A method and device for determining the homology of vulnerabilities in power distribution edge gateways
By collecting the load status and vulnerability data of the distribution edge gateway in real time, clustering processing and isolated forest algorithm detection, the homology discrimination reliability problem caused by the differences in vulnerability data of traditional distribution gateways is solved, and more efficient and accurate vulnerability detection is achieved, ensuring the security of the power system.
Patent Information
- Application Number
- CN202410719606.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-05
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2044-06-05
AI Technical Summary
There are differences in load conditions for traditional distribution gateway vulnerability data, which makes it difficult to guarantee the reliability of the vulnerability homology discrimination results.
The load situation and vulnerability data set of the distribution edge gateway are collected in real time through the CPU interface. When the load is less than the preset threshold, the vulnerability data set is clustered, and an isolated forest algorithm is used to detect outliers to determine the homology of the vulnerability.
It improves the detection efficiency and accuracy of homology vulnerabilities, ensures the stability and reliability of power supply, and improves the safety of the entire power system.
Smart Images

Figure CN118509236B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power distribution edge gateway security testing, and in particular to a method and device for determining the homology of vulnerabilities in power distribution edge gateways. Background Art
[0002] With the continuous development of the power industry, the requirements for distribution network security are becoming higher and higher. Ensuring that the distribution gateway vulnerability homology identification system can meet the power industry's security needs is an important basis for promoting the development of the power industry.
[0003] However, due to the differences in load conditions of traditional distribution gateway vulnerability data, the reliability of the judgment results obtained using the current distribution edge gateway vulnerability homology judgment method is difficult to guarantee. Summary of the invention
[0004] The present invention provides a method and device for determining the homology of vulnerabilities in a power distribution edge gateway, which improves the detection efficiency and accuracy of homology vulnerabilities in the power distribution gateway vulnerability detection, ensures the stability and reliability of power supply, and improves the safety of the entire power system.
[0005] In order to solve the above technical problems, the present invention provides a method for determining the homology of vulnerabilities in a power distribution edge gateway, comprising:
[0006] The load condition of the power distribution edge gateway and the power distribution edge gateway vulnerability data set are collected in real time through the CPU interface; wherein the power distribution edge gateway vulnerability data set includes the vulnerability data of each node of the power distribution edge gateway;
[0007] When the load condition of the power distribution edge gateway is less than a preset load threshold, clustering the vulnerability data set of the power distribution edge gateway to obtain a vulnerability data clustering result;
[0008] Based on the vulnerability data clustering result, an isolation forest algorithm is used to detect the distribution edge gateway vulnerability data set to obtain an outlier detection result;
[0009] According to the outlier detection result, the homology of the power distribution edge gateway vulnerabilities corresponding to the power distribution edge gateway vulnerability data set is determined.
[0010] Furthermore, when the load condition of the power distribution edge gateway is less than a preset load threshold, clustering processing is performed on the power distribution edge gateway vulnerability data set to obtain a vulnerability data clustering result, which is specifically:
[0011] The node sequence features of each node of the power distribution edge gateway are extracted based on the power distribution edge gateway vulnerability dataset;
[0012] Based on the node sequence characteristics of each node of the power distribution edge gateway, a number of singular points are screened out from each node of the power distribution gateway, and the singular points are determined as a number of cluster centers; wherein the singular points have time tags;
[0013] Calculate the cosine distance between the vulnerability data of each node of the power distribution edge gateway and each of the cluster centers, and divide the vulnerability data of each node of the power distribution edge gateway into the cluster where the corresponding cluster center is located according to the preset Davies-Bouldin index;
[0014] After the power distribution edge gateway vulnerability data set completes clustering processing, several clusters are formed.
[0015] Furthermore, the node sequence features of each node of the power distribution edge gateway are extracted according to the power distribution edge gateway vulnerability data set, specifically:
[0016] IDA pro is used to disassemble the power distribution edge gateway vulnerability dataset and obtain the node sequence characteristics of each node of the power distribution edge gateway.
[0017] Furthermore, based on the vulnerability data clustering result, the isolation forest algorithm is used to detect the distribution edge gateway vulnerability data set to obtain the outlier detection result, which is specifically:
[0018] Randomly construct a first hyperplane structure, and use the first hyperplane structure to perform several spatial cuts on the power distribution edge gateway vulnerability data set to form a power distribution gateway vulnerability data isolation tree;
[0019] Calculate the path length between each leaf node of the power distribution gateway vulnerability data isolation tree and the root node of the power distribution gateway vulnerability data isolation tree in sequence;
[0020] According to the path length between each leaf node of the power distribution gateway vulnerability data isolation tree and the root node of the power distribution gateway vulnerability data isolation tree, the average path length of the power distribution gateway vulnerability data isolation tree is calculated;
[0021] By comparing the average path length of the isolation tree of the distribution gateway vulnerability data and the Euler constant, the outlier detection result is obtained.
[0022] Furthermore, the first hyperplane structure is randomly constructed, and the first hyperplane structure is used to perform several spatial cuts on the power distribution edge gateway vulnerability data set to form a power distribution gateway vulnerability data isolation tree, specifically:
[0023] Randomly construct the first hyperplane structure;
[0024] Using the first hyperplane structure to perform spatial segmentation processing on the power distribution edge gateway vulnerability data set to form two vulnerability data subspaces;
[0025] The two vulnerability data subspaces are cyclically processed for secondary space cutting until each vulnerability data subspace contains only one distribution edge gateway vulnerability data, thereby forming a distribution gateway vulnerability data isolation tree; wherein, the leaf node of the distribution gateway vulnerability data isolation tree is a vulnerability data subspace containing only one distribution edge gateway vulnerability data.
[0026] Furthermore, the distribution gateway vulnerability data isolation tree is specifically:
[0027]
[0028] Where s(x,n) is the distribution gateway vulnerability data isolation tree; x is the leaf node of the distribution gateway vulnerability data isolation tree; n is the number of leaf nodes of the distribution gateway vulnerability data isolation tree; a is the number of clusters of the vulnerability data clustering result; E(h(x)) is the expected height parameter of the distribution gateway vulnerability data isolation tree; c(n) is the expected density parameter of the distribution gateway vulnerability data isolation tree.
[0029] Further, the path lengths between each leaf node of the power distribution gateway vulnerability data isolation tree and the root node of the power distribution gateway vulnerability data isolation tree are calculated in sequence, specifically:
[0030]
[0031] In the formula, x i is the i-th leaf node of the distribution gateway vulnerability data isolation tree; n is the number of leaf nodes of the distribution gateway vulnerability data isolation tree; x 0 is the root node of the distribution gateway vulnerability data isolation tree; H is the multidimensional set of distance data between each leaf node and the root node of the distribution gateway vulnerability data isolation tree; d(x i ,x 0 ) is the leaf node x i To the root node x 0 The path length between .
[0032] Furthermore, by comparing the average path length of the isolated tree of the distribution gateway vulnerability data and the Euler constant, the outlier detection result is obtained, which is specifically:
[0033] If the average path length of the isolation tree of the power distribution gateway vulnerability data is less than the Euler constant, then the outlier detection result is determined to be that there are no outliers in the power distribution edge gateway vulnerability data set;
[0034] If the average path length of the isolation tree of the power distribution gateway vulnerability data is greater than or equal to the Euler constant, it is determined that the outlier detection result is that there are outliers in the power distribution edge gateway vulnerability data set.
[0035] Further, the homology of the power distribution edge gateway vulnerabilities corresponding to the power distribution edge gateway vulnerability data set is determined according to the outlier detection result, specifically:
[0036] When the outlier detection result is that there is no outlier in the power distribution edge gateway vulnerability data set, it is determined that the power distribution edge gateway vulnerabilities corresponding to the power distribution edge gateway vulnerability data set are of the same source;
[0037] When the outlier detection result shows that there are outliers in the power distribution edge gateway vulnerability dataset, it is determined that the power distribution edge gateway vulnerability corresponding to the power distribution edge gateway vulnerability dataset is not homologous.
[0038] The present invention provides a method for determining the homology of vulnerabilities in a power distribution edge gateway, which collects the load condition of the power distribution edge gateway and the vulnerability data set of the power distribution edge gateway in real time through a CPU interface; when the load condition of the power distribution edge gateway is less than a preset load threshold, the vulnerability data set of the power distribution edge gateway is clustered to obtain a vulnerability data clustering result; based on the vulnerability data clustering result, an isolation forest algorithm is used to detect the vulnerability data set of the power distribution edge gateway to obtain an outlier detection result; according to the outlier detection result, the homology of the power distribution edge gateway vulnerability corresponding to the vulnerability data set of the power distribution edge gateway is determined. In the detection of vulnerabilities in the power distribution gateway, the present invention improves the detection efficiency and accuracy of homology vulnerabilities, and avoids the occurrence of safety accidents by timely identifying and repairing vulnerabilities, thereby ensuring the stability and reliability of power supply and improving the safety of the entire power system.
[0039] Accordingly, the present invention provides a device for determining the homology of vulnerabilities in a power distribution edge gateway, comprising: a collection module, a clustering module, a detection module and a determination module;
[0040] The acquisition module is used to collect the load condition of the power distribution edge gateway and the power distribution edge gateway vulnerability data set in real time through the CPU interface; wherein the power distribution edge gateway vulnerability data set includes the vulnerability data of each node of the power distribution edge gateway;
[0041] The clustering module is used to perform clustering processing on the power distribution edge gateway vulnerability data set when the load condition of the power distribution edge gateway is less than a preset load threshold, and obtain a vulnerability data clustering result;
[0042] The detection module is used to detect the distribution edge gateway vulnerability data set using an isolation forest algorithm based on the vulnerability data clustering result to obtain an outlier detection result;
[0043] The determination module is used to determine the homology of the power distribution edge gateway vulnerabilities corresponding to the power distribution edge gateway vulnerability data set according to the outlier detection result.
[0044] The present invention provides a device for distinguishing the homology of vulnerabilities in a power distribution edge gateway. Based on the organic combination between modules, the device collects the load condition of the power distribution edge gateway and the vulnerability data set of the power distribution edge gateway in real time through the CPU interface; when the load condition of the power distribution edge gateway is less than the preset load threshold, the vulnerability data set of the power distribution edge gateway is clustered to obtain the vulnerability data clustering result; based on the vulnerability data clustering result, the isolation forest algorithm is used to detect the vulnerability data set of the power distribution edge gateway to obtain the outlier detection result; according to the outlier detection result, the homology of the power distribution edge gateway vulnerability corresponding to the vulnerability data set of the power distribution edge gateway is distinguished. In the detection of vulnerabilities in the power distribution gateway, the present invention improves the detection efficiency and accuracy of homology vulnerabilities, avoids the occurrence of safety accidents by timely identifying and repairing vulnerabilities, thereby ensuring the stability and reliability of power supply and improving the safety of the entire power system. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] Figure 1 A flow chart of an embodiment of a method for determining the homology of vulnerabilities in a power distribution edge gateway provided by the present invention;
[0046] Figure 2 A schematic diagram of a flow chart of an embodiment of a method for clustering vulnerability data of a power distribution edge gateway provided by the present invention;
[0047] Figure 3 A structural schematic diagram of an embodiment of a device for determining the homology of vulnerabilities in a power distribution edge gateway provided by the present invention. DETAILED DESCRIPTION
[0048] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0049] The flowcharts shown in the accompanying drawings are only examples and do not necessarily include all the contents and operations / steps, nor must they be executed in the order described. For example, some operations / steps may also be decomposed, combined or partially merged, so the actual execution order may change according to actual conditions.
[0050] Some embodiments of the present invention are described in detail below in conjunction with the accompanying drawings. In the absence of conflict, the following embodiments and features in the embodiments can be combined with each other.
[0051] Example 1
[0052] See also Figure 1, is a flow chart of an embodiment of a method for determining the homology of vulnerabilities in a power distribution edge gateway provided by the present invention, the method comprising steps 101 to 104, each of which is specifically as follows:
[0053] Step 101: Collect the load status of the power distribution edge gateway and the power distribution edge gateway vulnerability data set in real time through the CPU interface; wherein the power distribution edge gateway vulnerability data set includes the vulnerability data of each node of the power distribution edge gateway.
[0054] In the first embodiment of the present invention, the data of the operation of the distribution edge gateway includes differentiated parameters under different load conditions. Different load conditions cause deviations in the judgment of the homology of the vulnerabilities of the distribution edge gateway. Therefore, when judging the homology of the vulnerabilities of the distribution edge gateway, the current load situation is obtained in real time according to the hardware performance of the distribution edge gateway, which can ensure the accuracy of the homology judgment.
[0055] Step 102: When the load condition of the power distribution edge gateway is less than a preset load threshold, clustering processing is performed on the power distribution edge gateway vulnerability data set to obtain a vulnerability data clustering result.
[0056] In the first embodiment of the present invention, a load threshold is set, and when the load of the power distribution edge gateway collected in real time is less than the load threshold, clustering processing of the power distribution edge gateway vulnerability data set is started. For example, the load threshold is set to 70% of the rated load, and when the load is less than 70% of the rated load, k-means clustering processing is performed on the vulnerability data of the power distribution edge gateway.
[0057] Further, in the first embodiment of the present invention, when the load condition of the power distribution edge gateway is less than a preset load threshold, clustering processing is performed on the power distribution edge gateway vulnerability data set to obtain a vulnerability data clustering result, specifically:
[0058] The node sequence features of each node of the power distribution edge gateway are extracted based on the power distribution edge gateway vulnerability dataset;
[0059] Based on the node sequence characteristics of each node of the power distribution edge gateway, a number of singular points are screened out from each node of the power distribution gateway, and the singular points are determined as a number of cluster centers; wherein the singular points have time tags;
[0060] Calculate the cosine distance between the vulnerability data of each node of the power distribution edge gateway and each of the cluster centers, and divide the vulnerability data of each node of the power distribution edge gateway into the cluster where the corresponding cluster center is located according to the preset Davies-Bouldin index;
[0061] After the power distribution edge gateway vulnerability data set completes clustering processing, several clusters are formed.
[0062] Further, in the first embodiment of the present invention, the node sequence features of each node of the power distribution edge gateway are extracted according to the power distribution edge gateway vulnerability data set, specifically:
[0063] IDA pro is used to disassemble the power distribution edge gateway vulnerability dataset and obtain the node sequence characteristics of each node of the power distribution edge gateway.
[0064] In the first embodiment of the present invention, see Figure 2 , is a flow chart of an embodiment of the method for clustering the vulnerability data of the power distribution edge gateway provided by the present invention. The k-means algorithm is used to cluster the power distribution gateway vulnerability data set, and the node sequence features corresponding to the power distribution gateway can be extracted to form a cluster center. Among them, there is a one-to-one correspondence between the information in the IDA pro disassembly and the power distribution gateway vulnerability data, so the disassembly processing by IDA pro can realize the extraction of the features of the node sequence. When the node of the power distribution gateway produces abnormal data, the node sequence features corresponding to the node will have a singular point with a time label, so the singular point in the node sequence feature is used as the center point of the cluster. After the cluster center is obtained, the cosine distance between each distribution gateway vulnerability data and each cluster center is calculated, and according to the preset Davies-Bouldin index, the distribution gateway vulnerability data with a cosine distance less than the Davies-Bouldin index is divided into the cluster where the corresponding cluster center is located. Among them, the Davies-Bouldin index can be set to between 0 and 1.5 according to the empirical value. By comparing the cosine distance and the Davies-Bouldin index, and by continuously updating and iterating the distance relationship between the distribution gateway node data and the cluster center, the clustering processing of the distribution gateway vulnerability data is completed.
[0065] Step 103: Based on the vulnerability data clustering result, an isolation forest algorithm is used to detect the distribution edge gateway vulnerability data set to obtain an outlier detection result.
[0066] Further, in the first embodiment of the present invention, based on the vulnerability data clustering result, the isolation forest algorithm is used to detect the distribution edge gateway vulnerability data set to obtain the outlier detection result, which is specifically:
[0067] Randomly construct a first hyperplane structure, and use the first hyperplane structure to perform several spatial cuts on the power distribution edge gateway vulnerability data set to form a power distribution gateway vulnerability data isolation tree;
[0068] Calculate the path length between each leaf node of the power distribution gateway vulnerability data isolation tree and the root node of the power distribution gateway vulnerability data isolation tree in sequence;
[0069] According to the path length between each leaf node of the power distribution gateway vulnerability data isolation tree and the root node of the power distribution gateway vulnerability data isolation tree, the average path length of the power distribution gateway vulnerability data isolation tree is calculated;
[0070] By comparing the average path length of the isolation tree of the distribution gateway vulnerability data and the Euler constant, the outlier detection result is obtained.
[0071] Further, in the first embodiment of the present invention, a first hyperplane structure is randomly constructed, and the first hyperplane structure is used to perform several spatial cuts on the power distribution edge gateway vulnerability data set to form a power distribution gateway vulnerability data isolation tree, specifically:
[0072] Randomly construct the first hyperplane structure;
[0073] Using the first hyperplane structure to perform spatial segmentation processing on the power distribution edge gateway vulnerability data set to form two vulnerability data subspaces;
[0074] The two vulnerability data subspaces are cyclically processed for secondary space cutting until each vulnerability data subspace contains only one distribution edge gateway vulnerability data, thereby forming a distribution gateway vulnerability data isolation tree; wherein, the leaf node of the distribution gateway vulnerability data isolation tree is a vulnerability data subspace containing only one distribution edge gateway vulnerability data.
[0075] Further, in the first embodiment of the present invention, the distribution gateway vulnerability data isolation tree is specifically:
[0076]
[0077] Where s(x,n) is the distribution gateway vulnerability data isolation tree; x is the leaf node of the distribution gateway vulnerability data isolation tree; n is the number of leaf nodes of the distribution gateway vulnerability data isolation tree; a is the number of clusters of the vulnerability data clustering result; E(h(x)) is the expected height parameter of the distribution gateway vulnerability data isolation tree; c(n) is the expected density parameter of the distribution gateway vulnerability data isolation tree.
[0078] In the first embodiment of the present invention, an isolation forest algorithm is used to identify the homology of distribution gateway vulnerabilities. First, a random hyperplane structure is constructed, and the original distribution gateway vulnerability data space is cut using the hyperplane structure to convert it into two subspaces. On this basis, the subspace is cut twice, and this cutting method is repeated until the number of distribution gateway vulnerability data nodes contained in each subspace is only one, and each subspace at this time is used as the leaf node of the isolated tree, and the result after the overall distribution gateway vulnerability data is cut is formed as an isolated tree. Among them, the number of leaf nodes of the distribution gateway vulnerability data isolation tree is equal to the number of data in the distribution gateway vulnerability data set.
[0079] Further, in the first embodiment of the present invention, the path lengths between each leaf node of the power distribution gateway vulnerability data isolation tree and the root node of the power distribution gateway vulnerability data isolation tree are calculated in sequence, specifically:
[0080]
[0081] In the formula, x i is the i-th leaf node of the distribution gateway vulnerability data isolation tree; n is the number of leaf nodes of the distribution gateway vulnerability data isolation tree; x 0 is the root node of the distribution gateway vulnerability data isolation tree; H is the multidimensional set of distance data between each leaf node and the root node of the distribution gateway vulnerability data isolation tree; d(x i ,x 0 ) is the leaf node x i To the root node x 0 The length of the path between .
[0082] Further, in the first embodiment of the present invention, by comparing the average path length of the isolated tree of the distribution gateway vulnerability data and the Euler constant, the outlier detection result is obtained, specifically:
[0083] If the average path length of the isolation tree of the power distribution gateway vulnerability data is less than the Euler constant, then the outlier detection result is determined to be that there are no outliers in the power distribution edge gateway vulnerability data set;
[0084] If the average path length of the isolation tree of the power distribution gateway vulnerability data is greater than or equal to the Euler constant, it is determined that the outlier detection result is that there are outliers in the power distribution edge gateway vulnerability data set.
[0085] In the first embodiment of the present invention, it is possible to determine whether there are outliers in the distribution gateway vulnerability data set based on the path length between the leaf node of the distribution gateway vulnerability data isolation tree and the root node of the distribution gateway vulnerability data isolation tree. First, the distance length between each leaf node and the root node in the distribution gateway vulnerability data isolation tree is calculated using the path length calculation formula, and then the path length average is calculated based on the calculation result. The path length average is compared with the Euler constant. If the path length average is less than the Euler constant, it is determined that there are no outliers in the distribution edge gateway vulnerability data set; if the path length average is greater than or equal to the Euler constant, it is determined that there are outliers in the distribution edge gateway vulnerability data set.
[0086] Step 104: According to the outlier detection result, the homology of the power distribution edge gateway vulnerabilities corresponding to the power distribution edge gateway vulnerability data set is determined.
[0087] Further, in the first embodiment of the present invention, according to the outlier detection result, the homology of the power distribution edge gateway vulnerability corresponding to the power distribution edge gateway vulnerability data set is determined, specifically:
[0088] When the outlier detection result is that there is no outlier in the power distribution edge gateway vulnerability data set, it is determined that the power distribution edge gateway vulnerabilities corresponding to the power distribution edge gateway vulnerability data set are of the same source;
[0089] When the outlier detection result shows that there are outliers in the power distribution edge gateway vulnerability dataset, it is determined that the power distribution edge gateway vulnerability corresponding to the power distribution edge gateway vulnerability dataset is not homologous.
[0090] In the first embodiment of the present invention, the homology of the power distribution edge gateway vulnerability can be determined based on the outlier detection result. When it is detected that there are no outliers in the power distribution edge gateway vulnerability data set, it means that there are no obvious outliers in the power distribution gateway vulnerability data set at this time, so the power distribution edge gateway vulnerability can be determined to be homologous; on the contrary, when it is detected that there are outliers in the power distribution edge gateway vulnerability data set, it means that there are obvious outliers in the power distribution gateway vulnerability data set at this time, and the power distribution edge gateway vulnerability is determined to be non-homologous.
[0091] In summary, the first embodiment of the present invention provides a method for determining the homology of vulnerabilities in a distribution edge gateway, which collects the load conditions of the distribution edge gateway and the vulnerability data set of the distribution edge gateway in real time through the CPU interface; when the load condition of the distribution edge gateway is less than the preset load threshold, the vulnerability data set of the distribution edge gateway is clustered to obtain the vulnerability data clustering result; based on the vulnerability data clustering result, the isolation forest algorithm is used to detect the vulnerability data set of the distribution edge gateway to obtain the outlier detection result; according to the outlier detection result, the homology of the distribution edge gateway vulnerabilities corresponding to the distribution edge gateway vulnerability data set is determined. In the detection of vulnerabilities in distribution gateways, the present invention improves the detection efficiency and accuracy of homology vulnerabilities, and avoids the occurrence of safety accidents by timely identifying and repairing vulnerabilities, thereby ensuring the stability and reliability of power supply and improving the safety of the entire power system.
[0092] Example 2
[0093] See also Figure 3 , is a structural diagram of an embodiment of a device for determining the homology of vulnerabilities in a power distribution edge gateway provided by the present invention, the device comprising a collection module 201, a clustering module 202, a detection module 203 and a determination module 204;
[0094] The collection module 201 is used to collect the load condition of the power distribution edge gateway and the power distribution edge gateway vulnerability data set in real time through the CPU interface; wherein the power distribution edge gateway vulnerability data set includes the vulnerability data of each node of the power distribution edge gateway;
[0095] The clustering module 202 is used to perform clustering processing on the power distribution edge gateway vulnerability data set when the load condition of the power distribution edge gateway is less than a preset load threshold, and obtain a vulnerability data clustering result;
[0096] The detection module 203 is used to detect the distribution edge gateway vulnerability data set using an isolation forest algorithm based on the vulnerability data clustering result to obtain an outlier detection result;
[0097] The determination module 204 is used to determine the homology of the power distribution edge gateway vulnerabilities corresponding to the power distribution edge gateway vulnerability data set according to the outlier detection result.
[0098] Further, in the second embodiment of the present invention, when the load condition of the power distribution edge gateway is less than a preset load threshold, clustering processing is performed on the power distribution edge gateway vulnerability data set to obtain a vulnerability data clustering result, specifically:
[0099] The node sequence features of each node of the power distribution edge gateway are extracted based on the power distribution edge gateway vulnerability dataset;
[0100] Based on the node sequence characteristics of each node of the power distribution edge gateway, a number of singular points are screened out from each node of the power distribution gateway, and the singular points are determined as a number of cluster centers; wherein the singular points have time tags;
[0101] Calculate the cosine distance between the vulnerability data of each node of the power distribution edge gateway and each of the cluster centers, and divide the vulnerability data of each node of the power distribution edge gateway into the cluster where the corresponding cluster center is located according to the preset Davies-Bouldin index;
[0102] After the power distribution edge gateway vulnerability data set completes clustering processing, several clusters are formed.
[0103] Further, in the second embodiment of the present invention, the node sequence features of each node of the power distribution edge gateway are extracted according to the power distribution edge gateway vulnerability data set, specifically:
[0104] IDA pro is used to disassemble the power distribution edge gateway vulnerability dataset and obtain the node sequence characteristics of each node of the power distribution edge gateway.
[0105] Further, in the second embodiment of the present invention, based on the vulnerability data clustering result, the isolation forest algorithm is used to detect the distribution edge gateway vulnerability data set to obtain the outlier detection result, which is specifically:
[0106] Randomly construct a first hyperplane structure, and use the first hyperplane structure to perform several spatial cuts on the power distribution edge gateway vulnerability data set to form a power distribution gateway vulnerability data isolation tree;
[0107] Calculate the path length between each leaf node of the power distribution gateway vulnerability data isolation tree and the root node of the power distribution gateway vulnerability data isolation tree in sequence;
[0108] According to the path length between each leaf node of the power distribution gateway vulnerability data isolation tree and the root node of the power distribution gateway vulnerability data isolation tree, the average path length of the power distribution gateway vulnerability data isolation tree is calculated;
[0109] By comparing the average path length of the isolation tree of the distribution gateway vulnerability data and the Euler constant, the outlier detection result is obtained.
[0110] Further, in the second embodiment of the present invention, a first hyperplane structure is randomly constructed, and the first hyperplane structure is used to perform several spatial cutting processes on the power distribution edge gateway vulnerability data set to form a power distribution gateway vulnerability data isolation tree, specifically:
[0111] Randomly construct the first hyperplane structure;
[0112] Using the first hyperplane structure to perform spatial segmentation processing on the power distribution edge gateway vulnerability data set to form two vulnerability data subspaces;
[0113] The two vulnerability data subspaces are cyclically processed for secondary space cutting until each vulnerability data subspace contains only one distribution edge gateway vulnerability data, thereby forming a distribution gateway vulnerability data isolation tree; wherein, the leaf node of the distribution gateway vulnerability data isolation tree is a vulnerability data subspace containing only one distribution edge gateway vulnerability data.
[0114] Further, in the second embodiment of the present invention, the distribution gateway vulnerability data isolation tree is specifically:
[0115]
[0116] Where s(x,n) is the distribution gateway vulnerability data isolation tree; x is the leaf node of the distribution gateway vulnerability data isolation tree; n is the number of leaf nodes of the distribution gateway vulnerability data isolation tree; a is the number of clusters of the vulnerability data clustering result; E(h(x)) is the expected height parameter of the distribution gateway vulnerability data isolation tree; c(n) is the expected density parameter of the distribution gateway vulnerability data isolation tree.
[0117] Further, in the second embodiment of the present invention, the path lengths between each leaf node of the power distribution gateway vulnerability data isolation tree and the root node of the power distribution gateway vulnerability data isolation tree are calculated in sequence, specifically:
[0118]
[0119] In the formula, x iis the i-th leaf node of the distribution gateway vulnerability data isolation tree; n is the number of leaf nodes of the distribution gateway vulnerability data isolation tree; x 0 is the root node of the distribution gateway vulnerability data isolation tree; H is the multidimensional set of distance data between each leaf node and the root node of the distribution gateway vulnerability data isolation tree; d(x i ,x 0 ) is the leaf node x i To the root node x 0 The path length between .
[0120] Further, in the second embodiment of the present invention, by comparing the average path length of the isolated tree of the distribution gateway vulnerability data and the Euler constant, the outlier detection result is obtained, specifically:
[0121] If the average path length of the isolation tree of the power distribution gateway vulnerability data is less than the Euler constant, then the outlier detection result is determined to be that there are no outliers in the power distribution edge gateway vulnerability data set;
[0122] If the average path length of the isolation tree of the power distribution gateway vulnerability data is greater than or equal to the Euler constant, it is determined that the outlier detection result is that there are outliers in the power distribution edge gateway vulnerability data set.
[0123] Further, in the second embodiment of the present invention, according to the outlier detection result, the homology of the power distribution edge gateway vulnerability corresponding to the power distribution edge gateway vulnerability data set is determined, specifically:
[0124] When the outlier detection result is that there is no outlier in the power distribution edge gateway vulnerability data set, it is determined that the power distribution edge gateway vulnerabilities corresponding to the power distribution edge gateway vulnerability data set are of the same source;
[0125] When the outlier detection result shows that there are outliers in the power distribution edge gateway vulnerability dataset, it is determined that the power distribution edge gateway vulnerability corresponding to the power distribution edge gateway vulnerability dataset is not homologous.
[0126] In summary, the second embodiment of the present invention provides a device for determining the homology of vulnerabilities in a power distribution edge gateway, which is based on the organic combination of modules and collects the load condition of the power distribution edge gateway and the vulnerability data set of the power distribution edge gateway in real time through the CPU interface; when the load condition of the power distribution edge gateway is less than the preset load threshold, the vulnerability data set of the power distribution edge gateway is clustered to obtain the vulnerability data clustering result; based on the vulnerability data clustering result, the isolation forest algorithm is used to detect the vulnerability data set of the power distribution edge gateway to obtain the outlier detection result; according to the outlier detection result, the homology of the power distribution edge gateway vulnerability corresponding to the vulnerability data set of the power distribution edge gateway is determined. In the detection of vulnerabilities in the distribution gateway, the present invention improves the detection efficiency and accuracy of homology vulnerabilities, and avoids the occurrence of safety accidents by timely identifying and repairing vulnerabilities, thereby ensuring the stability and reliability of power supply and improving the safety of the entire power system.
[0127] The specific embodiments described above further illustrate the purpose, technical solutions and beneficial effects of the present invention. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. It is particularly pointed out that for those skilled in the art, any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention should be included in the scope of protection of the present invention.
Claims
1. A method for determining the homology of vulnerabilities in a power distribution edge gateway, characterized in that: include: The load condition of the power distribution edge gateway and the power distribution edge gateway vulnerability data set are collected in real time through the CPU interface; wherein the power distribution edge gateway vulnerability data set includes the vulnerability data of each node of the power distribution edge gateway; When the load condition of the power distribution edge gateway is less than a preset load threshold, clustering the vulnerability data set of the power distribution edge gateway to obtain a vulnerability data clustering result; Based on the vulnerability data clustering result, an isolation forest algorithm is used to detect the distribution edge gateway vulnerability data set to obtain an outlier detection result; According to the outlier detection result, determining the homology of the power distribution edge gateway vulnerabilities corresponding to the power distribution edge gateway vulnerability data set; Among them, the method of determining the homology of the power distribution edge gateway vulnerability corresponding to the power distribution edge gateway vulnerability data set according to the outlier detection result is specifically as follows: When the outlier detection result is that there is no outlier in the power distribution edge gateway vulnerability data set, it is determined that the power distribution edge gateway vulnerabilities corresponding to the power distribution edge gateway vulnerability data set are of the same source; When the outlier detection result shows that there are outliers in the power distribution edge gateway vulnerability dataset, it is determined that the power distribution edge gateway vulnerability corresponding to the power distribution edge gateway vulnerability dataset is not homologous.
2. The method for determining the homology of vulnerabilities in a power distribution edge gateway according to claim 1 is characterized in that: When the load of the power distribution edge gateway is less than the preset load threshold, clustering is performed on the power distribution edge gateway vulnerability data set to obtain a vulnerability data clustering result, which is specifically: The node sequence features of each node of the power distribution edge gateway are extracted based on the power distribution edge gateway vulnerability dataset; Based on the node sequence characteristics of each node of the power distribution edge gateway, a number of singular points are screened out from each node of the power distribution gateway, and the singular points are determined as a number of cluster centers; wherein the singular points have time tags; Calculate the cosine distance between the vulnerability data of each node of the power distribution edge gateway and each of the cluster centers, and divide the vulnerability data of each node of the power distribution edge gateway into the cluster where the corresponding cluster center is located according to the preset Davies-Bouldin index; After the power distribution edge gateway vulnerability data set completes clustering processing, several clusters are formed.
3. The method for determining the homology of vulnerabilities in a power distribution edge gateway according to claim 2 is characterized in that: The node sequence features of each node of the power distribution edge gateway are extracted according to the power distribution edge gateway vulnerability data set, specifically: IDA pro is used to disassemble the power distribution edge gateway vulnerability dataset and obtain the node sequence characteristics of each node of the power distribution edge gateway.
4. The method for determining the homology of vulnerabilities in a power distribution edge gateway according to claim 1 is characterized in that: Based on the vulnerability data clustering result, the isolation forest algorithm is used to detect the distribution edge gateway vulnerability data set to obtain the outlier detection result, which is specifically: Randomly construct a first hyperplane structure, and use the first hyperplane structure to perform several spatial cuts on the power distribution edge gateway vulnerability data set to form a power distribution gateway vulnerability data isolation tree; Calculate the path length between each leaf node of the power distribution gateway vulnerability data isolation tree and the root node of the power distribution gateway vulnerability data isolation tree in sequence; According to the path length between each leaf node of the power distribution gateway vulnerability data isolation tree and the root node of the power distribution gateway vulnerability data isolation tree, the average path length of the power distribution gateway vulnerability data isolation tree is calculated; By comparing the average path length of the isolation tree of the distribution gateway vulnerability data and the Euler constant, the outlier detection result is obtained.
5. The method for determining the homology of vulnerabilities in a power distribution edge gateway according to claim 4 is characterized in that: The first hyperplane structure is randomly constructed, and the first hyperplane structure is used to perform several spatial cutting processes on the power distribution edge gateway vulnerability data set to form a power distribution gateway vulnerability data isolation tree, specifically: Randomly construct the first hyperplane structure; Using the first hyperplane structure to perform spatial segmentation processing on the power distribution edge gateway vulnerability data set to form two vulnerability data subspaces; The two vulnerability data subspaces are cyclically processed for secondary space cutting until each vulnerability data subspace contains only one distribution edge gateway vulnerability data, thereby forming a distribution gateway vulnerability data isolation tree; wherein, the leaf node of the distribution gateway vulnerability data isolation tree is a vulnerability data subspace containing only one distribution edge gateway vulnerability data.
6. The method for determining the homology of vulnerabilities in a power distribution edge gateway according to claim 5 is characterized in that: The distribution gateway vulnerability data isolation tree is specifically: Where s(x,n) is the distribution gateway vulnerability data isolation tree; x is the leaf node of the distribution gateway vulnerability data isolation tree; n is the number of leaf nodes of the distribution gateway vulnerability data isolation tree; a is the number of clusters of the vulnerability data clustering result; E(h(x)) is the expected height parameter of the distribution gateway vulnerability data isolation tree; c(n) is the expected density parameter of the distribution gateway vulnerability data isolation tree.
7. The method for determining the homology of vulnerabilities in a power distribution edge gateway according to claim 4, characterized in that: The path lengths between the leaf nodes of the power distribution gateway vulnerability data isolation tree and the root node of the power distribution gateway vulnerability data isolation tree are calculated in sequence, specifically: In the formula, x i is the i-th leaf node of the distribution gateway vulnerability data isolation tree; n is the number of leaf nodes of the distribution gateway vulnerability data isolation tree; x0 is the root node of the distribution gateway vulnerability data isolation tree; H is the multidimensional set of distance data between each leaf node and the root node of the distribution gateway vulnerability data isolation tree; d(x i ,x0) is the leaf node x i The length of the path to the root node x0.
8. The method for determining the homology of vulnerabilities in a power distribution edge gateway according to claim 4 is characterized in that: By comparing the average path length of the isolated tree of the distribution gateway vulnerability data and the Euler constant, the outlier detection result is obtained, which is specifically: If the average path length of the isolation tree of the power distribution gateway vulnerability data is less than the Euler constant, then the outlier detection result is determined to be that there are no outliers in the power distribution edge gateway vulnerability data set; If the average path length of the isolation tree of the power distribution gateway vulnerability data is greater than or equal to the Euler constant, it is determined that the outlier detection result is that there are outliers in the power distribution edge gateway vulnerability data set.
9. A device for determining the homology of vulnerabilities in a power distribution edge gateway, characterized in that: include: Acquisition module, clustering module, detection module and discrimination module; The acquisition module is used to collect the load condition of the power distribution edge gateway and the power distribution edge gateway vulnerability data set in real time through the CPU interface; wherein the power distribution edge gateway vulnerability data set includes the vulnerability data of each node of the power distribution edge gateway; The clustering module is used to perform clustering processing on the power distribution edge gateway vulnerability data set when the load condition of the power distribution edge gateway is less than a preset load threshold, and obtain a vulnerability data clustering result; The detection module is used to detect the distribution edge gateway vulnerability data set using an isolation forest algorithm based on the vulnerability data clustering result to obtain an outlier detection result; The discrimination module is used to discriminate the homology of the power distribution edge gateway vulnerabilities corresponding to the power distribution edge gateway vulnerability data set according to the outlier detection result; Among them, the method of determining the homology of the power distribution edge gateway vulnerability corresponding to the power distribution edge gateway vulnerability data set according to the outlier detection result is specifically as follows: When the outlier detection result is that there is no outlier in the power distribution edge gateway vulnerability data set, it is determined that the power distribution edge gateway vulnerabilities corresponding to the power distribution edge gateway vulnerability data set are of the same source; When the outlier detection result shows that there are outliers in the power distribution edge gateway vulnerability dataset, it is determined that the power distribution edge gateway vulnerability corresponding to the power distribution edge gateway vulnerability dataset is not homologous.
Citation Information
Patent Citations
Entity matching method based on non-main attribute outlier detection and computer program
CN108959577A
Network vulnerability identification method and system for multiple workflows
CN115378826A