A method and system for selecting priority of power system network security defense resources

By constructing a five-tuple model of the power cyber-physical system and optimizing the resource allocation algorithm, the problems of insufficient adaptive capability and unreasonable resource allocation in the network security defense of the power system were solved, realizing rapid response and collaborative defense between systems, and improving the security and stability of the power system.

CN119484072BActive Publication Date: 2025-10-28GUIZHOU POWER GRID CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411585014.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-07
Publication Date
2025-10-28
Estimated Expiration
2044-11-07

AI Technical Summary

Technical Problem

Existing power system network security defense technologies have problems such as insufficient adaptability, low resource allocation efficiency, slow real-time response speed, and unsatisfactory coordinated defense between systems.

Method used

A five-tuple model of a power cyber-physical system is constructed, and the working mechanism of the five-tuple model is analyzed. The attack and defense interaction is simulated through a finite state machine, and a defense resource priority selection algorithm is constructed to calculate the node state weight and resource cost, optimize resource allocation, and execute defense actions to isolate and repair attacks.

Benefits of technology

It has improved the ability to identify potential threats, enhanced the accuracy of security risk assessment, optimized resource utilization efficiency, improved the speed and effectiveness of defense measures, ensured the stability and rapid response capability of the system, and improved the safe and stable operation of the power system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119484072B_ABST
    Figure CN119484072B_ABST
Patent Text Reader

Abstract

This invention discloses a method and system for prioritizing cybersecurity defense resources in power systems, relating to the field of power system cybersecurity defense technology. The method includes constructing a five-tuple model of the power cyber-physical system and analyzing its working mechanism; constructing a defense resource priority selection algorithm; and using a defense action execution algorithm. The method described in this invention improves the ability to identify potential security threats, enhances the accuracy of the system's security risk assessment, provides a scientific basis for subsequent defense resource priority selection, improves the effectiveness of the overall defense strategy, maintains system stability, optimizes resource utilization efficiency, reduces unnecessary resource waste, and enhances the system's anti-attack capability and resilience, thereby ensuring the safe and stable operation of the power system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power system network security defense technology, specifically to a method and system for prioritizing power system network security defense resources. Background Technology

[0002] With the rapid development of information technology, the application of Cyber-Physical Systems (CPS) in the power industry has become increasingly mature. Accompanying this, the network security defense technology of the power system has also developed rapidly. From the initial simple protection measures to today's highly integrated and intelligent defense system, related technologies have undergone an evolution from static protection to dynamic monitoring, and from single defense methods to diversified strategy combinations. Current technologies cover multiple fields such as encrypted communication, distributed monitoring, big data analysis, and cloud computing, which have improved the power system's ability to identify and respond to network threats and provided strong technical support for the safe and stable operation of the power system.

[0003] However, in practical applications, existing technologies still have shortcomings, which to some extent affect the safe and stable operation of power systems. The defense system lacks completeness, and the coordination between different layers of technology is not ideal. The network threats faced by power systems are constantly changing, and existing defense technologies often struggle to keep up with these changes. Traditional intrusion detection systems (IDS) rely on pre-set attack signature databases, which may not be effective in identifying new attack methods. Furthermore, the long update and upgrade cycles of defense systems result in lagging system protection capabilities in the face of rapidly evolving network attacks. Insufficient human resources and technical expertise lead to ineffective implementation of defense measures, difficulty in timely patching of security vulnerabilities, low efficiency in responding to large-scale network attacks, and problems with privacy protection and data security. With the deep integration of power systems and the Internet, large amounts of user data and system operation data are collected and analyzed. Ensuring the security of this data and preventing data leakage and misuse are problems that current technologies need to address. To address these issues, this invention proposes a new power system network security defense method, aiming to improve the adaptive capability, resource allocation efficiency, real-time response speed, and inter-system coordination of the defense system. Summary of the Invention

[0004] In view of the above-mentioned problems, the present invention is proposed.

[0005] Therefore, the technical problem solved by this invention is that existing power system network security defense technologies and methods have insufficient adaptive capabilities, low resource allocation efficiency, slow real-time response speed, and the problem of how to effectively achieve inter-system collaborative defense.

[0006] To address the aforementioned technical problems, this invention provides the following technical solution: a method for prioritizing network security defense resources in a power system, comprising constructing a five-tuple model of a power cyber-physical system, analyzing the working mechanism of the five-tuple model, constructing a defense resource priority selection algorithm, and using a defense action execution algorithm.

[0007] As a preferred embodiment of the power system network security defense resource priority selection method described in this invention, the construction of the power cyber-physical system five-tuple model includes simulating the interaction between attackers and defenders through the transition rules of a finite state machine, where the node set N is represented as:

[0008] N = {N g N l N d N s N e}

[0009] Where, N g N represents a power plant node. l N represents a transmission line node. d N represents the distribution node. s N represents a substation node. e The terminal user node is represented by the permission set P as follows:

[0010] P = {p1, p2, p3}

[0011] Where p1 represents a low-privilege node, p2 represents a medium-privilege node, and p3 represents a high-privilege node, the state set S describes the state of the network system at different points in time, represented as:

[0012] S = {s0, s1, s2, s3}

[0013] Wherein, s0 represents the normal state, s1 represents the unstable state, s2 represents the slightly abnormal state, and s3 represents the severely abnormal state.

[0014] As a preferred embodiment of the power system network security defense resource priority selection method described in this invention, the construction of the power cyber-physical system five-tuple model further includes an event set E, E A E represents an attack event in the power system. D A defensive event in a power system is represented as:

[0015] E = {E A E D}

[0016] Among them, E A Including DDoS attacks, malware infections, and data tampering incidents, E DThis represents the system's detection, isolation, and remediation defensive actions. The event set contains events occurring in the network, including interactions between attackers and defenders. Each event represents the execution of an attack or defense operation at a single point in time. The occurrence of an event triggers a state transition. When an attack or defense event occurs, the state of the network system changes according to predetermined transition rules. Action set A represents the specific actions taken by the defender in different states, as follows:

[0017] A = {a1, a2, a3, a4}

[0018] Here, a1 represents attack detection, a2 represents attack isolation, a3 represents system repair, and a4 represents restoration to normal operation. Each action is a decision made based on the current state and events.

[0019] As a preferred embodiment of the power system network security defense resource priority selection method described in this invention, the working mechanism of the five-tuple model includes determining the risk to the system when a certain attack / defense event E occurs, with the current set of attack behaviors being E. A The security defense strategy set is E D For a single action e ai ∈E A e di ∈E D The probability of the resulting risk is expressed as:

[0020] r ij =f(e ai e dj )

[0021] Where, f(e) ai e dj ) for in e dj Under defensive strategy conditions, attack behavior e ai For the security risk value caused by the system security state s, calculate the system security coefficient, which is expressed as:

[0022] s ij =1-f(e ai e dj )

[0023] The relationship between the safety factor and the system state is expressed as:

[0024]

[0025] The system selects an appropriate action A based on the current state S and the nature of the event, and switches to the next state S′ according to the preset state transition function. By repeating this process at different stages of network attack and defense, the system simulates the continuous game between the attacker and the defender.

[0026] As a preferred embodiment of the power system network security defense resource priority selection method described in this invention, the method for constructing the defense resource priority selection algorithm includes selecting resources based on node state S. i And the impact on the power system, calculate the state weight S w (N i ), represented as:

[0027]

[0028] Where, α k It is node N i In state The influence coefficient is calculated based on the node's authority level in the power system, and the node's importance weight P is determined accordingly. w (N i ), represented as:

[0029] P w (N i )=β·P i

[0030] Where β represents the weighting coefficient, used to measure the impact of permissions on defense strategies.

[0031] As a preferred embodiment of the power system network security defense resource priority selection method described in this invention, the method for constructing the defense resource priority selection algorithm further includes computing node N. i Defense resource cost C i C i Including time cost and resource usage cost, expressed as:

[0032] C i =R i ·T i

[0033] Among them, R i T represents the scarcity of defensive resources. i The time required to respond to defensive measures, taking into account node status, permissions, and resource costs, is used to calculate the node's priority, expressed as:

[0034]

[0035] Nodes with higher priority will receive defense resources first. The allocation ratio of defense resources is calculated based on the node priority and is expressed as follows:

[0036]

[0037] Among them, R alloc (N i ) indicates that it is assigned to node Ni The resource ratio is m, where m is the total number of nodes.

[0038] As a preferred embodiment of the power system network security defense resource priority selection method described in this invention, the method of using the defense action execution algorithm includes initialization, defining a node set N, a permission set P, a state set S, an event set E, and an action set A according to the power system structure, performing real-time detection, continuously monitoring the network status of the power system, and capturing attack events E in real time. A Perform state assessment, evaluate the state of each node based on the attack events, and update the state S. i Priority calculation is performed according to the formula Priority(N) i Calculate the priority of each node, allocate resources, and assign defense resources R to each node according to the priority. alloc (N i ), Execute defensive actions, and perform defensive actions a on high-priority nodes. i The defense actions include isolation, repair, recovery, status updates, updating the system status S based on the defense effect, and recalculating the priority.

[0039] Another objective of this invention is to provide a power system network security defense resource priority selection system, which solves the problems of unreasonable resource allocation and low response efficiency in current power system network security defense technologies by constructing a defense resource priority selection algorithm.

[0040] As a preferred embodiment of the power system network security defense resource priority selection system described in this invention, it includes: a model building module, an algorithm selection module, and an algorithm execution module;

[0041] The model building module is used to build a five-tuple model of the power cyber-physical system and analyze the working mechanism of the five-tuple model; the algorithm selection module is used to build a defense resource priority selection algorithm; and the algorithm execution module is used to execute the algorithm using defense actions.

[0042] A computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program as a step in implementing a method for prioritizing network security defense resources in a power system.

[0043] A computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of a method for prioritizing network security defense resources in a power system.

[0044] The beneficial effects of this invention are as follows: The power system network security defense resource priority selection method provided by this invention constructs a five-tuple model of the power cyber-physical system, analyzes the working mechanism of the five-tuple model, improves the ability to identify potential security threats, enhances the accuracy of the system's security risk assessment, and provides a scientific basis for subsequent defense resource priority selection by analyzing the working mechanism of the five-tuple model, thereby improving the effectiveness of the overall defense strategy. The construction of a defense resource priority selection algorithm ensures that defense resources are preferentially allocated to key nodes, thus maintaining system stability. By calculating the cost of defense resources, the efficiency of resource utilization is optimized, reducing unnecessary resource waste. Resource allocation based on node priority improves the speed and effectiveness of defense measures. The use of a defense action execution algorithm ensures that the system can continuously monitor network status and quickly identify attack events. The system can dynamically adjust its defense strategy according to the current security situation. By executing defense actions and updating the status, the system can effectively isolate attacks, repair vulnerabilities, and restore normal operation, improving the system's anti-attack capability and resilience, thereby ensuring the safe and stable operation of the power system. This invention has achieved better results in power system network security defense resource priority selection, real-time response capability, and overall system defense effectiveness. Attached Figure Description

[0045] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0046] Figure 1 The first embodiment of the present invention provides an overall flowchart of a method for prioritizing network security defense resources in a power system.

[0047] Figure 2 The second embodiment of the present invention provides a flowchart of the defense resource deployment method for a power system network security defense resource priority selection method.

[0048] Figure 3 The diagram shows a 14-node power system structure for a power system network security defense resource priority selection method provided in the second embodiment of the present invention.

[0049] Figure 4 The following is an overall flowchart of a power system network security defense resource priority selection system provided in the third embodiment of the present invention. Detailed Implementation

[0050] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.

[0051] Example 1, referring to Figure 1 As an embodiment of the present invention, a method for prioritizing network security defense resources in a power system is provided, comprising:

[0052] S1: Construct a quintuple model of the power cyber-physical system and analyze the working mechanism of the quintuple model;

[0053] Furthermore, constructing a quintuple model of the power cyber-physical system involves simulating the interaction between attackers and defenders using the transition rules of a finite state machine. The node set N is represented as:

[0054] N = {N g N l N d N s N e}

[0055] Where, N g N represents a power plant node. l N represents a transmission line node. d N represents the distribution node. s N represents a substation node. e The terminal user node is represented by the permission set P as follows:

[0056] P = {p1, p2, p3}

[0057] Where p1 represents a low-privilege node, p2 represents a medium-privilege node, and p3 represents a high-privilege node, the state set S describes the state of the network system at different points in time, represented as:

[0058] S = {s0, s1, s2, s3}

[0059] Wherein, s0 represents the normal state, s1 represents the unstable state, s2 represents the slightly abnormal state, and s3 represents the severely abnormal state.

[0060] It should be noted that the construction of the five-tuple model of the power cyber-physical system also includes the event set E, E A E represents an attack event in the power system. D A defensive event in a power system is represented as:

[0061] E = {EA E D}

[0062] Among them, E A Including DDoS attacks, malware infections, and data tampering incidents, E D This represents the system's detection, isolation, and remediation defensive actions. The event set contains events occurring in the network, including interactions between attackers and defenders. Each event represents the execution of an attack or defense operation at a single point in time. The occurrence of an event triggers a state transition. When an attack or defense event occurs, the state of the network system changes according to predetermined transition rules. Action set A represents the specific actions taken by the defender in different states, as follows:

[0063] A = {a1, a2, a3, a4}

[0064] Here, a1 represents attack detection, a2 represents attack isolation, a3 represents system repair, and a4 represents restoration to normal operation. Each action is a decision made based on the current state and events.

[0065] It should also be noted that the working mechanism of the quintuple model includes, when a certain attack or defense event E occurs, determining the risk posed to the system, with the current set of attack behaviors being E. A The security defense strategy set is E D For a single action e ai ∈E A e di ∈E D The probability of the resulting risk is expressed as:

[0066] r ij =f(e ai e dj )

[0067] Where, f(e) ai e dj ) for in e dj Under defensive strategy conditions, attack behavior e ai For the security risk value caused by the system security state s, calculate the system security coefficient, which is expressed as:

[0068] s ij =1-f(e ai e dj )

[0069] The relationship between the safety factor and the system state is expressed as:

[0070]

[0071] The system selects an appropriate action A based on the current state S and the nature of the event, and switches to the next state S′ according to the preset state transition function. By repeating this process at different stages of network attack and defense, the system simulates the continuous game between the attacker and the defender.

[0072] It should also be noted that constructing a five-tuple model of the power cyber-physical system and analyzing its working mechanism improves the ability to identify potential security threats and enhances the accuracy of the system's security risk assessment. By analyzing the working mechanism of the five-tuple model, a scientific basis is provided for the subsequent priority selection of defense resources, thereby improving the effectiveness of the overall defense strategy.

[0073] S2: Construct a defense resource priority selection algorithm.

[0074] Furthermore, the construction of a defense resource priority selection algorithm includes prioritizing based on node state S. i And the impact on the power system, calculate the state weight S w (N i ), represented as:

[0075]

[0076] Where, α k It is node N i In state The influence coefficient is calculated based on the node's authority level in the power system, and the node's importance weight P is determined accordingly. w (N i ), represented as:

[0077] P w (N i )=β·P i

[0078] Where β represents the weighting coefficient, used to measure the impact of permissions on defense strategies.

[0079] It should be noted that constructing the defense resource priority selection algorithm also includes computing node N. i Defense resource cost C i C i Including time cost and resource usage cost, expressed as:

[0080] C i =R i ·T i

[0081] Among them, R i T represents the scarcity of defensive resources. i The time required to respond to defensive measures, taking into account node status, permissions, and resource costs, is used to calculate the node's priority, expressed as:

[0082]

[0083] Nodes with higher priority will receive defense resources first. The allocation ratio of defense resources is calculated based on the node priority and is expressed as follows:

[0084]

[0085] Among them, R alloc (N i ) indicates that it is assigned to node N i The resource ratio is m, where m is the total number of nodes.

[0086] It should also be noted that the construction of a defense resource priority selection algorithm ensures that defense resources are allocated to key nodes first, thereby maintaining the stability of the system. By calculating the cost of defense resources, the efficiency of resource utilization is optimized, unnecessary resource waste is reduced, and resource allocation based on node priority improves the speed and effectiveness of defense measures.

[0087] S3: Use the defensive action execution algorithm.

[0088] Furthermore, the defensive action execution algorithm includes initialization, defining a node set N, a permission set P, a state set S, an event set E, and an action set A based on the power system structure, performing real-time detection, continuously monitoring the network status of the power system, and capturing attack events E in real time. A Perform state assessment, evaluate the state of each node based on the attack events, and update the state S. i Priority calculation is performed according to the formula Priority(N) i Calculate the priority of each node, allocate resources, and assign defense resources R to each node according to the priority. alloc (N i ), Execute defensive actions, and perform defensive actions a on high-priority nodes. i The defense actions include isolation, repair, recovery, status updates, updating the system status S based on the defense effect, and recalculating the priority.

[0089] It should be noted that by using a defense action execution algorithm, the system can continuously monitor the network status and quickly identify attack events. The system can dynamically adjust its defense strategy according to the current security situation. By executing defense actions and updating the status, the system can effectively isolate attacks, fix vulnerabilities, and restore normal operation, thereby improving the system's anti-attack capability and resilience, and thus ensuring the safe and stable operation of the power system.

[0090] Example 2, refer to Figures 2-3This invention provides a method for prioritizing network security defense resources in a power system, as one embodiment of the present invention. To verify the beneficial effects of the invention, scientific demonstration is conducted through economic benefit calculations and simulation experiments.

[0091] First, the IEEE 14-bus grid system was selected as the experimental platform, and the algorithm flow is as follows: Figure 2 As shown, the topology is as follows Figure 3 As shown, the system simulates various network attack scenarios to verify the resource allocation strategy of the algorithm of this invention in dealing with complex attack scenarios. Referring to Table 1, the permissions of each node in the power grid are divided into levels. Nodes with high permissions, such as power plants, affect the stability of the entire system, while substations and user load nodes have lower permissions.

[0092] Table 1. Permission level allocation results for different nodes

[0093] serial number Node type Permission Level Permission value P 1、2、3 Main power station Advanced permissions 3 6、8 Secondary power station Advanced permissions 3 4、5 power transmission station Intermediate permissions 2 9、10、11、12、13、14 Load Node Intermediate permissions 2 7 substation Low-level privileges 1

[0094] Attack scenarios were set up and node status was assessed. Assuming that during system operation, node 4 was subjected to a DDoS attack and nodes 5 and 7 were affected by malware propagation, the status of these nodes was assessed and assigned corresponding status values. The results are shown in Table 2.

[0095] Table 2 Status assessment results of each node

[0096] Node number Node type State value Si Status Description 1、2、3 Main power station 0 normal 6、8 Secondary power station 0 normal 4 power transmission station 1 under DDoS attack 5 power transmission station 2 Malware attack 9、10、11、12、13、14 Load Node 0 normal 7 substation 2 Malware attack

[0097] Priority calculations were performed. Based on the node's status, permissions, and defense resource costs, the priority of each node was calculated using a priority formula. The results are shown in Table 3. The following are the priority calculation results for nodes 4, 5, and 7:

[0098] Table 3 shows the calculation results of the defense priority for each node.

[0099]

[0100] The allocation ratio of defense resources for each node is calculated based on the priority value. Assuming the total defense resources are 100 units, the resource allocation results for each node are shown in Table 4 using the resource priority allocation formula.

[0101] Table 4: Defense resource allocation results for each node

[0102] Node number Priority value (Ni) Resource allocation ratio Ralloc(Ni) 4 1.13 34.38% 5 1.11 35.16% 7 1 30.46%

[0103] Through calculation and allocation, it can be seen that under limited resources, the algorithm prioritizes allocating more resources to severely attacked and critical power generation and transmission nodes by comprehensively considering the node's status, permissions, and resource costs. This ensures that high-priority nodes are quickly protected. The results show that dynamic defense resource allocation can effectively reduce the spread of attacks and ensure that the system can protect high-priority nodes in a timely manner under limited resource conditions. Ultimately, it improves the overall defense effect and recovery speed of the system. The dynamic defense resource priority selection algorithm of this invention has been successfully applied to the IEEE 14-node power grid and its effectiveness in dealing with network attacks has been verified. Through reasonable priority calculation and resource allocation, the power system can effectively resist network attacks and ensure the safe and stable operation of the system.

[0104] Example 3, referring to Figure 4 As an embodiment of the present invention, a power system network security defense resource priority selection system is provided, including a model building module, an algorithm selection module, and an algorithm execution module.

[0105] The model building module is used to build a five-tuple model of the power cyber-physical system and analyze the working mechanism of the five-tuple model; the algorithm selection module is used to build a defense resource priority selection algorithm; and the algorithm execution module is used to execute the algorithm using defense actions.

[0106] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0107] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device.

[0108] More specific examples (a non-exhaustive list) of computer-readable media include: electrical connections (electronic devices) having one or more wires, portable computer disk drives (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which programs can be printed, because programs can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.

[0109] It should be understood that various parts of the present invention can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc. It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

[0110] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

Claims

1. A method for prioritizing network security defense resources in a power system, characterized in that, include: Construct a quintuple model of the power cyber-physical system and analyze the working mechanism of the quintuple model; Construct a defense resource priority selection algorithm; Use the defensive action execution algorithm; The construction of the five-tuple model of the power cyber-physical system includes simulating the interaction between attackers and defenders through the transition rules of a finite state machine. The node set N is represented as follows: N={N g ,N l ,N d ,N s ,N e } Among them, N g N represents a power plant node. l N represents a transmission line node. d N represents the distribution node. s N represents a substation node. e The terminal user node is represented by the permission set P as follows: P = {p1, p2, p3} Where p1 represents a low-privilege node, p2 represents a medium-privilege node, and p3 represents a high-privilege node, the state set S describes the state of the network system at different points in time, represented as: S = {s0, s1, s2, s3} Wherein, s0 represents the normal state, s1 represents the unstable state, s2 represents the slightly abnormal state, and s3 represents the severely abnormal state; The construction of the five-tuple model of the power cyber-physical system also includes an event set E, E A E represents an attack event in the power system. D A defensive event in a power system is represented as: And={And A ,AND D } Among them, E A Including DDoS attacks, malware infections, and data tampering incidents, E D This represents the system's detection, isolation, and remediation defensive actions. The event set contains events occurring in the network, including interactions between attackers and defenders. Each event represents the execution of an attack or defense operation at a single point in time. The occurrence of an event triggers a state transition. When an attack or defense event occurs, the state of the network system changes according to predetermined transition rules. Action set A represents the specific actions taken by the defender in different states, as follows: A = {a1, a2, a3, a4} Here, a1 represents attack detection, a2 represents attack isolation, a3 represents system repair, and a4 represents restoration to normal operation. Each action is a decision made based on the current state and events. The working mechanism of the quintuple model includes determining the risk posed to the system when an attack or defense event E occurs, with the current set of attack behaviors being E. A The security defense strategy set is E D For a single action e ai ∈E A ,e di ∈E D The probability of the resulting risk is expressed as: r ij =f(e ai ,e dj ) Where, f(e) ai ,e dj ) for in e dj Under defensive strategy conditions, attack behavior e ai For the security risk value caused by the system security state s, calculate the system security coefficient, which is expressed as: s ij =1-f(e ai ,e dj ) The relationship between the safety factor and the system state is expressed as: The system will select an appropriate action A based on the current state S and the nature of the event, and switch to the next state S' according to the preset state transition function. By repeating this process at different stages of network attack and defense, the system simulates the continuous game between the attacker and the defender. The algorithm for prioritizing defense resources includes selecting resources based on node status S. i And the impact on the power system, calculate the state weight S w (N i ), represented as: Among them, α k It is node N i In state The influence coefficient is calculated based on the node's authority level in the power system, and the node's importance weight P is determined accordingly. w (N i ), represented as: P w (N i )=β·P i Wherein, β represents the weighting coefficient, which is used to measure the impact of permissions on defense strategies; The algorithm for prioritizing defense resources also includes computing node N. i Defense resource cost C i This includes time cost and resource usage cost, expressed as: C i =R i ·T i Among them, R i T represents the scarcity of defensive resources. i The time required to respond to defensive measures, taking into account node status, permissions, and resource costs, is used to calculate the node's priority, expressed as: Nodes with higher priority will receive defense resources first. The allocation ratio of defense resources is calculated based on the node priority and is expressed as follows: Among them, R alloc (N i ) indicates that it is assigned to node N i The resource ratio, where m is the total number of nodes; The algorithm for executing defensive actions includes initialization, defining a node set N, a permission set P, a state set S, an event set E, and an action set A based on the power system structure, performing real-time detection, continuously monitoring the network status of the power system, and capturing attack events E in real time. A Perform state assessment, evaluate the state of each node based on the attack events, and update the state S. i Priority calculation is performed according to the formula Priority(N) i Calculate the priority of each node, allocate resources, and assign defense resources R to each node according to the priority. alloc (N i ), Execute defensive actions, and perform defensive actions a on high-priority nodes. i The defense actions include isolation, repair, recovery, status updates, updating the system status S based on the defense effect, and recalculating the priority.

2. A system employing the power system network security defense resource priority selection method as described in claim 1, characterized in that: It includes a model building module, an algorithm selection module, and an algorithm execution module; The model building module is used to construct a five-tuple model of the power cyber-physical system and analyze the working mechanism of the five-tuple model. The algorithm selection module is used to construct a defense resource priority selection algorithm; The algorithm execution module is used to execute the algorithm using defensive actions.

3. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the power system network security defense resource priority selection method as described in claim 1.

4. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the power system network security defense resource priority selection method as described in claim 1.

Citation Information

Patent Citations

  • Dynamic game method and device oriented to internet of things threat-defense resource allocation

    CN109639729A

  • Method for transmitting and sharing threat information based on dynamic attack surface

    CN111683057A