A method and system for detecting network attacks on a power converter system based on electrical signals

By calculating steady-state confidence boundaries and grey relational filtering features in a converter system, training a support vector machine model, and monitoring three-phase current and voltage signals in real time, the real-time and accuracy problems of network attack detection in converter systems are solved, achieving fast and accurate attack identification and protection.

CN118972141BActive Publication Date: 2025-11-25HUNAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411161651.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-23
Publication Date
2025-11-25
Estimated Expiration
2044-08-23

AI Technical Summary

Technical Problem

Existing technologies struggle to balance real-time performance and accuracy in network attack detection within converter systems. Furthermore, existing methods exhibit lag in detecting network attacks, failing to promptly disconnect the attack source and compromising system security.

Method used

By acquiring historical steady-state operating conditions and network attack data, calculating steady-state confidence boundaries, using the grey relational analysis method to filter effective features, training a support vector machine model, and monitoring three-phase current and voltage signals in real time, the system can quickly determine whether a network attack has occurred and disconnect the server based on the network attack type detection model, thus achieving rapid and accurate attack type identification.

Benefits of technology

It enables rapid and accurate detection of network attacks in converter systems, reducing detection time and preventing further damage to the system. It is suitable for critical infrastructure and balances real-time detection with high accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118972141B_ABST
    Figure CN118972141B_ABST
Patent Text Reader

Abstract

The application discloses a kind of converter system network attack detection method and system based on electric signal, the method includes: obtaining data set under historical steady state condition and historical network attack data set;According to the minimum value of the periodicity rule change of the trust factor calculated according to the data set under the steady state condition, steady-state trust boundary is obtained;According to the historical network attack data set and grey correlation degree method screening training data set, input machine learning model training obtains network attack type detection model;Real-time monitoring and collecting three-phase current signal and three-phase voltage signal of converter system, calculating trust factor, comparing trust factor and steady-state trust boundary to determine whether to suffer network attack, if suffer, disconnect server from attack source, and according to network attack type detection model, the type of network attack is judged in real time.The application solves the problem that existing network attack detection is difficult to consider detection real-time and detection accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network attack detection, and particularly relates to a converter system network attack detection method and system based on electrical signals. BACKGROUND

[0002] With the promotion of Industry 4.0 and the industrial internet, cyber-physical information systems have developed rapidly, and high interconnection and data sharing have been achieved between various systems. However, the increasing connectivity, expanding attack surface and different infrastructures of these complex systems also bring network security challenges. Current network security has been valued at the system level, but the security of the device level, especially the security of the converter system, has been largely ignored. Today's converters generally have communication functions and can be connected to the power grid or cloud services, which increases the risk of these devices being attacked. Therefore, it is of great significance to effectively and timely detect network attacks on the converter system.

[0003] Although some researches have explored the impact of network attacks on converter systems, most of the existing work mainly focuses on fault detection and diagnosis. Since the converter system plays a role in efficient control and transmission of electric energy, network attacks should be detected in time and effectively before the device fails to reduce losses. In order to solve the vulnerability brought by network attacks, model-based and data-driven methods have been proposed. However, due to the inevitable parameter mismatch when constructing the model and the complexity of the power electronic-based smart power system, model-based methods rely on accurate mathematical models of system health and are difficult to apply to practical engineering. In contrast, data-driven methods use measured data to detect network attacks without explicit mathematical models and have been widely applied, especially machine learning and deep learning models.

[0004] In time-series-based detection problems, the use of machine learning or deep learning models often requires balancing detection real-time performance with detection accuracy. Using data from fewer time sampling points means fewer effective features, thus impacting accuracy. As the attack time increases, the correlation between features and different network attack types strengthens. To obtain strongly correlated features and improve detection accuracy, more time sampling points are needed, leading to compromised real-time performance. In practical applications, network attack detection for converter systems should include two steps: 1) determining whether a network attack has occurred; 2) detecting the specific type of network attack. Existing methods complete both steps using a single algorithm model, meaning that detecting a specific network attack also confirms that a network attack has occurred. At this point, the algorithm model has already consumed a significant amount of time to accurately detect the network attack, and the converter system may have already experienced malfunctions and unavoidable losses due to the attack. Therefore, it is necessary to determine whether the system has encountered a network attack in the shortest possible time during step 1. If an attack is detected, the server's network connection should be immediately disconnected to cut off the attack source and ensure the system's operational stability is not further compromised. Only then should the specific type of network attack be detected, and adjustments made to address the system's unstable operation caused by different attack types.

[0005] In summary, existing technologies for detecting network attacks on converter systems can be broadly categorized into three types, each with its own shortcomings:

[0006] (1) Model-driven approach: Mathematical models are usually based on some assumptions, which may not be completely consistent with the real world situation, leading to model errors, especially when dealing with nonlinear, multivariable and high-dimensional problems; at the same time, mathematical models are usually difficult to deal with noise and uncertainty, which may lead to model instability.

[0007] (2) Data-driven approach: When applying data-driven approach to time series-based detection problems, the real-time performance and accuracy of detection should be coordinated. Some studies ignore the high computing power and long time consumption of complex models in order to obtain high accuracy, which is not suitable for engineering problems in emergency situations.

[0008] (3) Network Attack Detection Strategies: Current methods generally involve using a machine learning or deep learning algorithm to complete two detection steps (detecting whether a network attack has occurred and detecting the specific type of network attack). If the algorithm model is complex or requires a large amount of real-time detection data, the acquisition of detection results is already delayed, potentially causing irreparable vulnerabilities to the system security. This makes it unsuitable for emergency situations and critical infrastructure. The more data input to different machine learning algorithms and the more complex the model structure, the longer the computation time. It is worth noting that existing inventions only focus on detection accuracy and do not consider the impact of detection time. Summary of the Invention

[0009] (I) Technical problems to be solved

[0010] Based on the above problems, the present application provides an electric signal-based converter system network attack detection method and system to solve the problem that the existing network attack detection cannot balance detection real-time and detection accuracy.

[0011] (II) Technical solutions

[0012] Based on the above technical problems, the present application provides an electric signal-based converter system network attack detection method, comprising:

[0013] S1, obtaining a historical steady-state working condition data set and a historical network attack data set: the historical steady-state working condition data set includes three-phase current signals and three-phase voltage signals of the converter system under steady-state working conditions, the historical network attack data set includes three-phase current signals and three-phase voltage signals of the converter system, and the corresponding network attack type;

[0014] S2, determining a steady-state trusted boundary: calculating an influence factor according to the three-phase current signals and the three-phase voltage signals, calculating a trusted factor according to the influence factor, and obtaining the steady-state trusted boundary according to the minimum value of the periodic regular variation of the trusted factor calculated according to the data set under the steady-state working condition;

[0015] S3, training to obtain a network attack type detection model: taking the time series of each sampling point of the three-phase voltage signals and the three-phase current signals of the historical network attack data set as features, screening effective features by a gray correlation method to form a training data set, inputting the training data set into a machine learning model for training to obtain a network attack type detection model;

[0016] S4, real-time monitoring of network attacks and determination of network attack types: real-time monitoring and collecting three-phase current signals and three-phase voltage signals of the converter system, real-time calculation of the trusted factor, determination of network attacks when the real-time calculated trusted factor meets the network attack threshold requirements set according to the steady-state trusted boundary, disconnection of the server from the attack source, and real-time determination of the type of network attacks according to the network attack type detection model.

[0017] Further, in S2, the calculation of the influence factor according to the three-phase current signals and the three-phase voltage signals, and the calculation of the trusted factor according to the influence factor comprise:

[0018] S21, calculating the influence factor of the three-phase voltage according to the three-phase voltage signals, including the A-phase voltage influence factor, the B-phase voltage influence factor, the C-phase voltage influence factor, and the three-phase voltage average influence factor, i.e. af , V bf , Vcf and V sf :

[0019]

[0020] wherein, i represents the current time, i-1 represents the last time; Va i , Vb i and Vc i respectively represent the A-phase voltage, the B-phase voltage and the C-phase voltage at the current time; Va i-1 , Vb i-1 and Vc i-1 respectively represent the A-phase voltage, the B-phase voltage and the C-phase voltage at the last time; and α is a weight coefficient of the voltage fluctuation amplitude; and β is a weight coefficient of the voltage distortion degree.

[0021] S22, calculating an influence factor of three-phase current according to the three-phase current signal, including an A-phase current influence factor, a B-phase current influence factor, a C-phase current influence factor and a three-phase current average influence factor, namely I af , I bf , I cf and I sf :

[0022]

[0023] wherein, Ia i , Ib i and Ic i respectively represent the A-phase current, the B-phase current and the C-phase current at the current time; Ia i-1 , Ib i-1 and Ic i-1 respectively represent the A-phase current, the B-phase current and the C-phase current at the last time; I af , I bf , I cf and I sf respectively represent the A-phase current influence factor, the B-phase current influence factor, the C-phase current influence factor and the three-phase current average influence factor; and α is a weight coefficient of the current fluctuation amplitude; and β is a weight coefficient of the current distortion degree.

[0024] S23, introducing a sigmod function, and calculating a credibility factor Y_re according to the three-phase voltage average influence factor and the three-phase current average influence factor:

[0025]

[0026] Further, the α is 0.6, and the β is 0.4.

[0027] Further, the S3 includes:

[0028] S31, characterized by time series of three-phase voltage signals and three-phase current signals of the historical network attack data set, analyzing the correlation coefficient of each feature with different network attack types by a grey correlation degree method;

[0029] S32, the correlation coefficient greater than the average value of the correlation coefficient is used to form a training data set;

[0030] S33, the training data set is input into a machine learning model for training to obtain a network attack type detection model.

[0031] Further, the correlation coefficient of each feature with different network attack types by a grey correlation degree method comprises: taking label data corresponding to different attack situations as a reference sequence Y, selecting part of the electric signal time series in the network attack time as a comparison sequence X m , calculating the correlation coefficient between the reference sequence and the comparison sequence:

[0032]

[0033] In the formula, j=1, 2,..., n g , n g represents the total number of each factor data; m g is the number of factors; ζ min (j) and ζ max (j) are the minimum difference and the maximum difference between the sequences; γ represents the correlation coefficient of X m and Y; and p is a resolution coefficient.

[0034] Further, the p is 0.5.

[0035] Further, the machine learning model comprises a support vector machine model.

[0036] Further, in S4, the network attack threshold requirement set according to the steady-state trust boundary when the real-time calculated trust factor meets the requirement is that the number of times that the real-time calculated trust factor is lower than the steady-state trust boundary exceeds a set threshold.

[0037] The application also discloses a current transformer system network attack detection system based on electric signals, comprising:

[0038] at least one processor; and at least one memory connected in communication with the processor, wherein:

[0039] The memory stores program instructions executable by the processor, and the processor calling the program instructions can execute the method.

[0040] The application also discloses a non-transitory computer readable storage medium storing computer instructions, which make the computer execute the method.

[0041] (III) Beneficial Effects

[0042] The above technical solutions of the application have the following advantages:

[0043] (1) The application firstly determines a steady-state credible boundary according to a data set under a historical steady state, screens effective features according to a historical network attack data set and a grey correlation degree method, and trains a network attack type detection model; then, a credible factor is calculated in real time through a real-time monitored electric signal, whether a network attack is suffered is quickly judged through the steady-state credible boundary, the type of the network attack is quickly and accurately judged according to the network attack type detection model, so that regulation and repair can be carried out; the detection of whether the network attack is suffered and the detection of the specific network attack type are separately judged, so that the model can be simplified, the real-time detection and the detection accuracy are considered, and the application is suitable for a power electronic system configured with a converter and has generalization for network attacks;

[0044] (2) When the network attack is monitored, the server is disconnected from the attack source, and the converter system is prevented from being deeply damaged;

[0045] (3) The network attack type sample amount of the application is small, and the sample set is high-dimensional data based on a time sequence; the support vector machine model is adopted to solve the small sample data problem, and the kernel function method is adopted to solve the high dimension problem of data, so that the detection accuracy is considered while the detection time is reduced;

[0046] (4) The application effectively screens effective features through the grey correlation degree method, reduces feature redundancy, can effectively reduce the calculation amount of the model, and further reduces the detection time. BRIEF DESCRIPTION OF DRAWINGS

[0047] The features and advantages of the application will be more clearly understood through reference to the accompanying drawings, which are schematic and should not be understood as limiting the application, and in which:

[0048] Figure 1 A flowchart of a converter system network attack detection method based on an electric signal according to an embodiment of the application;

[0049] Figure 2 A flowchart of determining a steady-state credible boundary according to an embodiment of the application;

[0050] Figure 3 A three-phase voltage signal diagram, a three-phase current signal diagram and a credible factor diagram according to an embodiment of the application;

[0051] Figure 4A flow chart for training a network attack type detection model according to an embodiment of the present application;

[0052] Figure 5 A feature extraction schematic diagram of voltage signals and current signals according to an embodiment of the present application;

[0053] Figure 6 A flow chart for real-time monitoring of network attacks and judging network attack types according to an embodiment of the present application. DETAILED DESCRIPTION

[0054] The specific embodiments of the present application will be further described in detail below with reference to the accompanying drawings and embodiments. The following embodiments are used to illustrate the present application, but not to limit the scope of the present application.

[0055] The overall flow of the electric signal-based converter system network attack detection method of the present application is shown in FIG. Figure 1 The specific steps are as follows:

[0056] S1, obtaining a data set under a historical steady state condition and a historical network attack data set;

[0057] The data set under the historical steady state condition includes three-phase current signals and three-phase voltage signals of the converter system under the steady state condition, and the historical network attack data set includes three-phase current signals and three-phase voltage signals of the converter system, and corresponding network attack types;

[0058] The data set under the steady state condition is used to design a steady state boundary for judging network attacks. At the same time, the historical network attack data set is recorded for training a detection model to detect network attack types. The order of S2 and S3 is not required, which can be performed simultaneously or not simultaneously.

[0059] S2, determining a steady state trusted boundary: calculating an influence factor according to the three-phase current signals and the three-phase voltage signals, calculating a trusted factor according to the influence factor, and obtaining the steady state trusted boundary according to the minimum value of the periodic regular variation of the trusted factor calculated according to the data set under the steady state condition;

[0060] The data set under the steady state condition is used to design a steady state boundary for judging network attacks, and a steady state trusted boundary can be obtained in a stable operating condition. The steady state trusted boundary calculation flow is shown in FIG. Figure 2 The specific steps are as follows:

[0061] S21, calculating an influence factor of three-phase voltage according to the three-phase voltage signals, including an A-phase voltage influence factor, a B-phase voltage influence factor, a C-phase voltage influence factor, and a three-phase voltage average influence factor;

[0062] An influencing factor of three-phase voltage is calculated, and a proportion of a voltage difference between a current moment and a last moment in a voltage at the last moment is represented as a fluctuation amplitude of the voltage, and a proportion of a voltage difference between the current moment voltage and a steady-state average voltage in the steady-state average voltage is represented as a distortion degree of the voltage, as shown in formulas (1)-(4):

[0063]

[0064] In the formulas, i represents the current moment, i-1 represents the last moment; Va i , Vb i and Vc i represent A-phase voltage, B-phase voltage and C-phase voltage at the current moment respectively; Va i-1 , Vb i-1 and Vc i-1 represent A-phase voltage, B-phase voltage and C-phase voltage at the last moment respectively; V af , V bf , V cf and V sf represent A-phase voltage influencing factor, B-phase voltage influencing factor, C-phase voltage influencing factor and three-phase voltage average influencing factor respectively; and α is a weight coefficient of the voltage fluctuation amplitude, and β is a weight coefficient of the voltage distortion degree.

[0065] S22, an influencing factor of three-phase current is calculated according to the three-phase current signal, including A-phase current influencing factor, B-phase current influencing factor, C-phase current influencing factor and three-phase current average influencing factor;

[0066] As above, the influencing factor of the three-phase current is calculated, and a proportion of a current difference value between a current moment and a last moment in a current value at the last moment is represented as a fluctuation amplitude of the current, and a proportion of a current difference value between the current moment and a steady-state average current in the steady-state average current is represented as a distortion degree of the current, as shown in formulas (5)-(8):

[0067]

[0068]

[0069] In the formulas, Ia i , Ib i and Ic i represent A-phase current, B-phase current and C-phase current at the current moment respectively; Ia i-1 , Ib i-1 and Ic i-1 represent A-phase current, B-phase current and C-phase current at the last moment respectively; I af , I bf , I cf and I sfrespectively represent the A-phase current influence factor, the B-phase current influence factor, the C-phase current influence factor, and the three-phase current average influence factor; and a is a weight coefficient of the current fluctuation amplitude; and β is a weight coefficient of the current distortion degree.

[0070] S23, introducing a sigmod function, calculating a trust factor according to the three-phase voltage average influence factor and the three-phase current average influence factor;

[0071] In order to obtain stable boundary values and quickly detect network attacks, the sigmod function is introduced to avoid jumping output values, as shown in formula (9):

[0072]

[0073] In the formula, Y_re is the trust factor.

[0074] S24, obtaining a steady-state trust boundary according to a minimum value of periodic regular changes of the trust factor in the steady state;

[0075] Figure 3 Fig. (a) of the drawings shows a three-phase voltage signal diagram of Example 1, Figure 3 Fig. (b) of the drawings shows a three-phase current signal diagram of Example 1, Figure 3 Fig. (c) of the drawings shows a trust factor diagram of Example 1 in the steady state and when a network attack occurs. As can be known from Example 1, in the simulated converter system, even in the steady state, the calculated trust factor is not fixed, but changes periodically and regularly, and has a minimum value, which is 0.89 in this experiment. Therefore, this value can be used as a steady-state trust boundary. In Example 1, a false data injection attack is performed on the converter system at the first second, the weight coefficient a of the current and the current fluctuation amplitude is 0.6; and the weight coefficient β of the voltage and the current distortion degree is 0.4. In Example 1, at the first 1.0124s, the real-time calculated trust factor produces a mutation, and the trust factor at this time is 0.83, which is less than the steady-state trust boundary and is lower than the steady-state trust boundary value for a period of time.

[0076] S3, training to obtain a network attack type detection model: taking each sampling point of the time sequence of the three-phase voltage signal and the three-phase current signal of the historical network attack data set as a feature, screening effective features by a grey correlation degree method to form a training data set, inputting the training data set into a machine learning model for training to obtain the network attack type detection model; as shown in the following formula (10), specifically comprising: Figure 4

[0077] S31, taking each sampling point of the time sequence of the three-phase voltage signal and the three-phase current signal of the historical network attack data set as a feature, analyzing the correlation coefficients of each feature and different network attack types by a grey correlation degree method;​

[0078] The present application selects the time sequence of three-phase voltage signals and three-phase current signals at the time of network attack as a feature of each sampling point, and analyzes the correlation degree of each feature with different network attack types by a grey correlation degree (GRA) method. The GRA is a method for describing the influence degree between factors. The feature sequence in the present application is a time-based electrical signal sequence, which is affected by objective factors such as equipment operating conditions and subjective factors such as hacker network attacks, and presents a partially unknown grey characteristic, which is suitable for using the GRA. Therefore, the label data corresponding to different attack situations is taken as a reference sequence Y, and the electrical signal time sequence in part of the network attack time is selected as a comparison sequence X m , the correlation coefficient and its average value between the reference sequence and the comparison sequence are calculated The correlation between Y and X is represented as m

[0079]

[0080] In the formula, j = 1, 2, … n g , n g represents the total number of factor data; m g is the number of factors; ζ min (j) and ζ max (j) are the minimum difference and the maximum difference between the sequences; γ represents the correlation coefficient of X m and Y; and p is a resolution coefficient.

[0081] S32, grouping the features corresponding to the correlation coefficients greater than the average correlation coefficient to form a training data set;

[0082] Figure 5 The (a) graph in (a) represents the feature extraction of the voltage signal, Figure 5 The (b) graph in (b) represents the feature extraction of the current signal. In Example 2, the resolution coefficient p is 0.5, and the effective features in 0.2s of the voltage signal and the current signal are extracted, Figure 5 In the (a) graph of (a), the average correlation degree calculated for the voltage signal is 0.68, and the features greater than the average value are selected to form a data set for training the SVM model. Among the 200 features, 88 features are selected. Figure 5 In the (b) graph of (b), the average correlation degree calculated for the current signal is 0.69, and the features greater than the average value are selected as the training data set among the 200 features. Therefore, the grey correlation degree method proposed in the present application can effectively screen the effective features, reduce the feature redundancy, and effectively reduce the calculation amount of the model.

[0083] S33, inputting the training data set into a machine learning model for training to obtain a network attack type detection model;​​

[0084] In this embodiment, the machine learning model is a support vector machine model (SVM). Considering that the data of network attack types are not easy to collect, in order to obtain a high enough accuracy rate on a small sample data set, a support vector machine model (SVM) is constructed as a detection model. The SVM model can now be applied to solve the multi-classification problem. The SVM multi-classification method constructs N(N-1) / 2 hyperplanes for N-class problems, where each hyperplane is trained only using two-class data sets, that is, to solve the following quadratic programming problem:

[0085]

[0086] In the formula, θ is the normal vector of the hyperplane; ε is the relaxation variable; τ is the penalty factor, which determines the classification accuracy; x is the feature vector; y is the classification result; the real number is the threshold value; φ s represents the nonlinear space mapping; the subscript t represents the index of the sample in the union set of the i-th class and the j-th class, and t = 1, 2... sn, sn is the space dimension. The decision function of the binary SVM is:

[0087]

[0088] In the formula, λ is the Lagrange multiplier, and 0≤λ t ≤τ; K h is the kernel function; the subscript new represents new data. In a high-dimensional feature space, the radial basis kernel function can maintain the sensitivity to the local features of the data, and the value of the kernel function changes gently between different samples, which can provide a relatively consistent feature mapping. Therefore, the K h used in the present application is a radial basis kernel function:

[0089]

[0090] In the formula, ω is the radial basis width. The complete calculation process of this process is shown in Figure 5 .

[0091] Compared with other machine learning algorithms, the random forest algorithm is unstable due to random sampling and random feature selection, the BP neural network algorithm has slow learning speed, poor real-time performance in the identification process, and the identification accuracy is easily affected by the training sample. Considering that the network attack type sample is small, and the sample set is high-dimensional data based on time series, the SVM classifier is suitable for small sample data and has strong generalization ability. At the same time, the kernel function method is used to solve the high-dimensional data problem. In addition, the time complexity of the support vector machine depends on the number of network attack types and the number of features. Under the condition of limited network attack types, reducing the input of feature data can effectively reduce the detection time. Other machine learning models can also be used, but the effect of SVM is better.

[0092] S4, real-time monitoring of network attacks and determining the type of network attack: real-time monitoring and collecting three-phase current signals and three-phase voltage signals of the converter system, real-time calculating the confidence factor, when the real-time calculated confidence factor meets the network attack threshold requirement set according to the steady-state confidence boundary, it is determined that the network attack is suffered, the server is disconnected from the attack source, and the type of network attack is determined in real time according to the network attack type detection model. As shown in Figure 6

[0093] The phasor measurement unit (PMU) is used to monitor and collect three-phase current and three-phase voltage signals of the converter system in real time, and the sampling frequency is 10k-20k.

[0094] According to the method of S21-S23, the real-time calculated confidence factor is obtained. When the network attack is encountered, the oscillation change of the three-phase voltage and the three-phase current makes the real-time calculated confidence factor less than the steady-state confidence boundary, it is considered that the network attack is possibly suffered. In order to avoid the fluctuation caused by interference, the confidence factor value is continuously detected, and the number of times that the value is less than the boundary value is accumulated. When the set threshold value is reached, it is determined that the network attack is suffered. That is, when the number of times that the real-time calculated confidence factor is less than the steady-state confidence boundary exceeds the set threshold value, it is determined that the network attack is suffered, the server is disconnected from the attack source, and the specific type of network attack is determined in real time according to the network attack type detection model.

[0095] ​Finally, it needs to be explained that the above method can be converted into software program instructions, which can be implemented by using a system including a processor and a memory, or by computer instructions stored in a non-transitory computer readable storage medium. The integrated unit implemented in the form of a software function unit described above can be stored in a computer readable storage medium. The software function unit described above is stored in a storage medium, including a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute part of the steps of the method described in various embodiments of the application. And the foregoing storage medium includes: U disk, mobile hard disk, read-only memory (Read-Only Memory, ROM), random access memory (Random Access Memory, RAM), magnetic disk or optical disk and various program code storage media.

[0096] In summary, through the above-mentioned power converter system network attack detection method and system based on electrical signals, the following beneficial effects are obtained:

[0097] (1) Firstly, the steady-state trusted boundary is determined according to the data set under the historical steady-state working condition, the effective features are screened according to the historical network attack data set and the grey correlation degree method, and the network attack type detection model is trained; the trusted factor is calculated in real time through the real-time monitoring of the electrical signal, whether the network attack is suffered is quickly judged through the steady-state trusted boundary, the type of the network attack is quickly and accurately judged according to the network attack type detection model, so as to carry out regulation and repair; the detection of whether the network attack is suffered and the detection of the specific network attack type are separated to judge, so as to simplify the model, consider the detection real-time and the detection accuracy, and be suitable for the power electronic system configured with the power converter, and have generalization for the network attack;

[0098] (2) When the network attack is monitored, the server is disconnected from the attack source, and the power converter system is prevented from being deeply damaged;

[0099] (3) The network attack type sample amount of the present application is small, and the sample set is high-dimensional data based on time series, the support vector machine model is used to solve the small sample data problem, the kernel function method is used to solve the high-dimensional data problem, the detection accuracy is considered, and the detection time is reduced;

[0100] (4) The present application effectively screens the effective features by the grey correlation degree method, reduces the feature redundancy, can effectively reduce the calculation amount of the model, and further reduces the detection time.

[0101] It should be noted that the above examples are only used to illustrate the technical solutions of the present application, and not to limit them; although the embodiments of the present application are described in conjunction with the drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the present application, and such modifications and variations all fall within the scope defined by the appended claims.

Claims

1. A method for detecting cyber attacks on a power converter system network based on electrical signals, the method comprising: The method comprises the following steps: S1, obtaining a historical steady-state condition data set and a historical network attack data set: the historical steady-state condition data set comprises three-phase current signals and three-phase voltage signals of a converter system in a steady-state condition, and the historical network attack data set comprises three-phase current signals and three-phase voltage signals of the converter system and corresponding network attack types; S2, determining a steady-state credible boundary: calculating an influence factor based on the three-phase current signals and the three-phase voltage signals, calculating a credible factor based on the influence factor, and obtaining the steady-state credible boundary based on a minimum value of periodic regular changes of the credible factor calculated based on the historical steady-state condition data set; The calculation of the influence factor based on the three-phase current signals and the three-phase voltage signals and the calculation of the credible factor based on the influence factor comprise the following steps: S21, calculating an influence factor of three-phase voltage according to the three-phase voltage signal, including an A-phase voltage influence factor, a B-phase voltage influence factor, a C-phase voltage influence factor and a three-phase voltage average influence factor, i.e. V af , V bf , V cf and V sf : In the formula, i represents the current time, i-1 represents the previous time; Va i , Vb i , and Vc i respectively represent the A-phase voltage, the B-phase voltage, and the C-phase voltage at the current time; Va i-1 , Vb i-1 , and Vc i-1 respectively represent the A-phase voltage, the B-phase voltage, and the C-phase voltage at the previous time; V as 、 V bs and V cs respectively represent the A-phase steady-state average voltage, the B-phase steady-state average voltage, and the C-phase steady-state average voltage; and α is a weight coefficient of the voltage fluctuation amplitude, and β is a weight coefficient of the voltage distortion degree. S22, calculating an influence factor of three-phase current according to the three-phase current signal, including an A-phase current influence factor, a B-phase current influence factor, a C-phase current influence factor and a three-phase current average influence factor, i.e. I af , I bf , I cf , and I sf : wherein Ia i , Ib i and Ic i respectively represent the A-phase current, the B-phase current and the C-phase current at the current time; Ia i-1 , Ib i-1 and Ic i-1 respectively represent the A-phase current, the B-phase current and the C-phase current at the previous time; I af , I bf , I cf and I sf respectively represent the A-phase current influence factor, the B-phase current influence factor, the C-phase current influence factor and the three-phase current average influence factor; I as 、I bs and I cs respectively represent the A-phase steady-state average current, the B-phase steady-state average current and the C-phase steady-state average current; α is a weight coefficient of the current fluctuation amplitude; β is a weight coefficient of the current distortion degree; S23, introducing a sigmod function, and calculating a credible factor Y_re based on the three-phase voltage average influence factor and the three-phase current average influence factor; S3, training a network attack type detection model: taking each sampling point of a time sequence of the three-phase voltage signals and the three-phase current signals of the historical network attack data set as a feature, screening effective features to form a training data set by using a grey correlation degree method, inputting the training data set into a machine learning model for training, and obtaining the network attack type detection model; S4, real-time monitoring of network attacks and determination of network attack types: real-time monitoring and collecting three-phase current signals and three-phase voltage signals of a converter system, calculating a credible factor, determining that a network attack is suffered when the real-time calculated credible factor meets a network attack threshold requirement set based on the steady-state credible boundary, disconnecting a server from an attack source, and real-time determining a type of the network attack based on the network attack type detection model.

2. The electrical signal based power converter system network attack detection method of claim 1, wherein, The α is 0.6, and the β is 0.

4.

3. The electrical signal based power converter system network attack detection method of claim 1, wherein, The S3 comprises the following steps: S31, taking each sampling point of a time sequence of the three-phase voltage signals and the three-phase current signals of the historical network attack data set as a feature, and analyzing a correlation coefficient of each feature with different network attack types by using a grey correlation degree method; S32, forming a training data set by using features corresponding to correlation coefficients greater than an average value of the correlation coefficients; S33, inputting the training data set into a machine learning model for training, and obtaining the network attack type detection model.

4. The method of claim 3, wherein, The correlation coefficient between each feature and different network attack types is analyzed by the grey correlation degree method, including: taking the label data corresponding to different attack situations as a reference sequence Y, selecting the electric signal time sequence in part of the network attack time as a comparison sequence X m , calculating the correlation coefficient between the reference sequence and the comparison sequence: where j = 1, 2,... n g , n g denotes the total number of data for each factor; m g is the number of factors; ζ min (j) and ζ max (j) are the minimum and maximum differences between sequences; γ represents the correlation coefficient of X m and Y; and ρ is the resolution coefficient.

5. The electrical signal based power converter system network attack detection method of claim 4, wherein, The ρ is 0.

5.

6. The electrical signal based power converter system network attack detection method of claim 3, wherein, The machine learning model comprises a support vector machine model.

7. The electrical signal based power converter system network attack detection method of claim 1, wherein, In the S4, the network attack threshold requirement met by the real-time calculated credible factor based on the steady-state credible boundary is that a number of times that the real-time calculated credible factor is lower than the steady-state credible boundary exceeds a set threshold value.

8. A network attack detection system for converter systems based on electrical signals, characterized in that, The method comprises the following steps: at least one processor; and at least one memory connected with the processor in communication, wherein: the memory stores program instructions executable by the processor, and the processor calling the program instructions can execute the method in any one of claims 1 to 7.

9. A non-transitory computer-readable storage medium, comprising: The non-transitory computer readable storage medium stores computer instructions, and the computer instructions enable the computer to execute the method in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Attack recognition method based on random forest algorithm and energy storage coordination control device

    CN111107092A

  • Condition Monitoring Via Energy Consumption Audit in Electrical Devices and Electrical Waveform Audit in Power Networks

    US20220050130A1