A method and system for determining anomalies in an oil and gas pipeline network SCADA pipeline network
By acquiring real-time data and security assessments of oil and gas pipeline network nodes and utilizing big data platforms and neural network analysis, the anomaly detection and security vulnerability issues of traditional SCADA systems in complex networks are resolved, efficient anomaly detection and management are achieved, and the stable operation and safety of the oil and gas pipeline network are ensured.
Patent Information
- Application Number
- CN202411273685.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-12
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2044-09-12
AI Technical Summary
Traditional SCADA systems are unable to effectively process complex data and eliminate version issues in oil and gas pipeline networks, making it difficult to achieve efficient anomaly detection and management, especially as the network scale expands and operational complexity increases.
By acquiring real-time data from each node in the oil and gas pipeline network, we conduct anomaly detection and security assessment, generate vulnerability maintenance plans, utilize big data platforms for data storage and neural network analysis, optimize anomaly measurement rules, and promptly discover and correct anomalies.
It achieves real-time anomaly detection and timely discovery of security vulnerabilities in oil and gas pipeline networks, ensures stable operation of the pipeline network, improves data storage and analysis efficiency, and enhances the system's adaptability and security.
Smart Images

Figure CN119436007B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of oil and gas pipeline network governance analysis, in particular to an oil and gas pipeline network SCADA pipeline anomaly determination method and system. BACKGROUND
[0002] Traditionally, the method of monitoring and managing oil and gas pipeline networks mainly relies on SCADA (Supervisory Control and Data Acquisition) systems, which are responsible for real-time data acquisition, remote control and safety monitoring. However, as the scale of oil and gas pipeline networks expands and the complexity of operation increases, the challenges faced by the governance of pipeline systems also increase. Traditional SCADA systems are usually based on real-time data acquisition and monitoring, but when the SCADA system has version problems, it cannot effectively establish an analysis model.
[0003] Therefore, there is an urgent need to invent an oil and gas pipeline network SCADA pipeline anomaly determination method to solve the problem of being unable to exclude SCADA system version problems and being difficult to efficiently handle complex data in the case of expansion of network scale and increase of operation complexity. SUMMARY
[0004] The purpose of the present application is to provide an oil and gas pipeline network SCADA pipeline anomaly determination method and system, which aims to optimize the anomaly determination method through big data analysis to solve the problem of being unable to exclude SCADA system version problems and being difficult to efficiently handle complex data in the case of expansion of network scale and increase of operation complexity.
[0005] In one aspect, the present application provides an oil and gas pipeline network SCADA pipeline anomaly determination method, comprising the following steps: step S1: obtaining real-time data of each line node of the oil and gas network and performing anomaly determination;
[0006] Step S2: performing safety assessment and audit on the SCADA pipeline network to obtain vulnerability information;
[0007] Step S3: generating a vulnerability maintenance plan according to the vulnerability information, and generating an anomaly determination period each time a vulnerability plan is completed, and recording as a normal operation period when there is no vulnerability information;
[0008] Step S4: extracting the anomaly determination result of the SCADA pipeline network, processing the anomaly determination result, diagnosing the abnormal reason, and correcting, and recording as a fault period after correction;
[0009] Step S5: distributing the data of each period in the big data platform, setting a weight value for each type of information in the big data platform, and establishing a neural network data analysis model;
[0010] Step S6: update the weight value of the problem data according to the abnormal reason each time a new failure cycle is recorded, and optimize the abnormal determination rule.
[0011] Preferably, in the step S1, the real-time data includes real-time running data and real-time environment data of the node, and the abnormal determination includes a plurality of running abnormalities determined based on the relationship between the real-time running data and a plurality of preset alarm thresholds and a plurality of environmental abnormalities based on the environment data and the combustible gas accumulation degree of the oil and gas pipeline surrounding and the safety distance set between the oil and gas pipeline and the ignition source.
[0012] Preferably, in the step S2, the security assessment and audit of the SCADA network includes: using a vulnerability scanning tool and penetration testing technology to evaluate the SCADA network; reviewing the security policy, configuration file and permission settings of the SCADA network; auditing the communication and network environment of the SCADA network; checking the configuration of network equipment and firewall, network traffic and communication protocol security; evaluating the physical security measures of the SCADA network, including physical access control of equipment, security and monitoring system of computer room; auditing the log recording and event response capability of the SCADA network, checking the integrity and accuracy of the log, and evaluating the detection and response capability of the event.
[0013] Preferably, in the step S3, according to the influence fluctuation range of the SCADA network recorded by the vulnerability information and the error data type, a vulnerability maintenance plan with time period and vulnerability level is generated to ensure the security and stability of the SCADA network.
[0014] Preferably, in the step S4, the result of the abnormal determination is processed and the abnormal reason is diagnosed and corrected, including, when the running abnormality occurs, the abnormal data of the node is obtained, one or more dependent variable data of the abnormal data is adjusted, the data is lower than the alarm threshold, and the abnormal reason of the abnormal data is checked and corrected; when the environmental abnormality occurs, the severity of the environment of the node is judged at the first time, when the severity exceeds the standard, the emergency response is implemented immediately to carry out human on-site intervention, and when the severity does not exceed the standard, the humidity control or the wind treatment of the node is automatically run.
[0015] Preferably, in the step S5, the data of each line node in each normal running cycle is mapped by data mapping, and the index node is distributed and stored to the big data platform by different line nodes; the data of each line node in each abnormal determination cycle is mapped by data mapping, and the index node is distributed and stored to the big data platform by vulnerability information; each failure cycle is generated by abnormal reason, and the index node is distributed and stored to the big data platform.
[0016] Preferably, in the step S5, multiple additional fields are added to the data in each index for storing weight values, and the data is processed according to the correlation of each weight value to generate a multi-dimensional database, a data analysis model is established for each dimensional database, and the abnormal measurement method is optimized according to the analysis result.
[0017] Preferably, in the step S5, the multiple additional fields are used to store multiple weighting rules, a first weighting rule selects a first data in the real-time running data as a key assignment, and a gradient weight method is used to sequentially sort the dependent variable data of the first data according to the importance of the characteristics to correspondingly calculate, and a first field is added to each data corresponding to the first weighting rule; a second weighting rule selects a second data in the real-time running data as a key assignment, and a gradient weight method is used to sequentially sort the dependent variable data of the second data according to the importance of the characteristics to correspondingly calculate, and a second field is added to each data corresponding to the second weighting rule; a third weighting rule selects a third data in the real-time running data as a key assignment, and a gradient weight method is used to sequentially sort the dependent variable data of the third data according to the importance of the characteristics to correspondingly calculate, and a third field is added to each data corresponding to the third weighting rule; wherein, an nth weighting rule selects an nth data in the real-time running data as a key assignment, and a gradient weight method is used to sequentially sort the dependent variable data of the nth data according to the importance of the characteristics to correspondingly calculate, and an nth field is added to each data corresponding to the nth weighting rule, and a multi-dimensional database is generated after sorting.
[0018] Preferably, in the step S6, the weight value of the problem data is updated, wherein only the problem weight rule of the problem data as a key assignment is updated, and a gradient weight method is used to sequentially sort the corresponding calculation of the updated all data problem weight rule according to the importance of the characteristics, and the alarm threshold of the data in the abnormal measurement is optimized according to the key assignment object in the problem weight rule, and one or more dependent variable data related to the problem data is optimized according to the one-to-one correspondence of the problem weight rule.
[0019] On the other hand, the embodiment of the present application also provides an oil and gas pipeline network SCADA pipeline network anomaly measurement system, which is suitable for the oil and gas pipeline network SCADA pipeline network anomaly measurement method of the above-mentioned embodiments, comprising:
[0020] A monitoring module acquires real-time data of each line node of the oil and gas network and performs anomaly measurement;
[0021] A security module performs security evaluation and audit on the SCADA pipeline network to acquire vulnerability information;
[0022] A security maintenance module generates a vulnerability maintenance plan based on the vulnerability information, and generates an exception determination cycle whenever the vulnerability plan is completed, and records a normal operation cycle when there is no vulnerability information;
[0023] An operation maintenance module extracts the results of the exception determination of the SCADA pipeline network, processes the results of the exception determination, diagnoses the causes of the exception, makes corrections, and records a fault cycle after the corrections;
[0024] A data storage module distributes the data of each cycle in a distributed manner in a big data platform, sets a weight value for each type of information in the big data platform, and establishes a neural network data analysis model;
[0025] A data processing module updates the weight value of the problem data according to the cause of the exception each time a new fault cycle is recorded, and optimizes the exception determination rules.
[0026] Compared with the prior art, the oil and gas pipeline network SCADA pipeline network exception determination method and system has the beneficial effects that:
[0027] 1. By acquiring real-time data of each line node of the oil and gas network and performing exception detection, the abnormal conditions in the pipeline network, such as faults and leaks, can be found in a timely manner. This helps to take early warning and measures to prevent accidents and ensure the normal operation of the pipeline network.
[0028] 2. By performing security assessment and audit on the SCADA pipeline network, vulnerability information can be obtained, and security vulnerabilities in the pipeline network, such as weaknesses and attack surfaces, can be found in a timely manner. This helps to strengthen the security of the pipeline network and take appropriate repair and protection measures to protect the pipeline network from malicious attacks.
[0029] 3. According to the vulnerability information, a vulnerability maintenance plan is generated, and the vulnerability repair is performed according to the plan. This helps to systematically manage and maintain the security of the pipeline network, ensuring timely repair of vulnerabilities and reducing potential risks.
[0030] 4. The results of the exception determination are extracted and processed and diagnosed to find out the causes of the exception and make corrections, which helps to timely solve the faults in the operation of the pipeline network and ensure the stable operation of the pipeline network.
[0031] 5. The data of each cycle is distributed and stored in a distributed manner in a big data platform, which can provide a more efficient data storage and management method. By setting a weight value for each type of information in the big data platform and establishing a neural network data analysis model, data can be better utilized for analysis and prediction to discover hidden patterns and trends.
[0032] 6. Whenever a new failure cycle is recorded, the weight value of the problem data is updated according to the abnormal reason, and the abnormal determination rule is optimized. This helps to continuously optimize and improve the accuracy and reliability of abnormal detection, and improve the adaptive ability of the system. BRIEF DESCRIPTION OF DRAWINGS
[0033] Figure 1 is a flow block diagram of an oil and gas pipeline network SCADA pipeline network abnormal determination method according to an embodiment of the present application;
[0034] Figure 2 is a structural block diagram of an oil and gas pipeline network SCADA pipeline network abnormal determination system according to an embodiment of the present application. DETAILED DESCRIPTION
[0035] Exemplary embodiments of the present disclosure will be described in detail with reference to the accompanying drawings. Although exemplary embodiments of the present disclosure are shown in the drawings, it is understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood, and the scope of the present disclosure can be accurately conveyed to those skilled in the art. It should be noted that the embodiments in the present application and the features in the embodiments can be combined with each other without conflict. The present application will be described in detail below with reference to the accompanying drawings and in conjunction with the embodiments.
[0036] As shown in Figure 1 , an oil and gas pipeline network SCADA pipeline network abnormal determination method according to an embodiment of the present application comprises:
[0037] Step S1: Obtain real-time data of each line node of the oil and gas network and perform abnormal determination;
[0038] Step S2: Perform safety assessment and audit on the SCADA pipeline network to obtain vulnerability information;
[0039] Step S3: Generate a vulnerability maintenance plan according to the vulnerability information, and generate an abnormal determination cycle whenever a vulnerability plan is completed. When there is no vulnerability information, it is recorded as a normal operation cycle;
[0040] Step S4: Extract the abnormal determination result of the SCADA pipeline network, process the abnormal determination result, diagnose the abnormal reason, and correct it. After correction, it is recorded as a failure cycle;
[0041] Step S5: Distributively store the data of each cycle in the big data platform, set a weight value for each type of information in the big data platform, and establish a neural network data analysis model;
[0042] Step S6: updating the weight in real time with each data update; updating the weight value of the problem data according to the abnormal reason each time a new failure cycle is recorded, and optimizing the abnormal determination rule;
[0043] Step S7: analyzing the vulnerability information according to each data analysis each time a new abnormal determination cycle is recorded, and keeping or modifying the information in the big data platform according to the analysis result.
[0044] In some embodiments of the present application, in step S1, the real-time data includes real-time running data and real-time environmental data of the node, and the abnormal determination includes a plurality of running abnormalities determined based on the relationship between the real-time running data and a plurality of preset alarm thresholds and a plurality of environmental abnormalities based on the environmental data and the combustible gas accumulation degree of the oil and gas pipeline periphery and the safety distance set between the oil and gas pipeline and the ignition source.
[0045] In some embodiments of the present application, in step S2, the security assessment and audit of the SCADA network management includes: using a vulnerability scanning tool and penetration testing technology to evaluate the SCADA network; reviewing the security policy, configuration file and permission settings of the SCADA network; auditing the communication and network environment of the SCADA network; checking the configuration of network devices and firewalls, the security of network traffic and communication protocols; evaluating the physical security measures of the SCADA network, including physical access control of devices, security and monitoring system of the machine room; auditing the log recording and event response capability of the SCADA network, checking the integrity and accuracy of the logs, and evaluating the detection and response capability of the events.
[0046] In some embodiments of the present application, in step S3, a vulnerability maintenance plan with a time period and a vulnerability level is generated according to the influence fluctuation range of the SCADA network recorded by the vulnerability information and the error data type, to ensure the safety and stability of the SCADA network.
[0047] In some embodiments of the present application, in step S4, the result of the abnormal determination is processed and the abnormal reason is diagnosed and corrected, including, when a running abnormality occurs, adjusting one or more dependent variable data of the abnormal data of the node to make the data below the alarm threshold, and checking the abnormal reason of the abnormal data and performing correction processing; when an environmental abnormality occurs, the severity of the environment of the node is judged at the first time, when the severity exceeds the standard, an emergency response is implemented to immediately intervene manually on site, and when the severity does not exceed the standard, the node is automatically operated to control humidity or ventilate.
[0048] In some embodiments of the present application, in step S5, the data of each line node in each normal operation cycle is mapped by data mapping to generate index nodes distributed storage to the big data platform; the data of each line node in each abnormal measurement cycle is mapped by data mapping to generate index nodes distributed storage to the big data platform; and each fault cycle is stored to the big data platform by generating index nodes distributed storage according to abnormal reasons.
[0049] In some embodiments of the present application, in step S5, a plurality of additional fields are added to the data in each index for storing weight values, and the data is processed according to the correlation degree of each weight value to generate a multi-dimensional database. A data analysis model is established for each dimensional database, and the abnormal measurement method is optimized according to the analysis result.
[0050] In some embodiments of the present application, in step S5, the plurality of additional fields are used to store a plurality of weighting rules. A first weighting rule selects a first data in real-time operation data as a key assignment, and uses a gradient weight method to sequentially sort corresponding calculations according to the importance of the characteristics of the dependent variable data of the first data, and adds a first field corresponding to the first weighting rule to each data. A second weighting rule selects a second data in real-time operation data as a key assignment, and uses a gradient weight method to sequentially sort corresponding calculations according to the importance of the characteristics of the dependent variable data of the second data, and adds a second field corresponding to the second weighting rule to each data. A third weighting rule selects a third data in real-time operation data as a key assignment, and uses a gradient weight method to sequentially sort corresponding calculations according to the importance of the characteristics of the dependent variable data of the third data, and adds a third field corresponding to the third weighting rule to each data. Wherein, the nth weighting rule selects the nth data in real-time operation data as a key assignment, and uses a gradient weight method to sequentially sort corresponding calculations according to the importance of the characteristics of the dependent variable data of the nth data, and adds an nth field corresponding to the nth weighting rule to each data, and generates a multi-dimensional database after sorting.
[0051] Specifically, according to the calculation rule of the neural network, when the nth data and its dependent variable data are in a direct proportional relationship: assuming that the independent variable is X and the dependent variable is Y, and there is a direct proportional relationship between them; the following formula is used to calculate the gradient weight:
[0052] a) Forward propagation:
[0053] In the forward propagation process, the activation value A_i of each layer is calculated:
[0054] A_i = f(\sum_{j=1}^{n} W_{ij} \cdot A_{i-1} + b_i)
[0055] where W_{ij} represents the connection weight, A_{i-1} represents the activation value of the previous layer, b_i represents the bias term, and f represents the activation function.
[0056] b) Backpropagation:
[0057] During backpropagation, the gradient \frac{\partial L}{\partial A_i} of each layer is calculated:
[0058] \frac{\partial L}{\partial A_i} = \frac{\partial L}{\partial A_{i+1}} \cdot \frac{\partial A_{i+1}}{\partial A_i}
[0059] where L represents the loss function, and A_{i+1} represents the activation value of the next layer.
[0060] According to the proportional relationship, \frac{\partial L}{\partial A_i} can be expressed as:
[0061] \frac{\partial L}{\partial A_i} = k \cdot \frac{\partial L}{\partial Y} \cdot \frac{\partial Y}{\partial A_i}
[0062] where k is the proportionality coefficient, \frac{\partial L}{\partial Y} represents the partial derivative of the loss function with respect to the dependent variable Y, and \frac{\partial Y}{\partial A_i} represents the partial derivative of the dependent variable Y with respect to the activation value A_i.
[0063] According to the calculation rule of the neural network, when the nth data and its dependent variable data are in inverse proportion, the following relationship holds:
[0064] Specifically, assuming that the nth data, i.e., the independent variable, is X, and the dependent variable is Y, and they are in inverse proportion; the following formula is used to calculate the gradient weight:
[0065] a) Forward propagation:
[0066] During forward propagation, the activation value A_i of each layer is calculated:
[0067] A_i = f(\sum_{j=1}^{n} W_{ij} \cdot A_{i-1} + b_i)
[0068] where W_{ij} represents the connection weight, A_{i-1} represents the activation value of the previous layer, b_i represents the bias term, and f represents the activation function.
[0069] b) Backpropagation:
[0070] During backpropagation, the gradient \frac{\partial L}{\partial A_i} of each layer is calculated:
[0071] \frac{\partial L}{\partial A_i} = \frac{\partial L}{\partial A_{i+1}} \cdot \frac{\partial A_{i+1}}{\partial A_i}
[0072] where L represents the loss function, and A_{i+1} represents the activation value of the next layer.
[0073] According to the inverse relationship, \frac{\partial L}{\partial A_i} can be expressed as:
[0074] \frac{\partial L}{\partial A_i} = -k \cdot \frac{\partial L}{\partial Y} \cdot \frac{\partial Y}{\partial A_i}
[0075] where k is the proportionality coefficient, \frac{\partial L}{\partial Y} represents the partial derivative of the loss function with respect to the dependent variable Y, and \frac{\partial Y}{\partial A_i} represents the partial derivative of the dependent variable Y with respect to the activation value A_i.
[0076] It can be understood that a weight sharing technique is used to set the gradient weight, so that one main data has a greater impact on other data; in some cases, it may be desirable to assign higher weights to certain specific data samples in order to pay more attention to these samples when training the model, which is very useful when dealing with unbalanced data sets or focusing on the importance of specific samples, so a weighted loss function is used, in which the loss value of each sample is multiplied by a corresponding weight, in this way, by adjusting the weight, the sensitivity of the model to different samples can be controlled.
[0077] Specifically, the weight value updating method is:
[0078] The connection weight W_{ij} is updated using the gradient descent algorithm:
[0079] W_{ij}^{new}=W_{ij}^{old}-\eta\cdot\frac{\partial L}{\partial W_{ij}}
[0080] where \eta represents the learning rate, and \frac{\partial L}{\partial W_{ij}} represents the partial derivative of the connection weight.
[0081] Specifically, during the gradient calculation process, the gradient of each sample can be multiplied by the corresponding weight, so that the influence of the gradient will be greater on samples with higher weights, thereby more affecting the update of the model parameters. This way can make the model pay more attention to samples with higher weights and make more targeted adjustments.
[0082] In some embodiments of the present application, in step S6, the weight value of the problem data is updated, wherein only the problem weight rule valued as the focus of the problem data is updated, and the updated problem weight rule of all data is calculated according to the importance of the features in order using the gradient weight method, and the alarm threshold of the data in the abnormal determination is optimized according to the focus value object in the problem weight rule, and one or more dependent variable data related to the problem data is optimized according to the one-to-one correspondence of the problem weight rule.
[0083] In some embodiments of the present application, in step S7, the fluctuation range, error data type and correction parameter are obtained according to the vulnerability maintenance plan, and it is compared and analyzed whether there is an error in the historical storage data, if there is an error, the information in the big data platform is corrected, and if there is no error, the information in the big data platform is maintained.
[0084] Specifically, the fluctuation range, error data type and correction parameter related information are obtained from the vulnerability maintenance plan, which can include the expected data variation range, possible error types and corresponding correction parameters; the historical storage data is obtained from the big data platform and analyzed, which can use data analysis tools or write custom scripts to process data, and the purpose of analysis is to determine whether there is an error in the historical data; the fluctuation range and error data type in the vulnerability maintenance plan are compared and analyzed with the historical data, for each data point, check whether its value is within the expected fluctuation range and whether it matches the expected error data type; if an error is found in the historical data, correct the information in the big data platform according to the correction parameter in the vulnerability maintenance plan; this may involve correcting the error value in the data, deleting the error data or repairing the data by other ways; if no error is found in the historical data, the information in the big data platform remains unchanged and no modification is made.
[0085] In another aspect, referring to Figure 2 As shown in the preferred embodiments shown in the drawings, the present application also provides an oil and gas pipeline network SCADA pipeline network anomaly determination system, which is applicable to the oil and gas pipeline network SCADA pipeline network anomaly determination method of the above-mentioned embodiments, comprising:
[0086] A monitoring module acquires real-time data of each line node of the oil and gas pipeline network and performs anomaly determination;
[0087] A security module performs security assessment and audit on the SCADA pipeline network and acquires vulnerability information;
[0088] A security maintenance module generates a vulnerability maintenance plan according to the vulnerability information, and generates an anomaly determination period each time a vulnerability plan is completed, and records a normal operation period when there is no vulnerability information;
[0089] An operation maintenance module extracts the anomaly determination result of the SCADA pipeline network, processes the anomaly determination result, diagnoses the anomaly cause, performs correction, and records a fault period after correction;
[0090] A data storage module distributes the data of each period in a distributed manner in a big data platform, sets a weight value for each type of information in the big data platform, and establishes a neural network data analysis model;
[0091] A data processing module updates the weight value in real time each time the data is updated; and updates the weight value of the problem data according to the anomaly cause each time a new fault period is recorded, and optimizes the anomaly determination rule;
[0092] The data processing module further comprises, each time a new anomaly determination period is recorded, analyzing the vulnerability information according to each data analysis, and maintaining or correcting the information in the big data platform according to the analysis result.
[0093] It can be understood that the oil and gas pipeline network SCADA pipeline network anomaly determination system of the above-mentioned embodiments is applicable to the oil and gas pipeline network SCADA pipeline network anomaly determination method of the above-mentioned embodiments, and therefore the oil and gas pipeline network SCADA pipeline network anomaly determination system and the oil and gas pipeline network SCADA pipeline network anomaly determination method have the same beneficial effects, and therefore will not be described again.
[0094] So far, the technical solutions of the present application have been described in combination with the preferred embodiments shown in the drawings, but those skilled in the art can easily understand that the protection scope of the present application is obviously not limited to these specific embodiments. Those skilled in the art can make equivalent changes or replacements to related technical features without departing from the principles of the present application, and the technical solutions after the changes or replacements will fall within the protection scope of the present application.
[0095] The above merely illustrates the preferred embodiments of the present application, and is not used to limit the present application; for those skilled in the art, the present application can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A method for measuring abnormalities in an oil and gas pipeline network SCADA, characterized in that: include: Step S1: Acquire real-time data of nodes of each line of the oil and gas network and perform abnormality detection; Step S2: Conduct security assessment and audit of the SCADA network to obtain vulnerability information; Step S3: Generate a vulnerability maintenance plan based on the vulnerability information. Each time a vulnerability maintenance plan is completed, an abnormal measurement cycle is generated. If no vulnerability information exists, it is recorded as a normal operation cycle. Step S4: extracting abnormal measurement results of the SCADA pipe network, processing the abnormal measurement results, diagnosing the abnormal cause, and correcting it. The corrected result is recorded as a fault cycle; Step S5: Distribute and store the data of each abnormal measurement cycle, normal operation cycle, and fault cycle on the big data platform, set a weight value for each type of information in the big data platform, and establish a neural network data analysis model; Step S6: Whenever a new fault cycle is recorded, the weight value of the problem data is updated according to the abnormal cause, and the abnormality determination rule is optimized; Wherein, in said step S2, the security assessment and audit of the SCADA network management includes: using vulnerability scanning tools and penetration testing technology to assess the SCADA network; reviewing the security policies, configuration files and permission settings of the SCADA network; auditing the communication and network environment of the SCADA network; checking the configuration of network equipment and firewalls, network traffic and the security of communication protocols; assessing the physical security measures of the SCADA network, including physical access control of equipment, security of computer rooms and monitoring systems; auditing the log records and event response capabilities of the SCADA network, checking the integrity and accuracy of the logs, and assessing the detection and response capabilities of events; The step S5 further includes: generating index nodes based on different line nodes through data mapping for data of each line node in each normal operation cycle and distributing the data on the big data platform; generating index nodes based on vulnerability information for data of each line node in each abnormal measurement cycle and distributing the data on the big data platform; generating index nodes based on abnormal causes for each fault cycle and distributing the data on the big data platform; In step S5, multiple additional fields are added to the data in each index for storing weight values, and the data is processed according to the correlation of each weight value to generate a multi-dimensional database. A data analysis model is established for the database in each dimension, and the anomaly determination rules are optimized based on the analysis results; In step S5, the multiple additional fields are used to store multiple weighting rules. The first weighting rule selects the first data in the real-time running data as the key assignment, and uses the gradient weight method to sort the dependent variable data of the first data in sequence according to the importance of the features and calculates the corresponding ones.
2. The oil and gas pipeline network SCADA pipeline network anomaly detection method according to claim 1, characterized in that: In step S1, the real-time data includes the real-time operation data and real-time environmental data of the node, and the abnormality measurement includes a variety of operation abnormality measurements based on the relationship between the real-time operation data and a variety of preset alarm thresholds, and a variety of environmental abnormality measurements based on the concentration of combustible gas volume around the oil and gas pipeline and the safety distance between the oil and gas pipeline and the ignition source according to the real-time environmental data.
3. The oil and gas pipeline network SCADA pipeline network anomaly detection method according to claim 1, characterized in that: The step S3 further includes: generating a vulnerability maintenance plan with a time period and vulnerability level according to the impact fluctuation range of the vulnerability information on the SCADA network and the type of error data, so as to ensure the security and stability of the SCADA network.
4. The oil and gas pipeline network SCADA pipeline network anomaly detection method according to claim 2, characterized in that: In the step S4, the abnormal measurement results are processed, and the cause of the abnormality is diagnosed and corrected, including: when an operational abnormality occurs, the abnormal data of the corresponding node is obtained, one or more dependent variable data of the abnormal data is adjusted to make the abnormal data lower than a preset alarm threshold, and the abnormal cause of the abnormal data is checked and corrected; when an environmental abnormality occurs, the severity of the environment of the corresponding node is judged at the first time, when the severity exceeds the standard, an emergency response is implemented, and manual on-site intervention is carried out; when the severity does not exceed the standard, the corresponding node is automatically operated with humidity control or ventilation treatment.
5. The oil and gas pipeline network SCADA pipeline network anomaly detection method according to claim 1, characterized in that: The step S5 also includes: adding a first field to each data using the first weighting rule; the second weighting rule selects the second data in the real-time running data as the key assignment, and uses the gradient weight method to sort the dependent variable data of the second data in sequence according to the importance of the feature, and calculates accordingly, and adds a second field to each data using the second weighting rule; the third weighting rule selects the third data in the real-time running data as the key assignment, and uses the gradient weight method to sort the dependent variable data of the third data in sequence according to the importance of the feature, and calculates accordingly, and adds a third field to each data using the third weighting rule; further, the nth weighting rule selects the nth data in the real-time running data as the key assignment, and uses the gradient weight method to sort the dependent variable data of the nth data in sequence according to the importance of the feature, and calculates accordingly, and adds an nth field to each data using the nth weighting rule.
6. An oil and gas pipeline network SCADA pipe network anomaly detection system, suitable for use in an oil and gas pipeline network SCADA pipe network anomaly detection method according to any one of claims 1 to 5, characterized in that: include: The monitoring module obtains real-time data from nodes on each line of the oil and gas network and performs abnormality detection; Security module, which conducts security assessment and audit of SCADA pipe network and obtains vulnerability information; A security maintenance module generates a vulnerability maintenance plan based on the vulnerability information, generates an abnormality measurement cycle each time a vulnerability maintenance plan is completed, and records a normal operation cycle when the vulnerability information does not exist; The operation and maintenance module extracts abnormal measurement results of the SCADA pipe network, processes the abnormal measurement results, diagnoses the abnormal causes, and makes corrections. The corrections are recorded as a fault cycle; The data storage module distributes and stores the data of each abnormal measurement cycle, normal operation cycle, and fault cycle on the big data platform, sets a weight value for each type of information in the big data platform, and establishes a neural network data analysis model; The data processing module updates the weight value of the problem data according to the abnormal cause every time a new fault cycle is recorded, and optimizes the abnormality determination rules.
Citation Information
Patent Citations
Network security vulnerability tracking method and system thereof
CN112417462A
Transfer learning framework applied to fan fault detection
CN115456082A