A Vulnerability Assessment Method for Substation Communication Networks Based on Complex Network Theory
By constructing a substation communication network model and combining complex network theory and the CVSS scoring system, the link weight and the vulnerability values of nodes and links are quantified, solving the quantitative problem of vulnerability analysis in substation communication networks, realizing quantitative assessment and reducing subjectivity.
Patent Information
- Application Number
- CN202311087167.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-08-28
- Publication Date
- 2026-01-06
- Estimated Expiration
- 2043-08-28
AI Technical Summary
Existing technologies fail to effectively consider the differences in network security protection measures for different links in the vulnerability analysis of substation communication networks, making it difficult to quantify the difficulty of network attacks, and expert assessments are subjective.
A substation communication network model is constructed, link weights are generated based on complex network theory, and vulnerability exploitability indicators are quantified by combining the CVSS scoring system. The vulnerability values of nodes and links are calculated, and vulnerability structure assessment is carried out by integrating local and global information.
It quantifies the difficulty of network attacks on substations, provides a quantitative method for assessing vulnerable nodes and links, solves the problem of network attacks being fast and difficult to quantify, and reduces the subjectivity of expert assessments.
Smart Images

Figure CN117155799B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of communication network vulnerability structure mining, and particularly relates to a substation communication network vulnerability structure evaluation method based on complex network theory. BACKGROUND
[0002] Vulnerable entity evaluation in complex network is a basic problem in network analysis. Since different algorithms have different focuses in evaluation selection, local and global factors are considered as the division, and the influence of different attack strategies on vulnerability is also different. Therefore, it is very important to determine the vulnerable entity in the network.
[0003] Complex network theory is often used for power communication network evaluation. (1) Fan Bing, Tang Liangrui. Vulnerability analysis of power communication network, a characteristic index evaluation method is proposed to construct a power communication network model, and the loss of business importance caused by link is used to measure network vulnerability. (2) Yin Jun, Li Jianju, Huang Hongguang. Vulnerability analysis of power communication network based on link utilization rate, a research method of vulnerability of power communication network based on link utilization rate is proposed.
[0004] As for the vulnerability analysis of substation communication network, (3) Zhang Hao. Vulnerability evaluation of substation automation system in network environment, a vulnerability evaluation method of substation automation system in network environment is proposed, the vulnerability state diagram representing the attack process is constructed by formal definition of the system, and the vulnerability degree function of state transition is defined by taking the vulnerability degree factor and equivalent attack cost as parameters according to the characteristics of exponential distribution.
[0005] In the prior art, vulnerability analysis of the evaluated network is carried out from two aspects of complex network theory and formal definition of the attack process of the system, but when analyzing the network vulnerability structure, the different network security protection measures adopted by different links in the substation communication network are not considered, which leads to the difference between the difficulty of attack and the difficulty of attack not being found, and the network attack updates fast and is difficult to quantify, and expert evaluation has subjectivity. SUMMARY
[0006] The application proposes a substation communication network vulnerability structure evaluation method based on complex network theory to solve the technical problems existing in the prior art.
[0007] To achieve the above purpose, the application provides a substation communication network vulnerability structure evaluation method based on complex network theory, which comprises:
[0008] A substation communication network model is constructed, and a link weight is generated based on the attack path of the substation communication network model;
[0009] The complex network theory is combined with the link weight, and a plurality of node vulnerability degree values are calculated;
[0010] Based on the node vulnerability value, the local information and the global information of the link are integrated to calculate a plurality of link vulnerability values;
[0011] Based on the node vulnerability value and the link vulnerability value, a vulnerability structure of the substation communication network is evaluated.
[0012] Preferably, the process of generating the link weight comprises:
[0013] Based on the attack path, a plurality of links of the substation communication network model are quantified by a CVSS scoring system, and a link weight is calculated based on a vulnerability exploitable index in the CVSS scoring system.
[0014] Preferably, the vulnerability exploitable index comprises: attack path, attack complexity, required privilege and user interaction.
[0015] Preferably, the process of calculating a plurality of node vulnerability values comprises:
[0016] Based on the complex network theory, a node network relationship is obtained, wherein the node network relationship comprises: node degree and node betweenness;
[0017] Based on the node degree and the link weight, a node constraint coefficient is calculated;
[0018] Based on the node betweenness and the node constraint coefficient, a structural hole influence matrix is generated, and a plurality of node vulnerability values are calculated based on the structural hole influence matrix.
[0019] Preferably, the process of calculating the node constraint coefficient comprises:
[0020] Based on the node degree and the link weight, a link strength is calculated;
[0021] The link strength is accumulated to obtain a node strength;
[0022] Based on the link strength and the node strength, a relative importance function is obtained, and a node constraint coefficient is calculated based on the relative importance function.
[0023] Preferably, the process of generating the structural hole influence matrix comprises:
[0024] Based on the node betweenness, a node influence coefficient matrix is established;
[0025] Based on the node constraint coefficient and the node influence coefficient matrix, a structural hole influence matrix is generated.
[0026] Preferably, the process of calculating a plurality of link vulnerability values comprises:
[0027] Based on the node vulnerability value, the local information of the link is integrated to obtain a link local vulnerability value;
[0028] The global information of the link is integrated to obtain a link edge betweenness;
[0029] Based on the link local vulnerability and the link edge betweenness, a plurality of link vulnerability values are calculated.
[0030] Preferably, the process of calculating the link local vulnerability value comprises:
[0031] The node vulnerability value is normalized to obtain a node relative vulnerability value, the local information of the nodes at both ends of the link is obtained, and based on the node relative vulnerability value and the local information, the link local vulnerability value is calculated.
[0032] Preferably, the process of evaluating the vulnerable structure of the substation communication network based on the node vulnerability value comprises:
[0033] The node vulnerability values are arranged in descending order, and the greater the node vulnerability value is, the more vulnerable the node corresponding to the node vulnerability value is in the substation communication network.
[0034] Preferably, the process of evaluating the vulnerable structure of the substation communication network based on the link vulnerability value comprises:
[0035] The link vulnerability values are arranged in descending order, and the greater the link vulnerability value is, the more vulnerable the link corresponding to the link vulnerability value is in the substation communication network.
[0036] Compared with the prior art, the present application has the following advantages and technical effects:
[0037] The present application analyzes the attack path of the substation communication network, quantifies the attack difficulty of the substation network attack, and generates the link weight for the topology analysis of the communication network. BRIEF DESCRIPTION OF DRAWINGS
[0038] The accompanying drawings, which form a part of the present application, are intended to provide further understanding of the present application, and the illustrative embodiments of the present application and their description serve the purpose of explaining the present application. The accompanying drawings should not be regarded as an inappropriate limitation of the present application. In the drawings:
[0039] Figure 1A substation communication network fragile structure evaluation method flowchart of an embodiment of the present application;
[0040] Figure 2 A substation communication network structure schematic diagram of an embodiment of the present application;
[0041] Figure 3 A fragile node mining flowchart of an embodiment of the present application;
[0042] Figure 4 A fragile link evaluation method flowchart of an embodiment of the present application. DETAILED DESCRIPTION
[0043] It should be noted that the embodiments in the present application and the features in the embodiments can be combined with each other without conflict. The present application will be described in detail below with reference to the accompanying drawings and in combination with embodiments.
[0044] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a group of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described herein can be executed in an order different from that shown herein.
[0045] Embodiment one
[0046] As shown in the figure, the present embodiment provides a substation communication network fragile structure evaluation method based on complex network theory, which comprises: Figure 1
[0047] Constructing a substation communication network model, generating link weights based on the attack path of the substation communication network model;
[0048] Combining the complex network theory with the link weights, calculating a plurality of node vulnerability values;
[0049] Based on the node vulnerability values, integrating the local information and the global information of the link, calculating a plurality of link vulnerability values;
[0050] Based on the node vulnerability values and the link vulnerability values, respectively evaluating the fragile structure of the substation communication network.
[0051] In the present embodiment, the substation communication network structure is obtained by simplifying the real substation communication network, and is abstracted as a substation communication network topology model, and the result is shown in the figure. Figure 2
[0052] The set of nodes in the communication network is V={v i}, then the node v i and v j The constructed link is e i,j , and the link set is E = {e i,j}.
[0053] Network attacks can break through the firewall through remote access, enter the station control layer bus, and propagate along the information interaction path Figure 2 . The CVSS3.0 general vulnerability scoring system can be used to quantify each link. CVSS3.0 is published by the National Vulnerability Database of the United States and keeps the vulnerability data up to date, and comprehensively measures the harmfulness of the vulnerability to give a specific score to the vulnerability. Here, the vulnerability exploitation cost is calculated by the CVSS scoring system to represent the link weight.
[0054] The score of the vulnerability exploitation index is determined by the difficulty of exploiting the vulnerability and the complexity of the technical means taken to exploit the vulnerability. The vulnerability exploitation index is shown in Table 1:
[0055] Table 1
[0056]
[0057] For the weight of the edge between nodes, i.e., the probability of launching an attack on the subsequent node v j in the case that the previous node v i is successfully attacked, this probability is mainly related to the vulnerability exploitation cost of the subsequent node v j . If the vulnerability exploitation cost of the subsequent node v j is higher, the probability of being successfully attacked is lower. The calculation formula is:
[0058] W (i,j) = Cost = AV·AC·PR·UI (1)
[0059] Where W (i,j) is the link weight of the link e i,j .
[0060] First, mining of vulnerable nodes in the substation communication network based on complex network theory
[0061] To mine the vulnerable entities in the communication network, the vulnerable nodes need to be mined first. The mining process of the vulnerable nodes is shown in Figure 3 .
[0062] Step 1: Obtain the network relationship of nodes from complex network theory
[0063] To evaluate the subsequent nodes, the network relationship of the nodes is first obtained. From the complex network theory, the topology of the selected nodes is evaluated from the node degree and the node betweenness. The specific indicators are as follows:
[0064] (1) Node degree: The node degree is deg(vi ), represents the number of links directly associated with node v i ; the number of links with node v i as the starting point of the link is the node out-degree deg + (v i ), the number of links with node v i as the end point is the node out-degree deg - (v i ), there
[0065]
[0066] (2) Node betweenness B: Node betweenness B is used to represent the influence degree of node v i in the global network, there
[0067]
[0068] In formula (3), δ jk is the number of paths under the shortest route principle from node v j to v k , δ jk (i) is the number of paths in δ jk that pass through v i .
[0069] Second step: calculation based on improved structural hole link strength and node strength
[0070] If two independent nodes in the network topology do not exist directly or indirectly redundant relationship, the obstacle between them is called structural hole. The more "structural holes" occupied by node v i , the more fragile it is in the overall network topology. But in the actual network topology, the node has bias to its adjacent nodes, that is, more important adjacent nodes invest more contribution, and the network security protection level of different nodes is different, that is, the link security degree is different, not equal treatment. Therefore, the application of structural hole in the substation communication network not only needs to consider the number of node v i and its adjacent nodes, but also needs to consider the communication link strength connected between node v i and adjacent node v i .
[0071] In order to evaluate the node vulnerability of substation communication network, it is necessary to calculate the link strength and node strength:
[0072] (1) Consider the contribution degree paid by node v i to maintain the edge relationship of adjacent node v j , which is summarized in the link strength w(i, j), and its expression is:
[0073] w(i, j) = [deg(v i )+deg(v j )]*W (i,j) (4)
[0074] (2) On the basis of the strength w(i, j) of the link e i,j , the strength of each link is accumulated and processed, and the strength of the link is attributed to the strength w(i) of the node v i , and there is:
[0075] w(i) =∑ j∈Z(i) w(i, j) (5)
[0076] where Z(i) is a set of nodes connected to the node v i .
[0077] Step 3: Calculate the constraint coefficient
[0078] The relative importance function p(i, j) is used to measure the contribution of the node v i to maintain the adjacent node v j , and its expression is:
[0079] p(i, j) = w(i, j) / w(i) (6)
[0080] The contribution p(i, j) of the node v i to maintain the edge relationship of the adjacent node v j is used to calculate the constraint coefficient value C(i) of each node, and there is:
[0081] C(i) =∑[p(i, j) + p(i, q) * p(q, j)], i≠q≠j, q, j∈Z(i) (7)
[0082] where p(i, q) and p(q, j) represent the contribution of the nodes v i and v j to maintain the relationship of the common adjacent node v q .
[0083] Step 4: Generate node influence coefficient matrix and structural hole influence matrix
[0084] The influence of a node depends on two factors: the position information of the node and the adjacent information of the node, which can also be called the global influence of the node and the local influence of the node. To integrate the influences of the two, the node influence coefficient matrix and the structural hole influence matrix need to be constructed in turn:
[0085] (1) Combine the node betweenness to establish the node influence coefficient matrix H A , and there is:
[0086]
[0087] where H A (i, j) = e i,j ·B j represents the influence coefficient of node v j to node v i . The elements on the diagonal of the matrix are all 1, indicating that the influence coefficient of a node to itself is 100%. Thus, the influence degree of any node to other nodes in the network can be obtained.
[0088] (3) The influence degree between nodes is determined by using the node constraint coefficient, and the structural hole influence matrix H C is generated by combining the constraint coefficient and the influence coefficient matrix.
[0089]
[0090] where H C (i, j) = e i,j ·B j [C(j)] -1 represents the influence coefficient of node v j to node v i . The elements on the diagonal of the matrix are all 1, indicating that the influence coefficient of a node to itself is 100%. Thus, the influence degree of any node to other nodes in the network can be obtained. i i
[0091] Step 5: Calculate the node vulnerability value
[0092] To complete the vulnerability node measurement based on the improved structural hole, the vulnerability value F of node v
[0093] is required, which has:
[0094] Step 6: Obtain the vulnerable node set
[0095] The vulnerability values of all nodes in the substation communication network are calculated by the above steps and are arranged in descending order. The greater the value of F i , the more vulnerable the node v i is in the substation communication network. The top 20% of nodes with vulnerability values are taken to form the vulnerable node set.
[0096] Second, vulnerable link mining algorithm
[0097] After obtaining the node vulnerability value, the link vulnerability value can be calculated based on this, and the process is shown in Figure 4 .
[0098] Step 1: Complete the construction of the substation communication network model and obtain the node vulnerability value by the previous steps.
[0099] Step 2: Calculate the relative vulnerability value of the node.
[0100] To ensure that the node vulnerability values are on the same order of magnitude for subsequent calculations, the node vulnerability values need to be normalized to obtain the relative node vulnerability value τ. i ,have:
[0101]
[0102] in, This is the maximum value obtained by taking the square root of the vulnerability values of all nodes.
[0103] Step 3: Calculate the local vulnerability of the link
[0104] At the network topology level, the main considerations are the local and global information of nodes. The same approach is applied to vulnerable link mining. Therefore, it is necessary to first consider the local information of the nodes at both ends of the link, analyze the impact of the vulnerability of the nodes at both ends on the overall link vulnerability, and obtain the link's local vulnerability value PF(e). i,j Its expression is:
[0105] PF(e i,j ) = deg(v i )*τ i +deg(v j )*τ j (12)
[0106] Step 4: Calculate the edge betweenness of the link.
[0107] To reflect the global information attributes of the link, consider introducing link e. i,j The edge betweenness number EB(e) i,j The position and role of a link in information communication can be measured using the following expression:
[0108]
[0109] Where, δ kl For node v k to v l The number of paths under the shortest route principle, δ kl (e i,j ) is δ kl via link e i,j The number of paths.
[0110] Step 5: Calculate the link vulnerability value
[0111] By combining link local vulnerability with link edge betweenness, the link vulnerability F(e) can be calculated more efficiently. i,jWhen integrating local and global information of a link, its expression is:
[0112] F(e i,j )=α*PF(e i,j )+(1-α)*EB(e i,j (14)
[0113] Where α is the decision coefficient, and its value ranges from [0, 1]. Here, we take α = 0.5.
[0114] Step 6: Obtain the set of vulnerable links
[0115] To obtain the vulnerable node set, the above steps first calculate the vulnerability values of all links in the substation communication network and sort them in descending order. When F(e i,j The larger the value of ), the better the link e. i,j The more vulnerable a link is in the substation communication network, the more vulnerable it becomes. The top 20% of the links by vulnerability value are considered as the vulnerable link set.
[0116] The above description is merely a preferred embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for evaluating the fragile structure of a substation communication network based on complex network theory, characterized in that, The method comprises the following steps: constructing a substation communication network model, generating link weights based on attack paths of the substation communication network model; The process of generating link weights comprises: based on the attack paths, quantifying a plurality of links of the substation communication network model through a CVSS scoring system, and calculating the link weights based on a vulnerability exploit indicator in the CVSS scoring system; The vulnerability exploit indicator comprises: attack paths, attack complexity, required privileges, and user interaction. Combine the complex network theory with the link weights to calculate a plurality of node vulnerability values; The process of calculating a plurality of node vulnerability values comprises: based on the complex network theory, obtaining node network relationships, wherein the node network relationships comprise: node degree and node betweenness; based on the node degree and the link weights, calculating a node constraint coefficient; The process of calculating the node constraint coefficient comprises: based on the node degree and the link weights, calculating a link strength; accumulating the link strength to obtain a node strength; based on the link strength and the node strength, obtaining a relative importance function, and based on the relative importance function, calculating the node constraint coefficient; based on the node betweenness and the node constraint coefficient, generating a structural hole influence matrix, and based on the structural hole influence matrix, calculating a plurality of node vulnerability values; The process of generating the structural hole influence matrix comprises: based on the node betweenness, establishing a node influence coefficient matrix; based on the node constraint coefficient and the node influence coefficient matrix, generating the structural hole influence matrix; based on the node vulnerability values, integrating local information and global information of the links to calculate a plurality of link vulnerability values; The process of calculating the link local vulnerability value comprises: normalizing the node vulnerability values to obtain node relative vulnerability values, obtaining local information of nodes at both ends of the link, and based on the node relative vulnerability values and the local information, calculating the link local vulnerability value; The process of calculating a plurality of link vulnerability values comprises: based on the node vulnerability values, integrating local information of the links to calculate link local vulnerability values; integrating global information of the links to calculate link edge betweenness; based on the link local vulnerability and the link edge betweenness, calculating a plurality of link vulnerability values; based on the node vulnerability values and the link vulnerability values, respectively, performing vulnerability structure evaluation on the substation communication network.
2. The method for evaluating the vulnerable structure of a substation communication network based on complex network theory according to claim 1, characterized in that, The process of performing vulnerability structure evaluation on the substation communication network based on the node vulnerability values comprises: arranging the node vulnerability values in descending order, and the larger the node vulnerability value is, the more vulnerable the node corresponding to the node vulnerability value is in the substation communication network. 3.The method for evaluating the vulnerable structure of a substation communication network based on complex network theory according to claim 1, characterized in that, The process of performing vulnerability structure evaluation on the substation communication network based on the link vulnerability values comprises: arranging the link vulnerability values in descending order, and the larger the link vulnerability value is, the more vulnerable the link corresponding to the link vulnerability value is in the substation communication network.
Citation Information
Patent Citations
Power communication network vulnerability evaluation and routing optimization method
CN106789190A
Complex network important node sorting method based on compactness and structural hole
CN107317704A
Network attack path planning method and device, electronic equipment and storage medium
CN116015886A