A method for identifying network security risks in a power monitoring system
By performing time delay curve analysis and correlation identification on each link in the power monitoring system, marking abnormal links and judging abnormal identification, the problem of failure to effectively identify link transmission correlation changes in the prior art is solved, and the accuracy of network security risk identification and system stability and reliability are improved.
Patent Information
- Application Number
- CN202410892657.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-04
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2044-07-04
AI Technical Summary
In power monitoring systems, the prior art mainly focuses on abnormal situations in data transmission, and fails to effectively identify changes in transmission correlation between various links, resulting in a lack of a comprehensive understanding of system stability and reliability when identifying network security risks.
By monitoring and data acquisition of each link in the power system, the delay curve of each link is analyzed at random calibration time within the preset time, the delay correlation between each link is obtained, the delay correlation link is determined, and the abnormal link is marked based on the real-time delay value and the preset threshold value, and the conventional or alienated abnormality identification is judged.
Effectively identifying abnormal links and their time-delay related links improves the accuracy of identifying network security risks in the power monitoring system, and promptly identify abnormal situations in the network, such as network congestion, equipment failure or malicious attacks, thereby providing a basis for system optimization and security protection.
Smart Images

Figure CN118869280B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power monitoring systems, and particularly relates to a method for identifying network security risks in a power monitoring system. Background Art
[0002] The power system is one of the important national infrastructures. The demand for power resources in various industries shows an increasing trend year by year, requiring the entire power system to be safe, stable and reliable. With the wide application of computer and network communication technologies in power monitoring systems, the network security issues of power monitoring systems have become increasingly prominent. In order to strengthen the security management of power monitoring systems, prevent attacks on power monitoring systems by hackers and malicious codes, and ensure the safe and stable operation of the power system;
[0003] Power monitoring systems monitor and are used to adjust and control the operating states of equipment in each production unit of the power system, ensuring the safe operation and reliable power supply of the power system. With the continuous development of intelligent and information technologies, more and more emerging technologies are being applied in the power system, making the technologies, workload and work difficulty involved in power monitoring systems increase significantly during this process. In addition, modern power monitoring systems use computer network technologies to replace traditional distributed substation automation equipment technologies, bringing portability while also exposing power monitoring systems to multiple network threats;
[0004] Data passes through all nodes and links of the power monitoring system during transmission. Encryption and authentication mechanisms are adopted for each node and link to prevent data from being intercepted or tampered with during transmission;
[0005] A network security risk monitoring system and method for a power system disclosed in a patent with a patent publication number of CN115333770A relates to the technical field of network security. In the present invention, access anomaly analysis processing is performed on data access request information to obtain the corresponding data access anomaly degree; for each power data storage server, based on the data access anomaly degree corresponding to the data access request information obtained by the power data storage server, the data security degree corresponding to the power data storage server is determined; for each power data storage server, based on the data security degree corresponding to the power data storage server, the security protection processing method for performing data security protection processing on the power data storage server is determined, and data security protection processing is performed on the data stored in the power data storage server based on the security protection processing method. Based on the above method, the problem of poor data security protection effect in the prior art can be improved;
[0006] However, in a power monitoring system, the normal transmission between each link generally remains within a stable range, that is, the transmission correlation between each link. When identifying the network security risks of the power monitoring system, the abnormality of data transmission is generally identified, and the change of the transmission correlation between each link is not identified;
[0007] Therefore, when identifying the network security risks of the power monitoring system, not only the performance of a single link should be concerned, but also the transmission correlation between links should be concerned. By identifying highly correlated links, we can better understand the stability and reliability of the entire system. Based on this, a method for identifying the network security risks of the power monitoring system is proposed. Summary of the Invention
[0008] The purpose of the present invention is to provide a method for identifying the network security risks of a power monitoring system, which solves the technical problem that when identifying the network security risks of the power monitoring system, the abnormality of data transmission is generally identified, and the change of the transmission correlation between each link is not identified.
[0009] The purpose of the present invention can be achieved by the following technical solutions:
[0010] A method for identifying the network security risks of a power monitoring system includes the following steps:
[0011] Step 1: Monitor and collect data for each link of the power system;
[0012] Step 2: Randomly calibrate n calibration times within a preset time period T, analyze the time delays corresponding to each link at the n calibration times, and obtain the time delay curves corresponding to each link;
[0013] Step 3: Analyze according to the time delay values corresponding to the n calibration times on each time delay curve, obtain the correlation between each time delay curve, and obtain the time delay associated links corresponding to each link according to the correlation between each time delay curve;
[0014] Step 4: Compare the real-time time delay value of each link with a preset threshold value, and mark the link with the real-time time delay value greater than the preset value as an abnormal link;
[0015] Step 5: Obtain the time delay associated links corresponding to the abnormal links, and judge whether to generate a normal abnormal identifier or a dissimilated abnormal identifier according to whether the time delay associated links are abnormal links at the same time.
[0016] As a further solution of the present invention: The specific way to obtain the time delay curves corresponding to each link is:
[0017] A1: Randomly select one link from each link in the power system as the analysis link. Calibrate n calibration times within the preset time period T, and record the time delays R1_n of the analysis link at these times. Use the n calibration times as the abscissa and the corresponding time delay values R1_n as the ordinate to plot the time delay curve L1 of the analysis link;
[0018] A2: Repeat step A1 to obtain the time delay curves Lb corresponding to each link respectively, where n is the number of calibration times, b is the number of links, b≥1, n≥1.
[0019] As a further solution of the present invention: The specific method for calibrating n calibration times within the preset time period is:
[0020] Calibrate n times at a fixed time interval t. This is the specific method for calibrating n calibration times within the preset time period, where t = 30 seconds.
[0021] As a further solution of the present invention: The specific method for obtaining the time delay associated links corresponding to each link respectively is:
[0022] A01: From each link in the power system, select the same link as in step A1 as the analysis link. Mark the time delay values of the n calibration times on the time delay curve of the analysis link as R1_n, and mark the time delay values of the n calibration times on the time delay curves of other links as Wen, where e represents the number of other links after removing the analysis link, e = b - 1, e≥1. Calculate the similarity value Xe between the analysis link and each of the other links through the similarity analysis calculation formula. Determine the time delay curve with the similarity value Xe greater than the preset value Y1 as the time delay associated link of the analysis link;
[0023] A02: Repeat step A01 to obtain the time delay associated links corresponding to each link respectively.
[0024] As a further solution of the present invention: The similarity analysis calculation formula is specifically:
[0025]
[0026] Among them, are the means of R1_p and R1_n of the link respectively, and Wfp are the average values corresponding to the time delay values of other links after removing the analysis link respectively, n≥c≥1, e≥f≥1.
[0027] As a further solution of the present invention: The specific method for marking as an abnormal link is:
[0028] During the data transmission process, at regular time intervals J1, obtain the real-time delay values Gb of each link, compare the real-time delay values Gb with the preset threshold Y2. When Gb > Y2, mark the corresponding link as an abnormal link; when Gb ≤ Y2, do not perform any processing. Here, the time interval J1 is greater than 5 minutes.
[0029] As a further solution of the present invention: determine whether to generate a conventional abnormal identifier or an alien abnormal identifier. The specific method is as follows:
[0030] Respectively mark the number of delay-associated links corresponding to the abnormal link as h, and obtain the number g of delay-associated links that are simultaneously marked as abnormal links. When the ratio between g and h is greater than the preset limit value Y3, generate a conventional abnormal identifier; when the ratio between g and h is less than or equal to the preset limit value Y3, generate an alien abnormal identifier.
[0031] As a further solution of the present invention: when the ratio between g and h is greater than the preset limit value Y3 and less than the preset limit value Y4, only output the abnormal link, where Y4 > Y3.
[0032] As a further solution of the present invention: when the ratio between g and h is greater than the preset limit value Y3 and greater than or equal to the preset limit value Y4, generate a stop transmission signal to interrupt the data transmission. At the same time, package the data to be transmitted as an abnormal data packet and output the abnormal data packet together with the abnormal link.
[0033] Advantages of the present invention:
[0034] (1) In the present invention, by determining whether to generate a conventional abnormal identifier or an alien abnormal identifier, the abnormal identifier indicates that the abnormal delay value of the abnormal link is caused by a conventional original image, and the alien abnormal identifier indicates that the abnormal delay value of the abnormal link is not caused by a conventional original image. This is beneficial for relevant staff to further monitor the abnormal link, helps to timely identify abnormal situations in the network, such as network congestion, equipment failure or malicious attack, thereby providing a basis for system optimization and security protection, and further improving the accuracy of identifying network security risks in the power monitoring system.
[0035] (2) In the present invention, by generating a stop transmission signal to interrupt the data transmission, at the same time packaging the data to be transmitted as an abnormal data packet, and outputting the abnormal data packet together with the abnormal link, it avoids the continuous transmission of abnormal data, terminates the transmission of abnormal data in a timely manner, and further ensures network security in the power monitoring system. Description of the Drawings
[0036] The present invention will be further described below with reference to the accompanying drawings.
[0037] Figure 1It is a schematic structural diagram of the framework of a method for identifying network security risks in a power monitoring system according to the present invention;
[0038] Figure 2 It is a schematic structural diagram of the delay curve of the analysis link in a method for identifying network security risks in a power monitoring system according to the present invention. Detailed implementation manners
[0039] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0040] Embodiment 1
[0041] Please refer to Figure 1 - Figure 2 As shown, the present invention is a method for identifying network security risks in a power monitoring system, including the following steps:
[0042] Step 1, before identifying network security risks, monitor and collect the delays of each link in the power system:
[0043] Step 2: Obtain n calibration moments randomly calibrated within a preset time period T for each link, obtain the delays corresponding to each link at the n calibration moments respectively, and analyze them, and then obtain the delay curve corresponding to each link. The specific method is as follows:
[0044] It should be noted that the time interval between the n calibration moments can be a fixed time interval or random. Here, it is a preset fixed time interval t;
[0045] It should be noted that the delay refers to the time required from one end of a network to the other end, usually including transmission delay, propagation delay, processing delay and queuing delay. The specific values of the preset time period T and the fixed time interval t are determined by relevant staff according to actual needs. Here, t = 30 seconds;
[0046] A1: Randomly select one from each link in the power system as the analysis link;
[0047] A2: Record the delays corresponding to the n calibration moments of the analysis link within the preset time period T, and mark them as R1_n;
[0048] Take the n calibration moments as the abscissa and the delays R1_n corresponding to each calibration moment as the ordinate, obtain the coordinates of each calibration point, and import them into a two-dimensional coordinate system to obtain the delay curve L1 of the analysis link;
[0049] A3: Repeat steps A1 - A2 to obtain the delay curves Lb corresponding to each link respectively, where n is the number corresponding to the calibration time, b represents the number of links, b ≥ 1, n ≥ 1;
[0050] Step 3: Analyze according to the delay values corresponding to n calibration times on each delay curve, obtain the correlation between each delay curve, and then obtain the delay - associated links corresponding to each link respectively. The specific method is as follows:
[0051] A01: From each link in the power system, select the same link as in step A1 as the analysis link;
[0052] A02: Denote the delay values corresponding to n calibration times on the delay curve of the analysis link as R1 n, and denote the delay values corresponding to n calibration times on the delay curves of other links except the analysis link as Wen, where e represents the number of other links except the analysis link, e = b - 1, e ≥ 1;
[0053] A03: Obtain the similarity value Xe between the analysis curve and each other delay curve through the similarity - analysis calculation formula;
[0054] The similarity - analysis calculation formula is specifically as follows:
[0055]
[0056] Among them, are the mean values of R1 p and R1 n respectively, and Wfp is the average value corresponding to the delay values of other links except the analysis link, n ≥ c ≥ 1, e ≥ f ≥ 1;
[0057] Determine the delay curve with the similarity value Xe greater than the preset value Y1 as the delay - associated link related to the analysis link. The specific value of the preset value Y1 is determined by relevant personnel according to actual needs;
[0058] The larger the similarity value Xe, the higher the similarity between the delay curve of the corresponding link and the delay curve of the analysis link, that is, the higher the degree of synchronous change between the two delay curves, which means that there is a certain common influencing factor between the two links. For example, they both pass through the same network bottleneck or share the same physical transmission medium. In this case, if link 1 has an increase in delay due to some reason, such as network congestion, equipment failure, etc., then the delay - associated link 2 of link 1 will also increase the delay synchronously;
[0059] A04: Repeat steps A01 - A03 to obtain the delay - associated links corresponding to each link respectively;
[0060] By analyzing the correlation between each delay curve, the delay correlation links corresponding to each link are obtained, which is convenient for targeted analysis of abnormal links in the later stage;
[0061] Step 4: Obtain the real-time delay values of each link in the power monitoring system, compare them with the preset threshold value, and mark the links with real-time delay values greater than the preset value as abnormal links. The specific method is as follows:
[0062] When data is transmitted on each link, at every time interval J1, obtain the real-time delay values of each link and mark them as Gb. Compare the real-time delay value Gb with the preset threshold value Y2. When Gb > Y2, mark the corresponding link as an abnormal link. When Gb ≤ Y2, no processing is performed. The specific value of the preset threshold value Y2 is determined by relevant personnel according to actual needs, and J1 > 5 minutes;
[0063] Step 5: Obtain the delay correlation links corresponding to the abnormal links, and judge whether to generate a normal abnormal identifier or a dissimilated abnormal identifier according to whether the delay correlation links are also abnormal links at the same time. The specific method is as follows:
[0064] Mark the number of delay correlation links corresponding to the abnormal links as h respectively, and obtain the number g of delay correlation links that are also marked as abnormal links at the same time. When g / h is greater than the preset limit value Y3, it indicates that the proportion of the delay values of the delay correlation links corresponding to the abnormal links that are abnormal at the same time as the abnormal links is relatively large, and a normal abnormal identifier is generated. When g / h is less than or equal to the preset limit value Y3, it indicates that the proportion of the delay values of the delay correlation links corresponding to the abnormal links that are abnormal at the same time as the abnormal links is relatively small, and a dissimilated abnormal identifier is generated. The specific value of the preset limit value Y3 is determined by relevant personnel according to actual needs;
[0065] By analyzing the delays corresponding to each link at n calibration moments, the delay curves corresponding to each link are obtained. According to the delay values corresponding to the n calibration moments on each delay curve, the correlation between the delay curves is obtained. According to the correlation between the delay curves, the delay-related links corresponding to each link are obtained. The real-time delay values of each link in the power monitoring system are obtained and compared with the preset threshold value. The links with real-time delay values greater than the preset value are marked as abnormal links conventionally, and the delay-related links corresponding to the abnormal links are obtained. According to whether the delay-related links are abnormal links at the same time, a normal abnormality identifier or a dissimilated abnormality identifier is judged and generated. The abnormality identifier indicates that the delay value of the abnormal link is abnormal due to the normal original graph, and the dissimilated abnormality identifier indicates that the delay value of the abnormal link is abnormal not due to the normal original graph, which is beneficial for relevant staff to further monitor the abnormal links, helps to timely identify abnormal situations in the network, such as network congestion, equipment failure or malicious attack, so as to provide a basis for system optimization and security protection, and further improve the accuracy of identifying network security risks in the power monitoring system.
[0066] Embodiment 2
[0067] As Embodiment 2 of the present invention, when the present application is specifically implemented, compared with Embodiment 1, the technical solution of this embodiment is only different from that of Embodiment 1 in that in this embodiment,
[0068] When the ratio between g and h is greater than the preset limit value Y3 and less than the preset limit value Y4, only the abnormal links are output, which is beneficial for relevant staff to timely monitor and analyze the risks of the abnormal links and helps to timely identify abnormal situations in the network. The specific values of Y3 and Y4 are both determined by relevant personnel according to actual needs, satisfying Y4 > Y3;
[0069] When the ratio between g and h is greater than or equal to the preset limit value Y3 and greater than or equal to the preset limit value Y4, a stop transmission signal is generated to interrupt the data transmission. At the same time, the data to be transmitted is packaged into abnormal data packets, and the abnormal data packets are output together with the abnormal links, avoiding the continuous transmission of abnormal data and terminating the transmission of abnormal data in time, further ensuring network security in the power monitoring system;
[0070] Embodiment 3
[0071] As Embodiment 3 of the present invention, when the present application is specifically implemented, compared with Embodiment 1 and Embodiment 2, the technical solution of this embodiment is to combine and implement the solutions of the above Embodiment 1 and Embodiment 2.
[0072] The above formulas are all dimensionless and take their numerical calculations. The formulas are obtained by collecting a large amount of data for software simulation to get a formula closest to the actual situation. The preset parameters and threshold selection in the formulas are set by those skilled in the art according to the actual situation.
[0073] As described above, it is only the specific implementation manner of this application. However, the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered within the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.
Claims
1. A method for identifying network security risks in a power monitoring system, characterized in that: The following steps are involved: Step 1: Monitor and collect data from each link of the power system; Step 2: Randomly calibrate n calibration moments within a preset time length T, analyze the delays corresponding to each link at the n calibration moments, and obtain the delay curves corresponding to each link. The specific method is as follows: A1: Randomly select a link from each link of the power system as the analysis link, calibrate n calibration moments within the preset time length T, record the delay R1n of the analysis link at these moments, use the n calibration moments as the horizontal coordinate and the corresponding delay value R1n as the vertical coordinate to draw the delay curve L1 of the analysis link; A2: Repeat step A1 to obtain the delay curve Lb corresponding to each link, where n is the number of calibration moments, b is the number of links, b≥1, n≥1; Step 3: Analyze the delay values corresponding to the n calibration moments on each delay curve, obtain the correlation between the delay curves, and then obtain the delay associated links corresponding to each link according to the correlation between the delay curves. The acquisition method is as follows: A01: From each link of the power system, select the same link as in step A1 as the analysis link, mark the delay values of the delay curve of the analysis link at n calibration moments as R1n, and mark the delay values of the delay curves of other links at n calibration moments as Wen, where e represents the number of other links after removing the analysis link, e=b-1, e≥1, calculate the similarity value Xe between the analysis link and each other link through the similarity analysis calculation formula, and determine the delay curve with a similarity value Xe greater than a preset value Y1 as the delay associated link of the analysis link; A02: Repeat step A01 to obtain the delay associated links corresponding to each link; Step 4: Compare the real-time delay value of each link with the preset value threshold Y2, and mark the link whose real-time delay value is greater than the preset value Y2 as an abnormal link; Step 5: Obtain the delay-associated link corresponding to the abnormal link, and determine whether to generate a conventional abnormal flag or an alienated abnormal flag according to whether the delay-associated link is also an abnormal link. The specific determination method is as follows: The number of delay-associated links corresponding to the abnormal link is marked as h, and the number of delay-associated links marked as abnormal links at the same time is obtained. When the ratio between g and h is greater than the preset limit Y3, a regular abnormal flag is generated; when the ratio between g and h is less than or equal to the preset limit Y3, an alienated abnormal flag is generated.
2. A method for identifying network security risks of a power monitoring system according to claim 1, characterized in that: The specific method of calibrating n calibration moments within a preset time period is: The n moments are calibrated at a fixed time interval t, where t = 30 seconds.
3. A method for identifying network security risks of a power monitoring system according to claim 1, characterized in that: The specific method of marking an abnormal link is as follows: During the data transmission process, the real-time delay value Gb of each link is obtained at every time interval J1, and the real-time delay value Gb is compared with the preset value threshold Y2. When Gb>Y2, the corresponding link is marked as an abnormal link. When Gb≤Y2, no processing is performed. Here, the time interval J1 is greater than 5 minutes.
4. A method for identifying network security risks of a power monitoring system according to claim 1, characterized in that: When the ratio between g and h is greater than a preset limit value Y3 and less than a preset limit value Y4, only the abnormal link is output, Y4>Y3.
5. A method for identifying network security risks of a power monitoring system according to claim 4, characterized in that: When the ratio between g and h is greater than the preset limit value Y3 and greater than or equal to the preset limit value Y4, a stop transmission signal is generated to interrupt data transmission, and the data to be transmitted is packaged into an abnormal data packet, and the abnormal data packet is output simultaneously with the abnormal link.
Citation Information
Patent Citations
Network security risk monitoring system and method for power system
CN115333770A
Network anomaly detection method based on round-trip time delay time sequence and related device
CN114039889A
Passive and comprehensive hierarchical anomaly detection system and method
US20130054783A1