] S2-3-2: Calculate the device's alarm attack process value based on the attack step scoring table. The attack step scoring table is shown in Table 4 below:
[0080] Table 4 Attack step scoring table
[0081] Attack steps Reconnaissance and tracking Weapon Build Payload delivery Exploitation Install implant Command and Control Goal achieved Attack Step Scoring 1 3 4 5 8 9 10
[0082] Device's alarm attack process value I β The calculation formula is as follows:
[0083]
[0084] Where: q s is the number of attack steps corresponding to the s-th alarm, The sth alarm event corresponds to the i s The attack steps of each attack step are scored.
[0085] Furthermore, the specific execution method of step S3 is as follows:
[0086] S3-1: First, based on the characteristics of the power system and the types of input data, we categorize potential cyber attacks on power equipment into five categories: denial of service attacks, ransomware attacks, scanning attacks, time synchronization attacks, and virus attacks. We then apply temporal logic analysis to extract the alarm timing characteristics of each attack during its implementation.
[0087] S3-2: Based on the alarm timing characteristics of each type of attack in step S3-1, an attack library containing the timing logic of five types of attack alarm events is constructed.
[0088] S3-3: Identify potential network attacks in the input alarm event set based on the timing logic in the attack library. The specific identification logic for various network attacks is as follows:
[0089] a. Denial of Service: First, determine whether the device is under a denial of service attack based on whether the device CPU and memory usage exceed the device's maximum operating capacity. Then, determine the type of denial of service attack the device is under based on the IP link status. The denial of service attack judgment process is as follows: Figure 2 shown.
[0090] b. Ransomware attack: Different alarms will appear at different time points during the implementation of the ransomware attack. The present invention divides the ransomware attack process into three stages: early, middle, and late. When any three alarms in the three stages form a complete temporal logic structure, it can be determined that the device may be under a ransomware attack. The three-stage alarm content and logical sequence are as follows: Figure 3 shown.
[0091] c. Scanning attack: First, determine whether the device is likely to be attacked by a network based on the number and severity of scanning alarms, and then determine whether the device is currently under a scanning attack based on the number of IP address links. Figure 4 shown.
[0092] d. Time synchronization attack: First, judge it as a time difference alarm based on the time synchronization anomaly alarm, and then judge the time synchronization attack type based on the alarm frequency and time modification value. The time synchronization attack judgment logic is as follows: Figure 5 shown.
[0093] e. Virus attack: Whether the device has been attacked by a virus can be determined based on the virus log uploaded by the anti-virus system in the power grid. The virus log upload format is as follows:
[0094] Format: Virus name <space> virus type <space> detection result <space> detection method <space> infected file path <space> detection time <space> infected computer name <space> device IP address.
[0095] S3-4: First, assign points to each type of attack based on the degree of damage to the system. The scoring table is as follows:
[0096] Table 5 Scoring table for various attack types
[0097] Attack Number Attack Type Attack Type Scoring 1 Denial of Service 7 2 Ransomware attacks 8 3 Scanning Attack 4 4 Time synchronization attacks 5 5 Virus attack 10
[0098] Then, score the device based on the type of attack it suffers and the attack type, and calculate the device's attack threat level I γ , the calculation formula is as follows:
[0099]
[0100] Where: r is the number of the rth attack, f r Indicates the number of times the device suffers the rth attack, h r It represents the attack type score of the rth attack, and v represents the number of network attack types suffered by the device.
[0101] Furthermore, the specific execution method of step S4 is as follows:
[0102] S4-1: Calculate the device alarm ratio by combining the number of alarms generated by a single device within 24 hours (unit time) with the total number of alarms received by the security management platform for all devices within that period. The calculation formula is as follows:
[0103]
[0104] Where: Q is the alarm quantity ratio of the device, q qis the number of alarms generated by the qth device per unit time, q z It is the number of alarms received by the security management platform of the system dispatching center from all devices within a unit of time.
[0105] S4-2: Calculate the threat alarm ratio using the sum of the number of emergency alarms and major alarms generated by the device and the number of alarms generated by the device per unit time. The calculation formula is as follows:
[0106]
[0107] Where: F is the threat alarm ratio of the device, w m 、w q They are the number of emergency alarms and the number of major alarms generated by the equipment per unit time.
[0108] S4-3: First, take 1 hour as the unit and 1 month of alarms as the sample input, count the number of alarm peaks in 24 time periods each day, and then calculate the time characteristic value. The calculation formula is as follows:
[0109]
[0110] Where: E is the time characteristic value of the device, e max is the maximum number of alarm peaks in a single period, m ave The total number of days in this month.
[0111] S4-4: First, normalize the alarm quantity ratio, threat alarm ratio, and time characteristic value, and then calculate the device's alarm history characteristic value I δ , the calculation formula is as follows:
[0112] I δ =Q q +F q +E q
[0113] Where: Q q 、F q 、E q are the normalized values of the alarm quantity ratio, threat alarm ratio, and time characteristic value of the qth device respectively.
[0114] Furthermore, the specific execution method of step S5 is as follows:
[0115] S5-1: Calculate the energy level of the device based on the voltage level of the power node where the device is located.
[0116] Furthermore, the specific execution method of step S5-1 is as follows:
[0117] S5-1-1: For the equipment in the substation, calculate the energy level G of the equipment in the substation according to the voltage level of the substation where it is located. b , and its assignment method is shown in Table 6 below:
[0118] Table 6 Assignment of energy levels for equipment in substations
[0119]
[0120] S5-1-2: For the equipment in the power plant, calculate the energy level G of the equipment in the power plant based on the number of directly connected substations of the power plant, the energy level of each directly connected substation, and the energy supply ratio of the power plant to the directly connected substations. f , which is calculated as follows:
[0121]
[0122] Where: n represents the number of substations directly connected to the power plant, G b (i) represents the energy level of the i-th directly connected substation, P i is the active power output from the power plant to the i-th directly connected substation, P Z (i) is the total active power output by the i-th directly connected substation.
[0123] S5-1-3: For the equipment in the dispatching center, calculate the energy level G of the equipment in the dispatching center according to the energy level of each substation and power plant controlled by the dispatching center. z , which is calculated as follows:
[0124]
[0125] Where: s and p are the number of substations and power plants within the control range of the dispatching center, G b (i) is the energy level of the ith substation, G f (j) is the energy level of the j-th power plant.
[0126] S5-2: Calculate the associated security zone value of the device in the dispatch center based on the security zone where the device is located or the first associated security zone. The first associated security zone refers to the device with the closest logical link or the closest subordinate relationship. The associated security zone value L is shown in Table 7 below:
[0127] Table 7 Associated Security Zone Assignment
[0128] safe zone Safe Zone I Safe Zone II Safety Zone III Safe Zone IV Associated security zone assignment (L) 10 8 5 1
[0129] S5-3: Calculate the attribute importance of the device I according to the device's assigned energy level and associated security zone. ε , and its calculation formula is as follows:
[0130] I ε =G′(q)+L′(q)
[0131] Where G′(q) and L′(q) represent the normalized value of the energy level and the normalized value of the associated safety zone of the qth device, respectively.
[0132] Furthermore, the specific execution method of step S6 is as follows:
[0133] S6-1: Alarm level indicator value for equipment I α , the attack process value of the device I β , Device attack threat level I γ , Equipment alarm history feature classification I δ , the attribute importance of the equipment I ε Perform normalization processing.
[0134] S6-2: Based on the processing result in step S6-1, calculate the network attack threat level I of the device-level node. The calculation formula is as follows:
[0135] I=θ1I′ α +θ2I′ β +θ3I′ γ +θ4I′ δ +θ5I′ δ
[0136] Where: I′ α , I′ β , I′ γ , I′ δ , I′ δ are the normalized values of the device’s alarm level value, the device’s alarm attack process value, the device’s attack type score, the device’s alarm history feature value, and the device’s attribute importance; θ1, θ2, θ3, θ4, and θ5 are the index coefficients, which are 0.4, 0.1, 0.2, 0.1, and 0.2, respectively.
[0137] Furthermore, the specific execution method of step S7 is as follows:
[0138] S7-1: Calculate the power plant's equipment threat level N based on the four indicators of server (workstation) network attack threat level, database network attack threat level, network equipment network attack threat level, and security protection equipment network attack threat level obtained in step S6. pa , the calculation formula is as follows:
[0139]
[0140] Where: α, β, γ, and δ represent the server device threat coefficient, database threat coefficient, network device threat coefficient, and security protection device threat coefficient, respectively, and their values are 0.3, 0.1, 0.2, and 0.4; l a 、m a 、n a 、o a Represents the number of four types of equipment in the power plant: server (workstation) equipment, database, network equipment, and security equipment; I x (t p ), I y (t p ), I z (t p ), O w (t p ) represent the server equipment, database, network equipment, and safety protection equipment in the power plant. p The network attack threat level of each device-level node; p is the number of equipment in the power plant.
[0141] S7-2: Calculate the rated capacity attribute degree N of the power plant based on the capacity of a single power generation device in the power plant and the capacity of the largest power plant in the system. Pb , the calculation formula is as follows:
[0142]
[0143] Where: w p Indicates the number of power generation equipment in this power plant, Indicates the i p Rated capacity of power generation equipment, T max It indicates the rated capacity of the largest power plant in the system, and the capacity value depends on the actual situation of the system.
[0144] S7-3: Calculate the annual power generation attribute degree N of the power plant based on the actual annual power generation of the power plant and the total power generation of all power plants in the system Pc , the calculation formula is as follows:
[0145]
[0146] Where: W j represents the actual annual power generation of the jth power plant, and N represents the number of power plants in the system.
[0147] S7-4: Calculate the power plant network attack threat level N based on the power plant's equipment threat level, rated capacity attribute level, and annual power generation attribute level in steps S7-1 to S7-3. P , the calculation formula is as follows:
[0148] N P =N′ Pa +N′ Pb +N′ Pc
[0149] Where: N′ Pa , N′ Pb , N′ Pc They represent the normalized value of the power plant's equipment threat degree, the normalized value of the power plant's rated capacity attribute degree, and the normalized value of the power plant's annual power generation attribute degree, respectively.
[0150] Furthermore, the specific execution method of step S8 is as follows:
[0151] S8-1: Calculate the substation equipment threat level N based on the four indicators of server (workstation) network attack threat level, database network attack threat level, network equipment network attack threat level, and security protection equipment network attack threat level obtained in step S6. Ba , the calculation formula is as follows:
[0152]
[0153] Where: l b 、m b 、n b 、o b Respectively represent the number of four types of equipment in the substation: server (workstation), database, network equipment, and security equipment; I x (t b ), I y (t b ), I z (t b ), I w (t b ) represent the server equipment, database, network equipment, and safety protection equipment in the substation. b The network attack threat level of each device-level node; b is the number of equipment in the substation.
[0154] S8-2: According to the role of the substation in the system, the substation attributes are assigned points. The attribute points of the substation are assigned N Bb As shown in Table 8 below:
[0155] Table 8 Attribute scoring of substations
[0156] Substation type Hub substation Intermediate substation Regional substation Terminal substation <![CDATA[Attribute score assignment (N Bb )]]> 10 7 5 2
[0157] S8-3: Calculate the rated capacity value N of the substation based on the rated capacity of a single transformer in the substation and the maximum capacity of the substation in the system. Bc, the calculation formula is as follows:
[0158]
[0159] Where: Indicates the i-th b The rated capacity of the main transformer, s represents the number of main transformers in the substation, Q max Indicates the maximum capacity of the substation in the system.
[0160] S8-4: Calculate the load importance attribute value N of the substation based on the load quantity and load energy ratio of each level of load supplied by the substation Bd The calculation formula is as follows:
[0161]
[0162] Respectively represent the oth b The load of the first-level load node, the b The load of the second-level load node and the load of the mb-th third-level load node, Indicates the total amount of three-level load in the system. Respectively represent the substation associated with the o b The first level load energy supply ratio, the first b Secondary load energy supply ratio, mth b The three-level load energy supply ratio, x b 、y b 、z b They respectively represent the number of primary load nodes, secondary load nodes, and tertiary load nodes associated with the substation.
[0163] S8-5: Calculate the substation network attack threat level N according to the substation equipment threat level, substation attribute score, substation rated capacity value and substation load importance attribute value in steps S8-1 to S8-4. B , the calculation formula is as follows:
[0164] N B =γ1N′ Ba +γ2N′ Bb +γ3N′ Bc +γ4N′ Bd
[0165] Where: γ1, γ2, γ3, and γ4 represent the equipment threat weight of the substation, the attribute score weight of the substation, the rated capacity weight of the substation, and the load importance weight of the substation, which are 0.3, 0.3, 0.2, and 0.2 respectively; N′ Ba , N′ Bb , N′Bc , N′ Bd They respectively represent the normalized value of the substation's equipment threat degree, the normalized value of the substation's attribute score, the normalized value of the substation's rated capacity, and the normalized value of the substation's load importance.
[0166] Furthermore, the specific execution method of step S9 is as follows:
[0167] S9-1: Calculate the device threat level N of the dispatch center based on the server (workstation) device network attack threat level, database network attack threat level, network device network attack threat level, and security protection device network attack threat level obtained in step S6. za The calculation formula is as follows:
[0168]
[0169] l z 、m z 、n z 、o z Respectively represent the number of server devices, database devices, network devices and security protection devices in the dispatch center; I x (t z ), I y (t z ), I z (t z ), I w (t z ) represent the server equipment, database, network equipment, and security equipment in the dispatch center. z The network attack threat level of each device-level node; z The number of devices in the dispatch center.
[0170] S9-2: Calculate the substation threat level N of the dispatching center based on the substation network attack threat level and power plant network attack threat level of the substation and power plant within the dispatching range of the dispatching center. zb , the calculation formula is as follows:
[0171]
[0172] Where: n and m represent the number of power plants and substations within the dispatching range of the dispatching center respectively; N B (i) represents the substation network attack threat level of the i-th substation; N p (j) represents the power plant cyber attack threat level of the j-th power plant.
[0173] S9-3: Assign points to the dispatching center based on its dispatching level in the system. The scoring method is shown in the following table:
[0174] Scheduling Type National Survey National Dispatch Provincial Adjustment Provincial reserve adjustment Geological Survey County Adjustment <![CDATA[Scheduling level score assignment (N zc )]]> 10 8 6 4 2 1
[0175] S9-4: Calculate the load importance attribute value N of the dispatching center based on the load amount of each level of load provided by the dispatching center zd The calculation formula is as follows:
[0176]
[0177] Where: Respectively represent the 0th z The load of the first-level load node, the z The load of the secondary load node, Respectively represent the total primary load and the total secondary load in the system, ρ a , ρ b They represent the primary load weight and the secondary load weight, with values of 0.7 and 0.3 respectively. z 、y z They respectively represent the number of first-level load nodes and second-level load nodes within the control range of the dispatching center.
[0178] S9-5: Calculate the network attack threat level IVZ of the dispatching center based on the device threat level of the dispatching center, the substation threat level of the dispatching center, the dispatching level score of the dispatching center, and the load importance attribute value of the dispatching center in steps S9-1 to S9-4. The calculation formula is as follows:
[0179] N Z =N′ za +N′ zb +N′ zc +N′ zd
[0180] Where: N′ za , N′ zb , N′ zc , N′ zd They respectively represent the normalized value of the equipment threat level of the dispatching center, the normalized value of the substation threat level of the dispatching center, the normalized value of the dispatching level score of the dispatching center, and the normalized value of the load importance of the dispatching center.
[0181] Example 2
[0182] Embodiment 2 of the present invention provides a terminal device corresponding to the above-mentioned embodiment 1. The terminal device can be a processing device for a client, such as a mobile phone, a laptop computer, a tablet computer, a desktop computer, etc., to execute the method of the above-mentioned embodiment.
[0183] The terminal device of this embodiment includes a memory, a processor, and a computer program stored in the memory; the processor executes the computer program in the memory to implement the steps of the method in the above-mentioned embodiment 1.
[0184] In some implementations, the memory may be a high-speed random access memory (RAM), and may also include a non-volatile memory, such as at least one disk storage.
[0185] In other implementations, the processor may be a central processing unit (CPU), a digital signal processor (DSP), or other general-purpose processors, which are not limited herein.
[0186] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code. The scheme in the embodiment of the present application can be implemented in various computer languages, for example, object-oriented programming language Java and literal translation scripting language JavaScript, etc.
[0187] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0188] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0189] Although the preferred embodiments of the present application have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present application.
[0190] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.
Claims
1. A method for calculating the threat level of network attacks on power nodes, characterized in that: Use the following formula to calculate the dispatch center network attack threat level N Z : N Z =N′ za +N′ zb +N′ zc +N′ zd ; Among them, N′ za , N′ zb , N′ zc , N′ zd Represents the equipment threat level N of the dispatch center za Normalized value, substation threat degree N of the dispatching center zb Normalized value, dispatching level score N of the dispatching center zc Normalized value, load importance N of the dispatching center zd Normalized value; Equipment threat level N of the dispatch center za The calculation formula is: l z 、m z 、n z 、o z Respectively represent the number of server devices, database devices, network devices and security protection devices in the dispatch center; α, β, γ and δ represent the threat coefficient of server devices, database devices, network devices and security protection devices respectively; I x (t z ), I y (t z ), I z (t z ), I w (t z ) represent the server equipment, database, network equipment, and security equipment in the dispatch center. z The network attack threat level of each device-level node; z is the number of devices in the dispatch center; Substation threat level N zb The calculation formula is: n and m represent the number of power plants and substations within the dispatching center’s dispatching range, respectively; N B (i) represents the substation network attack threat level of the i-th substation; N p (j) represents the power plant cyber attack threat level of the j-th power plant; Load importance N zd The calculation formula is: Respectively represent the 0th z The load of the first-level load node, the z The load of the secondary load node, Respectively represent the total primary load and the total secondary load in the system, ρ a , ρ b Represents the primary load weight and the secondary load weight, x z 、y z They respectively represent the number of first-level load nodes and second-level load nodes within the control range of the dispatching center.
2. The method for calculating the threat level of network attack on power nodes according to claim 1 is characterized in that: The dispatch level is scored as follows: For national dispatch, the dispatch level is assigned a score of 10; For national dispatch, the dispatch level score is 8; For provincial dispatch, the dispatch level is assigned a score of 6; For provincial reserve dispatch, the dispatch level score is 4; For local dispatch, the dispatch level score is 2; For county dispatch, the dispatch level is assigned a score of 1.
3. The method for calculating the threat level of network attack on power nodes according to claim 1, characterized in that: Substation network attack threat level N B The calculation formula is: N B =γ1N′ Ba +γ2N′ Bb +γ3N′ Bc +γ4N′ Bd ; Among them, γ1, γ2, γ3, and γ4 represent the equipment threat weight of the substation, the attribute score weight of the substation, the rated capacity weight of the substation, and the load importance weight of the substation respectively; N′ Ba , N′ Bb , N′ Bc , N′ Bd Represents the equipment threat degree N of the substation Ba Normalized value, attribute assignment normalized value of substation, rated capacity N of substation Bc Normalized value, load importance of substation N Bd Normalized value.
4. The method for calculating the threat level of network attacks on power nodes according to claim 3 is characterized in that: Substation equipment threat level N Ba The calculation formula is: l b 、m b 、n b 、o b Respectively represent the number of server equipment, database equipment, network equipment and security protection equipment in the substation; I x (t b ), I y (t b ), I z (t b ), I w (t b ) represent the server equipment, database, network equipment, and safety protection equipment in the substation respectively. b The network attack threat level of each device-level node; b is the number of equipment in the substation.
5. The method for calculating the threat level of network attack on power nodes according to claim 3 is characterized in that: The attributes of the substation are assigned as follows: For hub substations, the attribute score is 10; For the intermediate substation, the attribute score is 7; For regional substations, the attribute is assigned a score of 5; For the terminal substation, the attribute is assigned as 2.
6. The method for calculating the threat level of power node network attacks according to claim 3 is characterized in that: Rated capacity of substation N Bc The calculation formula is: in, Indicates the i-th b The rated capacity of the main transformer, s represents the number of main transformers in the substation, Q max Indicates the maximum capacity of the substation in the system.
7. The method for calculating the threat level of network attack on power nodes according to claim 3, characterized in that: Substation load importance N Bd The calculation formula is: Respectively represent the oth b The load of the first-level load node, the b The load of the second-level load node and the mth b The load of the three-level load nodes, Indicates the total amount of three-level load in the system. Respectively represent the substation associated with the o b The first level load energy supply ratio, the first b Secondary load energy supply ratio, mth b The three-level load energy supply ratio, x b 、y b 、z b They respectively represent the number of primary load nodes, secondary load nodes, and tertiary load nodes associated with the substation.
8. The method for calculating the threat level of power node network attacks according to claim 3 is characterized in that: Power plant cyber attack threat level N p The calculation formula is: N P =N′ Pa +N′ Pb +N′ Pc ; N′ Pa , N′ Pb , N′ Pc Represents the equipment threat level N of the power plant pa Normalized value, rated capacity attribute degree N of power plant Pb Normalized value, annual power generation attribute degree N of power plant Pc Normalized value; Among them, l p 、m p 、n p 、o p Respectively represent the number of server equipment, database equipment, network equipment and security equipment in the power plant; I x (t p ), I y (t p ), I z (t p ), I w (t p ) represent the server equipment, database, network equipment, and safety protection equipment in the power plant. p The network attack threat level of each device-level node; p is the number of equipment in the power plant; w p Indicates the number of power generation equipment in the power plant, Indicates the i p Rated capacity of power generation equipment, T max Indicates the rated capacity of the largest power plant in the system, W j represents the actual annual power generation of the jth power plant, and N represents the number of power plants in the system.
9. The method for calculating the threat level of power node network attacks according to claim 3, characterized in that: The calculation formula of the network attack threat level I of the device-level node is: I=θ1I′ α +θ2I′ β +θ3I′ γ +θ4I′ δ +θ5I′ ε ; I′ α , I′ β , I′ γ , I′ δ , I′ ε I are the alarm level values of the equipment α Normalized value, device alarm attack process value I β Normalized value, device attack type score I γ Normalized value, device alarm history characteristic value I δ Normalized value, attribute importance of equipment I ε Normalized value; θ1, θ2, θ3, θ4, θ5 are the coefficients of each indicator; r is the number of the rth attack, f r Indicates the number of times the device suffers the rth attack, h r represents the attack type score of the rth attack, and v represents the number of network attack types suffered by the device; I δ =Q q +F q +E q , Q q 、F q 、E q are respectively the alarm quantity ratio, threat alarm ratio, and normalized value of time characteristic value of the qth device; the alarm quantity ratio q q is the number of alarms generated by the qth device per unit time, q z The number of alarms received by the security management platform of the system dispatch center from all devices per unit time; the threat alarm ratio w m 、w q The time characteristic value is the number of emergency alarms and the number of important alarms generated by the equipment per unit time. e max is the maximum number of alarm peaks in a single period, m ave is the total number of days in this month; I ε =G′(q)+L′(q), where G′(q) and L′(q) represent the normalized value of the energy level and the normalized value of the associated safety zone of the qth device, respectively; The calculation process of the energy level of the qth device includes: For the energy level G of the equipment in the substation b Set to 1 to 10; For the energy level G of the equipment in the power plant f : n represents the number of substations directly connected to the power plant, G b (i) represents the energy level of the i-th directly connected substation, P i is the active power output from the power plant to the i-th directly connected substation, P Z (i) is the total active power output by the i-th directly connected substation; For the energy level G of the equipment in the dispatching center z : p is the number of substations and power plants within the control range of the dispatching center, G b (i) is the energy level of the ith substation, G f (j) is the energy level of the j-th power plant; The associated security zone values are: 10 for security zone I, 8 for security zone II, 5 for security zone III, and 1 for security zone IV.
10. A terminal device comprising a memory, a processor, and a computer program stored in the memory; characterized in that: The processor executes the computer program to implement the steps of the method according to any one of claims 1 to 9.
Citation Information
Patent Citations
Power system fragile line assessment method and system considering network attack risks
CN113516357A
KR20210059542A