Network attack defense method based on hybrid security index evaluation and related device
Patent Information
- Application Number
- CN202311013654.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-08-11
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2043-08-11
AI Technical Summary
[0054]经由上述的技术方案可知,本申请首先基于FDIA的开销和DDoS攻击的开销,构建SCADA系统中各测量项的混合安全指数模型。接着,以SCADA系统受到攻击的影响最小为目标,求解所述混合安全指数模型,得到最优FDIA和DDoS攻击策略下SCADA系统的最优状态偏移。然后,基于所述最优状态偏移以及所述混合安全指数模型,确定SCADA系统中各测量项的目标混合安全指数。最后,基于每一测量项的目标混合安全指数以及网络攻击防御开销,确定每一测量项的网络攻击防御策略。本申请同时考虑了攻击者发起FDIA和DDoS攻击的开销,所构建的混合安全指数模型具有更好的普适性;此外,本申请实现了攻击者发起攻击难度的最大化,同时保证了网络攻击对SCADA系统性能影响的最小化。
Smart Images

Figure CN116886419B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of SCADA technology, and more specifically, to a network attack defense method and related equipment based on hybrid security index assessment. Background Technology
[0002] SCADA (Supervisory Control and Data Acquisition) systems are core modules in industrial control systems used for monitoring and controlling field equipment. They enable various functions such as equipment data acquisition, measurement, system state estimation, equipment control, parameter adjustment, and various signal alarms, forming the foundation for automated control and adaptive resource scheduling in industrial control systems. In traditional industrial control systems, to ensure system robustness and prevent significant deviations in measurement data due to abnormal measurement noise or network attacks, SCADA systems typically deploy anomaly detection systems. These systems cross-reference measurement data based on linear or nonlinear correlations to determine the presence of anomalies. Considering that network attacks such as FDIA (False Data Injection Attack) can bypass anomaly detection systems, leading to significant deviations in SCADA system measurement data, it is necessary to assess the security of SCADA systems under network attacks and construct defense strategies based on the assessment results. Summary of the Invention
[0003] In view of this, this application provides a network attack defense method and related equipment based on hybrid security index assessment to determine the network attack defense strategy for each measurement item.
[0004] To achieve the above objectives, the first aspect of this application provides a network attack defense method based on hybrid security index assessment, comprising:
[0005] Based on the overhead of FDIA and DDoS attack, a hybrid security index model for various measurement items in the SCADA system is constructed.
[0006] With the goal of minimizing the impact of attacks on the SCADA system, the hybrid security index model is solved to obtain the optimal state offset of the SCADA system;
[0007] Based on the optimal state offset and the hybrid safety index model, the target hybrid safety index for each measurement item in the SCADA system is determined.
[0008] Based on the target hybrid security index and network attack defense overhead for each metric, a network attack defense strategy is determined for each metric.
[0009] Preferably, the process of constructing a hybrid security index model for each measurement item in the SCADA system based on the overhead of FDIA and the overhead of DDoS attacks includes:
[0010] Based on the real-time status of each measurement item in the SCADA system and the measurement noise, the measurement model is determined;
[0011] By embedding FDIA, DDoS attack, FDIA overhead, and DDoS attack overhead into the measurement model, a hybrid security index model for each measurement item in the SCADA system is obtained.
[0012] Preferably, the process of determining the measurement model based on the real-time status of each measurement item in the SCADA system and the measurement noise includes:
[0013] Construct real-time status measurement models for each measurement item in the SCADA system:
[0014] y(k)=m[s(k)]+w(k)
[0015] Where y(k) represents the real-time state measurement model, which consists of the M×1 dimensional measurement vectors of each measurement item at time k, s(k) represents the N×1 dimensional state vector to be estimated, and m[] represents The measurement function, w(k), represents the M×1 dimensional measurement noise vector;
[0016] Based on the aforementioned real-time state measurement model, an asymptotically linear measurement model is constructed:
[0017] y′(k)=M(k)s(k)+w(k)
[0018] Where y′(k) is the measurement model, and M(k) is the Jacobian matrix of the first-order partial derivative of m(s) at s=s(k).
[0019] Preferably, the process of embedding FDIA, DDoS attack, FDIA overhead, and DDoS attack overhead into the measurement model to obtain a hybrid security index model for each measurement item in the SCADA system includes:
[0020] By embedding FDIA and DDoS attacks into the asymptotically linear measurement model, the measurement model after the attack is obtained:
[0021] y A (k)=I D (d)y′(k)+f(k)
[0022] Among them, y A (k) represents the measurement model after the attack, matrix I D(d) = I - diag(d), where matrix I represents the identity matrix, d represents the M×1 dimensional DDoS attack vector, diag(d) represents the diagonal matrix composed of the elements of d, and f(k) represents the M×1 dimensional FDIA vector.
[0023] By embedding the overhead of FDIA and DDoS attack into the post-attack measurement model, a hybrid security index model for each measurement item in the SCADA system is obtained:
[0024]
[0025] stf(k) = I D (d)M(k)u A,j ,d i ∈{0,1},0≤i≤M,f j >0
[0026] in, C represents the mixed safety index model for each measurement item. F C D These represent the costs of launching FDIA and DDoS attacks on a single measurement item, respectively. E represents the impact of FDIA and DDoS attacks on the state parameter estimation results. A,j This indicates the state shift of the SCADA system under FDIA and DDoS attacks.
[0027] Preferably, the process of solving the hybrid security index model to obtain the optimal state offset of the SCADA system, with the objective of minimizing the impact of attacks on the SCADA system, includes:
[0028] The hybrid safety index model for each measurement item in the SCADA system is converted into:
[0029]
[0030] stM (j,:) (k)u A,j ≠0
[0031] in, M is the hybrid safety index model after the j-th measurement item in the SCADA system is transformed. (j,:) This represents the j-th row of matrix M(k);
[0032] Based on the hybrid safety index model after the transformation of various measurement items in the SCADA system, the problem of solving the hybrid safety index model is transformed into a quadratic programming problem:
[0033]
[0034] stM (j,:)(k)u A,j =1
[0035] The quadratic programming problem was solved using the CVX toolkit on the MATLAB platform to obtain the optimal state offset of the SCADA system.
[0036] Preferably, the process of determining the target hybrid safety index for each measurement item in the SCADA system based on the optimal state offset and the hybrid safety index model includes:
[0037] Substituting the optimal state offset into the hybrid safety index model after the transformation of each measurement item in the SCADA system, we obtain the target hybrid safety index for each measurement item in the SCADA system:
[0038]
[0039] in, Let j be the target hybrid safety index for the j-th measurement item in the SCADA system. This represents the optimal state offset.
[0040] Preferably, the process of determining the network attack defense strategy for each measurement item based on the target hybrid security index and network attack defense overhead includes:
[0041] Based on the operating mode of the sensor to which each measurement item belongs, determine the network attack defense overhead of the measurement item;
[0042] Based on the following constraints, determine the network attack defense strategy for each measurement item:
[0043]
[0044] Where, ω HSI P represents the weight of the target hybrid security index. i ρ represents the network attack defense cost of the i-th test item. HSI This indicates the preset decision threshold.
[0045] The second aspect of this application provides a network attack defense device based on hybrid security index evaluation, comprising:
[0046] The hybrid security index model building unit is used to construct a hybrid security index model for each measurement item in the SCADA system based on the overhead of FDIA and the overhead of DDoS attacks.
[0047] The state offset calculation unit is used to solve the hybrid security index model with the goal of minimizing the impact of attacks on the SCADA system, and obtain the optimal state offset of the SCADA system.
[0048] The hybrid safety index determination unit is used to determine the target hybrid safety index of each measurement item in the SCADA system based on the optimal state offset and the hybrid safety index model.
[0049] The measurement item defense strategy determination unit is used to determine the network attack defense strategy for each measurement item based on the target hybrid security index and network attack defense overhead.
[0050] A third aspect of this application provides a network attack defense device based on hybrid security index evaluation, comprising: a memory and a processor;
[0051] The memory is used to store programs;
[0052] The processor is used to execute the program to implement the various steps of the network attack defense method based on hybrid security index evaluation described above.
[0053] The fourth aspect of this application provides a storage medium having a computer program stored thereon, which, when executed by a processor, implements the various steps of the network attack defense method based on hybrid security index assessment as described above.
[0054] As described in the above technical solution, this application first constructs a hybrid security index model for each measurement item in the SCADA system based on the overhead of FDIA and DDoS attacks. Next, with the objective of minimizing the impact of attacks on the SCADA system, the hybrid security index model is solved to obtain the optimal state offset of the SCADA system under optimal FDIA and DDoS attack strategies. Then, based on the optimal state offset and the hybrid security index model, the target hybrid security index for each measurement item in the SCADA system is determined. Finally, based on the target hybrid security index for each measurement item and the network attack defense overhead, the network attack defense strategy for each measurement item is determined. This application considers both the overhead of attackers launching FDIA and DDoS attacks, and the constructed hybrid security index model has better universality. Furthermore, this application maximizes the difficulty for attackers to launch attacks while minimizing the impact of network attacks on SCADA system performance. Attached Figure Description
[0055] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0056] Figure 1This is a schematic diagram of the network attack defense method based on hybrid security index evaluation disclosed in the embodiments of this application;
[0057] Figure 2 This is a schematic diagram of a network attack defense device based on hybrid security index evaluation disclosed in an embodiment of this application;
[0058] Figure 3 This is a schematic diagram of a network attack defense device based on hybrid security index assessment disclosed in an embodiment of this application. Detailed Implementation
[0059] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0060] The following describes a network attack defense method based on hybrid security index evaluation provided in an embodiment of this application. Please refer to... Figure 1 The network attack defense method based on hybrid security index evaluation provided in this application embodiment may include the following steps:
[0061] Step S101: Based on the overhead of FDIA and the overhead of DDoS attacks, construct a hybrid security index model for each measurement item in the SCADA system.
[0062] FDIA (False Data Injection Attack) is a cyberattack that targets the state parameter estimation process of SCADA systems. By tampering with the measurement data obtained by the SCADA system control center, it causes the estimated state parameters of the industrial system to deviate, and can bypass existing abnormal data detection systems.
[0063] A DDoS (Distributed Denial of Service) attack refers to an attack launched simultaneously by multiple attackers in different locations against one or more targets, or an attacker controlling multiple machines in different locations and using these machines to launch attacks against the victim simultaneously. Because the attack originates from different places, this type of attack is called a distributed denial-of-service attack, and there can be multiple attackers involved.
[0064] Among them, launching a DDoS attack has lower overhead and may cause the SCADA system to be unable to properly estimate the system's operating status. Therefore, compared to FDIA, an attacker launching a DDoS attack may cause greater damage.
[0065] Since existing technologies only consider the potential FDIA attack risk in SCADA systems, without considering the more prevalent DDoS attack risk, this invention considers the overhead of attackers launching both FDIA and DDoS attacks in the designed hybrid security index, making the hybrid security index more universal than the security index designed by the best existing technology.
[0066] The Security Index (SCI) is a performance metric used to assess the vulnerability of measurement data in a SCADA system. It guides SCADA system designers in evaluating the reliability of data from various measurements. Measurement data with lower SCI indices are more susceptible to cyberattacks. Specifically, its physical meaning is the minimum overhead required to launch a stealthy FDI attack given an attack on a particular measurement; that is, the minimum number of measurements that need to be compromised to achieve an FDIA attack.
[0067] Step S102: With the goal of minimizing the impact of attacks on the SCADA system, solve the hybrid security index model to obtain the optimal state offset of the SCADA system.
[0068] State offset represents the deviation of the SCADA system's state parameter estimation results under FDIA and DDoS attacks. It should be noted that the optimal state offset of a SCADA system is essentially the optimal state offset of the SCADA system under optimal FDIA and DDoS attack strategies. Therefore, the optimal state offset of a SCADA system means minimizing the impact of attacks on the SCADA system.
[0069] Step S103: Based on the optimal state offset and the hybrid safety index model, determine the target hybrid safety index for each measurement item in the SCADA system.
[0070] Step S104: Based on the target hybrid security index and network attack defense overhead of each measurement item, determine the network attack defense strategy for each measurement item.
[0071] Existing technologies only consider network attack overhead in their measurement data security indices, neglecting the impact of attacks on SCADA system performance. This application, however, designs a hybrid security index that considers both attack overhead and the resulting SCADA system state estimation bias, and based on this hybrid security index, designs an optimal defense strategy for the SCADA system. Compared to existing technologies, this application maximizes the difficulty for attackers to launch attacks while minimizing the impact of network attacks on SCADA system performance.
[0072] This application first constructs a hybrid security index model for each measurement item in the SCADA system based on the overhead of FDIA and DDoS attacks. Then, aiming to minimize the impact of attacks on the SCADA system, the hybrid security index model is solved to obtain the optimal state offset of the SCADA system under optimal FDIA and DDoS attack strategies. Next, based on the optimal state offset and the hybrid security index model, the target hybrid security index for each measurement item in the SCADA system is determined. Finally, based on the target hybrid security index for each measurement item and the network attack defense overhead, the network attack defense strategy for each measurement item is determined. This application considers both the overhead of attackers launching FDIA and DDoS attacks, and the constructed hybrid security index model has better universality; furthermore, this application maximizes the difficulty for attackers to launch attacks while minimizing the impact of network attacks on SCADA system performance.
[0073] In some embodiments of this application, step S101, which involves constructing a hybrid security index model for each measurement item in the SCADA system based on the overhead of FDIA and the overhead of DDoS attacks, may include:
[0074] S1. Based on the real-time status of each measurement item in the SCADA system and the measurement noise, determine the measurement model.
[0075] S2 embeds FDIA, DDoS attack, FDIA overhead, and DDoS attack overhead into the measurement model to obtain a hybrid security index model for each measurement item in the SCADA system.
[0076] In some embodiments of this application, the process of determining the measurement model based on the real-time status of each measurement item in the SCADA system and the measurement noise in S1 may include:
[0077] S11, Construct the real-time state measurement model y(k) for each measurement item in the SCADA system:
[0078] y(k)=m[s(k)]+w(k) (1)
[0079] Wherein, the real-time state measurement model y(k) consists of the M×1-dimensional measurement vectors of each measurement item at time k, s(k) represents the N×1-dimensional state vector to be estimated, and m[] represents The measurement function is w(k), which represents the M×1 dimensional measurement noise vector.
[0080] S12, Based on the real-time state measurement model, construct an asymptotically linear measurement model y′(k):
[0081] y′ (k) =M(k)s(k)+w(k) (2)
[0082] Where M(k) is the Jacobian matrix of the first-order partial derivatives of m(s) at s = s(k), that is:
[0083]
[0084] In some embodiments of this application, the process of embedding FDIA, DDoS attack, FDIA overhead, and DDoS attack overhead into the measurement model in S2 above to obtain a hybrid security index model of each measurement item in the SCADA system may include:
[0085] S21, embedding FDIA and DDoS attacks into the asymptotically linear measurement model y′(k), to obtain the measurement model y after the attack. A (k):
[0086] y A (k)=I D (d)y′ (k) +f(k) (4)
[0087] Wherein, matrix I D (d) = I - diag(d), where I represents the identity matrix, d represents the M×1 dimensional DDoS attack vector, diag(d) represents the diagonal matrix composed of the elements of d, and f(k) represents the M×1 dimensional FDIA vector.
[0088] S22, embeds the overhead of FDIA and DDoS attack into the post-attack measurement model y. A (k) yields the hybrid safety index model for each measurement item in the SCADA system.
[0089]
[0090] stf(k) = I D (d)M(k)u A,j ,d i ∈{0,1},0≤i≤M,f j >0 (5)
[0091] Where min represents finding the minimum value, C F C D Let C represent the overhead of launching an FDIA and DDoS attack on a single measurement item, respectively, satisfying: F >0 and C D >0; E represents the impact of FDIA and DDoS attacks on the state parameter estimation results, satisfying: E>0; A,j This indicates the state shift of the SCADA system under FDIA and DDoS attacks.
[0092] In some embodiments of this application, step S102, which aims to minimize the impact of attacks on the SCADA system and solve the hybrid security index model to obtain the optimal state offset of the SCADA system, may include:
[0093] S1, a hybrid safety index model for various measurement items in the SCADA system. Convert to
[0094]
[0095] stM (j,:) (k)u A,j ≠0 (6)
[0096] The assumption in the above equation is C. F >C D , M is the hybrid safety index model after the j-th measurement item in the SCADA system is transformed. (j,:) Let j represent the j-th row of matrix M(k).
[0097] S2, a hybrid safety index model based on the transformation of various measurement items in the SCADA system. The problem of solving the hybrid safety index model is transformed into a quadratic programming problem:
[0098]
[0099] stM (j,:) (k)u A,j =1 (7)
[0100] S3. Using the CVX toolkit on the MATLAB platform, the quadratic programming problem is solved to obtain the optimal state offset of the SCADA system.
[0101] Since minimizing the zero norm in equation (6) is an NP-hard (nondeterministic polynomial) problem that cannot be solved directly, the problem can be relaxed to minimizing the 2-norm. Specifically, based on the fundamental properties of quadratic matrix forms, equation (6) is transformed into equation (7). Here, arg min represents the value of the variable when the objective function reaches its minimum.
[0102] In some embodiments of this application, step S103, which determines the target hybrid safety index for each measurement item in the SCADA system based on the optimal state offset and the hybrid safety index model, may include:
[0103] Substituting the optimal state offset into the hybrid safety index model after the transformation of each measurement item in the SCADA system, we obtain the target hybrid safety index for each measurement item in the SCADA system:
[0104]
[0105] in, Let j be the target hybrid safety index for the j-th measurement item in the SCADA system. This represents the optimal state offset.
[0106] In some embodiments of this application, step S104, which determines the network attack defense strategy for each measurement item based on the target hybrid security index and network attack defense overhead, may include:
[0107] S1, based on the operating mode of the sensor to which each measurement item belongs, determines the network attack defense overhead for that measurement item.
[0108] For example, deploy a next-generation firewall for boundary isolation and intrusion prevention for a specific metric, or deploy encryption devices for transmission link encryption. After determining the network attack defense method, assess the total cost of purchasing and deploying network attack defense (including security protection equipment and security protection engineering implementation).
[0109] S2, Based on the following constraints, determine the network attack defense strategy for each measurement item:
[0110]
[0111] Where, ω HSI P represents the weight of the target hybrid security index. i ρ represents the network attack defense cost of the i-th test item. HSI This indicates the preset decision threshold.
[0112] Specifically, SCADA system designers can comprehensively consider factors such as system security, construction investment scale, and construction period to determine the optimal performance of ω. HSI and ρ HSI These two parameters are evaluated and optimized to achieve a trade-off among various indicators, thereby formulating the optimal network attack defense strategy, i.e., selecting the optimal weight parameter ω. HSI and ρ HSI The transmission process of each measurement item in equation (9) is protected.
[0113] To verify the network attack defense method provided in this application, relevant experiments were conducted in a smart grid simulation environment. Specifically, the network adopted an IEEE 14 bus SCADA system, and the SCADA system status parameters were generated by the smart grid parameter generation software package MATPOWER 6.2 on the MATLAB platform.
[0114] First, the traditional and hybrid security indices of the data for each measurement item (measurement items z1 to z24) were analyzed experimentally. The results show that for the IEEE 14 bus SCADA system, the general security index of measurement item z10 is significantly lower than that of other nodes. Therefore, from the perspective of attack overhead, the attacker's cost for attacking measurement item z10 is the lowest, and measurement item z10 can be considered the most vulnerable node. On the other hand, from the perspective of attack benefit, although FDIA and DDoS attacks incur attack overhead, they can lead to deviations in the SCADA system state estimation results. Therefore, both attack overhead and estimation deviation can be considered simultaneously, i.e., the hybrid security index of the measurement items. It can be seen that the hybrid security indices of each node vary considerably. Since attack benefit and hybrid security index are negatively correlated, measurement item z14 has the highest attack benefit, while measurement item z22 has the lowest attack benefit. Comparing measurement items z3 and z22, it can be seen that although the cost of attacking these two measurement items is basically the same, the attack benefit differs greatly. It can be seen that the state estimation error caused by attacking measurement item z3 is much greater than the state estimation error caused by attacking measurement item z22.
[0115] Secondly, the changes in the mixed security index of all nodes were analyzed when a single measurement item was protected. Experimental results show a strong correlation between the mixed security indices of some measurement item combinations. For example, for measurement item combinations z1, z2, z3, and z4, and measurement item combinations z21, z22, and z23, protecting any one of these measurement data significantly improves the mixed security index of the other three. This demonstrates that protecting single or some key measurement data can enhance the overall mixed security index of the SCADA system.
[0116] The network attack defense device based on hybrid security index evaluation provided in the embodiments of this application is described below. The network attack defense device based on hybrid security index evaluation described below can be referred to in correspondence with the network attack defense method based on hybrid security index evaluation described above.
[0117] Please see Figure 2 The network attack defense device based on hybrid security index evaluation provided in this application embodiment may include:
[0118] Hybrid security index model construction unit 21 is used to construct a hybrid security index model for each measurement item in the SCADA system based on the overhead of FDIA and the overhead of DDoS attacks.
[0119] The state offset calculation unit 22 is used to solve the hybrid security index model with the goal of minimizing the impact of attacks on the SCADA system, and obtain the optimal state offset of the SCADA system.
[0120] The hybrid safety index determination unit 23 is used to determine the target hybrid safety index of each measurement item in the SCADA system based on the optimal state offset and the hybrid safety index model.
[0121] The measurement item defense strategy determination unit 24 is used to determine the network attack defense strategy for each measurement item based on the target hybrid security index and network attack defense overhead of each measurement item.
[0122] In some embodiments of this application, the process by which the hybrid security index model construction unit 21 constructs a hybrid security index model for each measurement item in the SCADA system based on the overhead of FDIA and the overhead of DDoS attacks may include:
[0123] Based on the real-time status of each measurement item in the SCADA system and the measurement noise, the measurement model is determined;
[0124] By embedding FDIA, DDoS attack, FDIA overhead, and DDoS attack overhead into the measurement model, a hybrid security index model for each measurement item in the SCADA system is obtained.
[0125] In some embodiments of this application, the process by which the hybrid safety index model construction unit 21 determines the measurement model based on the real-time status of each measurement item in the SCADA system and the measurement noise may include:
[0126] Construct real-time status measurement models for each measurement item in the SCADA system:
[0127] y(k)=m[s(k)]+w(k)
[0128] Where y(k) represents the real-time state measurement model, which consists of the M×1 dimensional measurement vectors of each measurement item at time k, s(k) represents the N×1 dimensional state vector to be estimated, and m[] represents The measurement function, w(k), represents the M×1 dimensional measurement noise vector;
[0129] Based on the aforementioned real-time state measurement model, an asymptotically linear measurement model is constructed:
[0130] y′(k)=M(k)s(k)+w(k)
[0131] Where y′(k) is the measurement model, and M(k) is the Jacobian matrix of the first-order partial derivative of m(s) at s=s(k).
[0132] In some embodiments of this application, the process by which the hybrid security index model construction unit 21 embeds FDIA, DDoS attacks, the overhead of FDIA, and the overhead of DDoS attacks into the measurement model to obtain a hybrid security index model for each measurement item in the SCADA system may include:
[0133] By embedding FDIA and DDoS attacks into the asymptotically linear measurement model, the measurement model after the attack is obtained:
[0134] y A (k)=I D (d)y′(k)+f(k)
[0135] Among them, y A (k) represents the measurement model after the attack, matrix I D (d) = I - diag(d), where matrix I represents the identity matrix, d represents the M×1 dimensional DDoS attack vector, diag(d) represents the diagonal matrix composed of the elements of d, and f(k) represents the M×1 dimensional FDIA vector.
[0136] By embedding the overhead of FDIA and DDoS attack into the post-attack measurement model, a hybrid security index model for each measurement item in the SCADA system is obtained:
[0137]
[0138] stf(k) = I D (d)M(k)u A,j ,d i ∈{0,1},0≤i≤M,f j >0
[0139] in, C represents the mixed safety index model for each measurement item. F C D These represent the costs of launching FDIA and DDoS attacks on a single measurement item, respectively. E represents the impact of FDIA and DDoS attacks on the state parameter estimation results. A,j This indicates the state shift of the SCADA system under FDIA and DDoS attacks.
[0140] In some embodiments of this application, the process by which the state offset calculation unit 22 solves the hybrid security index model to obtain the optimal state offset of the SCADA system, with the goal of minimizing the impact of attacks on the SCADA system, may include:
[0141] The hybrid safety index model for each measurement item in the SCADA system is converted into:
[0142]
[0143] stM (j,:) (k)u A,j ≠0
[0144] in, M is the hybrid safety index model after the j-th measurement item in the SCADA system is transformed. (j,:) This represents the j-th row of matrix M(k);
[0145] Based on the hybrid safety index model after the transformation of various measurement items in the SCADA system, the problem of solving the hybrid safety index model is transformed into a quadratic programming problem:
[0146]
[0147] stM (j,:) (k)u A,j =1
[0148] The quadratic programming problem was solved using the CVX toolkit on the MATLAB platform to obtain the optimal state offset of the SCADA system.
[0149] In some embodiments of this application, the process by which the hybrid safety index determination unit 23 determines the target hybrid safety index of each measurement item in the SCADA system based on the optimal state offset and the hybrid safety index model may include:
[0150] Substituting the optimal state offset into the hybrid safety index model after the transformation of each measurement item in the SCADA system, we obtain the target hybrid safety index for each measurement item in the SCADA system:
[0151]
[0152] in, Let j be the target hybrid safety index for the j-th measurement item in the SCADA system. This represents the optimal state offset.
[0153] In some embodiments of this application, the process by which the measurement item defense strategy determination unit 24 determines the network attack defense strategy for each measurement item based on the target hybrid security index and network attack defense overhead may include:
[0154] Based on the operating mode of the sensor to which each measurement item belongs, determine the network attack defense overhead of the measurement item;
[0155] Based on the following constraints, determine the network attack defense strategy for each measurement item:
[0156]
[0157] Where, ω HSI P represents the weight of the target hybrid security index. i ρ represents the network attack defense cost of the i-th test item. HSI This indicates the preset decision threshold.
[0158] The network attack defense device based on hybrid security index evaluation provided in this application embodiment can be applied to network attack defense devices based on hybrid security index evaluation, such as computers. Optionally, Figure 3 The hardware structure block diagram of the network attack defense device based on hybrid security index evaluation is shown. Figure 3 The hardware structure of a network attack defense device based on a hybrid security index assessment may include: at least one processor 31, at least one communication interface 32, at least one memory 33, and at least one communication bus 34.
[0159] In this embodiment, the number of processor 31, communication interface 32, memory 33 and communication bus 34 is at least one, and processor 31, communication interface 32 and memory 33 communicate with each other through communication bus 34;
[0160] The processor 31 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of this application.
[0161] The memory 33 may include high-speed RAM, and may also include non-volatile memory, such as at least one disk storage device;
[0162] The memory 33 stores a program, and the processor 31 can call the program stored in the memory 33. The program is used for:
[0163] Based on the overhead of FDIA and DDoS attack, a hybrid security index model for various measurement items in the SCADA system is constructed.
[0164] With the goal of minimizing the impact of attacks on the SCADA system, the hybrid security index model is solved to obtain the optimal state offset of the SCADA system;
[0165] Based on the optimal state offset and the hybrid safety index model, the target hybrid safety index for each measurement item in the SCADA system is determined.
[0166] Based on the target hybrid security index and network attack defense overhead for each metric, a network attack defense strategy is determined for each metric.
[0167] Optionally, the refined and extended functions of the program can be found in the description above.
[0168] This application embodiment also provides a storage medium that can store a program suitable for execution by a processor, the program being used for:
[0169] Based on the overhead of FDIA and DDoS attack, a hybrid security index model for various measurement items in the SCADA system is constructed.
[0170] With the goal of minimizing the impact of attacks on the SCADA system, the hybrid security index model is solved to obtain the optimal state offset of the SCADA system;
[0171] Based on the optimal state offset and the hybrid safety index model, the target hybrid safety index for each measurement item in the SCADA system is determined.
[0172] Based on the target hybrid security index and network attack defense overhead for each metric, a network attack defense strategy is determined for each metric.
[0173] Optionally, the refined and extended functions of the program can be found in the description above.
[0174] In summary:
[0175] This application first constructs a hybrid security index model for each measurement item in a SCADA system based on the overhead of FDIA and DDoS attacks. Then, aiming to minimize the impact of attacks on the SCADA system, the hybrid security index model is solved to obtain the optimal state offset of the SCADA system under optimal FDIA and DDoS attack strategies. Next, based on the optimal state offset and the hybrid security index model, the target hybrid security index for each measurement item in the SCADA system is determined. Finally, based on the target hybrid security index for each measurement item and the network attack defense overhead, the network attack defense strategy for each measurement item is determined. This application considers both the overhead of attackers launching FDIA and DDoS attacks, and the constructed hybrid security index model has better universality. Furthermore, this application maximizes the difficulty for attackers to launch attacks while minimizing the impact of network attacks on SCADA system performance. In summary, this application comprehensively evaluates the overhead of attackers launching FDIA and DDoS attacks, the overhead of building a security protection system, and the deviation of system state estimation results after a network attack. It calculates the weighted average of the hybrid security index and security protection overhead for each measurement data, and provides security protection for sensors corresponding to measurement data with excessively high weighted average results. By dynamically adjusting the weighting coefficients of the hybrid security index and protection overhead, a trade-off between defense overhead and system performance is achieved. By taking into account the actual network operation and construction, the defense system parameters are adjusted to construct the optimal defense strategy.
[0176] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0177] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The various embodiments can be combined as needed, and the same or similar parts can be referred to each other.
[0178] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A network attack defense method based on hybrid security index assessment, characterized in that, include: Based on the overhead of FDIA and DDoS attack, a hybrid security index model for various measurement items in the SCADA system is constructed. With the goal of minimizing the impact of attacks on the SCADA system, the hybrid security index model is solved to obtain the optimal state offset of the SCADA system; Based on the optimal state offset and the hybrid safety index model, the target hybrid safety index for each measurement item in the SCADA system is determined. Based on the target hybrid security index and network attack defense overhead of each measurement item, determine the network attack defense strategy for each measurement item. The process of constructing a hybrid security index model for various measurement items in a SCADA system based on the overhead of FDIA and DDoS attacks includes: Based on the real-time status of each measurement item in the SCADA system and the measurement noise, the measurement model is determined; By embedding FDIA, DDoS attack, FDIA overhead, and DDoS attack overhead into the measurement model, a hybrid security index model for each measurement item in the SCADA system is obtained. The process of determining the measurement model based on the real-time status of each measurement item and the measurement noise in the SCADA system includes: Construct real-time status measurement models for each measurement item in the SCADA system: in, The real-time state measurement model represents the measurement items in the first... Moment The measurement vector composition of the dimension, Indicates to be estimated 3D state vector express The measurement function, express 3D measurement noise vector; Based on the aforementioned real-time state measurement model, an asymptotically linear measurement model is constructed: in, For the measurement model, for exist The first-order partial derivative Jacobian matrix at; The process of embedding FDIA, DDoS attack, FDIA overhead, and DDoS attack overhead into the measurement model to obtain a hybrid security index model for each measurement item in the SCADA system includes: By embedding FDIA and DDoS attacks into the asymptotically linear measurement model, the measurement model after the attack is obtained: in, The matrix represents the measurement model after an attack. ,matrix Represents the identity matrix. express Dimensional DDoS attack vector, Indicates by A diagonal matrix composed of the elements of the matrix. express 1D FDIA vector; By embedding the overhead of FDIA and DDoS attack into the post-attack measurement model, a hybrid security index model for each measurement item in the SCADA system is obtained: in, This represents a mixed safety index model for various measurement items. , These represent the overhead of launching an FDIA or DDoS attack on a single measurement item, respectively. This indicates the impact of FDIA and DDoS attacks on the state parameter estimation results. This indicates the state shift of the SCADA system under FDIA and DDoS attacks.
2. The method according to claim 1, characterized in that, The process of solving the hybrid security index model to obtain the optimal state offset of the SCADA system, with the goal of minimizing the impact of attacks on the SCADA system, includes: The hybrid safety index model for each measurement item in the SCADA system is converted into: in, This is the hybrid safety index model after the j-th measurement item in the SCADA system has been transformed. Representation matrix The j-th row; Based on the hybrid safety index model after the transformation of various measurement items in the SCADA system, the problem of solving the hybrid safety index model is transformed into a quadratic programming problem: The quadratic programming problem was solved using the CVX toolkit on the MATLAB platform to obtain the optimal state offset of the SCADA system.
3. The method according to claim 2, characterized in that, The process of determining the target hybrid safety index for each measurement item in the SCADA system based on the optimal state offset and the hybrid safety index model includes: Substituting the optimal state offset into the hybrid safety index model after the transformation of each measurement item in the SCADA system, we obtain the target hybrid safety index for each measurement item in the SCADA system: in, Let j be the target hybrid safety index for the j-th measurement item in the SCADA system. This represents the optimal state offset.
4. The method according to claim 3, characterized in that, The process of determining the network attack defense strategy for each metric based on the target hybrid security index and network attack defense overhead includes: Based on the operating mode of the sensor to which each measurement item belongs, determine the network attack defense overhead of the measurement item; Based on the following constraints, determine the network attack defense strategy for each measurement item: in, This indicates the weight of the target hybrid security index. This represents the network attack defense cost for the i-th test item. This indicates the preset decision threshold.
5. A network attack defense device based on hybrid security index assessment, characterized in that, include: The hybrid security index model building unit is used to construct a hybrid security index model for each measurement item in the SCADA system based on the overhead of FDIA and the overhead of DDoS attacks. The state offset calculation unit is used to solve the hybrid security index model with the goal of minimizing the impact of attacks on the SCADA system, and obtain the optimal state offset of the SCADA system. The hybrid safety index determination unit is used to determine the target hybrid safety index of each measurement item in the SCADA system based on the optimal state offset and the hybrid safety index model. The measurement item defense strategy determination unit is used to determine the network attack defense strategy for each measurement item based on the target hybrid security index and network attack defense overhead of each measurement item. The hybrid security index model construction unit constructs a hybrid security index model for each measurement item in the SCADA system based on the overhead of FDIA and the overhead of DDoS attacks. This process includes: Based on the real-time status of each measurement item in the SCADA system and the measurement noise, the measurement model is determined; By embedding FDIA, DDoS attack, FDIA overhead, and DDoS attack overhead into the measurement model, a hybrid security index model for each measurement item in the SCADA system is obtained. The hybrid safety index model construction unit determines the measurement model based on the real-time status of each measurement item in the SCADA system and the measurement noise, including: Construct real-time status measurement models for each measurement item in the SCADA system: in, The real-time state measurement model represents the measurement items in the first... Moment The measurement vector composition of the dimension, Indicates to be estimated 3D state vector express The measurement function, express 3D measurement noise vector; Based on the aforementioned real-time state measurement model, an asymptotically linear measurement model is constructed: in, For the measurement model, for exist The first-order partial derivative Jacobian matrix at; The process by which the hybrid security index model construction unit embeds FDIA, DDoS attacks, the overhead of FDIA, and the overhead of DDoS attacks into the measurement model to obtain the hybrid security index model for each measurement item in the SCADA system includes: By embedding FDIA and DDoS attacks into the asymptotically linear measurement model, the measurement model after the attack is obtained: in, The matrix represents the measurement model after an attack. ,matrix Represents the identity matrix. express Dimensional DDoS attack vector, Indicates by A diagonal matrix composed of the elements of the matrix. express 1D FDIA vector; By embedding the overhead of FDIA and DDoS attack into the post-attack measurement model, a hybrid security index model for each measurement item in the SCADA system is obtained: in, This represents a mixed safety index model for various measurement items. , These represent the overhead of launching an FDIA or DDoS attack on a single measurement item, respectively. This indicates the impact of FDIA and DDoS attacks on the state parameter estimation results. This indicates the state shift of the SCADA system under FDIA and DDoS attacks.
6. A network attack defense device based on hybrid security index assessment, characterized in that, include: Memory and processor; The memory is used to store programs; The processor is used to execute the program to implement each step of the network attack defense method based on hybrid security index assessment as described in any one of claims 1 to 4.
7. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements each step of the network attack defense method based on hybrid security index assessment as described in any one of claims 1 to 4.
Citation Information
Patent Citations
Network security dynamic defense decision-making method based on space-time game
CN112003854A
Method for realizing data security protection mechanism of networking data synchronization system
CN112948493A