A power system network attack simulation and security assessment system and method
By designing a power system cyber attack simulation and security assessment system and combining it with the OPAL-RT and MATPOWER tools, we solved the real-time dynamic environment adaptability and firmware security issues in existing technologies, achieved detailed assessment and efficient defense against cyber attacks, and ensured the stability of the power system.
Patent Information
- Application Number
- CN202411144995.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-20
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2044-08-20
AI Technical Summary
Existing power system simulation platforms lack the ability to adapt to real-time dynamic environments, and their firmware security protection is inadequate, leading to increased network attack threats, low simulation efficiency, and insufficient accuracy.
A power system cyber attack simulation and security assessment system is designed, which includes a management system, a communication network, and a physical power system simulator. OPAL-RT and MATPOWER tools are used for high-performance real-time simulation. Combined with the IEC-61850 and DNP3 protocols, the impact of cyber attacks is evaluated through network delay simulation and load balancing formulas.
It enables comprehensive simulation and analysis of network attacks, improves the defense capabilities and simulation efficiency of power systems, and ensures stable operation under complex network attacks.
Smart Images

Figure CN119276531B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power system security and simulation technology, specifically to a power system network attack simulation and security assessment system and method. Background Art
[0002] Power system security and simulation technology is an interdisciplinary field integrating information technology and power engineering, aiming to enhance the power system's defense capabilities against cyberattacks through simulation and modeling. This field encompasses not only traditional protection of the physical components of the power system but also security measures for network communication protocols, data transmission, and system operation. Simulation technology enables researchers to reproduce and analyze various cyberattack scenarios, such as denial-of-service (DoS) attacks and fictitious data injection (FDI), in virtual environments, thereby testing and optimizing the power system's cybersecurity strategies without affecting actual grid operation. In recent years, with the increasing adoption of digital and network technologies in power systems, the cybersecurity threats they face have also been increasing, making the research on power system security and simulation technology increasingly important. Research in this field helps to identify and patch potential security vulnerabilities in the system in advance, ensuring the grid maintains stable and safe operation in the face of complex cyberattacks.
[0003] Current shortcomings in power system security and simulation technologies include: existing power system simulation platforms primarily focus on static data processing, lacking adaptability to real-time dynamic environments and failing to perform efficient real-time hybrid simulations of complex power systems; insufficient firmware security protection measures, with existing power system firmware operation simulation technologies failing to adequately consider the needs of firmware security analysis and vulnerability discovery, making power system terminal equipment vulnerable to cyberattacks; and the simulation processing of large-scale power cyber-physical systems typically involves extensive data interaction, which not only consumes significant computing resources but may also lead to low simulation efficiency and insufficient accuracy. Summary of the Invention
[0004] In view of the above-mentioned problems, the present invention is proposed.
[0005] Therefore, the technical problem solved by this invention is to achieve comprehensive simulation and analysis of network attacks, as well as detailed assessment of the impact of attacks.
[0006] To solve the above-mentioned technical problems, the present invention provides the following technical solution: a power system network attack simulation and security assessment system, which includes the following steps,
[0007] The system includes a management system, a communication network, a physical power system simulator, and performance and security testing functions. The management system includes a client, a database, a human-machine interface, and a server. The communication network includes wireless communication technology and a network intrusion detection system. The physical power system simulator includes a power load balancing module, a power grid simulator, and power system analysis software.
[0008] As a preferred embodiment of the power system network attack simulation and security assessment system described in this invention, the management system is responsible for real-time monitoring and control of the power network.
[0009] The communication network is responsible for connecting the management system and the physical power system simulator. It simulates data transmission through the network simulator and evaluates network latency and communication efficiency. Specifically, it calculates data transmission time and transmission efficiency through network latency simulation technology.
[0010] The physical power system simulator simulates the operation of the actual power grid in a control environment, supports the simulation of network attacks, and observes the impact of network attacks on power balance through the power system load balance formula, thereby assessing the impact of network attacks on the stability and security of the power system.
[0011] The performance and security testing function assesses the performance loss and system resilience caused by network attacks by calculating throughput loss and system frequency changes, and identifies malicious activities or abnormal data flows by monitoring and analyzing data packets of the communication network in real time through the network intrusion detection system.
[0012] As a preferred embodiment of the power system network attack simulation and security assessment system described in this invention, the management system calculates the response time and stability of the power system; the communication network simulates data transmission between local area network nodes through a network simulator; the power load balancing module simulates and analyzes network attacks; the power grid simulator generates operating data and sends it to the management system through the communication network; after processing the received data, the management system performs system analysis and power generation control decisions using the IEC-61850 standard protocol.
[0013] As a preferred embodiment of the power system network attack simulation and security assessment system described in this invention, the communication network is further used to simulate the communication protocol efficiency and network latency. The network latency simulation function is responsible for implementing the communication protocols DNP3 and IEC-61850, and calculating the protocol efficiency and data transmission latency.
[0014] As a preferred embodiment of the power system network attack simulation and security assessment system described in this invention, the power system analysis software includes simulation tools OPAL-RT and MATPOWER, used to simulate the performance of the power system under normal and attacked states; OPAL-RT supports high-performance real-time simulation of the dynamic response of the power system, including changes in voltage, current and power, used to observe the physical response of the power system under network attacks such as FDI and DoS; and MATPOWER is used for steady-state analysis, including power flow calculation and system optimization.
[0015] As a preferred embodiment of the power system network attack simulation and security assessment system described in this invention, the network intrusion detection system is deployed on the network physical test platform of the power system, and the network intrusion detection system monitors and analyzes data packets of the communication network in real time to identify malicious activities or abnormal data streams.
[0016] The performance and security testing function is responsible for simulating different types of network attacks, observing the power system's response speed when faced with high-frequency requests and its data processing capabilities when abnormal data flows in, and further evaluating the power system's behavior under attack conditions and the effectiveness of related security strategies.
[0017] Another objective of this invention is to provide a method for simulating and assessing network attacks on power systems, which solves the problems of slow response speed and low recovery efficiency in existing methods through an automated response mechanism.
[0018] To solve the above-mentioned technical problems, the present invention provides the following technical solution: a method for simulating and assessing network attacks on power systems, comprising: system initialization, starting the management system, initializing the communication network, and deploying the communication protocol.
[0019] The management system establishes a communication connection with the physical power system simulator through a communication network, and evaluates network latency and communication efficiency.
[0020] We simulated a cyberattack using a physical power system simulator and analyzed the impact of the cyberattack on the power system balance using performance and security testing functions.
[0021] The management system receives simulation data from the physical power system simulator, calculates the system response time and stability indicators, and performs system analysis and power generation control decisions.
[0022] As a preferred embodiment of the power system network attack simulation and security assessment method described in this invention, the assessment of network latency and communication efficiency includes simulating data transmission between local area network nodes using a network simulator to obtain transmission efficiency, protocol efficiency, network latency, and data transmission latency.
[0023] The transmission efficiency is expressed as,
[0024]
[0025] The network latency is expressed as,
[0026]
[0027] The protocol efficiency is expressed as follows:
[0028]
[0029] The data transmission delay is expressed as,
[0030]
[0031] Among them, g e Indicates lost data packets, g h The total number of data packets sent is represented by τ0, and the basic network latency is represented by d. i and v i These are the transmission distance and network speed of the i-th segment, respectively, L 有效 L represents the amount of data effectively transmitted. 总 The total amount of data transmitted is represented by T, where L represents the packet length, R represents the link transmission efficiency, and T represents the total amount of data transmitted. 传播 This indicates the propagation delay of a signal in a medium.
[0032] The physical power system simulator simulates network attacks based on the power system load balance formula, evaluates the power system's recovery capability after being subjected to network attacks based on the recovery time model, and performs steady-state analysis based on MATPOWER.
[0033] The power system load balance formula is expressed as follows:
[0034]
[0035] Among them, P G,i P represents the power generation of the i-th node. D,i T represents the power consumption of the i-th node. ij This represents the power transmission loss from node i to node j.
[0036] The recovery time model is expressed as follows:
[0037]
[0038] Among them, T 恢复 C represents the time it takes for the power system to recover from an attack to normal operation. 恢复 S represents the number of control operations required to restore the power system. 恢复能力This represents the number of control operations performed by the power system per unit of time.
[0039] The steady-state analysis includes power flow calculation and system optimization.
[0040] The power flow calculation is expressed as follows:
[0041]
[0042] Among them, Y ik V represents the elements of the admittance matrix. i V represents the voltage at node i. k Let θ represent the voltage at node k. i θ k Let i and k be the phase angles of nodes i and k, respectively.
[0043] The impact of the analyzed network attacks on the power system balance is expressed as follows:
[0044] L 吞吐量 =T 正常 -T 攻击
[0045] Among them, L 吞吐量 T represents throughput loss. 正常 T represents the throughput of a power system when it is not under attack. 攻击 This indicates the throughput of the power system when it is under attack.
[0046] When the throughput loss exceeds the acceptable threshold, it indicates that the simulated attack exceeds the power system's tolerance.
[0047] The system response time is expressed as follows:
[0048] T = T 处理 +T 传输 +T 执行
[0049] The stability index is expressed as follows:
[0050]
[0051] Among them, T 处理 T represents the data processing time. 传输 T represents the data transmission time. 执行 The data execution time is represented by n, the number of failures is represented by m, and the total number of operations is represented by m.
[0052] The system analysis and power generation control decisions include, when the throughput loss is greater than the acceptable loss threshold, if the system response time does not exceed the response time threshold and the stability does not exceed the stability threshold, then enhanced monitoring and data analysis are carried out, and regular security audits and network traffic analysis are implemented.
[0053] When the throughput loss exceeds the acceptable threshold, if the system response time exceeds the response time threshold but the stability does not exceed the stability threshold, the fast response protocol is updated, including clarifying role responsibilities and action steps.
[0054] When the throughput loss exceeds the acceptable loss threshold, if the system response time does not exceed the response time threshold and the stability exceeds the stability threshold, the existing recovery process should be reviewed and optimized, including increasing the number of backup servers.
[0055] When the throughput loss exceeds the acceptable threshold, if the system response time exceeds the response time threshold and the stability exceeds the stability threshold, then upgrade the firewall rules and signature library, strengthen the security of existing hardware devices, and increase the frequency of data backup.
[0056] A computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the steps of the power system network attack simulation and security assessment system as described above.
[0057] A computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of a power system network attack simulation and security assessment system as described above.
[0058] The beneficial effects of this invention are as follows: By integrating a management system, communication network, and physical power system simulator, it achieves efficient simulation of the dynamic response and stability of the power system under network attacks; by adopting the distributed network protocol DNP3 and the international electrical communication standard IEC-61850, this invention ensures the security and reliability of data transmission, effectively improving the power system's defense capabilities against network attacks such as DoS and FDI attacks; furthermore, through various simulation and testing functions within the simulator, such as the real-time simulation tools OPAL-RT and MATPOWER, this platform can comprehensively evaluate the impact of network attacks, providing theoretical support and experimental data for the formulation of future security strategies and system optimization; the comprehensive application of these technical features not only solves the shortcomings of real-time hybrid simulation and firmware security protection in existing technologies, but also significantly improves simulation efficiency and accuracy, ensuring the stable operation of the power system in the face of complex network attacks. Attached Figure Description
[0059] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0060] Figure 1 The diagram shows the overall framework of a power system network attack simulation and security assessment system provided in the first embodiment of the present invention.
[0061] Figure 2 This is a schematic diagram of the power system data interaction and control process structure in a power system network attack simulation and security assessment system provided in the first embodiment of the present invention.
[0062] Figure 3 The following is an overall flowchart of a power system network attack simulation and security assessment method provided in the second embodiment of the present invention.
[0063] Figure 4 This is a schematic diagram of the physical model structure of an IEEE-14 bus system for a power system network attack simulation and security assessment method provided in the third embodiment of the present invention.
[0064] Figure 5 A comparison chart of power generation under FDI attack on the IEEE-14 bus system, provided as a third embodiment of the present invention, for a power system network attack simulation and security assessment method.
[0065] Figure 6 This is a diagram illustrating the network performance changes under a DoS attack, as provided in the third embodiment of the present invention, for a power system network attack simulation and security assessment method. Detailed Implementation
[0066] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.
[0067] Example 1, referring to Figures 1-2 As an embodiment of the present invention, a power system network attack simulation and security assessment system is provided, characterized in that:
[0068] S1: Management system, communication network, physical power system simulator, and performance and safety testing functions.
[0069] The management system is responsible for real-time monitoring and control of the power network.
[0070] The communication network is responsible for connecting the management system and the physical power system simulator. It simulates data transmission through the network simulator and evaluates network latency and communication efficiency. Specifically, it calculates data transmission time and efficiency using network latency simulation technology.
[0071] The physical power system simulator simulates the operation of a real power grid in a control environment, supports the simulation of network attacks, and observes the impact of network attacks on power balance through the power system load balancing formula, thus assessing the impact of network attacks on the stability and security of the power system.
[0072] The performance and security testing function assesses the performance loss and system resilience caused by network attacks by calculating throughput loss and system frequency changes, and identifies malicious activities or abnormal data flows by monitoring and analyzing data packets of the communication network in real time through the network intrusion detection system.
[0073] The management system calculates the response time and stability of the power system. The communication network simulates data transmission between local area network nodes through a network simulator. The power load balancing module simulates and analyzes network attacks. The power grid simulator generates operating data and sends it to the management system through the communication network. After processing the received data, the management system performs system analysis and power generation control decisions using the IEC-61850 standard protocol.
[0074] The communication network is further used for simulation functions of communication protocol efficiency and network latency. The network latency simulation function is responsible for implementing communication protocols DNP3 and IEC-61850, and calculating protocol efficiency and data transmission latency, such as... Figure 2 As shown, Figure 2 This diagram illustrates the data interaction and control process structure of a power system, showing the components on the server and client sides and their interaction methods. On the server side, components include power system analysis software and a power grid simulator, which generate and process data through server processes. On the client side, components also include power system analysis software and a power grid simulator, with the client-side executable program responsible for processing the data sent from the server. The entire system exchanges data using the IEC-61850 standard protocol to ensure the reliability of data transmission.
[0075] S2: The management system includes clients, databases, human-computer interfaces, and servers.
[0076] S3: Communication networks include wireless communication technology and network intrusion detection systems.
[0077] The network intrusion detection system is deployed on the network physical test platform of the power system. It monitors and analyzes data packets of the communication network in real time to identify malicious activities or abnormal data flows.
[0078] The performance and security testing function is responsible for simulating different types of network attacks, observing the power system's response speed when faced with high-frequency requests and its data processing capabilities when abnormal data flows in, and further evaluating the power system's behavior under attack conditions and the effectiveness of related security strategies.
[0079] S4: The physical power system simulator includes a power load balancing module, a power grid simulator, and power system analysis software.
[0080] Power system analysis software includes simulation tools OPAL-RT and MATPOWER, used to simulate the performance of power systems under normal and attacked conditions. OPAL-RT supports high-performance real-time simulation of the dynamic response of power systems, including changes in voltage, current and power, and is used to observe the physical response of power systems under network attacks such as FDI and DoS. MATPOWER is used for steady-state analysis, including power flow calculation and system optimization.
[0081] Example 2, refer to Figure 3 As an embodiment of the present invention, a method for simulating and assessing network attacks on power systems is provided, characterized in that it includes:
[0082] System initialization, startup of management system, initialization of communication network, and deployment of communication protocol.
[0083] The management system establishes a communication connection with the physical power system simulator through a communication network, and evaluates network latency and communication efficiency.
[0084] We simulated a cyberattack using a physical power system simulator and analyzed the impact of the cyberattack on the power system balance using performance and security testing functions.
[0085] The management system receives simulation data from the physical power system simulator, calculates the system response time and stability indicators, and performs system analysis and power generation control decisions.
[0086] Evaluating network latency and communication efficiency involves simulating data transmission between local area network nodes using a network simulator to obtain transmission efficiency, protocol efficiency, network latency, and data transmission latency.
[0087] Transmission efficiency is expressed as,
[0088]
[0089] Network latency is expressed as,
[0090]
[0091] Protocol efficiency is expressed as follows:
[0092]
[0093] Data transmission delay is expressed as,
[0094]
[0095] Among them, g e Indicates lost data packets, g h The total number of data packets sent is represented by τ0, and the basic network latency is represented by d. i and v i These are the transmission distance and network speed of the i-th segment, respectively, L 有效 L represents the amount of data effectively transmitted. 总 The total amount of data transmitted is represented by T, where L represents the packet length, R represents the link transmission efficiency, and T represents the total amount of data transmitted. 传播 This indicates the propagation delay of a signal in a medium.
[0096] The physical power system simulator simulates network attacks based on the power system load balance formula, evaluates the recovery capability of the power system after being subjected to network attacks based on the recovery time model, and performs steady-state analysis based on MATPOWER.
[0097] The power system load balancing formula is expressed as follows:
[0098]
[0099] Among them, P G,i P represents the power generation of the i-th node. D,i T represents the power consumption of the i-th node. ij This represents the power transmission loss from node i to node j.
[0100] The recovery time model is expressed as follows:
[0101]
[0102] Among them, T 恢复 C represents the time it takes for the power system to recover from an attack to normal operation. 恢复 S represents the number of control operations required to restore the power system. 恢复能力 This represents the number of control operations performed by the power system per unit of time.
[0103] Steady-state analysis includes power flow calculation and system optimization.
[0104] Power flow calculation is represented as follows:
[0105]
[0106] Among them, Y ik V represents the elements of the admittance matrix. iV represents the voltage at node i. k Let θ represent the voltage at node k. i θ k Let i and k be the phase angles of nodes i and k, respectively.
[0107] The impact of cyberattacks on power system balance is expressed as follows:
[0108] L 吞吐量 =T 正常 -T 攻击
[0109] Among them, L 吞吐量 T represents throughput loss. 正常 T represents the throughput of a power system when it is not under attack. 攻击 This indicates the throughput of the power system when it is under attack.
[0110] When the throughput loss exceeds the acceptable threshold, it indicates that the simulated attack exceeds the power system's tolerance.
[0111] In addition, to quantitatively analyze the impact of DoS attacks on power system stability, the following model was used to calculate the system frequency drop during the attack: Where Δf represents the system frequency change, P loss R is the power lost due to the attack, D is the system's total frequency response capability, and P is the damping coefficient. total This is the total power requirement of the system.
[0112] System response time is expressed as,
[0113] T = T 处理 +T 传输 +T 执行
[0114] The stability index is expressed as follows:
[0115]
[0116] Among them, T 处理 T represents the data processing time. 传输 T represents the data transmission time. 执行 The data execution time is represented by n, the number of failures is represented by m, and the total number of operations is represented by m.
[0117] System analysis and power generation control decisions include, when throughput loss exceeds the acceptable loss threshold, if the system response time does not exceed the response time threshold and the stability does not exceed the stability threshold, strengthening monitoring and data analysis, and implementing regular security audits and network traffic analysis.
[0118] When the throughput loss exceeds the acceptable threshold, if the system response time exceeds the response time threshold but the stability does not exceed the stability threshold, the fast response protocol is updated, including clarifying role responsibilities and action steps.
[0119] When the throughput loss exceeds the acceptable loss threshold, if the system response time does not exceed the response time threshold and the stability exceeds the stability threshold, the existing recovery process should be reviewed and optimized, including increasing the number of backup servers.
[0120] When the throughput loss exceeds the acceptable threshold, if the system response time exceeds the response time threshold and the stability exceeds the stability threshold, then upgrade the firewall rules and signature library, strengthen the security of existing hardware devices, and increase the frequency of data backup.
[0121] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, essentially, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0122] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device.
[0123] More specific examples of computer-readable media (a non-exhaustive list) include: electrical connections (electronic devices) having one or more wires, portable computer disk drives (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.
[0124] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.
[0125] Example 3, referring to Figures 4-6 In this embodiment, in order to verify the beneficial effects of the present invention, scientific demonstration is carried out through economic benefit calculation and simulation experiments.
[0126] Figure 4 This is a schematic diagram of the physical model structure of the IEEE-14 bus system, showing a complex network structure consisting of five generators and multiple transmission lines. In this model, the generators act as energy providers for the power system, transmitting power to each bus through the transmission lines. The buses, on the other hand, act as key nodes in power distribution, ensuring that power is effectively distributed throughout the system. This structure demonstrates the interaction logic of the three main components—generators, buses, and transmission lines—forming a mesh structure to enhance system reliability. Even if some lines fail, power supply can be maintained through other paths.
[0127] Figure 5This chart compares the power generation of the IEEE-14 bus system under FDI attacks, showing the actual power generation of each generator under normal operation and FDI attack conditions. The chart clearly indicates the power output of different generators under normal and FDI attack conditions, as well as their initial power. It shows that under an FDI attack, the power generation of most generators increases significantly, especially generators 3, 6, and 8, whose power generation increases significantly from zero. This reflects the potential for power system overload and increased system instability caused by FDI attacks. Furthermore, the chart reveals the impact of FDI attacks on power dispatch decisions, showing how attacks can mislead the power system into issuing incorrect operating commands, potentially leading to system overload or even imbalance.
[0128] Figure 6 The graph showing network performance changes under a DoS attack is divided into two parts. Figure 6 (a) illustrates the changes in packet input and output under normal operating conditions and DoS attack conditions. The X-axis represents time, extending from 0 seconds to 60 seconds, while the Y-axis records the number of packets processed per second. The red line in the graph represents the number of packets during a DoS attack, while the purple line shows the number of packets under normal operating conditions. Under normal operating conditions, packet traffic remains at a low and stable level, while during a DoS attack, the number of packets is significantly higher than normal and remains relatively stable throughout the observation period. The high traffic caused by the attack persists until the final stage, followed by a sudden drop; this sharp decrease may indicate the end of the attack or a change in the attack strategy. Figure 6(b) By displaying the changes in server response time before and after a DoS attack, the impact of a network attack on server performance is visually demonstrated. The X-axis represents the number of samples, ranging from 0 to 50, with each point representing a measurement of server response time. The Y-axis displays response time in milliseconds, extending from 0 to approximately 250 milliseconds. As can be seen from the graph, the 20th sampling point marks the start of the DoS attack. Before the attack, the curve is stable, with response time remaining at a low level. However, once the attack begins, the response time rises rapidly and shows significant fluctuations in subsequent samples, reflecting the difficulty the server faces in processing requests under high pressure. Attacks can cause master station failures, thereby impairing control and monitoring capabilities over the power network. DoS attacks prevent the provision of normal services by consuming target resources. In power systems, such attacks can severely degrade the responsiveness of critical operational equipment (such as remote terminal units in substations), affecting their ability to handle normal operational requests. Through simulated attacks, a significant increase in system communication latency and a decrease in data processing and transmission efficiency were observed. Experiments on the IEEE-14 bus system showed that the system's packet throughput dropped significantly during a DoS attack, and the system response time increased from less than 1 millisecond to approximately 164 milliseconds, severely impacting the performance and stability of the power system. Simulation results demonstrate that the attacked system experienced a significant performance degradation in data transmission and real-time monitoring, proving that in real-world power systems, such attacks could lead to widespread power outages and system disruptions.
[0129] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
Claims
1. A power system network attack simulation and security assessment system, characterized in that, include, Management system, communication network, physical power system simulator, and performance and safety testing functions; The management system includes a client, a database, a human-computer interface, and a server; The communication network includes wireless communication technology and a network intrusion detection system; The physical power system simulator includes a power load balancing module, a power grid simulator, and power system analysis software. The management system is responsible for real-time monitoring and control of the power network; The communication network is responsible for connecting the management system and the physical power system simulator. It simulates data transmission through the network simulator and evaluates network latency and communication efficiency. Specifically, it calculates data transmission time and transmission efficiency through network latency simulation technology. The physical power system simulator simulates the operation of the actual power grid in a control environment, supports the simulation of network attacks, and observes the impact of network attacks on power balance through the power system load balance formula, and evaluates the impact of network attacks on the stability and security of the power system. The performance and security testing function assesses the performance loss and system resilience caused by network attacks by calculating throughput loss and system frequency changes, and identifies malicious activities or abnormal data streams by real-time monitoring and analysis of data packets in the communication network through the network intrusion detection system. The evaluation of network latency and communication efficiency includes simulating data transmission between local area network nodes using a network simulator to obtain transmission efficiency, protocol efficiency, network latency, and data transmission latency. The transmission efficiency is expressed as, The network latency is expressed as, The protocol efficiency is expressed as follows: The data transmission delay is expressed as, Among them, g e Indicates lost data packets, g h The total number of data packets sent is represented by τ0, and the basic network latency is represented by d. i and v i These are the transmission distance and network speed of the i-th segment, respectively, L 有效 L represents the amount of data effectively transmitted. 总 The total amount of data transmitted is represented by T, where L represents the packet length, R represents the link transmission efficiency, and T represents the total amount of data transmitted. 传播 This indicates the propagation delay of a signal in a medium; The physical power system simulator simulates network attacks based on the power system load balance formula, evaluates the power system's recovery capability after being attacked by network attacks based on the recovery time model, and performs steady-state analysis based on MATPOWER. The power system load balance formula is expressed as follows: Among them, P G,i P represents the power generation of the i-th node. D,i T represents the power consumption of the i-th node. ij This represents the power transmission loss from node i to node j; The recovery time model is expressed as follows: Among them, T 恢复 C represents the time it takes for the power system to recover from an attack to normal operation. 恢复 S represents the number of control operations required to restore the power system. 恢复能力 This represents the number of control operations performed by the power system per unit of time.
2. The power system network attack simulation and security assessment system as described in claim 1, characterized in that: The management system calculates the response time and stability of the power system. The communication network simulates data transmission between local area network nodes through a network simulator. The power load balancing module simulates and analyzes network attacks. The power grid simulator generates operating data and sends it to the management system through the communication network. After processing the received data, the management system performs system analysis and power generation control decisions using the IEC-61850 standard protocol.
3. The power system network attack simulation and security assessment system as described in claim 2, characterized in that: The communication network is further used for simulating communication protocol efficiency and network latency. The network latency simulation function is responsible for implementing communication protocols DNP3 and IEC-61850 and calculating protocol efficiency and data transmission latency.
4. The power system network attack simulation and security assessment system as described in claim 3, characterized in that: The power system analysis software includes the simulation tools OPAL-RT and MATPOWER, which are used to simulate the performance of the power system under normal and attacked conditions. OPAL-RT supports high-performance real-time simulation of the dynamic response of the power system, including changes in voltage, current and power, and is used to observe the physical response of the power system under network attacks such as FDI and DoS. MATPOWER is used for steady-state analysis, including power flow calculation and system optimization.
5. The power system network attack simulation and security assessment system as described in claim 4, characterized in that: The network intrusion detection system is deployed on the network physical test platform of the power system. It monitors and analyzes data packets of the communication network in real time to identify malicious activities or abnormal data streams. The performance and security testing function is responsible for simulating different types of network attacks, observing the power system's response speed when faced with high-frequency requests and its data processing capabilities when abnormal data flows in, and further evaluating the power system's behavior under attack conditions and the effectiveness of related security strategies.
6. A method for simulating and assessing network attacks in a power system as described in any one of claims 1 to 5, characterized in that: include, System initialization: Start the management system, initialize the communication network, and deploy the communication protocol. The management system establishes a communication connection with the physical power system simulator through a communication network, and evaluates network latency and communication efficiency. We simulated network attacks using a physical power system simulator and analyzed the impact of network attacks on the power system balance using performance and security testing functions. The management system receives simulation data from the physical power system simulator, calculates the system response time and stability indicators, and performs system analysis and power generation control decisions.
7. A method for simulating and assessing network attacks on a power system as described in claim 6, characterized in that: The steady-state analysis includes power flow calculation and system optimization; The power flow calculation is expressed as follows: Among them, Y ik V represents the elements of the admittance matrix. i V represents the voltage at node i. k Let θ represent the voltage at node k. i θ k Let i and k be the phase angles of nodes i and k, respectively. The impact of the analyzed network attacks on the power system balance is expressed as follows: L 吞吐量 =T 正常 -T 攻击 Among them, L 吞吐量 T represents the throughput loss. 正常 T represents the throughput of a power system when it is not under attack. 攻击 This indicates the throughput of the power system when it is under attack. When the throughput loss exceeds the acceptable threshold, it indicates that the simulated attack exceeds the power system's tolerance. The system response time is expressed as follows: T=T 处理 +T 传输 +T 执行 The stability index is expressed as follows: Among them, T 处理 T represents the data processing time. 传输 T represents the data transmission time. 执行 The data execution time is represented by n, the number of failures is represented by m, and the total number of operations is represented by m. The system analysis and power generation control decisions include, when the throughput loss is greater than the acceptable loss threshold, if the system response time does not exceed the response time threshold and the stability does not exceed the stability threshold, then enhanced monitoring and data analysis are carried out, and regular security audits and network traffic analysis are implemented. When the throughput loss exceeds the acceptable loss threshold, if the system response time exceeds the response time threshold but the stability does not exceed the stability threshold, the fast response protocol is updated, including clarifying role responsibilities and action steps. When the throughput loss exceeds the acceptable threshold, if the system response time does not exceed the response time threshold and the stability exceeds the stability threshold, the existing recovery process should be reviewed and optimized, including increasing the number of backup servers. When the throughput loss exceeds the acceptable threshold, if the system response time exceeds the response time threshold and the stability exceeds the stability threshold, then upgrade the firewall rules and signature library, strengthen the security of existing hardware devices, and increase the frequency of data backup.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the power system network attack simulation and security assessment system according to any one of claims 1 to 5.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the power system network attack simulation and security assessment system according to any one of claims 1 to 5.
Citation Information
Patent Citations
Power system toughness evaluation method considering time delay cascading failure
CN114564825A
Power flow calculation method and device based on embedded weight deep neural network, and storage medium
CN116365524A