Method and system for improving monitoring accuracy of cyber-attack behavior of power system network

By combining DFI and DPI analysis techniques, abnormal attack behaviors in power system networks can be identified, solving the problem of frequent false alarms in traditional monitoring and achieving higher monitoring accuracy.

CN116346434BActive Publication Date: 2026-04-21GUANGDONG POWER GRID CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
GUANGDONG POWER GRID CO LTD
Filing Date
2023-03-03
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

The main reason why traditional power system network attack detection has many false alarms is that traditional feature matching technology uses static thresholds, which cannot be adapted and dynamically adjusted according to the actual business situation of the accessed object, resulting in insufficient detection accuracy.

Method used

DFI analysis technology is used to perform behavioral analysis on traffic data, identify communication protocols and message lengths, build a business characteristic model by combining CMDB basic data, and identify abnormal attack behavior through DPI analysis. The detection accuracy is improved by combining DFI and DPI detection technology.

Benefits of technology

By combining DFI and DPI, abnormal attack behaviors can be accurately identified, false alarms can be reduced, and the accuracy of power system network attack monitoring can be improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116346434B_ABST
    Figure CN116346434B_ABST
Patent Text Reader

Abstract

This application provides a method and system for improving the accuracy of power system network attack monitoring. It utilizes Direct Traffic Flow Analysis (DFI) technology to analyze collected traffic data and obtain traffic behavior information. Based on this information, it identifies the accessed service and the logical combination and sorting of communication protocols, and then combines this with CMDB (Content Management Database) basic data to construct a service characteristic model. Next, it performs Direct Traffic Flow Analysis (DPI) on the traffic data, and based on the analysis results and the service characteristic model, determines whether abnormal attack behavior exists within the traffic data. Therefore, by combining DFI and DPI analysis techniques to detect traffic data, and simultaneously judging abnormal attack behavior based on traffic behavior and the structural characteristics of the data packets themselves, the accuracy of power system network attack monitoring is significantly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of power system network security, and in particular to a method and system for improving the accuracy of power system network attack monitoring. Background Technology

[0002] Traditional power system network security data acquisition is limited by the synchronization and congestion of network communication. In order to improve performance, advanced event acquisition algorithms have made full use of asynchronous and non-blocking methods, but the performance is still difficult to meet the needs of large-scale event processing.

[0003] Furthermore, there are many false alarms in the attack monitoring of power system networks. The main reason for the high number of false alarms is that traditional feature matching technology uses static thresholds, which cannot be adapted and dynamically adjusted according to the actual business situation of the accessed object. Summary of the Invention

[0004] To overcome the problems existing in related technologies, this application provides a method and system for improving the accuracy of power system network attack behavior monitoring, which can improve the detection accuracy of attacks on power system networks and enhance the security of power system networks.

[0005] According to a first aspect of the embodiments of this application, a method for improving the accuracy of power system network attack behavior monitoring is provided, comprising the following steps:

[0006] DFI analysis technology is used to analyze the traffic behavior of the collected traffic data and obtain the traffic behavior information of the traffic data.

[0007] Based on the traffic behavior information, the communication protocol and communication message length field of the traffic data are identified;

[0008] The communication protocols of the identified traffic data are logically combined and sorted according to their corresponding communication message length fields.

[0009] Based on the traffic behavior information of the traffic data, the traffic data is used to perform asset location association to locate the accessed object business;

[0010] Based on the object business, the logical combination and sorting of the communication protocol, and the CMDB basic data, a business feature model is constructed; wherein, the business feature model includes an access behavior model and a communication message model;

[0011] DPI analysis is performed on the collected traffic data, and based on the analysis results and the business characteristic model, it is determined whether there are any abnormal attack behaviors in the traffic data.

[0012] According to a second aspect of the embodiments of this application, a system for improving the accuracy of monitoring network attack behavior in power systems is provided, comprising:

[0013] The traffic behavior detection module is used to perform traffic behavior analysis on the collected traffic data using DFI analysis technology to obtain traffic behavior information of the traffic data;

[0014] The identification module is used to identify the communication protocol and communication message length field of the traffic data based on the traffic behavior information;

[0015] The logic module is used to sort the communication protocols of the identified traffic data according to their corresponding communication message length fields.

[0016] The association module is used to perform asset location association on the traffic data based on the traffic behavior information of the traffic data, and locate the accessed object service;

[0017] The mapping module is used to map and construct a business feature model based on the object business, the logical combination and sorting of the communication protocol, and the CMDB basic data; wherein, the business feature model includes an access behavior model and a communication message model;

[0018] The judgment module is used to perform DPI analysis on the collected traffic data and, based on the analysis results and the business characteristic model, determine whether there are any abnormal attack behaviors in the traffic data.

[0019] This application discloses a method and system for improving the accuracy of power system network attack monitoring. It utilizes Direct Traffic Flow Analysis (DFI) technology to analyze collected traffic data and obtain traffic behavior information. Based on this information, it identifies the accessed service and the logical combination and sorting of communication protocols, then combines this with CMDB (Content Management Database) data to construct a service characteristic model. Next, it performs Direct Traffic Injection (DPI) analysis on the traffic data. Based on the analysis results and the service characteristic model, it determines whether abnormal attack behavior exists in the traffic data. Therefore, by combining DFI and DPI analysis techniques, and simultaneously judging abnormal attack behavior based on traffic behavior and the structural characteristics of the data packets themselves, the accuracy of power system network attack monitoring is significantly improved.

[0020] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application.

[0021] To better understand and implement this invention, the following detailed description is provided in conjunction with the accompanying drawings. Attached Figure Description

[0022] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0023] Figure 1 This is a schematic diagram of the operating environment for the method to improve the accuracy of monitoring network attack behavior in power systems, as shown in the embodiments of this application.

[0024] Figure 2 This is a flowchart illustrating a method for improving the accuracy of power system network attack behavior monitoring, as shown in one embodiment of this application.

[0025] Figure 3 This is a flowchart illustrating a method for asset location association of the traffic data in one embodiment of this application;

[0026] Figure 4 This is a flowchart illustrating a method for improving the accuracy of power system network attack monitoring, as shown in another embodiment of this application;

[0027] Figure 5 This is a schematic diagram illustrating the method for improving the accuracy of power system network attack monitoring according to an embodiment of this application;

[0028] Figure 6 This is a schematic diagram of the structure of a power system network attack behavior monitoring accuracy improvement system shown in an embodiment of this application. Detailed Implementation

[0029] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.

[0030] It should be understood that the described embodiments are merely some, not all, of the embodiments in this application. All other embodiments obtained by those skilled in the art based on the embodiments in this application without inventive effort are within the scope of protection of this application.

[0031] In the following description, when referring to the accompanying drawings, the same numbers in different drawings denote the same or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0032] In the description of this application, it should be understood that the terms "first," "second," "third," etc., are used only to distinguish similar objects and are not necessarily used to describe a specific order or sequence, nor should they be construed as indicating or implying relative importance. Those skilled in the art can understand the specific meaning of the above terms in this application according to the specific circumstances. The singular forms "a," "the," and "the" used in this application and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise. The words "if" or "when" as used herein can be interpreted as "when," "in response to a determination." Furthermore, in the description of this application, unless otherwise stated, "a plurality" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist; for example, A and / or B can represent: A alone, A and B simultaneously, or B alone. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship.

[0033] Please see Figure 1 This is a schematic diagram illustrating the application environment of the method for improving the accuracy of power system network attack monitoring, as shown in the embodiments of this application. Figure 1 As shown, the method for improving the accuracy of power system network attack monitoring can be applied to the field of power system network security applications. Its application environment includes a monitoring client 101 and a monitoring server 102, and the monitoring client 101 and the monitoring server 102 interact through a wired or wireless network.

[0034] Among them, monitoring client 101 refers to the client located at the gateway for collecting traffic data. It can be a monitoring client software program that is set up independently, or it can be combined with other traditional data collection programs, or it can exist in the form of a plug-in. It is used to collect traffic data at the gateway.

[0035] The hardware referred to by the monitoring client 101 essentially refers to computer equipment. Specifically, it can be computer equipment such as electronic devices and personal computers. The monitoring client 101 can access the Internet through a known network access method to establish a data communication link with the monitoring server 102.

[0036] Monitoring server 102, acting as a data server, can further connect to related running data servers and other servers providing related support, thereby forming a logically interconnected service cluster to provide services to related terminal devices, such as... Figure 1The monitoring client 101 shown provides services. The monitoring server 102 is mainly used to receive traffic data uploaded by the monitoring client 101 and perform detection techniques that combine DFI analysis and DPI analysis to determine abnormal attack behavior based on traffic behavior and the structural characteristics of the data packets themselves.

[0037] Example 1

[0038] The following will be combined with the appendix Figure 2 This application provides a detailed description of a method for improving the accuracy of monitoring network attack behavior in power systems, based on embodiments of the present application.

[0039] Please see Figure 2 This application provides a method for improving the accuracy of power system network attack monitoring, which mainly runs on the monitoring server 102 and includes the following steps:

[0040] Step S101: Using DFI analysis technology, perform traffic behavior analysis on the collected traffic data to obtain traffic behavior information of the traffic data;

[0041] Step S102: Identify the communication protocol and communication message length field of the traffic data based on the traffic behavior information;

[0042] Step S103: The communication protocols of the identified traffic data are logically combined and sorted according to their corresponding communication message length fields;

[0043] Step S104: Based on the traffic behavior information of the traffic data, perform asset location association on the traffic data to locate the accessed object service;

[0044] Step S105: Based on the object service, the logical combination and sorting of the communication protocol, and the CMDB basic data, map and construct a service feature model; wherein, the service feature model includes an access behavior model and a communication message model;

[0045] Step S106: Perform DPI analysis on the collected traffic data, and determine whether there are any abnormal attack behaviors in the traffic data based on the analysis results and the business characteristic model.

[0046] This application discloses a method for improving the accuracy of power system network attack monitoring. It utilizes Direct Traffic Flow Analysis (DFI) technology to analyze collected traffic data and obtain traffic behavior information. Based on this information, it identifies the accessed service and the logical combination and sorting of communication protocols, then combines this with CMDB (Content Management Database) data to construct a service characteristic model. Next, it performs Direct Traffic Injection (DPI) analysis on the traffic data. Based on the analysis results and the service characteristic model, it determines whether abnormal attack behavior exists in the traffic data. Therefore, by combining DFI and DPI analysis techniques, and simultaneously judging abnormal attack behavior based on traffic behavior and the structural characteristics of the data packets themselves, the accuracy of power system network attack monitoring is significantly improved.

[0047] For step S101, the collected traffic data is analyzed using DFI analysis technology to obtain traffic behavior information of the traffic data.

[0048] DFI (Deep / Dynamic Flow Inspection) technology differs from DPI (Deep Packet Inspection) technology in that it performs application-layer payload matching. DFI uses application identification technology based on traffic behavior, meaning that different application types are reflected in different states of session connections or data streams.

[0049] Systems based on DFI technology require less management and maintenance than DPI systems because the traffic characteristics of new and old applications of the same type do not change significantly, thus eliminating the need for frequent upgrades to the traffic behavior model. If data packets are transmitted encrypted, DPI-based flow control technology cannot identify the specific application, while DFI-based flow control technology remains unaffected because the application flow's state behavior characteristics are not fundamentally altered by encryption.

[0050] However, DFI only analyzes traffic behavior, so it can only classify application types in a general way. For example, it uniformly identifies applications that meet the P2P traffic model as P2P traffic, so it cannot completely and accurately identify attack behavior.

[0051] In this step, DFI analysis technology is first used to obtain the traffic behavior information of the traffic data. The traffic behavior information includes the source address, destination address, source port, destination port, and response information of the traffic data.

[0052] For step S102, the communication protocol and communication message length field of the traffic data are identified based on the traffic behavior information.

[0053] In the previous step, DFI analysis technology was used to analyze the traffic behavior of the collected traffic, which can analyze fields such as source address, destination address, source port, destination port, communication protocol, communication message length, and response status.

[0054] Then, in this step, based on the source address, destination address, source port, destination port, and response information, the communication protocol corresponding to the traffic data and its corresponding communication message length field are determined. First, the analysis object in this step is all collected traffic data. Second, by matching the above traffic behavior information, the communication protocol and communication message length field can be extracted and identified.

[0055] For step S103, the communication protocols of the identified traffic data are logically combined and sorted according to their corresponding communication message length fields.

[0056] Some power system networks require application systems that publish multiple protocols to access them normally and completely. Therefore, they will design multiple communication protocols, and each communication protocol needs to be initiated in a certain logical order, and each protocol has its corresponding message length.

[0057] Therefore, in this step, the communication protocol and communication message length fields extracted in the previous step are sorted by protocol exchange logic.

[0058] Furthermore, after sorting the communication protocols of the identified traffic data according to their corresponding communication message length fields, it is possible to further determine whether the sorted traffic data and the corresponding communication protocol have the same context order, and whether the communication message length of the traffic data is consistent with the communication message length field. If they are inconsistent, they are identified as abnormal communication messages.

[0059] The above method can be used to detect abnormal communication message requests. The judgment logic includes: a. whether the context order of the communication protocol is consistent; b. whether the message length of the communication protocol is consistent with the obtained message length field. These two judgment logics determine whether abnormal communication messages exist.

[0060] For step S104, based on the traffic behavior information of the traffic data, asset location association is performed on the traffic data to locate the accessed object service.

[0061] like Figure 3As shown, in this step, the destination IP, destination port, protocol type, and other information extracted in step S101 need to be used for asset location and association. During the location and association process, based on the Configuration Management Database (CMDB) asset database and combined with the destination IP and destination port in the traffic behavior information, the specific accessed object service is located.

[0062] For step S105, a business feature model is constructed by mapping based on the object business, the logical combination and sorting of the communication protocol, and the CMDB basic data.

[0063] A business feature model is constructed based on mappings such as asset association, protocol sequence, and CMDB basic data. The business feature model includes a two-level model, namely an access behavior model and a communication message model.

[0064] In one embodiment, based on the object service, the logical combination and sorting of the communication protocol, and historical data of the CMDB basic data, the K-means clustering algorithm is used to classify the access behavior model; DPI analysis is performed on the communication traffic data of the key monitoring services of critical assets to parse the load information in the key packets of the transmission process, and the K-means clustering algorithm is used based on the load information to classify the communication message model.

[0065] The primary model is the access behavior model. Based on historical data from the above three sources, including asset association, protocol sequence, and CMDB basic data, the K-means clustering algorithm is used to classify the access behavior model under normal circumstances.

[0066] The secondary model is a communication message model. It performs DPI analysis on the communication traffic of key monitoring services for critical assets, parsing the specific load information within key packets during transmission. Based on the load information, a K-means clustering algorithm is used to classify the communication message model under normal conditions.

[0067] DPI stands for Deep Packet Inspection. Building upon packet header analysis, DPI adds application-layer analysis, making it an application-layer-based traffic inspection and control technology. When IP packets, TCP, or UDP data streams pass through a DPI-based traffic management system, the system deeply reads the IP packet payload to reconstruct the application-layer information in the OSI 7-layer protocol, thus obtaining the entire application content. Then, it reshapes the traffic according to the system's defined management policies.

[0068] DPI identification technology can be divided into the following three categories based on different protocol types:

[0069] (1) Identification technology based on “feature words”: Different applications usually rely on different protocols, and different protocols have their own special “fingerprints”. These “fingerprints” may be specific ports, specific strings or specific bit sequences.

[0070] (2) Application Layer Gateway Identification Technology: For some services, the control flow and service flow are separate, and the service flow has no characteristics. The application layer gateway needs to first identify the control flow, and then parse it according to the protocol of the control flow through a specific application layer gateway to identify the corresponding service flow from the protocol content.

[0071] (3) Behavior pattern recognition technology: Behavior pattern recognition technology analyzes the behaviors that the terminal has already performed to determine the actions that the user is currently performing or is about to perform.

[0072] DPI (Distributed Packet Inspection) and DFI (Distributed Flow Inspection) technologies differ in their implementation mechanisms. Firstly, DPI requires packet-by-packet analysis and matching with a backend database. Secondly, DPI-based bandwidth management systems always lag behind new applications, necessitating continuous upgrades to the backend application database to keep pace with emerging protocols and applications; otherwise, they cannot effectively identify and manage bandwidth under new technologies, thus hindering pattern matching efficiency. Furthermore, because DPI employs packet-by-packet analysis and pattern matching, it can more accurately identify specific application types and protocols within traffic.

[0073] For step S106, DPI analysis is performed on the collected traffic data, and based on the analysis results and the business characteristic model, it is determined whether there are any abnormal attack behaviors in the traffic data.

[0074] Based on DPI analysis, business analysis can be used to identify three scenarios, each of which can be assigned a different attack level label.

[0075] (1) Perform DPI analysis on the collected traffic data to obtain the corresponding data packet feature data. If the data packet feature data matches the preset attack behavior feature data, then add a first attack level mark to the traffic data. In the first case, based on the abnormal business data identified by the original feature matching of DPI, perform credibility identification and use the first attack level mark to identify the attack behavior as medium to high credibility, for example, it can be quantified as level 3.

[0076] (2) Perform DPI analysis on the collected traffic data to obtain the corresponding load content. If the load content does not conform to the business characteristic model, add a second attack level mark to the traffic data.

[0077] In the second case, if the load content analyzed by DPI does not conform to the aforementioned business characteristic model, including the access behavior model and communication message model, it is identified as abnormal data. The credibility is then marked by adding the second attack level flag, indicating that the attack behavior credibility is medium, for example, it can be quantified as level 2.

[0078] (3) If the traffic data is simultaneously marked with the first attack level tag and the second attack level tag, then the first attack level tag and the second attack level tag are converted into the third attack level tag.

[0079] In the third case, if both of the above conditions are met, namely, the DPI feature matching is abnormal and it does not conform to the business feature model, the credibility is identified by adding the third attack level marker, and the credibility of the attack behavior is identified as high, for example, it can be quantified as level 4.

[0080] This application presents a method for improving the accuracy of power system network attack monitoring. It combines DFI (Distributed Fiber Optic Indicator) and DPI (Distributed Pixel Pixel) technologies, employing a credibility-based approach to attack behavior. This defines the authenticity of attack actions and improves the accuracy of attack traffic identification, reducing false alarms.

[0081] Furthermore, such as Figure 4 As shown, after determining whether there are abnormal attack behaviors in the traffic data based on the analysis results and the business characteristic model in step S106, the following step S107 can be further executed:

[0082] For traffic data marked with a third attack level, data is extracted to form an activity heatmap, and the accuracy of abnormal attack behavior is verified a second time based on the activity heatmap.

[0083] For traffic data marked with a third attack level, the activity characteristics of the attacker corresponding to its source IP address are extracted, and an attacker activity heatmap is drawn. For traffic data marked with second and third attack levels, its source IP address is extracted. If its source IP address matches the distribution range of the attacker activity heatmap, a higher attack level mark is added. The attacker activity characteristics include activity time, access targets, and communication packet payload content.

[0084] By using the above method, data is extracted from attackers whose attack behavior was previously identified as highly credible, and an activity heatmap is generated to perform a secondary verification of the accuracy of the attack actions.

[0085] For attacks marked as high-level, extract the attacker's (source IP) activity characteristics, including time, accessed objects, and communication packet payload content, and draw an attacker activity heatmap.

[0086] Then, for the attack behaviors extracted in step S106 that have been marked with the second and third attack levels, the attack source is compared. If it is within the range of the activity heatmap, its attack level mark is increased by one level. If it is not within the range of the activity heatmap, the original attack level mark is maintained.

[0087] In one embodiment, the attack level marker can be set to 5 levels: the fifth attack level marker, indicating that the attack behavior is extremely credible; the fourth attack level marker, indicating that the attack behavior is highly credible; the third attack level marker, indicating that the attack behavior is moderately credible; the second attack level marker, indicating that the attack behavior is moderately credible; and the first attack level marker, indicating that the attack behavior is low credible.

[0088] By using the above methods, credibility values ​​are assigned to attack behaviors targeting key targets, and the accuracy of attack behavior monitoring is improved based on the credibility level of the attack behavior. Attack behaviors with higher credibility, such as those marked with the fourth or fifth attack level, are subject to manual intervention.

[0089] This application, based on an asynchronous non-blocking mechanism, designs a unique technical approach that integrates DPI and DFI. Through parallel computing algorithms, it significantly improves the accuracy of attack behavior detection. Simultaneously, it ensures the sequential flow of event processing, avoiding the "false alarms" that can easily occur in a purely asynchronous mode.

[0090] The schematic diagram of this application is as follows: Figure 5 As shown, traffic analysis combines DFI and DPI analysis. In terms of specific analytical logic, it is achieved through steps such as traffic protocol identification, asset location and association, protocol exchange logic sequencing, business characteristic modeling, identification of abnormal business behavior, and attacker activity heatmap analysis. By employing these technologies in applications using multi-protocol publishing services, the accuracy of identifying attack behavior is significantly improved.

[0091] Example 2

[0092] As another embodiment of this application, a system for improving the accuracy of monitoring network attack behavior in power systems is provided.

[0093] Please see Figure 6 , Figure 6 This is a schematic diagram of a power system network attack behavior monitoring accuracy improvement system according to this application. The power system network attack behavior monitoring accuracy improvement system includes:

[0094] The traffic behavior detection module 601 is used to perform traffic behavior analysis on the collected traffic data using DFI analysis technology to obtain traffic behavior information of the traffic data;

[0095] The identification module 602 is used to identify the communication protocol and communication message length field of the traffic data based on the traffic behavior information;

[0096] Logic module 603 is used to sort the communication protocols of the identified traffic data according to their corresponding communication message length field.

[0097] The association module 604 is used to perform asset location association on the traffic data based on the traffic behavior information of the traffic data, and locate the accessed object service.

[0098] The mapping module 605 is used to map and construct a service feature model based on the object service, the logical combination and sorting of the communication protocol, and the CMDB basic data; wherein, the service feature model includes an access behavior model and a communication message model;

[0099] The judgment module 606 is used to perform DPI analysis on the collected traffic data and, based on the analysis results and the business characteristic model, determine whether there are any abnormal attack behaviors in the traffic data.

[0100] It should be noted that Embodiment 2 described above is an apparatus embodiment of this application and can be used to execute the method in Embodiment 1 of this application. For details not disclosed in the apparatus embodiments of this application, please refer to the method embodiments of this application.

[0101] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0102] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1The computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function selected in one or more boxes.

[0103] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function selected in one or more boxes.

[0104] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0105] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, like read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0106] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0107] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0108] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. A method for improving the accuracy of monitoring network attack behavior in power systems, characterized in that, Includes the following steps: DFI analysis technology is used to analyze the traffic behavior of the collected traffic data and obtain the traffic behavior information of the traffic data. Identifying the communication protocol and communication message length field of the traffic data based on the traffic behavior information includes: analyzing the source address, destination address, source port, destination port, and response information of the traffic data using DFI analysis technology; and determining the communication protocol corresponding to the traffic data and its corresponding communication message length field based on the source address, destination address, source port, destination port, and response information. The communication protocols of the identified traffic data are logically combined and sorted according to their corresponding communication message length fields. Based on the traffic behavior information of the traffic data, the traffic data is used to perform asset location association to locate the accessed object business; Based on the object business, the logical combination and sorting of the communication protocol, and the CMDB basic data, and based on the DPI analysis of the communication traffic data of the key monitoring business of the critical assets, a business characteristic model is constructed; wherein, the business characteristic model includes an access behavior model and a communication message model; Perform DPI analysis on the collected traffic data, and based on the analysis results and the business characteristic model, determine whether there are any abnormal attack behaviors in the traffic data, including: DPI analysis is performed on the collected traffic data to obtain the corresponding data packet feature data. If the data packet feature data matches the preset attack behavior feature data, a first attack level mark is added to the collected traffic data. DPI analysis is performed on the collected traffic data to obtain the corresponding load content. If the load content does not conform to the business characteristic type, a second attack level mark is added to the collected traffic data. If the collected traffic data is simultaneously marked with the first attack level flag and the second attack level flag, then the first attack level flag and the second attack level flag are converted into the third attack level flag.

2. The method for improving the accuracy of power system network attack behavior monitoring according to claim 1, characterized in that, The step of logically combining and sorting the communication protocols of the identified traffic data according to their corresponding communication message length fields includes: The communication protocols of the identified traffic data are logically combined and sorted according to their corresponding communication message length fields. Then, it is determined whether the order of the sorted traffic data and the corresponding communication protocol is consistent, and whether the communication message length of the traffic data is consistent with the communication message length field. If they are inconsistent, they are identified as abnormal communication messages.

3. The method for improving the accuracy of power system network attack behavior monitoring according to claim 1, characterized in that, Based on the traffic behavior information of the traffic data, the steps for performing asset location association on the traffic data and locating the accessed object service include: Based on the CMDB asset database, the destination IP and destination port in the traffic behavior information can be used to locate the specific accessed object service.

4. The method for improving the accuracy of power system network attack behavior monitoring according to claim 1, characterized in that, The steps for mapping and constructing a business feature model based on the object business, the logical combination and sorting of the communication protocol, and the CMDB basic data include: Based on the object business, the logical combination and sorting of the communication protocol, and the historical data of the CMDB basic data, the K-means clustering algorithm is used to classify the access behavior model. DPI analysis is performed on the communication traffic data of key monitoring services for critical assets to parse the load information in key packets during transmission. Based on the load information, the K-means clustering algorithm is used to classify the communication message model.

5. The method for improving the accuracy of power system network attack behavior monitoring according to claim 1, characterized in that, After determining whether there are any abnormal attack behaviors in the traffic data, the following steps are also included: For traffic data marked with a third attack level, data is extracted to form an activity heatmap, and the accuracy of abnormal attack behavior is verified a second time based on the activity heatmap.

6. The method for improving the accuracy of power system network attack behavior monitoring according to claim 5, characterized in that, The steps for secondary verification of the accuracy of abnormal attack behavior based on the activity heatmap include: For traffic data marked with the third attack level, the activity characteristics of the attacker corresponding to its source IP address are extracted, and an attacker activity heatmap is drawn. For traffic data marked with the second and third attack levels, its source IP address is extracted. If its source IP address matches the distribution range of the attacker activity heatmap, then a higher attack level mark is added to it.

7. The method for improving the accuracy of power system network attack behavior monitoring according to claim 6, characterized in that, The attacker's activity characteristics include the time of activity, the objects accessed, and the content of communication message payloads.

8. A system for improving the accuracy of monitoring network attack behavior in power systems, characterized in that, include: The traffic behavior detection module is used to perform traffic behavior analysis on the collected traffic data using DFI analysis technology to obtain traffic behavior information of the traffic data; The identification module is used to identify the communication protocol and communication message length field of the traffic data based on the traffic behavior information, including: analyzing the source address, destination address, source port, destination port and response information of the traffic data through DFI analysis technology; and determining the communication protocol and its corresponding communication message length field of the traffic data based on the source address, destination address, source port, destination port and response information. The logic module is used to sort the communication protocols of the identified traffic data according to their corresponding communication message length fields. The association module is used to perform asset location association on the traffic data based on the traffic behavior information of the traffic data, and locate the accessed object service; The mapping module is used to sort the object services, the communication protocol logic combination, and CMDB basic data, and to perform DPI analysis based on the communication traffic data of key monitoring services for critical assets, and to map and construct a service feature model; wherein, the service feature model includes an access behavior model and a communication message model; The judgment module is used to perform DPI analysis on the collected traffic data, and based on the analysis results and the business characteristic model, determine whether there are abnormal attack behaviors in the traffic data, including: DPI analysis is performed on the collected traffic data to obtain the corresponding data packet feature data. If the data packet feature data matches the preset attack behavior feature data, a first attack level mark is added to the collected traffic data. DPI analysis is performed on the collected traffic data to obtain the corresponding load content. If the load content does not conform to the business characteristic type, a second attack level mark is added to the collected traffic data. If the traffic data is simultaneously marked with the first attack level flag and the second attack level flag, then the first attack level flag and the second attack level flag are converted into the third attack level flag.

Citation Information

Patent Citations

  • Information security monitoring method and system

    CN108063753A

  • System, method and computer-accessible medium for network intrusion detection

    US20170257388A1