Multi-threshold network attack detection method integrating ellipsoid and polytope state estimation domain

By combining the ellipsoid and polyhedral state estimation domains in a networked control system and adopting a multi-threshold detection method, the problems of large computational complexity and conservative judgment in the existing technology are solved, and flexible and accurate detection of network attacks is achieved.

CN118972133BActive Publication Date: 2025-10-10SHANGHAI MARITIME UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411127474.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-16
Publication Date
2025-10-10
Estimated Expiration
2044-08-16

AI Technical Summary

Technical Problem

Existing network attack detection methods rely on specific mathematical models or statistical models, which are difficult to be effectively applied in actual industrial production scenarios. In addition, existing set membership estimation methods are conservative when judging network attacks and cannot accurately determine the extent of the attack.

Method used

A multi-threshold network attack detection method based on the comprehensive ellipsoid and polyhedral state estimation domain is adopted. By constructing a discrete time-varying networked control system, designing prediction filters and observers, using centrally symmetric polytopes to describe the prediction set and ellipsoids to describe the observation set, combining the Monte Carlo method to calculate the area of ​​the intersection part, and setting multiple thresholds through the K-means clustering algorithm to judge the degree of attack.

Benefits of technology

While ensuring detection accuracy, it reduces the amount of calculation, improves the flexibility and accuracy of attack detection, and can effectively judge the minor, mild, moderate and severe levels of network attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118972133B_ABST
    Figure CN118972133B_ABST
Patent Text Reader

Abstract

The application relates to a multi-threshold network attack detection method integrating an ellipsoid and a polytope state estimation domain, and comprises the following steps: a discrete time-varying form of a networked control system is constructed; a prediction filter and an observer are respectively designed for the case that the networked control system is subjected to a false information injection attack, so that a system state prediction set and a system state observation set are obtained, wherein the system state prediction set is described by using a central symmetric polytope, and the system state observation set is described by using an ellipsoid; the intersection area of the central symmetric polytope and the ellipsoid is calculated; the relationship between the intersection area and different set thresholds is judged; and a network attack detection result containing an attacked degree is obtained. Compared with the prior art, the application has the advantages of avoiding excessive calculation amount while ensuring accuracy and real-time performance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of networked control technology, and in particular to a multi-threshold network attack detection method for a comprehensive ellipsoid and polyhedral state estimation domain. Background Art

[0002] For typical networked control systems—those that transmit system data over open networks—malicious attacks, such as DoS attacks, false information injection attacks, and replay attacks, can cause data transmission problems. Therefore, timely detection of attacks, their location, and the implementation of appropriate control strategies are crucial for the safe and stable operation of networked control systems.

[0003] Currently available attack detection methods primarily include Kalman filter-based detectors, weighted least squares methods, Bayesian detection methods based on binary assumptions, and fault detection and isolation techniques. The basic idea behind these methods is to calculate the residual between the actual system output and the model's predicted output, then compare the residual with a pre-set threshold. If the threshold is exceeded, the system is considered to be under attack. However, these detection methods all rely on specific mathematical or statistical models and require that noise and external disturbances follow a certain probability distribution, requirements that are often difficult to meet in actual industrial production scenarios. Therefore, consideration is given to modeling external disturbances encountered in actual production, as well as measurement and process noise in control systems, as unknown but bounded (UBB) noise. To address UBB noise, researchers have begun studying set membership estimation methods. Because the estimated result from set membership estimation can be expressed as a feasible set rather than a single estimated value, the use of set membership estimation methods for detecting network attacks has been proposed in recent years. First, a set membership estimator is designed to obtain a one-step-ahead prediction set of the system state and an actual estimate set. The system is then judged to determine whether it is under attack by determining whether there is an intersection between the two sets. Normally, both sets should contain the true state of the system. When the two sets do not intersect, it can be assumed that the system is affected by an attack, resulting in errors in data collection and calculation. When the two sets intersect, it is assumed that there is no attack or that the impact of the attack is minimal. This method of determining whether an attack exists solely by determining whether the two sets intersect is somewhat conservative. For example, when there is only a small intersection between the two sets, the aforementioned criteria can be used to determine that there is no attack. However, in reality, the system is under attack, and the intersection no longer contains the true state value of the system. Summary of the Invention

[0004] The purpose of the present invention is to provide a multi-threshold network attack detection method for a comprehensive ellipsoid and polyhedral state estimation domain that maintains detection accuracy while reducing the amount of calculation.

[0005] The object of the present application can be achieved by the following technical solutions:

[0006] A multi-threshold network attack detection method integrating ellipsoid and polytope state estimation domains, comprising the following steps:

[0007] A discrete time-varying form of networked control system is constructed;

[0008] A prediction filter and an observer are designed for the case that the networked control system is subjected to false information injection attack, to obtain a system state prediction set and a system state observation set, wherein the system state prediction set is described by a central symmetric polytope, and the system state observation set is described by an ellipsoid;

[0009] The intersection area of the central symmetric polytope and the ellipsoid is calculated, the relationship between the intersection area and different threshold values set is judged, and a network attack detection result containing the degree of attack is obtained.

[0010] Further, the expression of the discrete time-varying form of networked control system is:

[0011]

[0012] wherein w k and v k belong to the following ellipsoid sets:

[0013]

[0014] wherein x k+1 is the state vector of the system at k+1 time, A, B and C represent the state transition matrix, the control matrix and the measurement matrix of the system respectively, x k represents the state vector of the system at k time, u k represents the input vector of the system, w k represents the process noise of the system, v k represents the measurement noise of the system, y k is the measurement data of the system at k time, is a known matrix with compatible dimension, is an ellipsoid set of the system process noise, is an ellipsoid set of the system measurement noise.

[0015] Further, the expression form of the prediction filter is:

[0016]

[0017] wherein, is the system state prediction value at k time, is the system state observation value at time k, A, B, and C represent the system state transfer matrix, control matrix, and measurement matrix respectively, T, L, and N are the prediction filter parameters, and y k is the measurement data of the system at time k.

[0018] Furthermore, the observer design step includes:

[0019] In the case where the sensor channel of the networked control system is attacked by false information injection, the measurement data actually received by the estimator is defined;

[0020] Based on the actual measurement data received, an observer is designed to obtain the system state prediction value and integrate the system state observation set.

[0021] Furthermore, the measurement data actually received by the estimator is:

[0022]

[0023] Among them, a k The set of ellipsoids belonging to:

[0024]

[0025] Where, is the actual measurement data received by the system at time k, y k is the actual output of the system at time k, a k False information injected by attackers, is a known matrix with compatible dimensions, is the ellipsoid set of false information.

[0026] Furthermore, the observer is expressed as:

[0027]

[0028] Where, is the system state observation value at time k+1, is the system state observation value at time k, G k 、J k are the observer parameters, A, B and C represent the state transfer matrix, control matrix and measurement matrix of the system respectively. is the measurement data actually received by the system at time k+1.

[0029] Furthermore, the Monte Carlo method is used to calculate the area of ​​the intersection, and the calculation process is:

[0030] Drawing the centrosymmetric polyhedron and the ellipsoid on the same picture;

[0031] Place α random points in the centrally symmetric polyhedron, calculate the number β of points that fall simultaneously in the ellipsoid, and calculate the area of ​​the intersection based on β and α.

[0032] Furthermore, the step of calculating the area of ​​the intersection portion includes:

[0033] Calculate the ratio of the area of ​​the intersecting parts. The calculation expression is:

[0034]

[0035] Calculate the area of ​​the intersection part, the calculation expression is:

[0036] S=R×S p

[0037] Where R is the area ratio of the intersection to the central symmetric polyhedron, S is the area of ​​the intersection, and S p is the area of ​​the centrosymmetric polyhedron.

[0038] Furthermore, the step of setting different thresholds includes:

[0039] The intersection area S and the intersection area ratio R obtained in the prior step are processed using the K-means clustering algorithm to obtain the data values ​​of the two cluster center points as different thresholds S1 and S2 for judging the degree of attack.

[0040] Furthermore, the relationship between the area of ​​the intersection and different set thresholds is:

[0041] If S=1, the networked control system is not attacked, where S is the area of ​​the intersection;

[0042] If 0≤S<S1, the networked control system is under serious attack, where S1 is the set first threshold;

[0043] If S1<S<S2, the networked control system is under moderate attack, where S2 is the set second threshold;

[0044] If S2<S≤1, the networked control system is slightly attacked.

[0045] Compared with the prior art, the present invention has the following beneficial effects:

[0046] (1) The traditional detection method uses two ellipsoids to describe the prediction set and the observation set of the system state quantity, and the calculation amount is large, and a large number of iterations need to be performed, and the present application combines the characteristics of the central symmetric polyhedron with small calculation amount, and the observation set and the prediction set of the system state quantity are described by ellipsoids and central symmetric polyhedrons respectively, and the degree of attack is judged by calculating the size of the intersection area, which can avoid excessive calculation amount while ensuring accuracy.

[0047] (2) The area size of the irregular intersection figure obtained by the Monte Carlo method is used, and then the prior data is classified by the K-means clustering algorithm to obtain a plurality of classification thresholds for judging the attack situation, so as to judge different degrees of attack of the system, compared with the existing detection method which only judges whether the attack exists or not by whether there is intersection or not, the detection method proposed in the present application is more flexible. BRIEF DESCRIPTION OF DRAWINGS

[0048] Figure 1 It is a method flowchart of the present application;

[0049] Figure 2 It is the intersection of the prediction set and the observation set under different conditions of the present application;

[0050] Figure 3 It is a schematic diagram of the Monte Carlo method for calculating the intersection area of the present application.

[0051] Figure 4 It is a schematic diagram of the K-means clustering algorithm of the present application. DETAILED DESCRIPTION

[0052] The present application will be described in detail below in combination with the drawings and specific embodiments. The present embodiment is implemented on the premise of the technical solution of the present application, and gives a detailed implementation mode and specific operation process, but the protection scope of the present application is not limited to the following examples.

[0053] The present embodiment provides a multi-threshold network attack detection method combining ellipsoid and polyhedron state estimation domain, which is designed based on the basic principle of set member estimation algorithm. The basic idea of set member estimation method is to provide a set for system state estimation instead of a single numerical point. Any element in this set may be the true value of the system state, so it is called feasible set. For example Figure 2As shown, when there is no attack in the system, the prediction set and observation set obtained by the set membership estimation method both contain the true value of the system state, so there is always an intersection between the centrally symmetric polyhedron and the ellipsoid obtained by drawing; however, when the attacker injects false information into the sensor channel of the system, causing a sudden change in the system's measured output, the prediction value or observation value obtained by set membership estimation deviates from the true value, and the prediction set or observation set no longer contains the true value of the system state, and the two may not intersect. This embodiment uses an ellipsoid to describe the actual observation set of the system, which can change the parameters of the observer according to the real-time changes in the system state, thereby ensuring the accuracy of the observation value; the predicted value of the system state is described by a centrally symmetric polyhedron, and the parameters of the predictor can be obtained with only one calculation, greatly reducing the amount of calculation. Using a method combining the two sets to detect attacks can avoid excessive calculations while ensuring accuracy and real-time performance.

[0054] Specifically, if Figure 1 As shown, the method includes the following steps:

[0055] Step 1: Construct the system state prediction set and system state observation set of the networked control system.

[0056] Consider the networked control system as a discrete time-varying system of the following form:

[0057]

[0058] Among them, x k represents the state vector of the system, u k represents the input vector of the system, y k represents the measured output of the system, A, B and C represent the state transfer matrix, control matrix and measurement matrix of the system respectively. k represents the process noise of the system, v k Denotes the measurement noise of the system, and assumes that both noises are unknown bounded noises, belonging to the following ellipsoid sets:

[0059]

[0060] in is a known matrix with compatible dimensions.

[0061] In the case where the sensor channel of the networked control system is attacked by false information injection, the measurement data actually received by the estimator is defined as:

[0062]

[0063] where a k represents the false information injected by the attacker. Assume that the false information is unknown and bounded and belongs to the following ellipsoid set:

[0064]

[0065] in is a known matrix with compatible dimensions.

[0066] The prediction filter is designed as follows:

[0067]

[0068] Where T, L, and N are the parameters of the prediction filter to be determined. The predicted values ​​of the system state obtained by the prediction filter are described by a centrosymmetric polyhedron. Describing the predicted values ​​of the system state using a centrosymmetric polyhedron allows the predictor parameters to be obtained in a single calculation, significantly reducing the computational effort.

[0069] The designed observer is as follows:

[0070]

[0071] Among them G k 、J k The observer parameters to be determined are given by the observer. The observations of the system state obtained by the observer are described by an ellipse. Using an ellipsoid to describe the actual observation set of the system allows the observer parameters to be changed in response to real-time changes in the system state, thereby ensuring the accuracy of the observations.

[0072] Step 2: Calculate the area of ​​the intersecting part.

[0073] The obtained centrosymmetric polyhedron and ellipsoid are plotted on a two-dimensional plane, and the Monte Carlo method is used to calculate the area of ​​the intersection between the two. The specific process is as follows: Figure 3 As shown, first place α random points in the central symmetric polyhedron, then calculate the number of points that fall into the ellipsoid at the same time and record it as β, and get the ratio of the intersection area to the area of ​​the central symmetric polyhedron, which is recorded as R, where Then we can consider the area of ​​the intersection of the two to be S, where S = R × S p , where S p is the area of ​​the centrosymmetric polyhedron.

[0074] Step 3: Determine the intensity of the attack on the system.

[0075] like Figure 4 As shown in the figure, the area size S and area ratio R of the intersection obtained through the prior step are classified by the K-means clustering algorithm on the large amount of prior data obtained, and the obtained cluster center point values ​​S1 and S2 are used as thresholds for judging the attack situation:

[0076] If S=1, the networked control system is not attacked, where S is the area of ​​the intersection;

[0077] If 0≤S<S1, the networked control system is severely attacked;

[0078] If S1<S<S2, the networked control system is under moderate attack;

[0079] If S2<S≤1, the networked control system is slightly attacked.

[0080] In summary, this embodiment takes into account the conservatism and limitations of existing methods and designs a set membership estimation attack detection method that combines ellipsoids and centrosymmetric polytopes for attacked networked control systems. The set membership estimation method is used to obtain the intersection graph of the estimated set and the predicted set. The Monte Carlo method is then used to calculate the size and area ratio of the irregular intersection area. The K-means clustering algorithm is used to classify the prior data to obtain multiple thresholds, thereby judging the different degrees of attack on the system.

[0081] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.

[0082] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.

Claims

1. A multi-threshold network attack detection method based on the state estimation domain of integrated ellipsoid and polyhedron, characterized in that: The following steps are involved: Construct discrete time-varying networked control systems; Aiming at the situation where networked control systems are attacked by false information injection, a prediction filter and an observer are designed respectively to obtain a system state prediction set and a system state observation set, wherein the system state prediction set is described by a centrally symmetric polyhedron, and the system state observation set is described by an ellipsoid. The intersection area of ​​the centrally symmetric polyhedron and the ellipsoid is calculated, and the relationship between the intersection area and different set thresholds is determined to obtain a network attack detection result including the degree of attack.

2. The multi-threshold network attack detection method based on the integrated ellipsoid and polyhedral state estimation domain according to claim 1 is characterized in that: The expression of the discrete time-varying networked control system is: , in, 、 Belong to the following ellipsoid sets respectively: , Where, for k +1 time the state vector of the system, They represent the state transfer matrix, control matrix and measurement matrix of the system respectively, express k The state vector of the system at time t, represents the input vector of the system, represents the process noise of the system, represents the measurement noise of the system, for The measurement data of the time system, is a known matrix with compatible dimensions, is the ellipsoid set of system process noise, The set of ellipsoids that measure the noise for the system.

3. The multi-threshold network attack detection method based on the integrated ellipsoid and polyhedral state estimation domain according to claim 1 is characterized in that: The prediction filter is expressed as: , Where, for The predicted value of the system state at the moment, for k The observed value of the system state at time They represent the state transfer matrix, control matrix and measurement matrix of the system respectively, is the prediction filter parameter, for The measurement data of the time system, represents the input vector of the system.

4. The multi-threshold network attack detection method based on the integrated ellipsoid and polyhedral state estimation domain according to claim 1 is characterized in that: The observer design step includes: In the case where the sensor channel of the networked control system is attacked by false information injection, the measurement data actually received by the estimator is defined; Based on the actual measurement data received, an observer is designed to obtain the system state prediction value and integrate the system state observation set.

5. The multi-threshold network attack detection method based on the integrated ellipsoid and polyhedral state estimation domain according to claim 4 is characterized in that: The measurement data actually received by the estimator is: , in, The set of ellipsoids belonging to: , Where, for k The measurement data actually received by the system at the moment, for k The actual output of the system at that moment, False information injected by attackers, is a known matrix with compatible dimensions, is the ellipsoid set of false information.

6. The multi-threshold network attack detection method based on the integrated ellipsoid and polyhedral state estimation domain according to claim 4 is characterized in that: The expression of the observer is: , Where, for k +1 time system state observation value, for k The observed value of the system state at time are the observer parameters, They represent the state transfer matrix, control matrix and measurement matrix of the system respectively, for The measurement data actually received by the system at the moment, represents the input vector of the system.

7. The multi-threshold network attack detection method based on the integrated ellipsoid and polyhedral state estimation domain according to claim 1 is characterized in that: The Monte Carlo method is used to calculate the area of ​​the intersection, and the calculation process is: Drawing the centrosymmetric polyhedron and the ellipsoid on the same picture; Place a Random points, calculate the number of points that fall within the ellipsoid at the same time , and according to and Calculate the area of ​​the intersection.

8. The multi-threshold network attack detection method based on the integrated ellipsoid and polyhedral state estimation domain according to claim 7 is characterized in that: The step of calculating the area of ​​the intersection portion includes: Calculate the ratio of the area of ​​the intersecting parts. The calculation expression is: , Calculate the area of ​​the intersection part, the calculation expression is: , Where, is the area ratio of the intersecting part to the centrosymmetric polyhedron, is the area of ​​the intersection, is the area of ​​the centrosymmetric polyhedron.

9. The multi-threshold network attack detection method based on the integrated ellipsoid and polyhedral state estimation domain according to claim 8 is characterized in that: The steps of setting different thresholds include: The area of ​​the intersection obtained according to the priori step and the ratio of the area of ​​the intersecting parts , using K-means clustering algorithm to process, get the data values ​​of two cluster centers, which are used as different thresholds to judge the degree of attack 、 .

10. The multi-threshold network attack detection method based on the integrated ellipsoid and polyhedral state estimation domain according to claim 1 is characterized in that: The relationship between the area of ​​the intersection and the different thresholds set is: like When , the networked control system is not attacked, is the area of ​​the intersection; like When the network control system is seriously attacked, is the first threshold value set; like When , the networked control system is under medium attack, among which is the set second threshold; like When , the networked control system is slightly attacked.

Citation Information

Patent Citations

  • Active attack detection method for improving detection rate

    CN114063602A

  • Method and apparatus for assessing risk of vehicle, and system for monitoring attack

    WO2024065283A1