Power distribution terminal information-physical bidirectional cross-domain attack analysis method

By locating the attack entry point in the distribution terminal and establishing a cyber-physical multi-zone cross-domain coupling model, and using Bayesian methods to filter attack links, the problem of detecting and warning of cross-domain attacks in the distribution network was solved, achieving accurate characterization and defense of cross-domain attacks, and improving the security and stability of the power grid.

CN116566658BActive Publication Date: 2026-02-24ZHEJIANG UNIV
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202310413385.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-18
Publication Date
2026-02-24
Estimated Expiration
2043-04-18

AI Technical Summary

Technical Problem

Existing technologies are insufficient for comprehensive detection and early warning of cross-domain attacks in distribution networks. In particular, given the surge in cross-domain interactions at edge terminals, the dispersed nature of terminal nodes, and the diversity of investment entities, there is an urgent need for a bidirectional cross-domain attack analysis method for distribution terminals that combines information and physical domains to reveal the attack mechanisms and propagation methods.

Method used

By locating the attack entry point and target of the power distribution terminal, a cross-domain coupling model of information and physical domains is established. Bayesian methods are used to screen out the links with the highest attack probability for defense. Combining the bidirectional sparse topology graph of the physical domain and the information domain, a cross-domain attack analysis method is constructed.

Benefits of technology

It enables accurate characterization and defense against cross-domain attacks on power distribution terminals, improving the stability and security of the power grid. It can locate attack entry points and propagation links, and support the construction and response to attack links.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116566658B_ABST
    Figure CN116566658B_ABST
Patent Text Reader

Abstract

The application discloses a power distribution terminal information-physical bidirectional cross-domain attack analysis method and belongs to the field of network security. Analysis and research are conducted from two aspects of a multi-source bidirectional cross-domain attack entrance and attack target positioning and multi-region cross-domain attack link construction. The multi-source bidirectional cross-domain attack entrance and attack target positioning aims to detect vulnerabilities of terminal device software and hardware function modules, establish a mapping relationship list of the vulnerabilities and device states, and position the bidirectional cross-domain attack entrance and attack target. The multi-region cross-domain attack propagation link construction aims to analyze information between devices and physical connection coupling relationships according to business logic, establish a physical information multi-region cross-domain coupling model in combination with a power distribution network architecture, and calculate the most possible cross-domain attack propagation link so as to carry out targeted defense. Through analysis of two stages of vulnerability exploitation and attack propagation in the attack process, accurate characterization of the cross-domain attack can be formed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network security, specifically relating to a method for analyzing bidirectional cross-domain attacks on power distribution terminals (information and physical domains). Background Technology

[0002] With the continuous development of information technology, big data, artificial intelligence, and automation technology, the intelligence level of traditional industrial control systems and infrastructure has increased. Information technology is being widely applied to distribution network terminal equipment, making the power distribution network system increasingly open, which brings new challenges to the traditional, relatively closed power distribution network system. At the same time, the new power system based on new energy sources is accelerating, with the installed capacity and proportion of new energy power generation, represented by distributed photovoltaic and wind power, continuing to expand and entering a stage of rapid development. Unlike the traditional power grid, the new power system is characterized by a high proportion of new energy power generation, a high degree of power electronics, and a high degree of freedom in power generation and consumption. This leads to enhanced coordination of "generation-transmission-distribution-consumption," more complex system operation and control, and an increase in intelligent terminals such as "operation-distribution-consumption." Among these, the distribution network user side can participate in grid regulation through distributed new energy power generation and adjustable loads, resulting in a significant increase in cross-domain interaction and thus facing new security threats such as cyber-physical cross-domain attacks.

[0003] Numerous security incidents have demonstrated that the operating environments of many distribution terminals are uncontrolled, posing significant security risks. Attackers can exploit "cyber-physical" cross-domain interactions, using distribution terminals as entry points and "stepping stones" to carry out cross-domain attacks such as modifying runtime code, spreading network viruses, and injecting physical signals. Ultimately, these attacks can spread to the control station system and internal networks, seriously threatening distribution network security in zones I and II. Therefore, there is an urgent need to propose a bidirectional cyber-physical cross-domain attack analysis method for distribution terminals to accurately characterize cross-domain attacks.

[0004] Currently, research on cross-domain attack early warning has been conducted both domestically and internationally. For example, the Berkeley National Laboratory in the United States has developed a microphasor measurement device to detect and provide early warning of cross-domain attacks from the information domain to the physical domain in distribution networks in real time. my country has also conducted research on information domain network attack situation awareness and physical domain equipment failure prediction in traditional information-physical systems. However, due to the characteristics of the distribution network, such as the surge in cross-domain interactions at edge terminals, the dispersion of terminal nodes, and the diversity of investment entities, existing work is insufficient to comprehensively detect and provide early warning of cross-domain attacks in distribution networks. There is an urgent need to conduct security detection and early warning of cross-domain attack processes through three steps: "attack mechanism revelation - system anomaly detection - situational prediction and early warning."

[0005] To address the above issues, this paper proposes a bidirectional cross-domain attack method targeting distribution terminals, focusing on information and physical systems. It identifies hidden vulnerabilities in the terminal's sensing, computing, and execution modules during the energy conversion and processing stages, pinpointing potential attack entry points. Based on this, a multi-zone cross-domain coupling model of the distribution network's information and physical systems is established to calculate feasible and effective cross-domain attack propagation paths. Ultimately, the paper reveals the cross-domain attack mechanism targeting distribution terminals, clarifying possible attack entry points and propagation methods. This provides a theoretical foundation for subsequent attack localization, blocking, and response efforts, which is crucial. In conclusion, designing a bidirectional cross-domain attack analysis method for distribution terminals is essential. Summary of the Invention

[0006] This invention proposes a bidirectional cross-domain attack analysis method for power distribution terminals, which accurately characterizes cross-domain attacks, helps to precisely defend against threats, and improves power grid stability.

[0007] The method is as follows:

[0008] A method for analyzing bidirectional cross-domain attacks involving power distribution terminal information and physical systems includes the following steps:

[0009] Step S1: Based on the physical domain and information domain, locate the attack entry point and attack target of the power distribution terminal;

[0010] Step S2: Based on the attack entry point and attack target, find the attack propagation link with the highest probability of attack and defend against the link.

[0011] Furthermore, step S1 specifically includes:

[0012] We obtain existing attack events targeting sensor, actuator, and controller functional modules in power distribution terminals from the physical and information domains, identify power distribution terminal vulnerabilities, and establish a mapping list between power distribution terminal vulnerabilities and power distribution terminal status.

[0013] The system detects the current status of the power distribution terminal, identifies vulnerabilities based on the mapping relationship list, and locates the attack entry point and attack target based on the corresponding vulnerability.

[0014] Furthermore, step S2 specifically includes:

[0015] Based on the connection and coupling relationship between the functional modules in the power distribution terminal in the information domain and the physical domain, an information-physical multi-zone cross-domain coupling model is established, and then all possible attack links are obtained based on the model.

[0016] Using Bayesian methods, the link with the highest probability of attack is selected from all possible attack links, and then that link is defended.

[0017] Furthermore, the method for constructing the aforementioned cyber-physical multi-region cross-domain coupling model is as follows:

[0018] Based on the internal functional modules and their connection relationships, the power distribution terminal model is obtained;

[0019] In the power distribution terminal model, the physical domain functional modules are regarded as physical nodes, and the actual physical connections between the physical domain functional modules are regarded as edges connecting the physical nodes. Considering the directionality of the edges connecting the physical nodes, a bidirectional sparse topology graph G of the physical domain is obtained. p =(V p E p μ p ), where V p E represents the set of physical nodes. p Let μ represent the set of physical edges. p This represents the preset physical edge weights;

[0020] By treating the information domain functional modules in the power distribution terminal model as information nodes and the fiber optic links for information transmission as edges connecting these information nodes, and ignoring the directionality of the edges connecting the information nodes, we obtain a bidirectional sparse topology graph G for the information domain. c =(V c E c μ c ), where V c E represents the set of information nodes. c Let μ represent the set of information edges. c Let μ represent the set of information edge weights, where each information edge weight is μ. c_ij The calculation formula is:

[0021] μ c_ij =(k i k j ) σ

[0022] In the formula: σ is the weighting coefficient, k i k j It is the degree of the i-th and j-th information nodes connected by information edges;

[0023] Based on the connection and coupling relationship between the physical domain functional modules and the information domain functional modules in the power distribution terminal model, inter-domain link coupling edges are added between the bidirectional sparse topology graph of the physical domain and the bidirectional sparse topology graph of the information domain to obtain the information-physical multi-zone cross-domain coupling model.

[0024] Furthermore, the power distribution terminal model is specifically as follows:

[0025] The set of internal functional modules of the power distribution terminal is represented as V(D) = {v1, v2, ..., v...} n}, where v i Representing the i-th functional module, the existence form of the functional module is divided into physical domains D.p and information domain D d The physical domain functional module V(D) p The device is divided into functional hardware modules; the information domain's functional modules V(D) represent the hardware components of the device. d E(D) represents the logical components of a device divided by function; the set of connections between these functional modules is represented as E(D) = {e1, e2, ..., e...}. m}, where e i Represents the i-th connection relationship; based on the set of functional modules and the set of connection relationships, the power distribution terminal model D = (V(D), E(D)) is constructed, where V(D) = (V(D)) / (E(D)). p ), V(D d )).

[0026] Furthermore, the attack link takes the physical node corresponding to the attack entry point as the starting point of the attack link and the physical node corresponding to the attack target as the ending point of the attack link. The starting point and the ending point of the attack link are composed of information nodes. Adjacent nodes in the attack link have connection coupling edges or information edges in the information-physical multi-zone cross-domain coupling model.

[0027] Furthermore, using a Bayesian method, after satisfying the conditions of the cyber-physical multi-domain coupling model and all possible attack links, the probability of all possible attack links is calculated, and the link with the highest attack probability is selected from all possible attack links, specifically:

[0028] 1) For each possible attack link, such as E = (v1, v2, v3, v4, v5), obtain the nodes and edges of the attack link;

[0029] 2) Based on the binary probability distribution of each node, where 1 represents a node being attacked and 0 represents a node not being attacked, obtain the prior probability of each node being attacked, i.e., obtain p(v i =1), i = 1, 2, 3, 4, 5;

[0030] 3) Determine the direction of each edge, and calculate the conditional probability of the edge using the Bayesian method. The conditional probability represents the probability that a child node will be attacked given the state of its parent node, i.e., calculate P(v...). i =1|v i-1 The value of (=1);

[0031] 4) Calculate the probability of the attack chain:

[0032] Based on the calculated conditional probabilities of each edge, the posterior probability of each link is calculated; the link with the highest posterior probability is output as the link with the highest probability of attack.

[0033] The beneficial effects of this invention are:

[0034] This invention proposes a bidirectional cross-domain attack analysis method for power distribution terminals, which can design cross-domain attack methods to target the security vulnerabilities of massive interconnected terminal devices in power distribution networks, realize the control of the working status of terminal devices, locate the cross-domain attack entry point and attack target of the power distribution network system, and support the research on attack link construction. Attached Figure Description

[0035] Figure 1 This is a flowchart of a two-way cross-domain attack analysis method for power distribution terminal information and physical domains according to the present invention;

[0036] Figure 2 This is a diagram showing the relationship between the analysis method and the attack process;

[0037] Figure 3 This is a schematic diagram of a functional vulnerability model;

[0038] Figure 4 This is a schematic diagram of a cyber-physical multi-domain coupling model. Detailed Implementation

[0039] The present invention will be further described below with reference to the accompanying drawings and embodiments.

[0040] This invention proposes a method for analyzing bidirectional cross-domain attacks involving power distribution terminal information and physical domains, such as... Figure 1 and Figure 2 As shown, the details are as follows:

[0041] Step S1: Locating the multi-source bidirectional cross-domain attack entry point and target of the power distribution terminal.

[0042] In response to the massive interconnection of power distribution terminal equipment, this study examines the internal functional modules of the terminal equipment from both physical and information domain perspectives. This reveals hidden vulnerabilities in the energy conversion and processing of modules such as sensors, actuators, and controllers. A mapping list between existing vulnerabilities and the terminal status is established. The current terminal status is then detected, and vulnerabilities are identified based on the mapping list. Finally, the attack entry point and target are located based on the corresponding vulnerabilities.

[0043] In this embodiment, for a wind speed measurement functional module, the following is established: Figure 3The functional vulnerability model is shown. The wind speed measurement module consists of an accelerometer, filter, amplifier, and analog-to-digital converter cascaded together. Wind speed causes the spring in the accelerometer to deform. The potentiometer, acting as a displacement sensing element, senses the acceleration signal. After being converted by the transducer, it becomes an analog electrical signal, which is then processed sequentially by the filter and amplifier. Finally, it is converted into a digital electrical signal by the analog-to-digital converter, which is the output of the sensing module and sent to the processor for subsequent calculations. This part represents the information conversion from the physical domain to the information domain at the terminal device level. Under normal circumstances, this functional module can accurately measure the current acceleration and convert it into a wind speed value. In the figure, the transfer function between input and output is y = f(x1, n + a′), where a′ = [h1(a1), ..., h m (a m )], h i Let i = 1, 2, ..., m be the transduction effect transfer function. The input-to-output transfer function can effectively perform analog-to-digital conversion and other processing on normal acceleration signals. However, the internal mechanical structure of sensors such as accelerometers has inherent resonant frequencies. An acoustic attack could trigger resonance in these internal mechanical structures, generating erroneous sensing signals a′. An attacker could then modulate these signals to produce a controllable sensor output y. Therefore, the aforementioned a′ that could be exploited by an attacker... i Let i = 1, 2, ..., m, which represent the vulnerabilities in the wind speed measurement module. The above is a functional vulnerability model established for the wind speed measurement module to identify its vulnerabilities. Similarly, for other functional modules of the terminal equipment, functional models can be established based on the energy conversion and processing stages to analyze existing vulnerabilities. After obtaining the hidden vulnerabilities of the equipment's sensors, actuators, controllers, and other modules in the energy conversion and processing process, a mapping list between existing vulnerabilities and the device's terminal status can be established. Then, by detecting the current status of the device terminal, vulnerabilities can be identified based on the mapping list, and the attack entry point and target can be located based on the corresponding vulnerabilities.

[0044] Step S2: Construction of the multi-zone cross-domain attack propagation link for power distribution terminals

[0045] S2-1: Analyze the connection and coupling relationships of multiple devices in the information and physical domains, and establish an information-physical multi-zone cross-domain coupling model.

[0046] From the perspective of fulfilling business functions, massively interconnected power distribution terminal devices can all be abstractly described as functional entities composed of interconnected different functional modules. A functional module refers to a basic functional module with actual physical, logical, or cognitive significance; its significance lies in the function it can perform. For a device, the significance of each functional module is its designed function. For example, a sensor's function is sensing, an amplifier's function is signal amplification, a filter's function is signal filtering, and a CPU's function is computation. The connection relationship between functional modules represents the reachability of information between them; this connection relationship is directional, such as an input-output relationship. Functional modules and their topological relationships represent the system design and architecture of a terminal device, and the functional entity formed by the interconnection of these functional modules implements the business functions of that terminal device.

[0047] The set of functional modules is represented as V(D) = {v1, v2, ..., v...} n}, where v i Let E(D) represent the i-th functional module; the set of connections between functional modules is represented as E(D) = {e1, e2, ..., e...}. m}, where e i Let e1 represent the i-th connection relationship, for example, e1 = {v1, v2} represents that information can flow from functional module v1 to v2. Then, the terminal device composed of these functional modules V(D) and their connection relationships E(D) can be represented as D = (V(D), E(D)). Since the implementation of functions involves different categories, such as software and hardware, for the convenience of subsequent threat analysis, the existence of functional modules in the terminal device D is further divided into physical domains D. p and information domain D d That is, V(D) = (V(D)) p ), V(D d The functional module V(D) of the physical domain p The functional modules of a device are categorized by function, such as sensors, signal processing devices and circuits, processors, memory, actuators, etc.; the functional modules of the information domain V(D) d () represents the logical components of a device divided by function, such as system processes, instructions, programs, functions, algorithms, etc.

[0048] Based on the functional coupling model of a single terminal device, we further establish an information-physical multi-zone cross-domain coupling model for multiple terminals, starting from the connection relationship in the information domain and physical domain.

[0049] The information system in the distribution network information domain is abstracted as information nodes (such as programs running on terminals, traffic between various devices, etc.), and the fiber optic links for information transmission are edges. The information domain of the distribution network can be represented as a bidirectional sparse topology graph with m information nodes and n communication links: Gc = (V c E c μ c ), where the information node set V c ={v c1 v c2 , ..., v cn}, Information edge set E c ={e c13 e c12 , ..., e cnm}, information edge weight μ c_ij The degree function for the two information nodes it connects:

[0050] μ c_ij =(k i k j ) σ

[0051] In the formula: σ is the weighting coefficient (0≤σ≤1), k i It is information node v ci The degree.

[0052] like Figure 4 As shown, each device in the physical domain of the distribution network is abstracted as a physical node (such as a smart meter concentrator, load control terminal, etc.), and the actual physical connections between physical nodes are represented by edges. The differences in properties of different physical nodes and the direction of physical signal transmission are distinguished. The physical domain of the distribution network can be represented as a bidirectional sparse topology graph: G p =(V p E p μ p ), where the set of physical nodes V p ={v p1 v p2 , ..., v pm}, physical edge set E p ={e p13 e p12 , ..., e pnm}, physical edge weight μ p The physical signal transmission metric for the two physical nodes it connects to is determined by the specific business requirements.

[0053] For example, if the attack entry point is v in the current state p1 The target of the attack is v p5 By combining the above models, all possible attack chains can be found:

[0054] E1=(v p1 ,v c1 ,v c3 ,v c5 ,v p5 )

[0055] E2=(v p1 ,v c1 ,v c4 ,v c5 ,v p5 )

[0056] E3=(v p1 ,v c1 ,v c2 ,v c3 ,v c5 ,v p5 )

[0057] E4=(v p1 ,v c1 ,v c2 ,v c6 ,v c5 ,v p5 )

[0058] E5=(v p1 ,v c1 ,v c2 ,v c6 ,v c7 ,v c5 ,v p5 )

[0059] E6=(v p1 ,v c1 ,v c2 ,v c6 ,v c7 ,v c8 ,v c5 ,v p5 )

[0060] E7=(v p1 ,v c1 ,v c2 ,v c6 ,v c7 ,v c9 ,v c8 ,v c5 ,v p5 )

[0061] E8=(v p1 ,v c1 ,v c2 ,v c6 ,v c7 ,v c9 ,vc10 v c5 v p5 )

[0062] E9=(v p1 v c1 v c2 v c6 v c7 v c9 v c8 v c10 v c5 v p5 )

[0063] E 10 ~E 15 v in E4 to E9 c1 v c2 Add v between c3

[0064] S2-2: Based on the attack chain obtained in S2-1, use Bayesian methods to find the most likely attack chain in order to implement targeted defense. The steps are as follows:

[0065] (1) Determine the nodes and edges of the attack graph: Based on the information-physical multi-region cross-domain coupling model already established in S2-1, determine the nodes and edges of the attack graph, for E1=(v p1 v c1 v c3 v c5 v p5 ), node v p1 v c1 v c3 v c5 v p5 The edges are the connecting lines between the nodes, namely p1-c1, c1-c3, c3-c5, and c5-p5.

[0066] (2) Define a probability distribution for each node: Use a binary probability distribution to represent the state of a node being attacked as 1 or 0, each with a probability. Taking c1 as an example, c1 has two states: being attacked or not being attacked. That is, p(c1=1) is the probability that c1 is attacked, and p(c1=0) is the probability that c1 is not attacked.

[0067] (3) Determine the direction and conditional probability of the edge: For each edge, its direction and conditional probability need to be determined. The conditional probability represents the probability that the child node will be attacked given the state of the parent node. For E1 = (v p1 v c1 v c3 v c5 v p5The directions of its four edges are p1-c1, c1-c3, c3-c5, and c5-p5. For different systems, the prior probabilities and conditional probabilities of each node are different. These probabilities will be obtained by detecting and statistically analyzing the system. Here, we assume that the prior probabilities of each node obtained through detection and statistics are as follows:

[0068] p(v p1 =1)=0.2:v p1 The probability of being attacked is 20%.

[0069] p(v c1 =1)=0.1:v c1 The probability of being attacked is 10%.

[0070] p(v c3 =1)=0.05:v c3 The probability of being attacked is 5%;

[0071] p(v c5 =1)=0.01:v c5 The probability of being attacked is 1%.

[0072] p(v p5 =1)=0.3:v p5 The probability of being attacked is 30%.

[0073] Meanwhile, the conditional probabilities are as follows:

[0074] P(v c1 =1|v p1 =1)=0.8: in v p1 In the event of an attack, v c1 The probability of being attacked is 80%.

[0075] P(v c3 =1|v c1 =1)=0.5: in v c1 In the event of an attack, v c3 The probability of being attacked is 50%.

[0076] P(v c5 =1|v c3 =1)=0.3: in v c3 In the event of an attack, v c5 The probability of being attacked is 30%.

[0077] P(v p5 =1|v c5 =1)=0.9: in v c5 In the event of an attack, v p5 The probability of being attacked is 90%.

[0078] (4) Calculate the probability of the attack link: By calculating the conditional probability of each attack link, the probability value can be obtained. The conditional probability is calculated using Bayes' theorem, that is, given the observations, the posterior probability of each link is calculated. For E1=(v p1 v c1 v c3 v c5 v p5 ), p(E1)=p(v p1 =1)·p(v c1 =1|v p1 =1)·p(v c3 =1|v c1 =1)·p(v c5 =1|v c3 =1)·p(v p5 =|v c5 =1) =0.0216. Therefore, the attack link E1 = (v p1 v c1 v c3 v c5 v p5 The probability of ) is 0.0216. Note that this is just an example; in reality, the prior probability and conditional probability need to be determined based on the specific scenario and data.

[0079] (5) Select the attack link with the highest probability: Select the attack link with the highest probability as the final result.

[0080] The above examples are merely specific embodiments of the present invention. Obviously, the present invention is not limited to the above embodiments and many variations are possible. All variations that can be directly derived or conceived by those skilled in the art from the disclosure of the present invention should be considered within the scope of protection of the present invention.

Claims

1. A method for analyzing bidirectional cross-domain attacks involving power distribution terminal information and physical domains, characterized in that, Includes the following steps: Step S1: Based on the physical domain and information domain, locate the attack entry point and attack target of the power distribution terminal; Step S1 specifically includes: We obtain existing attack events targeting sensor, actuator, and controller functional modules in power distribution terminals from the physical and information domains, identify power distribution terminal vulnerabilities, and establish a mapping list between power distribution terminal vulnerabilities and power distribution terminal status. Detect the current status of the power distribution terminal, identify vulnerabilities based on the mapping relationship list, and locate the attack entry point and attack target based on the corresponding vulnerabilities; Step S2: Based on the attack entry point and attack target, identify the attack propagation path with the highest probability of attack and defend against that path; Step S2 specifically involves: Based on the connection and coupling relationship between the functional modules in the power distribution terminal in the information domain and the physical domain, an information-physical multi-zone cross-domain coupling model is established, and then all possible attack links are obtained based on the model. Using Bayesian methods, the link with the highest probability of attack is selected from all possible attack links, and that link is then defended. The method for constructing the information-physical multi-region cross-domain coupling model is as follows: Based on the internal functional modules and their connection relationships, the power distribution terminal model is obtained; In the power distribution terminal model, the physical domain functional modules are regarded as physical nodes, and the actual physical connections between the physical domain functional modules are regarded as edges connecting the physical nodes. Considering the directionality of the edges connecting the physical nodes, a bidirectional sparse topology graph of the physical domain is obtained. ,in, Represents the set of physical nodes. Represents the set of physical edges. This represents the preset physical edge weights; By treating the information domain functional modules in the power distribution terminal model as information nodes and the fiber optic links for information transmission as edges connecting these information nodes, and ignoring the directionality of the edges connecting the information nodes, a bidirectional sparse topology graph of the information domain is obtained. ,in, Represents a set of information nodes. Represents the set of information edges. This represents the set of information edge weights, where each information edge weight... The calculation formula is: ; In the formula: These are the weighting coefficients. The first one connected by information edges The degree of each information node; Based on the connection and coupling relationship between the physical domain functional modules and the information domain functional modules in the power distribution terminal model, inter-domain link coupling edges are added between the bidirectional sparse topology graph of the physical domain and the bidirectional sparse topology graph of the information domain to obtain the information-physical multi-zone cross-domain coupling model. The process of using Bayesian methods to filter out the most likely attack path from all possible attack paths specifically involves: 1) For each possible attack chain, obtain the nodes and edges of the attack chain; 2) Based on the binary probability distribution of each node, where 1 indicates that the node has been attacked and 0 indicates that the node has not been attacked, obtain the prior probability of each node being attacked. 3) Determine the direction of each edge and calculate the conditional probability of the edge using the Bayesian method. The conditional probability represents the probability that the child node will be attacked given the state of the parent node. 4) Calculate the probability of the attack chain: Based on the calculated conditional probabilities of each edge, the posterior probability of each link is calculated; the link with the highest posterior probability is output as the link with the highest probability of attack.

2. The method for analyzing bidirectional cross-domain attacks on power distribution terminals based on information and physical domains according to claim 1, characterized in that, The power distribution terminal model is specifically as follows: The set of internal functional modules of the power distribution terminal is represented as ,in Representing the Each functional module is divided into physical domains. and information domain Functional modules of the physical domain The hardware components of a device are divided by function; the functional modules of the information domain. The device is represented by logically structured modules based on function; the set of connections between these functional modules is represented as... ,in Representing the The set of functional modules and the set of connection relationships constitute the power distribution terminal model. ,in .

3. The method for analyzing bidirectional cross-domain attacks on power distribution terminals based on information and physical domains according to claim 1, characterized in that, The attack chain starts at the physical node corresponding to the attack entry point and ends at the physical node corresponding to the attack target. The attack chain starts and ends at information nodes. Adjacent nodes in the attack chain have connection coupling edges or information edges in the information-physical multi-zone cross-domain coupling model.

Citation Information

Patent Citations

  • Dynamic path exploration method for intelligent grid cross-layer attack

    CN109150872A

  • Method for constructing security threat model of terminal equipment based on functional domain

    CN112270136A

  • Attack risk coupling modeling method for power intranet terminal equipment

    CN113472738A