An intelligent traceability method for network security alarms in a power monitoring system based on a knowledge graph and graph convolutional network
By building a network security traceability method for power monitoring system based on knowledge graph and graph convolution network, the problems of high artificial dependence and low efficiency in the existing technology are solved, and the rapid and accurate traceability of massive alarm information is achieved, and the network security monitoring capabilities of the power system are improved.
Patent Information
- Application Number
- CN202411390512.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-08
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2044-10-08
AI Technical Summary
The existing network security traceability method of power monitoring systems relies on manual experience and cannot quickly process massive alarm information. The mining and utilization of alarm information is low, and it cannot meet the rapid traceability needs of power systems.
Based on the method of knowledge graph and graph convolution network, by constructing network security knowledge graphs, obtaining vectorized expressions of alarm records, training graph convolutional neural networks, generating intelligent network security alarm traceability models, and using graph convolutional neural networks and attention mechanisms for alarm traceability.
It has achieved rapid, accurate and intelligent traceability of massive alarm information, improved the intelligence of network security traceability of power system, reduced manual intervention, and improved traceability efficiency.
Smart Images

Figure CN119299152B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of power systems and their automation, and in particular to an intelligent traceability method for network security alerts of a power monitoring system based on a knowledge graph and a graph convolutional network. Background Art
[0002] The safe operation of the power system is the foundation and lifeblood of the national economic development, and the network security of the power monitoring system is the frigate for the safe and stable operation of the power system. The traditional network security system mainly traces the alarm information based on expert experience judgment. The alarm information collected by the monitoring center is traced by the staff to find the alarm reason and then the disposal measures are given. Once a large number of alarm messages flood in within a short time, it is impossible to achieve rapid traceability by manual judgment methods, which may lead to accidents. Therefore, there is an urgent need to study a network security alarm traceability method that does not rely on manual experience and can quickly process a large amount of alarm information.
[0003] As a hot research topic in the new power system, the artificial intelligence technology provides new ideas for solving network security problems with its high processing speed and the characteristic of not relying on manual assistance. In recent years, the scale of the power grid has become increasingly large. The use of new power monitoring devices and the large-scale access of intermittent clean energy have made the models constructed by traditional methods increasingly complex and unable to meet the current power grid's requirements for alarm traceability. Machine learning and deep learning, as artificial intelligence technologies that can efficiently process big data, algorithms such as support vector machines, convolutional neural networks, and long short-term memory networks have been applied to event classification and traceability tasks. Although the above machine learning and deep learning methods have improved the intelligence of network security, the textual and vectorized languages cannot accurately and concisely represent the entities and relationships in the alarm reasons, resulting in low efficiency in mining and utilizing alarm information.
[0004] In response to the above problems, scholars have introduced knowledge graphs into related research. The knowledge graph is a data organization structure based on graphs, with more accurate knowledge representation capabilities. It can not only accurately represent a large number of alarm entities but also concisely represent the relationships between entities. Some scholars have proposed a knowledge graph construction framework for power grid dispatching fault handling services, providing a solution idea for auxiliary decision-making in fault scenarios. However, the neural network with vector inputs cannot pay attention to the knowledge system hidden in the "graph" structure of graph data, resulting in the artificial intelligence agent ignoring some effective information.
[0005] In summary, the existing network security traceability methods have problems such as high artificial dependence, inability to quickly process a large amount of alarm information, and low efficiency in mining and utilizing alarm information. Therefore, it is necessary to fully consider the intelligence and efficiency of alarm traceability and study an intelligent traceability method for network security alerts of a power monitoring system based on a knowledge graph and a graph convolutional network. Summary of the Invention
[0006] The object of the present invention is to provide an intelligent traceability method for network security alarms in a power monitoring system based on a knowledge graph and a graph convolutional network, comprising the following steps:
[0007] 1) Based on the historical data of network security alarm record texts, construct a network security knowledge graph representing a large number of alarm entities and relationships;
[0008] 2) Based on the network security knowledge graph, obtain the vectorized expression of the current network security alarm record text, and perform format conversion to generate input data;
[0009] 3) Construct a graph convolutional neural network, and train the graph convolutional neural network to obtain an intelligent traceability model for network security alarms in a power monitoring system;
[0010] 4) Input the input data into the intelligent traceability model for network security alarms in a power monitoring system to generate network security alarm traceability information.
[0011] Furthermore, the steps of constructing a network security knowledge graph representing alarm entities and relationships include:
[0012] 1.1) Knowledge extraction: Extract the vocabulary representing entities and relationships in the network security alarm record based on semantic matching technology to generate alarm text triples;
[0013] 2.1) Graph generation: Based on multiple text triples, generate a network security knowledge graph representing alarm entities and relationships;
[0014] 3.1) Knowledge representation: Perform vectorization processing on the vocabulary representing entities and relationships to obtain triples (h, r, t) representing entities and relationships; where h is the head entity vector, r is the relationship vector, and t is the tail entity vector; the relationship vector r is the transformation of the projection of the head entity h and the tail entity t on a certain hyperplane.
[0015] Furthermore, the steps of knowledge extraction include:
[0016] 1.1.1) Perform word segmentation on the alarm information using the Jieba word segmentation library; among them, the dictionary model is used to match and segment common words, and the probability model is used to segment industry-specific words; the types of common words include but are not limited to discovery, policy, and access, and the types of industry-specific words include but are not limited to address and port;
[0017] 1.1.2) Match the segmented alarm information according to the semantic characteristics of various alarm entities, define the relationships between various entities, and form network security alarm text triples in the form of (head entity, relationship, tail entity) according to the entities extracted from each alarm information and the defined relationships between entities.
[0018] Furthermore, the TransH model is used to vectorize the vocabulary representing entities and relationships.
[0019] Furthermore, during the training of the TransH model, the head entity vector h and the tail entity vector t are projected onto the hyperplane W r to obtain the projected vectors of the head entity vector h and the tail entity vector t, denoted as h ⊥ and t ⊥ respectively, and the projected vectors h ⊥ , t ⊥ , and r ⊥ are used as training data; r ⊥ is the projected vector of the relationship vector on the hyperplane W r .
[0020] Among them, the projected vectors h ⊥ , t ⊥ , and r ⊥ satisfy the following equation:
[0021] h ⊥ + r ⊥ ≈ t ⊥ (1).
[0022] Furthermore, during format conversion, the one-hot encoding technique is used to convert the alarm reason into a one-hot vector.
[0023] Furthermore, the input data includes A and H (0) ; A ∈ n×n is the original adjacency matrix; the element A ij = 1 in the adjacency matrix A indicates that there is an edge connection between node i and node j, otherwise it is 0; H (0) ∈ n×m includes the feature vectors of each node.
[0024] Furthermore, during the training of the graph convolutional neural network, the weight matrix is adjusted through the backpropagation method;
[0025] Among them, the propagation method between the l-th layer and the (l + 1)-th layer of the graph convolutional neural network is as follows:
[0026]
[0027] In the formula: A is the adjacency matrix of the graph; σ is the activation function; W (l) is the weight matrix to be trained; H (l+1) , H (l) are the outputs of the (l + 1)-th layer and the l-th layer of the graph convolutional neural network respectively.
[0028] Furthermore, the graph convolutional neural network incorporates an attention mechanism;
[0029] The attention mechanism Attention(Q, S) is expressed as follows:
[0030] Attention(Q, S) = ∑<Q, S>.S(3)
[0031] Where: S represents the information source to be processed, that is, the feature vectors of all neighbor nodes; Q is the feature vector of the current central node;
[0032] The attention coefficients between nodes in the graph convolutional neural network are as follows:
[0033]
[0034] Where: a ic is the attention coefficient between node i and node c; x i is the initial attribute information vector of node i; W ∈ R n '×n is to map the node feature vector from n dimensions to n' dimensions; D(i) is the set of neighbor nodes of node i; || represents the concatenation operation. x c and x d are the initial attribute information vectors of nodes c and d; node d is a neighbor node of node i; LeakyReLU is the activation function.
[0035] Furthermore, the power monitoring system network security alarm intelligent traceability model includes multiple basic classifiers;
[0036] When generating network security alarm traceability information, the weighted voting method is used to process the outputs of these basic classifiers to obtain the final network security alarm traceability information.
[0037] The technical effect of the present invention is beyond doubt. Based on actual alarm data and combined with the problems existing in the current power system network security early warning, an artificial intelligence model based on the knowledge graph and deep learning algorithm is designed specifically to realize the intelligence of power system network security traceability early warning and perform fast and accurate intelligent traceability on a large amount of alarm information. Brief Description of the Drawings
[0038] Figure 1 is the knowledge graph construction flow chart based on knowledge extraction and knowledge representation;
[0039] Figure 2 is the illustration of TransE and TransH models;
[0040] Figure 3 is the overall view of the knowledge graph constructed based on actual data;
[0041] Figure 4 is the working flow chart of the graph convolutional neural network;
[0042] Figure 5 It is a flowchart of oversampling and ensemble learning;
[0043] Figure 6 It is the data distribution of the training set;
[0044] Figure 7 It is the data distribution of the test set;
[0045] Figure 8 It is an example diagram of the ROC curve;
[0046] Figure 9 It is the verification of the knowledge graph effect;
[0047] Figure 10 It is the verification of the graph attention network effect;
[0048] Figure 11 It is the comparison of ROC results. Specific implementation manner
[0049] The present invention will be further described below in conjunction with embodiments, but it should not be understood that the above-mentioned subject scope of the present invention is limited to the following embodiments. Without departing from the above technical idea of the present invention, various substitutions and changes made according to the common general technical knowledge and conventional means in the art should be included within the protection scope of the present invention.
[0050] Embodiment 1:
[0051] Refer to Figures 1 to 11 , a method for intelligent tracing of network security alarms in a power monitoring system based on a knowledge graph and a graph convolutional network, comprising the following steps:
[0052] 1) Based on the historical data of network security alarm record texts, construct a network security knowledge graph representing alarm entities and relationships;
[0053] 2) Based on the network security knowledge graph, obtain the vectorized expression of the current network security alarm record text, and perform format conversion to generate input data;
[0054] 3) Construct a graph convolutional neural network, and train the graph convolutional neural network to obtain a network security alarm intelligent tracing model for the power monitoring system;
[0055] 4) Input the input data into the network security alarm intelligent tracing model for the power monitoring system to generate network security alarm tracing information.
[0056] The steps of constructing a network security knowledge graph representing alarm entities and relationships include:
[0057] 1.1) Knowledge extraction: Extract the words representing entities and relationships in the network security alarm record based on semantic matching technology to generate alarm text triples;
[0058] 1.2) Knowledge graph generation: Based on multiple text triples, generate a cybersecurity knowledge graph representing alert entities and relationships;
[0059] 1.3) Knowledge representation: Vectorize the vocabulary representing entities and relationships to obtain triples (h, r, t) representing entities and relationships; where h is the head entity vector, r is the relationship vector, and t is the tail entity vector; the relationship vector r is the transformation of the projections of the head entity h and the tail entity t on a certain hyperplane.
[0060] The steps of knowledge extraction include:
[0061] 1.1.1) Perform word segmentation on the alert information using the Jieba word segmentation library; among them, use the dictionary model to match and segment common words, and use the probability model to segment industry-specific words; the types of common words include but are not limited to discovery, policy, and access, and the types of industry-specific words include but are not limited to address and port;
[0062] 1.1.2) Match the word-segmented alert information according to the semantic characteristics of various alert entities, define the relationships between various entities, and form a cybersecurity alert text triple in the form of (head entity, relationship, tail entity) according to the entities extracted from each alert information and the defined relationships between entities.
[0063] Vectorize the vocabulary representing entities and relationships through the TransH model.
[0064] When training the TransH model, project the head entity vector h and the tail entity vector t onto the hyperplane W r to obtain the projection vectors of the head entity vector h and the tail entity vector t, denoted as h ⊥ and t ⊥ , and use the projection vectors h ⊥ , t ⊥ , r ⊥ as training data; r ⊥ is the projection vector of the relationship vector on the hyperplane W r ;
[0065] Among them, the projection vectors h ⊥ , t ⊥ , r ⊥ satisfy the following formula:
[0066] h ⊥ +r ⊥ ≈t ⊥ (1).
[0067] When performing format conversion, use the one-hot encoding technique to convert the alert reason into a one-hot vector.
[0068] The input data includes A and H (0) ; A ∈ n×n is the original adjacency matrix; the element A ij = 1 in the adjacency matrix A indicates that there is an edge connection between node i and node j, otherwise it is 0; H (0) ∈ n×m includes the eigenvectors of each node.
[0069] During the training process of the graph convolutional neural network, the weight matrix is adjusted by the backpropagation method;
[0070] Among them, the propagation method between the l-th layer and the (l + 1)-th layer of the graph convolutional neural network is as follows:
[0071]
[0072] In the formula: A is the adjacency matrix of the graph; σ is the activation function; W is the weight matrix to be trained.
[0073] The graph convolutional neural network cited the attention mechanism;
[0074] The attention mechanism Attention(Q, S) is expressed as follows:
[0075] Attention(Q, S) = ∑<Q, S>.S(3)
[0076] In the formula: S represents the information source to be processed, that is, the eigenvectors of all neighbor nodes; Q is the eigenvector of the current central node;
[0077] The attention coefficients between nodes of the graph convolutional neural network are as follows:
[0078]
[0079] In the formula: a ic is the attention coefficient between node i and node c; x i is the initial attribute information vector of node i; W ∈ R n '×n is to map the node eigenvector from n dimensions to n' dimensions; D(i) is the set of neighbor nodes of node i; || represents the concatenation operation. x c 、x d are the initial attribute information vectors of nodes c and d; node d is a neighbor node of node i; LeakyReLU is the activation function.
[0080] The network security alarm intelligent traceability model of the power monitoring system includes multiple basic classifiers;
[0081] When generating the network security alert traceability information, the weighted voting method is used to process the outputs of these basic classifiers to obtain the final network security alert traceability information.
[0082] Embodiment 2:
[0083] An intelligent traceability method for network security alerts in a power monitoring system based on a knowledge graph and a graph convolutional network, comprising the following steps:
[0084] 1) Based on the historical data of network security alert record texts, construct a network security knowledge graph representing alert entities and relationships;
[0085] 2) Based on the network security knowledge graph, obtain the vectorized expression of the current network security alert record text, and perform format conversion to generate input data;
[0086] 3) Construct a graph convolutional neural network and train the graph convolutional neural network to obtain an intelligent traceability model for network security alerts in the power monitoring system;
[0087] 4) Input the input data into the intelligent traceability model for network security alerts in the power monitoring system to generate network security alert traceability information.
[0088] Embodiment 3:
[0089] An intelligent traceability method for network security alerts in a power monitoring system based on a knowledge graph and a graph convolutional network, the technical content is the same as that of Embodiment 2. Further, the steps of constructing a network security knowledge graph representing alert entities and relationships include:
[0090] 1) Knowledge extraction: Based on semantic matching technology, extract the vocabulary representing entities and relationships in the network security alert records to generate alert text triples;
[0091] 2) Graph generation: Based on multiple text triples, generate a network security knowledge graph representing alert entities and relationships;
[0092] 3) Knowledge representation: Perform vectorization processing on the vocabulary representing entities and relationships to obtain triples (h, r, t) representing entities and relationships; where h is the head entity vector, r is the relationship vector, and t is the tail entity vector; the relationship vector r is the transformation of the projection of the head entity h and the tail entity t on a certain hyperplane.
[0093] Embodiment 4:
[0094] An intelligent traceability method for network security alerts in a power monitoring system based on a knowledge graph and a graph convolutional network, the technical content is the same as any one of Embodiments 2-3. Further, the steps of knowledge extraction include:
[0095] 1) Propose a word segmentation technology for cybersecurity alert information based on the Jieba word segmentation library: Perform word segmentation on the alert information using the Jieba word segmentation library. For common words such as discovery, policy, and access, use the dictionary model for matching and word segmentation. For industry-specific words such as addresses and ports, use the probability model for word segmentation;
[0096] 2) Propose a triple method for cybersecurity alert text based on semantic matching technology: Match the segmented alert information according to the semantic characteristics of various alert entities, define the relationships between various entities, and form a cybersecurity alert text triple in the form of (head entity, relationship, tail entity) according to the relationships between the entities extracted from each alert information and the defined entities;
[0097] Example 5:
[0098] An intelligent traceability method for network security alerts in a power monitoring system based on a knowledge graph and a graph convolutional network, the technical content is the same as any one of Examples 2-4. Further, the vocabulary representing entities and relationships is vectorized through the TransH model.
[0099] Example 6:
[0100] An intelligent traceability method for network security alerts in a power monitoring system based on a knowledge graph and a graph convolutional network, the technical content is the same as any one of Examples 2-5. Further, when training the TransH model, project the head entity vector h and the tail entity vector t onto the hyperplane W r to obtain the projection vectors of the head entity vector h and the tail entity vector t, denoted as h ⊥ and t ⊥ , and use the projection vectors h ⊥ , t ⊥ , r ⊥ as training data; r ⊥ is the projection vector of the relationship vector on the hyperplane W r ;
[0101] Among them, the projection vectors h ⊥ , t ⊥ , r ⊥ satisfy the following formula:
[0102] h ⊥ +r ⊥ ≈t ⊥ (1).
[0103] Example 7:
[0104] An intelligent traceability method for network security alerts in a power monitoring system based on a knowledge graph and a graph convolutional network, the technical content is the same as any one of Examples 2-6. Further, when performing format conversion, use one-hot encoding technology to convert the alert reason into a one-hot vector.
[0105] Example 8:
[0106] An intelligent traceability method for network security alarms of a power monitoring system based on a knowledge graph and a graph convolutional network. The technical content is the same as any one of Examples 2-7. Further, the input data includes A and H (0) ; A ∈ n×n is the original adjacency matrix; the element A ij = 1 in the adjacency matrix A indicates that there is an edge connection between node i and node j, otherwise it is 0; H (0) ∈ n×m includes the feature vectors of each node.
[0107] Example 9:
[0108] An intelligent traceability method for network security alarms of a power monitoring system based on a knowledge graph and a graph convolutional network. The technical content is the same as any one of Examples 2-8. Further, during the training process of the graph convolutional neural network, the weight matrix is adjusted by the backpropagation method;
[0109] Among them, the propagation method between the l-th layer and the (l + 1)-th layer of the graph convolutional neural network is as follows:
[0110]
[0111] In the formula: A is the adjacency matrix of the graph; σ is the activation function; W (l) is the weight matrix to be trained; H (l+1) , H (l) are the outputs of the (l + 1)-th layer and the l-th layer of the graph convolutional neural network.
[0112] Example 10:
[0113] An intelligent traceability method for network security alarms of a power monitoring system based on a knowledge graph and a graph convolutional network. The technical content is the same as any one of Examples 2-9. Further, the graph convolutional neural network incorporates an attention mechanism;
[0114] The attention mechanism is expressed as follows:
[0115] Attention(Q, S) = ∑<Q, S>.S(3)
[0116] In the formula: S represents the information source to be processed, that is, the feature vectors of all neighbor nodes; Q is the feature vector of the current central node;
[0117] The attention coefficient between nodes of the graph convolutional neural network is as follows:
[0118]
[0119] In the formula: aic is the attention coefficient between node i and node c; x i is the initial attribute information vector of node i; W ∈ R n '×n maps the node feature vector from n dimensions to n' dimensions; D(i) is the set of neighbor nodes of node i; || represents the concatenation operation.
[0120] Embodiment 11:
[0121] An intelligent traceability method for network security alarms in a power monitoring system based on a knowledge graph and a graph convolutional network, the technical content is the same as any one of Embodiments 2-10. Further, the intelligent traceability model for network security alarms in the power monitoring system includes multiple basic classifiers;
[0122] When generating network security alarm traceability information, the weighted voting method is used to process the outputs of these basic classifiers to obtain the final network security alarm traceability information.
[0123] Embodiment 12:
[0124] An intelligent traceability method for network security alarms in a power monitoring system based on a knowledge graph and a graph convolutional network. First, aiming at the problem that a large number of alarm entities and relationships cannot be accurately and concisely represented by textual and vectorized languages, a knowledge graph construction and knowledge representation technology for streamlining the representation of a large number of network security alarm entities and relationships is proposed to achieve a streamlined representation of entities in a large number of alarm information. Second, aiming at the problem that deep learning methods such as convolutional neural networks with vectors as inputs cannot fully utilize the graph data of the network security knowledge graph, an efficient and accurate intelligent traceability method for network security alarms based on a graph convolutional network and an attention mechanism is further proposed, using the graph convolutional network to fully utilize the graph data and the attention mechanism to strengthen the utilization of alarm information-related entities in the sub-graph of the network security knowledge graph. Finally, aiming at the problem that the probability of alarm causes such as device operations and regional alarms is too small, resulting in sample imbalance and the graph attention network being too biased towards network security alarms with a high proportion, a technology for dealing with the sample imbalance problem of network security alarm traceability based on oversampling and Bagging ensemble learning is proposed, solving the problem of low traceability accuracy caused by unbalanced alarm causes. Verified by data provided by a certain actual power grid company, it shows that the proposed method can quickly and accurately perform intelligent traceability on a large number of alarm information, verifying the effectiveness and practical potential of the proposed method. The specific method steps are as follows:
[0125] (1) Knowledge graph construction and knowledge representation technology for streamlining the representation of a large number of network security alarm entities and relationships
[0126] The construction of the network security knowledge graph consists of two steps: knowledge extraction, graph construction, and knowledge representation. The specific steps are as follows.
[0127] 1) A network security alert information word segmentation technology based on the Jieba word segmentation library is proposed. Each network security alert sample consists of information such as "alert description", "alert site", "alert device", and "alert reason". Among them, the "alert description" contains the IP and port where the alert occurred, in a form similar to "Detected an access that does not conform to the security policy, port a of local address 10.70.xxx.xxx, accessing port b of remote address 10.70.xxx.xx"; the "alert site" contains the site and voltage level where the alert occurred, in a form similar to "110KV xx Substation"; the "alert reason" is the cause of the alert given by the staff after analysis, that is, the label for training the network security alert traceability model. Therefore, Jieba word segmentation is performed on alert information such as "alert description", "alert site", and "alert device". Network security alert information consists of common words and industry-specific words in the power industry. First, the Jieba word segmentation library uses the dictionary model to match and segment common words such as "detected", "policy", and "access" in the network security alert information; further, for the remaining industry-specific words such as "address", "port", and "substation" in the network security alert information, the probability model is used for word segmentation. In summary, through Jieba word segmentation, the network security alert statement can be split into word forms. For example, the word segmentation result of the above "alert description" is: "Detected / does not conform to / security / policy / of / access, local / address / 10.70.xxx.xxx / of / a / port, accessing / remote / address / 10.70.xxx.xx / of / b / port"; the word segmentation result of the "alert site" is: "110 / KV / xx / Substation", providing input for subsequent entity and relationship extraction.
[0128] 2) Propose a triple method for cybersecurity alert texts based on semantic matching technology. In cybersecurity alert information, there are alert entities such as sites, devices, IPs, ports, and site voltage levels. Sites and voltage levels are recorded in the "alert site"; IPs and ports are recorded in the "alert details". First, match the word-form alert information obtained in 1) according to the semantic characteristics of the alert entities. The semantic matching technology scans the input word-form alert information one by one and matches it according to the semantic characteristics of the alert entities. For example, in the alert information mentioned in 1), "110KV" is an entity of the voltage level type, "xx Substation" is an entity of the site type, and "10.70.xxx.xxx" is an entity of the IP type. Further, define the relationships between different types of cybersecurity alert entities. There are "belong to" or "own" relationships between every two types of alert entities. For example, a site "belongs to" a voltage level, a site "owns" devices, and an IP "owns" a port. Finally, according to the relationships between the entities extracted from each alert information and the defined entities, form cybersecurity alert text triples in the form of (head entity, relationship, tail entity). Since there are only two types of relationships, "own" and "belong to", in the cybersecurity alert text triples, but there are a variety of massive entities such as sites, devices, and IPs, there are the following three types of alert text triples: ① One-to-one: (Substation A, belong to, 110KV), (Power Plant B, belong to, 220KV); ② One-to-many: (10.70.xxx.xx, own, a port), (10.70.xxx.xx, own, c port); ③ Many-to-one: (Wind Farm C, belong to, 220KV), (Photovoltaic Power Station D, belong to, 220KV). By extracting entities and relationships, the word-form cybersecurity alert information is transformed into cybersecurity alert text triples, providing input for the subsequent construction of the cybersecurity alert knowledge graph.
[0129] After knowledge extraction, multiple corresponding triples can be inferred from each alert detail. Taking an alert information in the sample as an example, the results are shown in Table 1:
[0130] Table 1 Example of Alert Extraction Results
[0131]
[0132]
[0133] The task of knowledge representation is to present the semantic relationships in the cybersecurity knowledge graph, and present the literal information such as entities and relationships to the computer in digital form for understanding. In the knowledge graph, triples are used to store instances, that is, (h, r, t). Among them, h is the head entity, r is the relationship, and t is the tail entity. The Trans E model represents relationships and entities as vectors in the same space. Given a fact (h, r, t), the vector r representing the relationship is interpreted as the translation between the head entity vector h and the tail entity vector t, that is, satisfying:
[0134] h + r ≈ t (1)
[0135] However, since the model can only efficiently represent the relationship pattern of one entity corresponding to one entity, for the cybersecurity system, the same entity may have multiple entity relationships, and a vast number of entities ultimately form an intricate network. The Trans E model based on a two-dimensional plane cannot handle one-to-many and many-to-many relationships well. To solve the complex relationship problem that the Trans E model cannot handle, the present invention introduces a knowledge graph embedding method Trans H based on hyperplane translation. Trans H regards the relationship r as the transformation of the projection of the head entity h and the tail entity t on a certain hyperplane. Trans H regards the vector on the hyperplane as the vector representation of the relationship, rather than placing the relationship vector and the entity vector in the same vector space as Trans E. The head vector (h) and the tail vector (t) are projected onto the hyperplane W r to obtain the projection vectors of h and t, which are h ⊥ and t ⊥ . During the training process, h, r, and t follow the following equation:
[0136] h ⊥ + d ⊥ ≈ t ⊥ (2)
[0137] During the training process of Trans H, the original h and t vectors are not used, but W r is used to project h and t. For different relationships, h and t can have different performances, avoiding the two entities being too close during the training process. Therefore, using the Trans H model, the alarm information of the power monitoring system can be transformed from the text information that cannot be directly understood by the computer into digital vector information, providing data information for subsequent traceability tasks.
[0138] Since the entities and relationships in the alarm information have been extracted during the construction of the knowledge graph of the power situation awareness system, the entities, relationships, and attributes in the alarm information triples can be directly vectorized using knowledge representation technology, and the results are shown in Table 2:
[0139] Table 2 Results of knowledge graph representation learning
[0140] Entity name Vector form 500KV XX Substation [0.223,……,0.352] XX Center [0.536,……,0.831]
[0141] After entity relationship extraction based on semantic matching technology and knowledge graph representation learning based on Trans H for 70,110 alarm messages provided by a certain actual power grid company, all the information required for constructing a power system network security knowledge graph was obtained. The Py2neo module was used to construct a power system network security knowledge graph on the Neo4j database. Alarm IP, alarm site, alarm device, alarm port, and voltage level of the alarm site were used as entity information, and the relationships between entities were represented by vector arrows, and the relationships were described on the vector arrows, forming a network security knowledge graph as shown in Figure 3 with 12,000 nodes and 23,000 relationships. When a new alarm message is input, the network security knowledge graph will match the entities in it. When a matching entity is retrieved, starting from this entity, it will search for adjacent nodes along the existing relationships. Finally, the adjacent nodes and the starting node together form a new graph data, and each node and relationship has a unique vector corresponding to it, realizing the accurate characterization of the features of network security alarm data.
[0142] (2) Intelligent traceability method based on graph convolutional neural network
[0143] The intelligent traceability method consists of two parts: input-output construction and intelligent reasoning.
[0144] For a graph convolutional neural network, it is impossible to directly use graph data or text information as input for traceability reasoning, and an input format that conforms to the graph convolutional neural network needs to be constructed. During the construction of the power monitoring system knowledge graph, the representation learning technology based on Trans H has been used to vectorize graph data and text data. Therefore, the vectorized data needs to be constructed into an input form that conforms to the graph convolutional neural network.
[0145] The input of the graph convolutional neural network consists of A and H (0) where A is the original adjacency matrix A ij = 1 indicates that there is an edge connection between node i and node j, otherwise it is 0, and H (0) is composed of the feature vectors of each node. Since each node and relationship has a unique feature vector, A is an n×n matrix, and H (0) is an n×m matrix, where m is the dimension of the feature vector. For the graph convolutional neural network model, the weight matrix W is initially a random matrix, and the parameters are adjusted by backpropagation during the network training. The output H of the l-th layer (l)It will be the input matrix of the l+1 layer. Since the graph convolutional neural network is supervised deep learning, reasonably constructing the output content is also an important part of improving the training efficiency. By traversing the data provided by a certain actual power grid company, the alarm reasons can be divided into the following five categories: daily equipment operations, zone four and zone five alarms, user access attempts, redundant services, and others. One-hot encoding is used to encode these five alarm reasons.
[0146] The graph convolutional network is an extension of the traditional convolutional network in the non-Euclidean space. It can not only automatically extract the features of input variables using multiple graph convolutional layers, but also take into account the topological structure between each node, making it very suitable for processing complex graph data. Compared with traditional machine learning, the graph convolutional neural network can not only utilize the local feature information of samples, but also learn the structural information representing local correlations. Each update of node features is the result of the joint action of multiple structurally adjacent nodes. The propagation method between layers of the GCN is shown in Equation (3).
[0147]
[0148] In the formula: A is the adjacency matrix of the graph; σ is the activation function; W is the weight matrix to be trained
[0149] However, the graph convolutional network assigns the same weights to different neighbor nodes in the same-order neighborhood, and its combination of neighbor node features and the graph structure is closely related, which limits the generalization ability of the trained model on other graph structures. It is not easy for a single GCN to assign different learning weights to different neighboring nodes. Since there is a large amount of redundant information in the alarm information, in order to focus on the effective information during the convolution process, an attention mechanism is added to the GCN to form a graph attention network (GAT).
[0150] The attention mechanism optimizes the model and makes a more accurate judgment by assigning different weights to different parts of interest in the model and extracting more important and key information from them. GAT considers the geometric relationship between the target node and other nodes spatially, can adaptively aggregate neighbor nodes and assign different weight coefficients to them, so as to better integrate the correlation of distribution network node features into the alarm traceability model. The attention mechanism can be expressed as shown in (4).
[0151] Attention(Q,S)=∑<Q,S>.S(4)
[0152] In the formula: S represents the information source to be processed, that is, the feature vectors of all neighbor nodes; Q is some prior information, that is, the feature vector of the current central node.
[0153] The main steps of the GAT algorithm are usually node feature transformation, calculation of attention coefficients between nodes, and information aggregation. First, it is necessary to perform feature transformation on nodes and calculate the attention coefficients between nodes. Taking node i and its neighbor node c as an example:
[0154]
[0155] In the formula: a ic is the attention coefficient between node i and node c; x i is the initial attribute information vector of node i; W ∈ R n '×n is to map the node feature vector from n dimensions to n' dimensions; D(i) is the set of neighbor nodes of node i; || represents the concatenation operation;
[0156] The specific implementation process of intelligent traceability is as follows.
[0157] Step 1: Extract entities and relationships from the original alarm information to generate power system network security triples.
[0158] Step 2: Use the Neo4j graph database to generate a power system network security knowledge graph from the power system network security triples, complete knowledge expansion and knowledge generation using the knowledge graph, learn entity relationships based on the Trans H model, and vectorize complex text information.
[0159] Step 3: According to the input features of the graph convolutional neural network, construct an association matrix A and a feature matrix X, and use one-hot encoding technology to convert the alarm reason into a one-hot vector.
[0160] Step 4: Build a GCN network, which is jointly composed of GCN layers and an attention mechanism. Determine hyperparameters such as the network depth n and the hidden layer size, and set relevant parameters such as the solver, learning rate, and number of iterations.
[0161] Step 5: Use the training set to train the GCN network, and the validation set to assist network training until convergence and stability.
[0162] Step 6: Use the trained GCN network to test the samples in the test set and output the traceability results.
[0163] (3) Multi-agent integrated traceability method based on ensemble learning
[0164] Since in the alarm information of the power monitoring system, the proportions of various alarm reasons vary greatly, and there is a problem of sample imbalance in the data, which in turn leads to potential problems such as insufficient learning and poor classification performance in the network training process. Therefore, an ensemble learning method is used to improve the model, integrating a single GCN network into multiple base classifiers, and using the weighted voting method to output the traceability results.
[0165] Considering that there is a huge difference in the occurrence frequencies of alarm causes in actual power system alarm information, the unbalanced sample labels pose great difficulties for the learning of artificial intelligence, resulting in large prediction deviations of the obtained artificial intelligence agents in some cases. An alarm traceability method based on ensemble learning is proposed to deal with the problem of unbalanced alarm information labels. The specific process is as shown and is divided into the following four modules:
[0166] Module 1: Randomly extract the original training set through the Bootstraping module to form 10 randomly generated base training sets
[0167] Module 2: Provide the randomly generated base training sets to 10 basic classifiers, and each classifier outputs a unique vector result
[0168] Module 3: Use the voting method to count the output results of each classifier and finally output the result with the highest frequency
[0169] Through ensemble learning, the learning ability of the model for alarm causes with fewer samples is enhanced, and finally an artificial intelligence agent for a complete network security alarm system is realized.
[0170] Example 13:
[0171] Verification of a network security alarm intelligent traceability method for a power monitoring system based on a knowledge graph and a graph convolutional network is as follows:
[0172] (1) Training sample acquisition and preprocessing
[0173] In this example, data provided by a certain actual power company is used for training, which includes a total of 70,110 pieces of alarm information from March 23, 2023 to May 22, 2023. The composition of the alarm information is mainly shown in Table 3. Among them, "alarm description", "alarm site", "source site", "alarm device" and "alarm cause" are the input contents of the model constructed by the present invention, and the training set and test set are divided according to a ratio of 9:1.
[0174] Table 3 Example of alarm information
[0175]
[0176] Table 4 Trans H model parameters
[0177] Trans H Model Parameters Value Learning rate 0.001 Embeddingdim (Dimension of the embedding vector) 50 Margin (Parameter of the loss function) 1.0 Norm (Type of norm used when calculating the score) 1
[0178] (2) Evaluation indicators
[0179] The present invention uses common evaluation methods in the fields of machine learning and deep learning to evaluate the constructed model. The evaluation indicators are precision (P recision ) and recall (Recall ) The accuracy rate (A ccuracy ) and F 1_score , and the specific definitions are as follows:
[0180] P recision = T P / (T P + F P )(1)
[0181]
[0182] Wherein T P , T N , F P , F N are the elements in the confusion matrix. T P refers to the correctly predicted positive examples, T N refers to the correctly predicted negative examples, F P refers to the negative examples with the true value being wrongly predicted as positive examples, F N refers to the positive examples with the true value being wrongly predicted as negative examples, as shown in Table 5.
[0183] Table 5 Confusion Matrix of Classification Problems
[0184] Detected as positive Detected as negative Actually positive TP (true positive) FN (false negative) Actually negative FP (false positive) TN (true negative)
[0185] The ROC curve takes each value of the prediction result as a possible judgment threshold, and the corresponding sensitivity and specificity are calculated therefrom. The false positive rate (FPR) is used as the abscissa, as in (5); the true positive rate (TPR), that is, the sensitivity, is used as the ordinate to draw the curve, as in (6).
[0186]
[0187] The size of the area under its curve (AUC) is used as a measure of the prediction accuracy of the model, and its value range is [0, 1]. The larger the value, the stronger the judgment ability of the model. For this model, the tracing process can be regarded as a process of classifying the alarm details into five categories. Therefore, the ROC curve is used as the evaluation index.
[0188] (3) Model Parameter and Comparative Example Setting
[0189] To verify the effectiveness of the knowledge graph - graph convolution early warning model built by the present invention, the power system network security early warning data provided by a certain actual power grid company is used as the experimental object, and 70,110 effective alarm messages therein are used to verify the model. The model parameters are shown in the following table.
[0190] Table 6 GCN Model Parameters
[0191]
[0192]
[0193] To compare and analyze the improvement effects of knowledge graphs, graph convolutional neural networks, and ensemble learning on the alarm traceability task, the present invention selects four models, namely, GRU neural network, Bi LSTM-Attention, knowledge graph + SVM, and knowledge graph + GCN (excluding ensemble learning), and compares them with Neo4j + GCN + ensemble learning established in the present invention.
[0194] (4) Verification of the effect of the knowledge graph
[0195] To verify that the knowledge graph has a better classification effect on alarm information than traditional models, the knowledge graph + GCN (excluding ensemble learning) model is compared with the power grid alarm information classification model based on the GRU neural network and the power grid alarm model based on Bi LSTM-Attention. The power grid alarm information classification model based on the GRU neural network and the power grid alarm model based on Bi LSTM-Attention are both based on deep learning methods.
[0196] As can be seen from the result graph, the GRU model and the Bi LSTM model cannot identify the alarm cause models other than "redundant services", which proves that traditional knowledge representation models cannot classify alarm causes. However, after vectorizing the text using the knowledge graph, some alarm causes can be identified.
[0197] (5) Verification of the effect of the graph attention network
[0198] To verify the improvement of the graph attention neural network on the network security warning effect, the knowledge graph + GCN (excluding ensemble learning) model is compared with the knowledge graph + SVM, where SVM is a machine learning method. By comparing the effects of machine learning and deep learning, it can be seen from the graph that compared with traditional machine learning methods, the deep learning-based model has stronger recognition ability for various alarm causes.
[0199] (6) Verification of the effect of ensemble learning
[0200] To verify that ensemble learning can improve the classification effect of the knowledge graph-graph convolution model on alarm information, the classification effects of the knowledge graph + GAT (excluding ensemble learning) model and the knowledge graph + GAT + ensemble learning model on alarm information are compared. Since both the knowledge graph + GAT (excluding ensemble learning) model and the knowledge graph + GAT + ensemble learning model can identify alarm information, the ROC graph can be used to compare their results.
[0201] It can be seen from the ROC curve that the performance of M1 is better than that of M2 and M2 is better than that of M3. Therefore, the model of knowledge graph + graph convolutional neural network has a higher accuracy than the model of knowledge graph + machine learning. After adding ensemble learning, the AUC value of the model is close to 1, and the accuracy is further improved.
[0202] In summary, based on the actual alarm data and combined with the problems existing in the current power system network security warning, the present invention specifically designs an artificial intelligence model based on the knowledge graph and deep learning algorithm to realize the intelligence of power system network security traceability warning and quickly and accurately perform intelligent traceability on a large amount of alarm information.
Claims
1. An intelligent traceability method for network security alerts in a power monitoring system based on a knowledge graph and a graph convolutional network, characterized in that, The following steps are involved: 1) Based on the historical text data of cybersecurity alarm records, a cybersecurity knowledge graph is constructed to represent the entities and relationships of massive cybersecurity alarms; 2) Based on the network security knowledge graph, the vectorized expression of the current network security alarm record text is obtained through knowledge representation, and the format is converted to generate input data; 3) Construct a graph convolutional neural network and train it to obtain an intelligent tracing model for network security alarms in the power monitoring system; 4) Input the input data into the intelligent tracing model of network security alarm of the power monitoring system to generate network security alarm tracing information; The steps to construct a cybersecurity knowledge graph that represents alert entities and relationships include: 1.1) Knowledge extraction: Extract words representing entities and relationships in network security alarm records based on semantic matching technology to generate triples of alarm text; 1.2) Graph generation: Generate a network security knowledge graph representing alarm entities and relationships based on multiple text triples; 1.3) Knowledge representation: Vectorize the words representing entities and relationships to obtain a triple (h, r, t) representing entities and relationships; where h is the head entity vector, r is the relationship vector, and t is the tail entity vector; the relationship vector r is the transformation of the head entity h and the tail entity t projected on a certain hyperplane; The TransH model is used to vectorize the words representing entities and relations. When performing format conversion, the alarm cause is converted into a one-hot vector using the one-hot encoding technique; The alarm reasons can be divided into the following five categories: daily equipment operation, four-zone and five-zone alarms, user access attempts, redundant services, and others. These five categories of alarm reasons are encoded using one-hot encoding; The Trans H model parameters include learning rate = 0.001, embedding dim = 50, loss function parameter Margin = 1.0, and the norm type Norm = 1 used when calculating the score.
2. The intelligent traceability method for network security alarms of the power monitoring system based on the knowledge graph and graph convolutional network according to claim 1, characterized in that, The steps of knowledge extraction include: 1) Jieba word segmentation database is used to segment the alarm information. The dictionary model is used to match and segment common words, and the probability model is used to segment industry-specific words. 2) Match the segmented alarm information according to the semantic characteristics of each type of alarm entity, and define the relationship between each type of entity. According to the entities extracted from each alarm information and the relationship between the defined entities, form a network security alarm text triple in the form of (head entity, relationship, tail entity).
3. The intelligent traceability method for network security alarms of a power monitoring system based on a knowledge graph and a graph convolutional network according to claim 1, characterized in that, During the training of the TransH model, project the head entity vector h and the tail entity vector t onto the hyperplane W r to obtain the projection vectors of the head entity vector h and the tail entity vector t, denoted as h ⊥ and t ⊥ respectively, and use the projection vectors h ⊥ , t ⊥ , and r ⊥ as training data; r ⊥ is the projection vector of the relation vector on the hyperplane W r . Among them, the projection vectors h ⊥ , t ⊥ , r ⊥ satisfy the following formula: h ⊥ +r ⊥ ≈t ⊥ (1).
4. A method for intelligent tracing of network security alerts in a power monitoring system based on a knowledge graph and a graph convolutional network according to claim 1, characterized in that, The input data includes A and H (0) ; A ∈ n×n is the original adjacency matrix; the element A ij = 1 in the adjacency matrix A indicates that there is an edge connection between node i and node j, otherwise it is 0; H (0) ∈ n×m includes the eigenvectors of each node.
5. The intelligent traceability method for network security alarms of the power monitoring system based on the knowledge graph and graph convolutional network according to claim 1, characterized in that, During the training of graph convolutional neural networks, the weight matrix is adjusted through the back-propagation method; Among them, the propagation method between the lth layer and the l+1th layer of the graph convolutional neural network is as follows: Where: A is the adjacency matrix of the graph; matrix σ is the activation function; W (l) is the weight matrix to be trained; H (l+1) , H (l) are the outputs of the (l + 1)-th and l-th layers of the graph convolutional neural network.
6. The intelligent traceability method for network security alerts of the power monitoring system based on the knowledge graph and the graph convolutional network according to claim 1, wherein The graph convolutional neural network uses an attention mechanism; The attention mechanism Attention(Q,S) is expressed as follows: Attention(Q,S)=∑<Q,S>.S(3) Where: S represents the information source that needs to be processed, that is, the feature vectors of all neighbor nodes; Q is the feature vector of the current central node; The attention coefficients between nodes of the graph convolutional neural network are as follows: Where: a ic is the attention coefficient between node i and node c; x i is the initial attribute information vector of node i; W ∈ R n'×n is to map the node feature vector from n dimensions to n' dimensions; D(i) is the set of neighbor nodes of node i; || represents the concatenation operation; x c , x d are the initial attribute information vectors of nodes c and d; node d is a neighbor node of node i; LeakyReLU is the activation function.
7. An intelligent traceability method for network security alarms of a power monitoring system based on a knowledge graph and a graph convolutional network according to claim 1, characterized in that, The intelligent tracing model for network security alarms in power monitoring systems includes multiple basic classifiers; When generating network security alert traceability information, the weighted voting method is used to process the outputs of these basic classifiers to obtain the final network security alert traceability information.
Citation Information
Patent Citations
Distributed system fault root cause tracing method based on knowledge graph technology
CN113377567A
Network security situation awareness method based on graph neural network and related equipment
CN113783876A