Active defense method and system for unknown threats

Through the combination of intelligent threat warning, detection and adaptive defense modules, the lack of initiative and autonomy of security technology in the power information network is solved, and a refined security protection system has been formed, which has improved the defense capabilities of the power network.

CN119011255BActive Publication Date: 2025-08-12INFORMATION & COMM BRANCH OF STATE GRID JIANGSU ELECTRIC POWER +3
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411113330.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2023-08-16
Filing Date
2024-08-14
Publication Date
2025-08-12
Estimated Expiration
2044-08-14

AI Technical Summary

Technical Problem

The existing power information network security technology lacks initiative and autonomy, is incomplete in defense, is unable to respond to transformed attacks in a timely manner, relies on static protection rules and manual operations, and lacks global situational awareness and flexibility for network security threats.

Method used

The intelligent threat warning module is used to collect network data in real time, analyze it through the unknown threat detection module, generate threat analysis reports, and the adaptive defense disposal module triggers the corresponding defense strategy to form a refined and adaptive security protection system.

Benefits of technology

It improves the monitoring and early warning capabilities of system security incidents, improves the defense level of the overall power network, and realizes active defense and automatic response to unknown threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119011255B_ABST
    Figure CN119011255B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and system for active defense against unknown threats. The method comprises: using an intelligent threat warning module to perform threat prediction on network data collected in real time from an electric power information network to obtain threat warning information, and sending the threat warning information to an unknown threat detection module; using the unknown threat detection module to perform threat detection and analysis on the unknown threat network data in the threat warning information upon receiving the threat warning information, generating a threat analysis report; and sending the threat analysis report to an adaptive defense disposal module; using the adaptive defense disposal module to trigger defense disposal operations corresponding to a preset threat defense strategy based on the threat analysis report, thereby forming a more refined and adaptive security protection system, improving the monitoring and warning capabilities of system security events, and enhancing the overall defense level of the electric power network.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority to patent application number 202311028145.8 (the filing date of the prior application is August 16, 2023, and the name of the invention is "An active defense system and method for unknown threats"). Technical Field

[0002] The present invention relates to the technical field of power systems, and in particular to an active defense method and system for unknown threats. Background Art

[0003] The power information network refers to a network in the power system that uses computer technology and communication technology to interconnect power equipment in order to realize functions such as intelligence, informatization and remote control.

[0004] The current network security risks faced by the power information network include: (1) network attacks. Hackers may enter the power information network through various means and attack and destroy the system, such as DDoS attacks, malware attacks, data tampering, etc. These attacks may cause power grid outages, data leakage and information security issues; (2) human operation errors. The power information network involves many human operations, such as system maintenance and network management. If an operation error occurs, it may cause system failure or information leakage; (3) social engineering attacks. Through disguise, deception, information collection and other means, information about the system or application is obtained to achieve the purpose of entering the computer system or network; (4) IoT device security issues. The IoT devices commonly used in the power information network have some security vulnerabilities, such as default passwords and failure to upgrade in time. These problems are easily exploited by attackers. In response to the above network security risks, corresponding security measures need to be taken to ensure the safe operation of the power information network.

[0005] While existing security technologies address some traditional network security issues, they are deficient in three key areas for the development of power information networks. First, traditional power network security defense systems are mostly based on passive defenses, relying primarily on technologies such as antivirus software, firewalls, and identity authentication. For example, while firewall technology can effectively block most illegal intrusions by configuring certain security access rules, these configurations are static. As attack vectors diversify, proactive security protection becomes less effective and lacks detection flexibility. Second, from a technical perspective, power network security defenses primarily focus on perimeter defenses, failing to comprehensively analyze threats and developing a sensitive understanding of the overall cybersecurity threat landscape. This results in an inability to respond promptly to evolving attacks, reducing defense effectiveness. Third, traditional defenses rely heavily on manual operations by operations and maintenance engineers, lacking autonomy. Summary of the Invention

[0006] The present invention provides an active defense method and system for unknown threats to address the problems of existing security technologies in power information networks, such as lack of initiative and autonomy, and incomplete defense, to form a more refined and adaptive security protection system, improve the monitoring and early warning capabilities of system security incidents, and enhance the overall power network defense level.

[0007] In a first aspect, an embodiment of the present invention provides a method for proactively defending against unknown threats, including:

[0008] Through the intelligent threat warning module, threat prediction is performed on the network data collected in real time from the power information network to obtain threat warning information, and the threat warning information is sent to the unknown threat detection module;

[0009] Upon receiving the threat warning information, the unknown threat detection module performs threat detection and analysis on the unknown threat network data in the threat warning information to generate a threat analysis report; and sends the threat analysis report to the adaptive defense disposal module;

[0010] The adaptive defense handling module triggers a defense handling operation corresponding to a preset threat defense strategy according to the threat analysis report.

[0011] In a second aspect, an embodiment of the present invention provides an active defense system for unknown threats, including:

[0012] An intelligent threat warning module is used to perform threat prediction on network data collected in real time from the electric power information network to obtain threat warning information, and send the threat warning information to the unknown threat detection module;

[0013] an unknown threat detection module, configured to, upon receiving the threat warning information, perform threat detection and analysis on the unknown threat network data in the threat warning information, generate a threat analysis report, and send the threat analysis report to the adaptive defense disposal module;

[0014] The adaptive defense processing module is used to trigger the defense processing operation corresponding to the preset threat defense strategy according to the threat analysis report.

[0015] The technical solution of the embodiment of the present invention is to perform threat prediction on the network data collected in real time from the electric power information network through the intelligent threat warning module to obtain threat warning information, and send the threat warning information to the unknown threat detection module; through the unknown threat detection module, when receiving the threat warning information, perform threat detection and analysis on the unknown threat network data in the threat warning information to generate a threat analysis report; and send the threat analysis report to the adaptive defense disposal module; through the adaptive defense disposal module, trigger the defense disposal operation corresponding to the preset threat defense strategy according to the threat analysis report, thereby solving the problems of the existing security technology of the electric power information network, lack of initiative and autonomy, and incomplete defense, forming a more refined and adaptive security protection system, improving the monitoring and early warning capabilities of system security events, and improving the overall power network defense level.

[0016] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0018] Figure 1 A flowchart of a method for proactively defending against unknown threats provided in Example 1 of the present invention;

[0019] Figure 2 A flowchart of a method for proactively defending against unknown threats provided in the second embodiment of the present invention;

[0020] Figure 3 This is a schematic diagram of the structure of an active defense system for unknown threats provided in Example 3 of the present invention. DETAILED DESCRIPTION

[0021] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.

[0022] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0023] Example 1

[0024] Figure 1 This is a flow chart of an active defense method for unknown threats provided by the first embodiment of the present invention. This embodiment is applicable to the situation of defending against unknown threats in the power information network. The method can be executed by an active defense system for unknown threats. The active defense system for unknown threats can be implemented in the form of hardware and / or software. The active defense system for unknown threats can be configured in electronic devices. Figure 1 As shown, the method includes:

[0025] S110 , using the intelligent threat warning module, performing threat prediction on the network data collected in real time from the electric power information network to obtain threat warning information, and sending the threat warning information to the unknown threat detection module.

[0026] Specifically, the intelligent threat warning module performs threat prediction on the network data collected in real time from the power information network according to the preset warning mechanism to obtain threat warning information, thereby realizing active warning of unknown threats.

[0027] S120. When receiving threat warning information, the unknown threat detection module performs threat detection and analysis on the unknown threat network data in the threat warning information, generates a threat analysis report, and sends the threat analysis report to the adaptive defense disposal module.

[0028] Specifically, when the unknown threat detection module receives threat warning information, it performs threat detection and analysis on the collected unknown threat network data according to the preset detection and analysis methods, generates a threat analysis report, and realizes active detection and comprehensive analysis of unknown threats.

[0029] S130 , triggering a defense disposal operation corresponding to a preset threat defense strategy according to the threat analysis report through the adaptive defense disposal module.

[0030] Specifically, after receiving the threat analysis report, the adaptive defense disposal module triggers the defense disposal operation corresponding to the preset threat defense strategy according to the threat analysis report, thereby realizing automatic defense against unknown threats.

[0031] The technical solution of the embodiment of the present invention uses an intelligent threat warning module to perform threat prediction on network data collected in real time from the power information network to obtain threat warning information, and sends the threat warning information to an unknown threat detection module; when the threat warning information is received, the unknown threat detection module performs threat detection and analysis on the unknown threat network data in the threat warning information to generate a threat analysis report; and sends the threat analysis report to an adaptive defense disposal module; through the adaptive defense disposal module, defense disposal operations corresponding to preset threat defense strategies are triggered according to the threat analysis report, thereby forming a more refined and adaptive security protection system, improving the monitoring and early warning capabilities of system security incidents, and enhancing the overall power network defense level.

[0032] Example 2

[0033] Figure 2 This is a flow chart of an active defense method for unknown threats provided by the second embodiment of the present invention. Based on the above embodiment, this embodiment further refines the functions of the intelligent threat warning module, the unknown threat detection module, and the adaptive defense disposal module. Figure 2 As shown, the method includes:

[0034] S210. Based on a multi-level self-feedback anonymous reward mechanism of fog computing, network data collected from different network devices in the power information network are aggregated to obtain an aggregation vector.

[0035] Specifically, since there are many devices in the power grid, and different devices produce different types of data during production, the primary task in predicting whether there are unknown threats in network data is to quickly aggregate and process the collected network data. Fog computing is a system-level architecture that aims to uniformly distribute resources and services from the cloud to the Internet of Things. Because cloud computing cannot keep up with the explosive growth of data from edge devices, aggregators use fog nodes to sense and aggregate data, thus breaking away from the dilemma of resource constraints. Fog computing has the following five main advantages: distributed and low-latency computing; exceeding the resource limitations of terminal devices; (iii) sustainable energy consumption; coping with data explosion and network traffic pressure; and intelligent computing. Therefore, improving energy sustainability based on intelligent fog computing on network devices is promising.

[0036] A multi-level, self-feedback, anonymous reward mechanism based on fog computing uses a self-feedback mechanism configured for fog nodes on the data aggregator to ensure timely and high-quality completion of data aggregation tasks. For urgent and high-demand data aggregation tasks, if the amount of data received in a short period of time is expected to fail to meet the task requirements, the data aggregator connects with more fog nodes and increases the reward level for fog nodes. If the amount of data received in a short period of time exceeds the expected amount, the data aggregator reduces the reward level for fog nodes to improve data quality and avoid communication congestion. For fog nodes with an abnormally high number of nodes, the amount of data they provide is limited to prevent data from a single area from dominating the total data, thereby weakening the impact of data from other areas.

[0037] The multi-level, self-feedback, anonymous reward mechanism based on fog computing is implemented within a system architecture consisting of five entities: network devices, relay servers, fog nodes, data aggregators, and blockchain. Network devices collect network data and are typically deployed on various heterogeneous power terminals at the edge, generating power-related traffic data, log data, and system call records. Relay servers can be considered third-party trusted platforms that collaborate with the power grid. Fog nodes, consisting of a group of edge devices, assist the aggregator in completing aggregation tasks. After completing tasks, they receive rewards from the data aggregator via the blockchain based on workload. The data aggregator, the main body of the power grid's cloud service master, initiates data aggregation tasks and simultaneously communicates with multiple fog nodes to prevent communication and computational bottlenecks and ensure timely processing of edge data sent from devices in different locations. Monero blockchain can be used as the blockchain. Monero uses ring signatures, ring-confidential transactions, and stealth addresses to obfuscate the source, amount, and destination of all transactions. Transactions on the chain cannot be associated with specific users or real identities.

[0038] Fog nodes and network devices are registered on the relay server and bound to each other based on their geographical location. A fog node sends a send permission to the corresponding network device. A fog node can be bound to multiple network devices, and the send permission is updated periodically.

[0039] In an optional embodiment, the multi-level self-feedback anonymous reward mechanism based on fog computing aggregates network data collected from different network devices in the power information network to obtain an aggregate vector, including the following steps:

[0040] S211. Register each of the network devices and fog nodes on a relay server, and allocate the network devices to fog nodes in the area; the relay server is a third-party trusted platform.

[0041] S212: Issue a data aggregation task to each fog node through the data aggregator, so that each fog node generates a sending license for the corresponding network device.

[0042] S213: forwarding the sending permission certificate issued by the fog node to each of the network devices through the relay server, so that each of the network devices sends the expected sending data volume to the relay server based on the sending permission certificate;

[0043] S214: Generate a reward voucher for the network device according to the estimated amount of data to be sent by the relay server, and send the reward voucher to the corresponding network device, so that the network device anonymously sends the real-time collected network data and the reward voucher to the fog node in the area;

[0044] S215. Forwarding the network data and the reward voucher to a data aggregator through the fog node;

[0045] S216. Aggregate the network data through the data aggregator to obtain an aggregation vector, and provide rewards to the network device according to the reward certificate through the blockchain, and provide rewards to the fog node according to the workload of the fog node.

[0046] Specifically, the data aggregator issues data aggregation tasks to fog nodes. The fog nodes generate transmission permits for the corresponding network devices and transmit the task information and transmission permits to the relay server. The relay server transmits the transmission permits and task information to the network devices in the fog node's area and collects network data collected by the network devices. The network devices send the estimated amount of data to the relay server. The relay server conducts a reward evaluation based on data quantity, data quality, and the data's contribution to power threat warnings, and returns a reward certificate and transmission permit to the network devices. The network devices anonymously transmit the real-time collected network data and reward certificates to the fog nodes in their area. The fog nodes forward the received network data and reward certificates to the data aggregator. The data aggregator aggregates the network data to obtain an aggregation vector. Through the blockchain, fog nodes are rewarded based on their workload, and data collection devices are rewarded based on the reward certificates.

[0047] S220 , performing feature extraction, similarity calculation, and feature encoding on the aggregated vector to obtain a coded key-value pair vector between each network device.

[0048] The encoding key-value pair vector is a vector composed of encoding key-value pairs of data similarity and corresponding network data.

[0049] Specifically, the aggregation vector can be expressed as info = (a1, a2, ..., a m ,b1,b2,…,b n ,c1,c2,…,c k); where a1, a2, …, a m Represents network data of m dimensions from device a, b1, b2, ..., b n Represents the network data of n dimensions from device b, c1, c2, ..., c k Represents k dimensions of network data originating from device c. Each aggregated vector is sequentially embedded, similarity calculated, and feature encoded to obtain the encoded key-value pair vectors between each network device. The similarity between network data from different network devices is used to reflect the threat characteristics of the network data.

[0050] In an optional embodiment, the step of performing feature extraction, similarity calculation and feature encoding on the aggregated vector to obtain the encoded key-value pair vector between each network device includes: for each aggregated data, selecting an adaptive embedding model to perform an embedding operation on the target data according to the type of each target data in the aggregated data to obtain an embedding vector; splicing the embedding vectors of each target data in the aggregated data to obtain a spliced embedding vector; calculating the similarity matrix of each spliced embedding vector, and obtaining each similarity vector from the similarity matrix row by row; associating each similarity data in the similarity vector with the corresponding two network data to form a key-value pair; encoding the key-value pair according to the network devices corresponding to the sources of the two network data in the key-value pair to obtain an encoded key-value pair; and forming an encoded key-value pair vector according to the encoded key-value pair corresponding to each similarity data in the similarity vector.

[0051] Specifically, according to the type of each target data in the aggregated data, an adaptive embedding model is selected to embed the target data to obtain an embedding vector, that is,

[0052] (x1,x2,…,x m )=Model1(a1,a2,…,a m );

[0053] (y1,y2,…,y n )=Model2(b1,b2,…,b n );

[0054] (z1,z2,…,z k )=Model3(c1,c2,…,c k );

[0055] Concatenate multiple embedding vectors to obtain the concatenated embedding vector E info :

[0056] E info =(x1,x2,…,x m ,y1,y2,…,yn ,z1,z2,…,z k ).

[0057] Due to the large variety and volume of data in power grid scenarios, the embedding vector dimension corresponding to each piece of network data is very high. If early warning information is predicted in batches according to the existing spliced embedding vectors, it will inevitably require a large amount of computing resources and be very costly to implement. Therefore, an embodiment of the present invention provides a fast feature conversion method to compress the dimension of the feature vector to facilitate the application of subsequent steps.

[0058] The embodiment of the present invention calculates the concatenated embedding vector E info The similarity between network data between different network devices is obtained to obtain the similarity matrix M info ,Right now:

[0059]

[0060] in,

[0061]

[0062] From the similarity matrix M info Get each similarity vector by row in , and you will get the similarity vector between each device and the rest of the devices, such as:

[0063] F x_info =(s x,x ,s x,y ,…,s x,z );

[0064] Among them, F x_info It represents the similarity of network data between the x-th network device and other network devices.

[0065] Each similarity data in the similarity vector is associated with the corresponding two network data to form a key-value pair, and the key-value pair is encoded according to the network device corresponding to the source of the two network data in the key-value pair to obtain an encoded key-value pair; and an encoded key-value pair vector is formed according to the encoded key-value pair corresponding to each similarity data in the similarity vector.

[0066] Optionally, the key-value pair is encoded according to the network device corresponding to the source of the two network data in the key-value pair, and the step of obtaining the encoded key-value pair includes: determining a binary encoding field of corresponding bits according to the total number of network devices in the power information network; wherein the field position of the binary encoding field being the first numerical value is the network device number corresponding to the source of the network data in the encoded key-value pair; converting the binary encoding field into a decimal encoding field; and obtaining the encoded key-value pair after adding the decimal encoding field to the similarity data in the key-value pair.

[0067] For example, if the total number of network devices in the electric power information network is 0, a binary code field with 0 bits is given and initialized as:

[0068]

[0069] For any dimension of data that comes from the i-th and j-th data sources, change the corresponding position of the binary code field from 0 to 1, and we get:

[0070]

[0071] Convert the binary code field to a decimal code field, add it to the similarity data in the key-value pair, and use it as the device tag to obtain the encoded key-value pair, namely:

[0072] <info:(F x ,F y ,…,F z ) T >

[0073] F x =F x_info +F x_rel =(s x,x +s′ x,x ,sx ,y +s′ x,y ,…,s x,z +s′ x,z );

[0074] F y =F y_info +F y_rel =(s y,x +s′ y,x ,s y,y +s′ y,y ,…,s y,z +s′ y,z );

[0075] F z =F z_info +F z_rel =(s z,x +s′ z,x ,s z,y +s′ z,y ,…,s z,z +s′ z,z ).

[0076] Among them, s′ x,x Represents similarity data s x,x The decimal encoding field of s′ x,yRepresents similarity data s x,y The decimal encoding field, s′ x,z , s′ y,x , s′ y,y , s′ y,z , s′ z,x , s′ z,y and s′ z,z The meaning is similar.

[0077] S230, using multi-channel technology and self-attention mechanism to perform threat prediction on each encoded key-value pair in the encoded key-value pair vector to obtain threat warning information containing unknown threat network data; and sending the threat warning information to the unknown threat detection module.

[0078] Specifically, the multi-channel warning system aims to process information between each device and the rest of the devices in a separate channel. Finally, by combining the output information from multiple channels, the global warning probability can be estimated at the current time, forming a two-stage warning process.

[0079] In an optional embodiment, the step of using multi-channel technology and self-attention mechanism to perform threat prediction on each encoded key-value pair in the encoded key-value pair vector to obtain threat warning information containing unknown threat data includes: in a single channel of the multi-channel, processing the corresponding single encoded key-value pair vector based on the self-attention mechanism to obtain a single-channel key-value pair processing vector; aggregating the key-value pair processing results of each single-channel key-value pair processing vector in each dimension to obtain a single-dimensional key-value pair processing vector in each dimension; inputting each single-dimensional key-value pair processing vector into a threat prediction network model to obtain a threat warning score; the threat prediction network model includes a multi-dimensional deep neural network and a fully connected layer; if the threat warning score is greater than the score threshold, the network data corresponding to the encoded key-value pair vector is determined as unknown threat network data, and the unknown threat network data and the corresponding network device information are encapsulated as threat warning information.

[0080] Specifically, in the multi-channel warning in the embodiment of the present invention, the warning strategies of different channels are the same, so the specific steps are described by taking one channel as an example.

[0081] In a single channel of multiple channels, the corresponding single encoding key-value pair vector F is obtained based on the self-attention mechanism. x The attention score is calculated using the scaled dot product attention defined in the Transformer architecture, such as:

[0082]

[0083] Where Q, K, and V represent queries, keys, and values, respectively, and are all learnable parameter matrices. The self-attention mechanism differs from the attention mechanism in that the queries, keys, and values in the model come from the same sequence object. The self-attention mechanism processes the corresponding single encoded key-value pair vector to obtain a single-channel key-value pair processing result. The specific processing formula is:

[0084] SA(F x )=Attention(F x W Q ,F x W K ,F x W V );

[0085] Among them, W Q ,W K ,W V are parameter matrices that are iterated during the training process.

[0086] The key-value pair processing results of each single-channel key-value pair processing vector in each dimension are aggregated to obtain a single-dimensional key-value pair processing vector in each dimension. The method may be: channel merging the single-channel key-value pair processing results of each channel to obtain a multi-channel key-value pair processing matrix, such as:

[0087]

[0088] And obtain the key-value pair processing results of each column in the multi-channel key-value pair processing matrix by column, and obtain each key-value pair processing column vector, such as

[0089]

[0090] Input each of the single-dimensional key-value pair processing vectors into a threat prediction network model to obtain a threat warning score; the threat prediction network model includes a multi-dimensional deep neural network and a fully connected layer; such as:

[0091] Score1=ReLU(0,T1W1+b1)W2+b2

[0092] Among them, W1, W2, b1, b2 are all learnable parameters, and ReLU() indicates that the activation function is the ReLU (Rectified Linear Unit) function.

[0093] After processing each dimension, a warning score is obtained for each dimension. The warning scores for each dimension are input into a single fully connected layer to output the final threat warning score. If the threat warning score is greater than the score threshold, the network data corresponding to the encoded key-value pair vector is determined to be unknown threat network data, and the unknown threat network data and the corresponding network device information are encapsulated as threat warning information.

[0094] S240. When receiving threat warning information, the unknown threat detection module performs threat detection and analysis on the unknown threat network data in the threat warning information, generates a threat analysis report, and sends the threat analysis report to the adaptive defense disposal module.

[0095] Specifically, the key issue in univariate time series threat detection is how to model complex nonlinear time correlations. However, most studies only consider the system's short-term time dependencies and lack consideration of the system's long-term time dependencies. The unknown threat detection module provided by the embodiments of the present invention is mainly composed of a layered multi-head attention network module, which is used to receive information about the existence of unknown threats from the intelligent prediction and warning module. It combines hour-level and daily-level features to obtain high-level time features to detect multiple categories of unknown threats, solve the problem of periodic long-term time dependencies in the power system, and improve the threat detection rate.

[0096] Optionally, the unknown threat detection module is configured with a hierarchical multi-head attention network model, a multi-layer perceptron and a classification model; the hierarchical multi-head attention network model includes: an embedding layer, multiple time-level multi-head self-attention layers and a day-level multi-head self-attention layer.

[0097] In an optional embodiment, upon receiving the threat warning information, the unknown threat detection module performs threat detection and analysis on the unknown threat network data in the threat warning information, and the step of generating a threat analysis report includes:

[0098] S241. Obtain historical daily network data of the unknown threat network data, and construct multiple time-level unknown threat data sequences based on the unknown threat network data and the historical daily network data.

[0099] S242: Input each of the time-level unknown threat data sequences into the embedding layer to obtain each of the time-level unknown threat embedding vectors, and map the time-level unknown threat embedding vectors into time-level unknown threat key-value pair vectors;

[0100] S243. Input the time-level unknown threat key-value pair vectors into the corresponding time-level multi-head self-attention layer to obtain each time-level feature vector, and input the last time-level feature in each time-level feature vector into the day-level multi-head self-attention layer to obtain a day-level feature vector.

[0101] S244: Input the concatenated feature vector of the last time-level feature vector and the day-level feature vector into a multi-layer perceptron to obtain the threat distribution probability of the unknown threat network data;

[0102] S245. Input the threat distribution probability into a classification model to obtain a threat type;

[0103] S246: Generate a threat analysis report based on the unknown threat network data, the threat warning information, and the threat type.

[0104] The time-level unknown threat data sequence may be understood as an unknown threat data sequence consisting of one hour or multiple hours.

[0105] Specifically, upon receiving the unknown threat network data x in the threat warning information t At this time, the historical daily network data of unknown threat network data is obtained to form multiple time-level unknown threat data sequences x t-24w+1 ,…,x t-23w-1 ,x t-23w 、x t-2w+1 ,…,x t-w-1 ,x t-w ,…,x t-w+1 ,…,x t-1 ,x t Where w represents the number of network data in the historical time period sampled every hour. The embedding layer is used to transform each time-level unknown threat data sequence into an input embedding vector g with a dimension of d. t , the embedding module contains the "position code" pos enc to take advantage of the order of input data.

[0106] g t =emb(x t )+pos enc (x t );

[0107] The sequence x of the nth hour is transformed into t-nw+1 ,x t-nw+2 ,…,x t-(n-1)w Embedded into g t-nw+1 ,g t-nw+2 ,…,g t-(n-1)w The time-level unknown threat embedding vector is obtained from the input token of . The time-level unknown threat embedding vector is mapped to a time-level unknown threat key-value pair vector, which specifically includes the query Q, key K and value V in the self-attention:

[0108]

[0109] in and is the linear projection matrix.

[0110] The time-level unknown threat key-value pair vectors are input into the corresponding time-level multi-head self-attention layer, and the scaled dot product is applied in the time-level multi-head self-attention layer to determine the output of each head, denoted as head h :

[0111]

[0112] By connecting the outputs of all heads and then projecting them again, we get the feature vectors of each time level, which are recorded as:

[0113] y n =MultiHead(Q,K,V)=Cat(head1,head2,...,head H )Φ O .

[0114] The last time-level feature y in each time-level feature vector is t-23w ,y t-22w ,...,y t A vector is formed as the input of the daily multi-head self-attention layer. Considering the periodic long-term time dependency of the power flow data time series, the daily attention network is used, and its input is the 24 time-level features learned by the time-level attention network, and the daily multi-head self-attention feature y′ is further extracted. t-23w ,y′ t-22w ,...,y′ t .

[0115] The time-level feature vector of the last hour learned by the time-level attention network and the day-level feature vector learned by the day-level attention network are concatenated and then sent to the MLP network with the sigmoid function to obtain the threat distribution probability O at timestamp t. t :

[0116] O t =MLP([y t ,y′ t ])

[0117] When training this module, binary cross entropy loss is used as the objective function to reduce the threat distribution probability O t and the true label G t The difference between L BCE And update the network parameters through the gradient descent algorithm:

[0118] L BCE =-G t log(O t )-(1-Gt )log(1-O t )

[0119] The threat distribution probability O t Perform softmax to confirm the threat type a t A threat analysis report is generated based on the unknown threat network data, threat warning information, and threat type, and the threat analysis report is sent to the adaptive defense disposal module.

[0120] In another optional embodiment, the unknown threat detection module can be trained using a secure federated learning system based on an editable blockchain. This system primarily comprises a network layer, a learning layer, and a blockchain layer. The network layer utilizes an edge computing-based power IoT network, the learning layer implements local model training and aggregation across different IoT nodes, and the blockchain layer stores model parameters in the cloud. A Chameleon hash function that supports trapdoor updates replaces traditional hash functions. Hash collisions enable blockchain updates without destroying the original chain, thus achieving an editable blockchain and preventing key and model parameter leakage.

[0121] S250. Triggering a defense disposal operation corresponding to a preset threat defense strategy according to the threat analysis report through the adaptive defense disposal module.

[0122] In an optional embodiment, the step of triggering, by the adaptive defense handling module, a defense handling operation corresponding to a preset threat defense strategy according to the threat analysis report includes:

[0123] S251. Construct a software-defined network architecture for the electric power information network.

[0124] Specifically, detailed information on the network architecture, components, and infrastructure in the power Internet of Things environment based on software-defined networking (SDN) is used to create a software-defined network architecture for the power information network. The software-defined network architecture for the power information network contains N real nodes consisting of servers and IoT nodes. The IoT nodes collect data and transmit it to the server periodically through one or more hops. The path from the IoT node to the server node consists of a series of nodes. In the power information network, IoT nodes and servers with different functions are distributed in different virtual local area networks (VLANs). The IoT network uses an SDN controller located on a remote server, which interacts with an SDN-enabled switch and manages traffic between IoT nodes and servers connected to the switch through communication channels such as cables or wireless signals.

[0125] S252. Construct a digital twin system of the power information network based on digital twin technology and the software-defined network architecture.

[0126] Specifically, digital twin technology is used to construct a digital twin system for the power information network. This digital twin system is used to monitor the status and performance of power IoT system components in real time, predict system behavior under different operating conditions, and support maintenance and operational decisions. The specific steps are: Continuously collect data in real time from the real physical power system. This involves collecting critical information related to terminal facilities, IoT gateways, IoT management facilities, security facilities, and other relevant system parameters within the power IoT environment. This raw data is then meticulously processed and cleaned, including noise filtering, standardization, and outlier detection. This meticulous processing ensures high-quality, accurate data for the digital twin model, accurately reflecting the current state of the power IoT system. Machine learning algorithms are applied to the clean data obtained from the data acquisition and processing systems. Statistical models and data analysis techniques are used to identify patterns and relationships in the power IoT system data, thereby gaining a deep understanding of the system's operational dynamics. Dynamic simulations are performed under a variety of operating conditions and disturbances to make the digital twin model realistic. Simulation tools provide a secure environment for testing and optimizing defense strategies and evaluating the effectiveness of different mitigation techniques. They provide an opportunity to measure the potential impact of adjustments without risking the real system. At the heart of the digital twin framework is a feedback loop connecting physical and virtual systems. This bidirectional communication channel is essential for enabling real-time system interaction and control. Adjustments made in the digital twin (such as modifying defense strategies or parameters) can be virtually tested to observe potential impacts on the real system.

[0127] S253. In the digital twin system, defensive measures are taken against the unknown threat network data according to the preset threat defense strategy corresponding to the threat type in the threat analysis report.

[0128] Optionally, for unknown threat network data whose threat type is a distributed denial of service attack, the distributed denial of service attack is mitigated by a software-defined network controller.

[0129] Specifically, the main goal of the mitigation mechanism is to minimize the damage caused by the attack, protect the power IoT network resources and maintain normal network activity. The remote SDN controller activates the congestion control algorithm. This algorithm manages and regulates network traffic to prevent network congestion and ensure that the network remains operational. Under the control of the remote SDN controller, the enabled OpenFlow (OF) switch must terminate specific connections and transfer network resources to the appropriate network host. This action is taken to isolate potentially malicious traffic and ensure that authorized users can access the resources they need even during an attack. The OF switch follows the instructions of the SDN controller to determine whether the traffic request from a specific source host constitutes a DDoS attack. In this way, network resources are granted to authorized users so that normal network activity can continue.

[0130] Optionally, for network data whose threat type is other unknown threat except for distributed denial of service attack, an initial defense strategy population is randomly generated; each individual in the initial defense strategy population is divided into a first subpopulation and a second subpopulation according to fitness; the first subpopulation is input into a genetic algorithm loop for crossover to generate a first offspring; the second subpopulation is input into a particle swarm optimization loop for iterative update to generate a second offspring; using the elite selection method, individuals are selected from the first offspring and the second offspring to merge into a selected defense strategy population; the selected defense strategy population is input into a teaching optimization algorithm to obtain a target defense strategy population; using a reinforcement learning algorithm, the target defense strategy population is updated and optimized according to a reward function to obtain an optimal defense strategy population; the optimal defense strategy population is used as the initial defense strategy population for a new round, and the step of dividing each individual in the initial defense strategy population into a first subpopulation and a second subpopulation according to fitness is returned to execute until a preset termination condition is reached, and the individual with the highest fitness in the optimal defense strategy population is used as the final defense strategy.

[0131] Specifically, if the threat type is unknown threat network data other than distributed denial of service attacks, define the parameters for evolutionary learning and reinforcement learning. Randomly generate an initial population of defense strategies within the solution space of threat response measures, with each individual representing a possible defense strategy combination. These strategy combinations cover defense measures across all layers and stacks, including hardware, operating systems, and business software. Define the parameters required for the genetic algorithm (GA), particle swarm optimization (PSO), and teaching-based optimization algorithm (TLBO), such as population size, crossover probability, mutation probability, number of particles, and maximum number of iterations.

[0132] For each individual in the initial defense strategy population, its defensive effectiveness is evaluated and its fitness value is calculated. For example, the population is sorted by fitness value, with the 50% of individuals with higher fitness values forming the first subpopulation A, and the 50% of individuals with lower fitness values forming the second subpopulation B. The 50% of subpopulation A with higher fitness values is input into a genetic algorithm (GA) loop, where individuals are selected from subpopulation A for crossover. This selection can be done using methods such as roulette wheel selection and tournament selection. Crossover and mutation operations are performed to ultimately generate offspring. The 50% of the subpopulation with lower fitness values is input into a particle swarm optimization (PSO) loop, where velocity and position updates are performed and offspring are generated. After multiple iterations, the positions of the individuals in the particle swarm become the new offspring.

[0133] Using an elite selection method, individuals with high fitness values are selected from the offspring of the genetic algorithm (GA) and particle swarm optimization (PSO) to form a selected defense strategy population. This population is then fed into the teaching-learning-based optimization (TLBO) algorithm to obtain the target defense strategy population. During the teaching phase, the individual with the highest fitness value in the population serves as the teacher. Other individuals learn from the teacher to update themselves and improve their fitness values. During the learning phase, individuals learn from each other, collaborating and competing to further optimize the population.

[0134] Combined with the reinforcement learning Q-learning algorithm, the strategy of each individual in the target defense strategy population is updated and optimized according to the reward function to ensure that they can dynamically adapt to the changing threat environment. In an embodiment of the present invention, the action space of the Q-learning algorithm refers to a combination of defense strategies that can be adopted. These strategies may involve adjustments to hardware configurations, changes to operating system security policies, the application of software patches, or dynamic changes in network routing, etc. Each action corresponds to a possible combination of defense measures. The Q table is initialized using the threat type generated in the previous step and the optimized corresponding population (defense strategy combination). The Q table records the Q value of each state-action pair, and the Q value reflects the long-term benefits that can be obtained by choosing a certain action in a specific state.

[0135] In each iteration, based on the current Q-table, an optimal action is selected and its defensive effectiveness is evaluated. Common selection strategies include the ε-greedy strategy. After selecting an action, the combination of defense strategies is applied to the network, generating a new network security state. The reward value for this defense strategy combination is then calculated based on a reward function, and the Q value is updated using the Bellman equation. The optimized Q-table records the optimal defense strategies under different states. This table can be used to quickly identify the optimal defensive measures for a specific network state, serving as a reference for subsequent defense strategy generation and adjustment. The Q-learning algorithm ultimately outputs an optimal defense strategy combination that, through continuous iterative learning, can adapt to a changing threat environment.

[0136] The updated population is used as the input of a new round of algorithm, and the above steps are continued until the preset termination condition is reached (such as reaching the maximum number of iterations or the fitness value meets the requirements), and the individual with the highest fitness in the optimal defense strategy population is used as the final defense strategy.

[0137] The technical solution of the embodiment of the present invention uses an intelligent threat warning module to perform threat prediction on network data collected in real time from the power information network to obtain threat warning information, and sends the threat warning information to an unknown threat detection module; when the threat warning information is received, the unknown threat detection module performs threat detection and analysis on the unknown threat network data in the threat warning information to generate a threat analysis report; and sends the threat analysis report to an adaptive defense disposal module; through the adaptive defense disposal module, defense disposal operations corresponding to preset threat defense strategies are triggered according to the threat analysis report, thereby forming a more refined and adaptive security protection system, improving the monitoring and early warning capabilities of system security incidents, and enhancing the overall power network defense level.

[0138] Example 3

[0139] Figure 3 This is a schematic diagram of the structure of an active defense system for unknown threats provided by the third embodiment of the present invention. Figure 3 As shown, the system includes:

[0140] An intelligent threat warning module 310 is configured to perform threat prediction on network data collected in real time from the electric power information network to obtain threat warning information, and send the threat warning information to the unknown threat detection module;

[0141] The unknown threat detection module 320 is configured to, upon receiving the threat warning information, perform threat detection and analysis on the unknown threat network data in the threat warning information, generate a threat analysis report, and send the threat analysis report to the adaptive defense disposal module;

[0142] The adaptive defense handling module 330 is configured to trigger a defense handling operation corresponding to a preset threat defense strategy according to the threat analysis report.

[0143] Optional, intelligent threat warning module, including:

[0144] The data aggregation submodule is used to aggregate the network data collected from different network devices in the power information network based on the multi-level self-feedback anonymous reward mechanism of fog computing to obtain the aggregation vector;

[0145] An embedding operation submodule, configured to perform embedding operations, similarity calculations, and feature encoding on the aggregated vectors to obtain encoding key-value pair vectors between the network devices; the encoding key-value pair vectors are vectors consisting of encoding key-value pairs of data similarities and corresponding network data;

[0146] A threat prediction submodule is configured to use multi-channel technology and a self-attention mechanism to perform threat prediction on each encoded key-value pair in the encoded key-value pair vector to obtain threat warning information containing unknown threat network data;

[0147] The warning information sending submodule is used to send the threat warning information to the unknown threat detection module.

[0148] Optionally, the data aggregation submodule is specifically used to:

[0149] Registering each of the network devices and fog nodes on a relay server, and allocating the network devices to fog nodes in the area; the relay server is a third-party trusted platform;

[0150] Issue data aggregation tasks to each fog node through the data aggregator, so that each fog node generates a sending license certificate for the corresponding network device;

[0151] forwarding the sending permission certificate issued by the fog node to each of the network devices through the relay server, so that each of the network devices sends an estimated sending data volume to the relay server based on the sending permission certificate;

[0152] The relay server generates a reward voucher for the network device according to the expected amount of data to be sent, and sends the reward voucher to the corresponding network device, so that the network device anonymously sends the real-time collected network data and the reward voucher to the fog node in the area;

[0153] forwarding the network data and the reward voucher to a data aggregator through the fog node;

[0154] The network data is aggregated by the data aggregator to obtain an aggregation vector, and a reward is provided to the network device according to the reward certificate through the blockchain, and a reward is provided to the fog node according to the workload of the fog node.

[0155] Optionally, the embedded operation submodule includes:

[0156] an embedding operation unit, configured to select an adaptive embedding model for each aggregated data according to the type of each target data in the aggregated data, perform an embedding operation on the target data, and obtain an embedding vector;

[0157] a splicing unit, configured to splice the embedding vectors of the target data in the aggregated data to obtain a spliced embedding vector;

[0158] A similarity calculation unit, configured to calculate a similarity matrix of each of the concatenated embedding vectors, and obtain each similarity vector from the similarity matrix row by row;

[0159] A key-value pair generating unit, configured to associate each similarity data in the similarity vector with the corresponding two network data to form a key-value pair;

[0160] an encoding unit, configured to encode the key-value pair according to network devices corresponding to sources of two network data in the key-value pair to obtain an encoded key-value pair;

[0161] The encoding key-value pair vector generating unit is used to form an encoding key-value pair vector according to the encoding key-value pair corresponding to each similarity data in the similarity vector.

[0162] Optional encoding unit, specifically used for:

[0163] Determine a binary code field of corresponding digits according to the total number of network devices in the power information network; wherein the field position of the binary code field having the first value is the network device number corresponding to the source of the network data in the coding key-value pair;

[0164] Converting the binary coded field into a decimal coded field;

[0165] After adding the decimal encoding field to the similarity data in the key-value pair, an encoded key-value pair is obtained.

[0166] Optional threat prediction submodule, specifically used for:

[0167] In a single channel of the multi-channel, the corresponding single encoded key-value pair vector is processed based on the self-attention mechanism to obtain a single-channel key-value pair processing vector;

[0168] Aggregating the key-value pair processing results of each of the single-channel key-value pair processing vectors in each dimension to obtain a single-dimensional key-value pair processing vector in each dimension;

[0169] Inputting each of the single-dimensional key-value pair processing vectors into a threat prediction network model to obtain a threat warning score; the threat prediction network model includes a multi-dimensional deep neural network and a fully connected layer;

[0170] If the threat warning score is greater than the score threshold, the network data corresponding to the encoded key-value pair vector is determined to be unknown threat network data, and the unknown threat network data and corresponding network device information are encapsulated into threat warning information.

[0171] Optionally, the unknown threat detection module is configured with a hierarchical multi-head attention network model, a multi-layer perceptron, and a classification model; the hierarchical multi-head attention network model includes: an embedding layer, multiple time-level multi-head self-attention layers, and a day-level multi-head self-attention layer;

[0172] The unknown threat detection module 320 includes:

[0173] a time-level sequence generation submodule, configured to obtain historical daily network data of the unknown threat network data, and form a plurality of time-level unknown threat data sequences based on the unknown threat network data and the historical daily network data;

[0174] a vector mapping submodule, configured to input each of the time-level unknown threat data sequences into the embedding layer, obtain each of the time-level unknown threat embedding vectors, and map the time-level unknown threat embedding vectors into a time-level unknown threat key-value pair vector;

[0175] A feature extraction submodule is configured to input the time-level unknown threat key-value pair vectors into the corresponding time-level multi-head self-attention layer to obtain each time-level feature vector, and input the last time-level feature in each time-level feature vector into the day-level multi-head self-attention layer to obtain a day-level feature vector;

[0176] A perception submodule, configured to input the concatenated feature vector of the last time-level feature vector in each of the time-level feature vectors and the day-level feature vector into a multi-layer perceptron to obtain a threat distribution probability of the unknown threat network data;

[0177] A threat type determination submodule, configured to input the threat distribution probability into a classification model to obtain a threat type;

[0178] The analysis report generation submodule is used to generate a threat analysis report based on the unknown threat network data, the threat warning information and the threat type.

[0179] Optionally, the adaptive defense handling module 330 includes:

[0180] A network architecture construction submodule, used to construct a software-defined network architecture of the power information network;

[0181] A digital twin submodule, configured to construct a digital twin system of the power information network based on digital twin technology and the software-defined network architecture;

[0182] The threat defense submodule is used to perform defense processing on the unknown threat network data in the digital twin system according to the preset threat defense strategy corresponding to the threat type in the threat analysis report.

[0183] Optionally, the threat defense submodule is specifically configured to:

[0184] For unknown threat network data whose threat type is a distributed denial of service attack, mitigating the distributed denial of service attack by using a software-defined network controller;

[0185] For network data of unknown threats other than distributed denial of service attacks, randomly generating an initial defense strategy population; dividing each individual in the initial defense strategy population into a first subpopulation and a second subpopulation according to fitness; inputting the first subpopulation into a genetic algorithm loop for crossover to generate a first offspring; and inputting the second subpopulation into a particle swarm optimization loop for iterative update to generate a second offspring;

[0186] Using an elite selection method, selecting individuals from the first offspring and the second offspring to merge into a selected defense strategy population; inputting the selected defense strategy population into a teaching optimization algorithm to obtain a target defense strategy population;

[0187] Using the reinforcement learning algorithm, the target defense strategy population is updated and optimized according to the reward function to obtain the optimal defense strategy population;

[0188] The optimal defense strategy population is used as the initial defense strategy population for a new round, and the step of dividing each individual in the initial defense strategy population into a first subpopulation and a second subpopulation according to fitness is returned to execute until a preset termination condition is achieved, and the individual with the highest fitness in the optimal defense strategy population is used as the final defense strategy.

[0189] The active defense system for unknown threats provided by the embodiment of the present invention can execute the active defense method for unknown threats provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.

[0190] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.

[0191] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.

Claims

1. A method for proactively defending against unknown threats, comprising: Through the intelligent threat warning module, threat prediction is performed on the network data collected in real time from the power information network to obtain threat warning information, and the threat warning information is sent to the unknown threat detection module; When receiving the threat warning information, the unknown threat detection module performs threat detection and analysis on the unknown threat network data in the threat warning information to generate a threat analysis report; and sending the threat analysis report to the adaptive defense disposal module; Triggering, through the adaptive defense handling module, a defense handling operation corresponding to a preset threat defense strategy according to the threat analysis report; The step of performing threat prediction on network data collected in real time from the electric power information network to obtain threat warning information, and sending the threat warning information to the unknown threat detection module includes: Based on the multi-level self-feedback anonymous reward mechanism of fog computing, the network data collected from different network devices in the power information network are aggregated to obtain the aggregation vector; Performing embedding operations, similarity calculations, and feature encoding on the aggregated vectors to obtain encoding key-value pair vectors between the network devices; the encoding key-value pair vectors are vectors consisting of encoding key-value pairs of data similarities and corresponding network data; Using multi-channel technology and self-attention mechanism to perform threat prediction on each encoded key-value pair in the encoded key-value pair vector to obtain threat warning information containing unknown threat network data; The threat warning information is sent to the unknown threat detection module.

2. The active defense method for unknown threats according to claim 1, characterized in that: The multi-level self-feedback anonymous reward mechanism based on fog computing aggregates network data collected from different network devices in the power information network to obtain an aggregate vector, including the following steps: Registering each network device and each fog node on a relay server, and allocating the network device to the fog node in the area; the relay server is a third-party trusted platform; Issue data aggregation tasks to each fog node through the data aggregator, so that each fog node generates a sending license certificate for the corresponding network device; forwarding the sending permission certificate issued by the fog node to each of the network devices through the relay server, so that each of the network devices sends an estimated sending data volume to the relay server based on the sending permission certificate; The relay server generates a reward voucher for the network device according to the expected amount of data to be sent, and sends the reward voucher to the corresponding network device, so that the network device anonymously sends the real-time collected network data and the reward voucher to the fog node in the area; forwarding the network data and the reward voucher to a data aggregator through the fog node; The network data is aggregated by the data aggregator to obtain an aggregation vector, and a reward is provided to the network device according to the reward certificate through the blockchain, and a reward is provided to the fog node according to the workload of the fog node.

3. The active defense method for unknown threats according to claim 1, characterized in that: The step of performing embedding operation, similarity calculation and feature encoding on the aggregated vector to obtain the encoded key-value pair vectors between each network device includes: For each aggregated data, according to the type of each target data in the aggregated data, an adaptive embedding model is selected to perform an embedding operation on the target data to obtain an embedding vector; splicing the embedding vectors of each target data in the aggregated data to obtain a spliced embedding vector; Calculating a similarity matrix of each of the concatenated embedding vectors, and obtaining each similarity vector from the similarity matrix row by row; Associating each similarity data in the similarity vector with the corresponding two network data to form a key-value pair; Encoding the key-value pair according to the network devices corresponding to the sources of the two network data in the key-value pair to obtain an encoded key-value pair; A coded key-value pair vector is constructed according to the coded key-value pairs corresponding to each similarity data in the similarity vector.

4. The active defense method for unknown threats according to claim 3, characterized in that: The step of encoding the key-value pair according to the network devices corresponding to the sources of the two network data in the key-value pair to obtain the encoded key-value pair includes: Determine a binary code field of corresponding digits according to the total number of network devices in the power information network; wherein the field position of the binary code field having the first value is the network device number corresponding to the source of the network data in the coding key-value pair; Converting the binary coded field into a decimal coded field; After adding the decimal encoding field to the similarity data in the key-value pair, an encoded key-value pair is obtained.

5. The active defense method for unknown threats according to claim 1, characterized in that: The step of using multi-channel technology and self-attention mechanism to perform threat prediction on each encoded key-value pair in the encoded key-value pair vector to obtain threat warning information containing unknown threat data includes: In a single channel of the multi-channel, the corresponding single encoded key-value pair vector is processed based on the self-attention mechanism to obtain a single-channel key-value pair processing vector; Aggregating the key-value pair processing results of each of the single-channel key-value pair processing vectors in each dimension to obtain a single-dimensional key-value pair processing vector in each dimension; Inputting each of the single-dimensional key-value pair processing vectors into a threat prediction network model to obtain a threat warning score; the threat prediction network model includes a multi-dimensional deep neural network and a fully connected layer; If the threat warning score is greater than the score threshold, the network data corresponding to the encoded key-value pair vector is determined to be unknown threat network data, and the unknown threat network data and corresponding network device information are encapsulated into threat warning information.

6. The active defense method for unknown threats according to claim 1, characterized in that: The unknown threat detection module is configured with a hierarchical multi-head attention network model, a multi-layer perceptron, and a classification model; the hierarchical multi-head attention network model includes: an embedding layer, multiple time-level multi-head self-attention layers, and a daily multi-head self-attention layer; when the unknown threat detection module receives the threat warning information, the unknown threat network data in the threat warning information is subjected to threat detection and analysis, and the steps of generating a threat analysis report include: Acquire historical daily network data of the unknown threat network data, and construct a plurality of time-level unknown threat data sequences based on the unknown threat network data and the historical daily network data; Inputting each of the time-level unknown threat data sequences into the embedding layer to obtain each of the time-level unknown threat embedding vectors, and mapping the time-level unknown threat embedding vectors into time-level unknown threat key-value pair vectors; Input the time-level unknown threat key-value pair vectors into the corresponding time-level multi-head self-attention layer to obtain each time-level feature vector, and input the last time-level feature in each time-level feature vector into the day-level multi-head self-attention layer to obtain a day-level feature vector; Inputting the concatenated feature vector of the last time-level feature vector in each of the time-level feature vectors and the day-level feature vector into a multi-layer perceptron to obtain the threat distribution probability of the unknown threat network data; Inputting the threat distribution probability into a classification model to obtain a threat type; A threat analysis report is generated based on the unknown threat network data, the threat warning information, and the threat type.

7. The active defense method for unknown threats according to claim 1, characterized in that: The step of triggering, by the adaptive defense handling module, a defense handling operation corresponding to a preset threat defense strategy according to the threat analysis report includes: Constructing a software-defined network architecture for the electric power information network; Building a digital twin system of the power information network based on digital twin technology and the software-defined network architecture; In the digital twin system, defense processing is performed on the unknown threat network data according to the preset threat defense strategy corresponding to the threat type in the threat analysis report.

8. The active defense method for unknown threats according to claim 7, characterized in that: In the digital twin system, the step of performing defense processing on the unknown threat network data according to the preset threat defense strategy corresponding to the threat type in the threat analysis report includes: For unknown threat network data whose threat type is a distributed denial of service attack, mitigating the distributed denial of service attack by using a software-defined network controller; For network data of unknown threats other than distributed denial of service attacks, randomly generating an initial defense strategy population; dividing each individual in the initial defense strategy population into a first subpopulation and a second subpopulation according to fitness; inputting the first subpopulation into a genetic algorithm loop for crossover to generate a first offspring; and inputting the second subpopulation into a particle swarm optimization loop for iterative update to generate a second offspring; Using an elite selection method, selecting individuals from the first offspring and the second offspring to merge into a selected defense strategy population; inputting the selected defense strategy population into a teaching optimization algorithm to obtain a target defense strategy population; Using the reinforcement learning algorithm, the target defense strategy population is updated and optimized according to the reward function to obtain the optimal defense strategy population; The optimal defense strategy population is used as the initial defense strategy population for a new round, and the step of dividing each individual in the initial defense strategy population into a first subpopulation and a second subpopulation according to fitness is returned to execute until a preset termination condition is achieved, and the individual with the highest fitness in the optimal defense strategy population is used as the final defense strategy.

9. An active defense system for unknown threats, characterized in that: Includes: An intelligent threat warning module is used to perform threat prediction on network data collected in real time from the power information network to obtain threat warning information, and send the threat warning information to the unknown threat detection module; An unknown threat detection module is used to perform threat detection and analysis on the unknown threat network data in the threat warning information upon receiving the threat warning information, and generate a threat analysis report; and sending the threat analysis report to the adaptive defense disposal module; An adaptive defense processing module is used to trigger a defense processing operation corresponding to a preset threat defense strategy according to the threat analysis report; The intelligent threat warning module includes: The data aggregation submodule is used to aggregate the network data collected from different network devices in the power information network based on the multi-level self-feedback anonymous reward mechanism of fog computing to obtain the aggregation vector; An embedding operation submodule, configured to perform embedding operations, similarity calculations, and feature encoding on the aggregated vectors to obtain encoding key-value pair vectors between the network devices; the encoding key-value pair vectors are vectors consisting of encoding key-value pairs of data similarities and corresponding network data; A threat prediction submodule is configured to use multi-channel technology and a self-attention mechanism to perform threat prediction on each encoded key-value pair in the encoded key-value pair vector to obtain threat warning information containing unknown threat network data; The warning information sending submodule is used to send the threat warning information to the unknown threat detection module.

Citation Information

Patent Citations

  • Power network information security active defense system based on big data

    CN108848069A