Method for constructing power facility network security behavior effect model and network protection system
By obtaining the node list of abnormal entities in the power facility network security behavior effect model, judging effective nodes and determining the set of fault nodes, the problem of poor model reusability in the prior art is solved, and the scalability and reusability of the power facility network security behavior effect model is realized.
Patent Information
- Application Number
- CN202211677507.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-26
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2042-12-26
AI Technical Summary
The prior art lacks scalability and reusability in the construction of the network security behavior effect model of power facilities, resulting in the need to reconstruct the model when the entity changes, and cannot be effectively reused.
When the entity in the power physical domain is abnormal, the node list of the abnormal entity is obtained, the valid nodes are judged, the set of faulty nodes is determined, and the power facility network security behavior effect model is built to ensure the scalability and reusability of the model.
The scalability and reusability of the network security behavior effect model of power facilities is realized, and it can quickly adapt to and generate the changed network security behavior effect model when the entity node changes.
Smart Images

Figure CN116319278B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular, to a method for constructing a network security behavior effect model of power facilities and a network protection system. Background Art
[0002] The cross-domain effects of power network security behaviors include system-level effects and cross-domain effects generated by power network security games:
[0003] Among them, the construction of the cross-domain security behavior effect model of power CPS generally uses graph theory to abstract the network structure and business scheduling of the power system to construct the associated interaction description of the power physical domain and information, and solve the fusion problem of the physical domain and the information domain; or draw on the cascading failure of the power grid, refine the information entities and construct the cascading failure model of the power grid through the power flow algorithm.
[0004] However, in the above modeling methods, the modeling is based on existing entities. Once the entities change, it is necessary to reconstruct the security behavior effect model according to the changed entities and re-simulate the effects generated by the security behaviors, which is not reusable and has poor scalability. Summary of the Invention
[0005] The problem solved by the present invention is how to establish a network security behavior effect model with scalability.
[0006] To solve the above problems, the present invention provides a method for constructing a network security behavior effect model of power facilities, including:
[0007] After the power physical domain entity is abnormal, obtain the node list of the abnormal entity;
[0008] Judge the valid nodes in the node list, and the valid nodes include the first valid in-nodes and the first valid out-nodes;
[0009] Judge whether the out-nodes of each of the first valid in-nodes are faulty. If so, determine the affected nodes according to the faulty nodes, judge the fault conditions of the affected nodes, and obtain the first set of faulty nodes;
[0010] Judge whether the in-nodes of each of the first valid out-nodes are faulty. If it is determined that the in-nodes of the first valid out-nodes are faulty, determine the fault conditions of the affected nodes according to the faulty nodes, and obtain the second set of faulty nodes;
[0011] Determine the set of faulty nodes according to the first set of faulty nodes and the second set of faulty nodes.
[0012] Optionally, to determine whether the out-nodes of each of the first valid in-nodes are faulty, if so, determine the affected nodes according to the faulty nodes, and determine the fault conditions of the affected nodes, the first set of faulty nodes obtained includes:
[0013] Obtain the list of valid out-nodes of the first valid in-node as the first list;
[0014] Determine whether the first list is an empty list;
[0015] If the first list is an empty list, obtain all the valid in-nodes of the nodes in the first list as the second list, obtain all the valid out-nodes in the second list, return to the step of determining whether the first list is an empty list, and traverse all the nodes with an empty list of valid out-nodes as the first set of faulty nodes.
[0016] Optionally, after determining whether the first list is an empty list, it further includes:
[0017] If the first list is not an empty list, re-shunt the out-nodes of the nodes in the first list;
[0018] Determine whether the shunted out-nodes meet the fault conditions, where the node where the out-node that meets the fault conditions is located is the out-power line fault node, and the fault conditions include that the power of the shunted out-node is greater than the preset maximum power;
[0019] If so, determine whether the third list is an empty list, where the third list includes the list of valid in-nodes of the out-power line fault node;
[0020] If the third list is an empty list, determine whether the fourth list is an empty list, where the fourth list includes the list of valid out-nodes of the out-power line fault node;
[0021] If the fourth list is not an empty list, further determine whether the fifth list is an empty list, where the fifth list includes the list of valid in-nodes of the valid out-nodes of the out-power line fault node.
[0022] Optionally, after if so, determine whether the third list is an empty list, it further includes:
[0023] If the list of valid in-nodes of the out-power line fault node is not an empty list, but the list of valid out-nodes of the out-power line fault node is an empty list, return to the step of determining whether the first list is an empty list.
[0024] Optionally, determine whether the in-node of each of the first valid out-nodes is faulty. If it is determined that the in-node of the first valid out-node is faulty, determine the fault condition of the affected nodes according to the faulty node, and obtain a second set of faulty nodes, including:
[0025] Obtain the list of valid in-nodes of the first valid out-node as the sixth list;
[0026] Determine whether the sixth list is an empty list;
[0027] If the sixth list is an empty list, use the nodes in the sixth list as the faulty nodes of the outgoing circuit, and traverse all nodes with an empty list of valid in-nodes as the second set of faulty nodes.
[0028] Optionally, before determining the set of faulty nodes according to the first set of faulty nodes and the second set of faulty nodes, further include:
[0029] When the associated nodes of a node meet the preset conditions, determine the set of faulty nodes according to the fault conditions of the affected nodes, where the associated contacts include out-nodes and in-nodes, and the preset conditions include that the list of valid out-nodes and the list of valid in-nodes of the associated nodes are not empty.
[0030] Optionally, the node list includes a list of valid out-nodes and a list of valid in-nodes. The list of valid out-nodes includes all valid out-nodes of the abnormal entity, and the list of valid in-nodes includes all valid in-nodes of the abnormal entity.
[0031] Optionally, the method for constructing the power facility network security behavior effect model further includes a power network protection effect model, and the power network protection effect model includes:
[0032] Obtain a list of network protection nodes;
[0033] Determine whether the defense of the nodes in the list of network protection nodes is successful;
[0034] If so, change the node status to the down state, and determine whether the nodes in the down state cause the associated nodes to go down;
[0035] If the associated nodes go down, further determine whether the associated nodes of the associated nodes go down until no new down nodes are added, and use the down result as the protection result.
[0036] Optionally, the method for constructing the power facility network security behavior effect model further includes a power network intrusion effect model, and the power network intrusion effect model includes:
[0037] Obtain the down nodes;
[0038] Obtain heterogeneous nodes of the crashed node;
[0039] Judge the crashing results of the associated nodes of the heterogeneous nodes until no new crashing nodes are added, and use the crashing results as intrusion results.
[0040] Compared with the prior art, after an anomaly occurs in the entity domain, the present invention uses the topological connections of each entity node to determine a list of valid nodes related to the abnormal entity, then divides the valid nodes into valid outgoing nodes and valid incoming nodes, and respectively determines the fault conditions of the outgoing nodes and incoming nodes of the abnormal entity, determines the first fault node set and the second fault node set, so as to determine the impact brought by the security behavior in terms of both outgoing nodes and incoming nodes, that is, determine the network security behavior effect. The present invention is not limited to the rules of entity connections in the power professional technical field, but focuses on starting from the influence rules and effects of power information dissemination, determines the fault conditions of outgoing nodes or incoming nodes. When an entity node is added, deleted or modified, the valid outgoing nodes and valid incoming nodes of the changed node are used as the node list, and through the existing model, the network security behavior effect of the changed entity domain can be obtained, ensuring the scalability and reusability of the effect model.
[0041] On the other hand, the present invention also provides a power facility network protection system, including an entity model, an action model, and a power facility network security behavior effect model, and the power facility network security behavior effect model is constructed by the power facility network security behavior effect model construction method as described above.
[0042] The beneficial effects of the shown power facility network protection system compared with the prior art are the same as those of the power facility network security behavior effect model construction method, and will not be elaborated here. Description of the Drawings
[0043] Figure 1 It is a schematic flowchart of the power facility network security behavior effect model construction method according to an embodiment of the present invention;
[0044] Figure 2 It is a schematic flowchart after refining step S300 of the power facility network security behavior effect model construction method according to an embodiment of the present invention;
[0045] Figure 3 It is a schematic flowchart after step S320 of the power facility network security behavior effect model construction method according to an embodiment of the present invention;
[0046] Figure 4 It is a schematic flowchart after refining step S400 of the power facility network security behavior effect model construction method according to an embodiment of the present invention;
[0047] Figure 5 Schematic flowchart of the power network protection effect model of the method for constructing the power facility network security behavior effect model according to an embodiment of the present invention;
[0048] Figure 6 Schematic flowchart of the power network intrusion effect model of the method for constructing the power facility network security behavior effect model according to an embodiment of the present invention. Detailed implementation manners
[0049] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following detailed description of the specific embodiments of the present invention will be given with reference to the accompanying drawings. Although some embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be construed as limited to the embodiments described herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present invention. It should be understood that the drawings and embodiments of the present invention are only for exemplary purposes and are not used to limit the protection scope of the present invention.
[0050] It should be understood that the steps described in the method embodiments of the present invention can be executed in different orders and / or executed in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present invention is not limited in this regard.
[0051] The term "including" and its variations used herein are open-ended, that is, "including but not limited to". The term "based on" is "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments"; the term "optionally" means "optional embodiments". The relevant definitions of other terms will be given in the following description. It should be noted that the concepts such as "first" and "second" mentioned in the present invention are only used to distinguish different devices, modules, or units, and are not used to limit the order of functions performed by these devices, modules, or units or their interdependent relationships.
[0052] It should be noted that the modifications of "one" and "multiple" mentioned in the present invention are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly specified in the context, it should be understood as "one or more".
[0053] As Figure 1 shown, a method for constructing a power facility network security behavior effect model provided by an embodiment of the present invention includes a power network protection cross-domain effect model, and the power network protection cross-domain effect model includes:
[0054] Step S100, after the power physical domain entity is abnormal, obtain the node list of the abnormal entity.
[0055] The power infrastructure refers to the framework based on the Cyber-Physical System (CPS) of electricity, which is composed of the fusion of the physical domain and the information domain of electricity. It is compatible with electrical technologies such as intelligent power distribution, renewable energy grid connection, and smart grid restoration. Among them, the information domain of electricity is the main target of network security protection actions. Network security actions occurring in the information domain of electricity may cause a larger-scale network effect in the power grid system and even other combat domains.
[0056] Network security behavior refers to personal (collective) behaviors such as malicious (accidental) destruction, modification, leakage, and protection of the hardware, software, and data in the network system, including network intrusion behavior, network protection actions, etc.
[0057] The entity anomaly in the physical domain of electricity indicates that a certain entity in the entity model has been affected by network security behavior. For example, when the power station node is damaged or modified, the entity model of the power station node will indicate an anomaly. At this time, the nodes related to the abnormal entity are obtained.
[0058] In one embodiment, the nodes related to the entity include the nodes physically connected to the entity and the nodes informationally connected to the entity. For example, the substation electrically connected to the power station is the node physically connected to the power station; the control center node communicatively connected to the power station is the node informationally connected to the power station.
[0059] Since an entity node is often connected to multiple nodes, when an anomaly occurs in the physical domain entity, all the nodes associated with the physical domain entity are obtained to form a node list.
[0060] In one embodiment, the nodes include entities such as power stations, substations, distribution stations, load centers, and dispatch centers. When the node is a power station, its out-nodes can be nodes such as substations.
[0061] Step S200, determine the valid nodes in the node list, and the valid nodes include the first valid in-nodes and the first valid out-nodes.
[0062] After obtaining the node list associated with the abnormal physical domain entity, determine the valid nodes of each node in the node list, and divide the valid nodes into the first valid in-nodes and the first valid out-nodes.
[0063] In one embodiment, after node A fails due to an attack, a list of valid nodes of node A is obtained. The list includes valid outgoing node 1, valid outgoing node 2, valid incoming node 1, and valid incoming node 2. Then, valid incoming node 1 and valid incoming node 2 are taken as the first valid incoming nodes, and valid outgoing node 1 and valid outgoing node 2 are taken as the first valid outgoing nodes. Determining the first valid incoming nodes and the first valid outgoing nodes can help determine the outgoing and incoming nodes of the faulty node and preliminarily determine the cascading propagation effect of the faulty node in the entire power grid.
[0064] Step S300: Determine whether the outgoing nodes of each of the first valid incoming nodes are faulty. If so, determine the affected nodes based on the faulty node, and determine the fault conditions of the affected nodes to obtain the first set of faulty nodes.
[0065] After determining the first valid incoming nodes, determine whether the outgoing nodes of each first valid incoming node are faulty nodes. When there are faulty nodes among the outgoing nodes of the first valid incoming nodes, further determine whether the outgoing and incoming nodes of the faulty node are abnormal, that is, whether they are faulty nodes; among the first valid incoming nodes, the nodes that are not faulty are normal nodes, and the outgoing and incoming nodes of normal nodes are not further determined.
[0066] Step S400: Determine whether the incoming nodes of each of the first valid outgoing nodes are faulty. If it is determined that the incoming nodes of the first valid outgoing nodes are faulty, determine the fault conditions of the affected nodes based on the faulty node to obtain the second set of faulty nodes.
[0067] After determining the first valid outgoing nodes, determine whether the incoming nodes of each first valid outgoing node are faulty nodes. When there are faulty nodes among the incoming nodes of the first valid outgoing nodes, further determine whether the outgoing and incoming nodes of the faulty node are abnormal, that is, whether they are faulty nodes; among the first valid incoming nodes, the nodes that are not faulty are normal nodes, and the outgoing and incoming nodes of normal nodes are not further determined.
[0068] Step S500: Determine the set of faulty nodes based on the first set of faulty nodes and the second set of faulty nodes.
[0069] Determine all faulty nodes and normal nodes according to steps S300 and S400. When traversing all nodes or no new faulty nodes are added, take all faulty nodes as the set of faulty nodes. Thus, the cross-domain effect of power network protection is determined. Determine the cross-domain effect affected by network security behaviors according to the faulty entities and the connected nodes.
[0070] Optionally, as Figure 2As shown, determining whether the out - nodes of each of the first valid in - nodes are faulty. If so, determining the affected nodes based on the faulty nodes, and judging the fault conditions of the affected nodes, the first faulty - node set obtained includes:
[0071] Step S310, obtaining the list of valid out - nodes of the first valid in - node as the first list;
[0072] Step S320, judging whether the first list is an empty list;
[0073] Step S330, if the first list is an empty list, obtaining all the valid in - nodes of the nodes in the first list as the second list, obtaining all the valid out - nodes of the second list, returning to the step of judging whether the first list is an empty list, and traversing all the nodes with an empty list of valid out - nodes as the first faulty - node set.
[0074] Obtaining all the valid out - nodes of the first valid in - node, that is, all the valid out - nodes associated with all the valid in - nodes of the faulty node A. Taking these lists of valid out - nodes as the first list, the fault conditions of the out - nodes related to the nodes related to the faulty node can be obtained.
[0075] Judging whether the first list is an empty list. When the first list is an empty list, it means that the nodes where the valid out - nodes in the first list are located have no valid out - nodes and all the out - power lines are faulty. At this time, it is necessary to further trace and judge the valid in - nodes of the nodes in the first list, taking the list composed of these nodes as the second list, and judging whether the other valid out - nodes of the nodes in the second list are also out - circuit faulty, that is, returning to the step of judging whether the first list is an empty list. According to the loop - before tracing, judge whether the valid in - nodes of the faulty node A are faulty nodes, and then judge whether the valid in - nodes of the faulty nodes are faulty nodes, so as to determine all the faulty nodes in the in - node direction layer by layer.
[0076] Optionally, as Figure 3 shown, after judging whether the first list is an empty list, it further includes:
[0077] Step S321, if the first list is not an empty list, re - shunting the out - nodes of the nodes in the first list;
[0078] Step S322, judging whether the shunted out - nodes meet the fault conditions, where the nodes where the out - nodes that meet the fault conditions are located are the out - power - line faulty nodes, and the fault conditions include that the power of the shunted out - nodes is greater than the preset maximum power;
[0079] Step S323, if satisfied, determine whether the third list is an empty list, where the third list includes the list of valid in-nodes of the out-power line fault node;
[0080] Step S324, if the third list is an empty list, determine whether the fourth list is an empty list, where the fourth list includes the list of valid out-nodes of the out-power line fault node;
[0081] Step S325, if the fourth list is not an empty list, further determine whether the fifth list is an empty list, where the fifth list includes the list of valid in-nodes of the valid out-nodes of the out-power line fault node.
[0082] In one embodiment, after step S320, when it is determined that the first list is not an empty list, it means that the nodes in the first list have valid out-nodes. At this time, the out-nodes in the first list are re-shunted. If the power of the shunted out-node is greater than the preset maximum power, the out-node fails, and the out-power line of the out-node fails. If the power of the shunted out-node is less than or equal to the preset maximum power, no other operations are performed, and the node is not a fault node.
[0083] When a node meets the fault condition, that is, the out-power line of the node fails, further determine the fault conditions of the other in-nodes of the node, and determine whether the third list is an empty list. If the third list is an empty list, it means that the node also has no valid in-nodes, indicating that the node fails and the out-power line fails. Further trace whether the out-node of the node in the third list is an empty node, that is, determine whether the fourth list is an empty list. If the fourth list is not an empty list, it means that the node has valid in-nodes, and it is necessary to further determine the in-node list of the out-node, that is, determine whether the fifth list is empty. This process extends forward layer by layer until there are no fault nodes, indicating that the fault condition extends to this point and ends.
[0084] In another embodiment, when the valid out-nodes in the fourth list or the fifth list are empty, determine whether the associated nodes have been traversed. If the fault status no longer spreads, then end the deduction of the effect model, and the determined fault nodes are all the fault nodes in the direction of the valid in-nodes.
[0085] Optionally, after the step of if satisfied, determine whether the third list is an empty list, it further includes:
[0086] If the list of valid in-nodes of the out-power line fault node is not an empty list, but the list of valid out-nodes of the out-power line fault node is an empty list, return to the step of determining whether the first list is an empty list.
[0087] When the third list is not an empty list, it indicates that this node has valid incoming nodes but no valid outgoing nodes, and the node is down. The incoming nodes of this node may be affected by attacks. Obtain the valid outgoing node lists of the incoming nodes of each node in the third list respectively, obtain the outgoing node failure conditions in the incoming node direction, and re-judge the failure conditions in the incoming node direction in the third node list through step S320.
[0088] Optionally, as Figure 4 shown, determine whether the incoming nodes of each of the first valid outgoing nodes are faulty. If it is determined that the incoming nodes of the first valid outgoing nodes are faulty, then determine the failure conditions of the affected nodes according to the faulty nodes. The obtained second faulty node set includes:
[0089] Step S410, obtain the valid incoming node list of the first valid outgoing node as the sixth list;
[0090] Step S420, determine whether the sixth list is an empty list;
[0091] Step S430, if the sixth list is an empty list, then use the nodes in the sixth list as the outgoing circuit faulty nodes, and traverse all nodes with an empty valid incoming node list as the second faulty node set.
[0092] For the faulty node A, it is also necessary to judge the fault influence situation in the outgoing node direction. Obtain the valid incoming node list of the first valid outgoing node as the sixth list, and judge whether the sixth list is an empty list, that is, whether the nodes in the outgoing node direction of node A have valid incoming nodes. When the nodes in the sixth list do not have valid incoming nodes, similar to steps S323, S324, and S325, if the valid incoming node list is empty, then the node has no valid incoming nodes, the node is down, and the outgoing circuit is faulty. Then judge whether the valid outgoing node list is empty. If the valid outgoing node list is not empty, then obtain the incoming node list of the outgoing node, and further judge whether the valid incoming node list of the valid outgoing node is empty until no new faulty nodes are added; if the valid incoming node list is not empty but the outgoing list is empty, then the node has incoming but no outgoing, the node is down, which has an impact on the incoming node of this node. Judge the incoming nodes respectively, that is, return to step S320 to judge the incoming nodes of the next layer.
[0093] Optionally, before determining the faulty node set according to the first faulty node set and the second faulty node set, it further includes:
[0094] When the associated nodes of the node meet the preset conditions, determine the faulty node set according to the failure conditions of the affected nodes, where the associated nodes include outgoing nodes and incoming nodes, and the preset conditions include that the valid outgoing node list and the valid incoming node list of the associated nodes are not empty.
[0095] Optionally, the node list includes a valid out-node list and a valid in-node list. The valid out-node list includes all valid out-nodes of the abnormal entity, and the valid in-node list includes all valid in-nodes of the abnormal entity.
[0096] Optionally, as Figure 5 shown, the method for constructing the power facility network security behavior effect model further includes a power network protection effect model, and the power network protection effect model includes:
[0097] Obtain a network protection node list;
[0098] Judge whether the defense of the nodes in the network protection node list is successful;
[0099] If so, change the node status to the down state, and judge whether the down state of the node causes the associated node to go down;
[0100] If the associated node goes down, further judge whether the associated node of the associated node goes down until no new down nodes are added, and take the down result as the protection result.
[0101] The power network protection effect model simulates the network attack and defense game and the same-network effect propagation effect in a typical network attack scenario for the power information domain. By judging whether the defense of the nodes is successful, and then determining the impact of all down nodes on the working states of the upper and lower levels of the nodes according to the judgment result, and finally determining the list of affected nodes.
[0102] Optionally, as Figure 6 shown, the method for constructing the power facility network security behavior effect model further includes a power network intrusion effect model, and the power network intrusion effect model includes:
[0103] Obtain down nodes;
[0104] Obtain the heterogeneous nodes of the down nodes;
[0105] Judge the down result of the associated nodes of the heterogeneous nodes until no new down nodes are added, and take the down result as the intrusion result.
[0106] The power network intrusion effect model simulates that when entities in the power information domain are under network intrusion, it will have a cross-domain impact on the electrical states of related same-network power information domain entities and heterogeneous power physical domain entities, causing a large-scale cascading effect, and determining the heterogeneous nodes affected by the network intrusion through the power network intrusion effect model.
[0107] On the other hand, an embodiment of the present invention provides a power facility network protection system, including an entity model, an action model, and a power facility network security behavior effect model, where the power facility network security behavior effect model is constructed by the power facility network security behavior effect model construction method as described above.
[0108] The beneficial effects of the power facility network protection system compared with the prior art are the same as those of the power facility network security behavior effect model construction method, which will not be elaborated here.
[0109] Another embodiment of the present invention provides an electronic device, including a memory and a processor; the memory is used to store a computer program; the processor is used to implement the power facility network security behavior effect model construction method as described above when executing the computer program.
[0110] Another embodiment of the present invention provides a computer-readable storage medium storing a computer program, which implements the power facility network security behavior effect model construction method as described above when the computer program is executed by a processor.
[0111] Now, an electronic device that can be used as a server or a client of the present invention will be described. It is an example of a hardware device that can be applied to various aspects of the present invention. The electronic device is intended to represent various forms of digital electronic computer devices, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0112] The electronic device includes a computing unit, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) or a computer program loaded from a storage unit into a random access memory (RAM). In the RAM, various programs and data required for device operation can also be stored. The computing unit, ROM, and RAM are connected to each other through a bus. An input / output (I / O) interface is also connected to the bus.
[0113] A computer system can include a client and a server. The client and the server are generally far from each other and usually interact through a communication network. The relationship between the client and the server is generated by computer programs running on the corresponding computers and having a client-server relationship with each other.
[0114] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM), etc. In this application, the units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of the embodiments of the present invention. In addition, the functional units in each embodiment of the present invention can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.
[0115] Although the present disclosure is disclosed as above, the scope of protection of the present disclosure is not limited thereto. Those skilled in the art can make various changes and modifications without departing from the spirit and scope of the present disclosure, and these changes and modifications will all fall within the protection scope of the present invention.
Claims
1. A method for constructing a power facility network security behavior effect model, characterized in that, it includes: After a power physical domain entity is abnormal, obtain the node list of the abnormal entity; Judge the valid nodes in the node list, and the valid nodes include the first valid incoming nodes and the first valid outgoing nodes; Judge whether the outgoing nodes of each of the first valid incoming nodes are faulty. If so, determine the affected nodes according to the faulty nodes, judge the fault conditions of the affected nodes, and obtain the first set of faulty nodes, including: obtaining the valid outgoing node list of the first valid incoming node as the first list; judging whether the first list is an empty list; if the first list is an empty list, obtain all the valid incoming nodes of the nodes in the first list as the second list, obtain all the valid outgoing nodes in the second list, return to the step of judging whether the first list is an empty list, and traverse all the nodes with an empty valid outgoing node list as the first set of faulty nodes; After judging whether the first list is an empty list, it further includes: if the first list is not an empty list, re-shunt the outgoing nodes of the nodes in the first list; judge whether the shunted outgoing nodes meet the fault conditions, where the node where the outgoing node that meets the fault conditions is located is the outgoing line fault node, and the fault conditions include that the power of the shunted outgoing node is greater than the preset maximum power; if it is satisfied, judge whether the third list is an empty list, where the third list includes the valid incoming node list of the outgoing line fault node; if the third list is an empty list, judge whether the fourth list is an empty list, where the fourth list includes the valid outgoing node list of the outgoing line fault node; if the fourth list is not an empty list, further judge whether the fifth list is an empty list, where the fifth list includes the valid incoming node list of the valid outgoing nodes of the outgoing line fault node; Judge whether the incoming nodes of each of the first valid outgoing nodes are faulty. If it is determined that the incoming nodes of the first valid outgoing nodes are faulty, determine the fault conditions of the affected nodes according to the faulty nodes, and obtain the second set of faulty nodes; Determine the set of faulty nodes according to the first set of faulty nodes and the second set of faulty nodes.
2. The method for constructing a power facility network security behavior effect model according to claim 1, characterized in that, after judging whether the third list is an empty list if it is satisfied, it further includes: if the valid incoming node list of the outgoing line fault node is not an empty list, but the valid outgoing node list of the outgoing line fault node is an empty list, return to the step of judging whether the first list is an empty list.
3. The method for constructing a power facility network security behavior effect model according to claim 2, characterized in that, judging whether the incoming nodes of each of the first valid outgoing nodes are faulty. If it is determined that the incoming nodes of the first valid outgoing nodes are faulty, determining the fault conditions of the affected nodes according to the faulty nodes, and obtaining the second set of faulty nodes includes: obtaining the valid incoming node list of the first valid outgoing node as the sixth list; Determine whether the sixth list is an empty list; If the sixth list is an empty list, use the nodes in the sixth list as the out-circuit fault nodes, and traverse all the nodes with an empty valid in-node list as the second fault node set.
4. The method for constructing a power facility network security behavior effect model according to claim 3, characterized in that, Before determining the fault node set according to the first fault node set and the second fault node set, it further includes: When the associated nodes of a node meet the preset conditions, determine the fault node set according to the fault conditions of the affected nodes, where the associated nodes include out-nodes and in-nodes, and the preset conditions include that the valid out-node list of the associated nodes is not empty and the valid in-node list is not empty.
5. The method for constructing a power facility network security behavior effect model according to claim 4, characterized in that, The node list includes a valid out-node list and a valid in-node list. The valid out-node list includes all valid out-nodes of the abnormal entity, and the valid in-node list includes all valid in-nodes of the abnormal entity.
6. The method for constructing a power facility network security behavior effect model according to any one of claims 1-5, characterized in that, The power facility network security behavior effect model further includes a power network protection effect model, and the power network protection effect model includes: Obtain a network protection node list; Judge whether the defense of the nodes in the network protection node list is successful; If so, change the node status to the down state, and judge whether the nodes in the down state cause the associated nodes to go down; If the associated nodes go down, further judge whether the associated nodes of the associated nodes go down until no new down nodes are added, and use the down result as the protection result.
7. The method for constructing a power facility network security behavior effect model according to any one of claims 1-5, characterized in that, The power facility network security behavior effect model further includes a power network intrusion effect model, and the power network intrusion effect model includes: Obtain the down nodes; Obtain the heterogeneous nodes of the down nodes; Judge the down results of the associated nodes of the heterogeneous nodes until no new down nodes are added, and use the down result as the intrusion result.
8. A power facility network protection system, characterized in that, It includes an entity model, an action model and a power facility network security behavior effect model, and the power facility network security behavior effect model is constructed by the method for constructing a power facility network security behavior effect model according to any one of claims 1-7.
Citation Information
Patent Citations
Anti-attack communication network fault cascade risk influence analysis method
CN107769962A
Power communication network fault recovery method based on service characteristics and node reliability
CN111130898A